Health Auto Export now advertises "the integrated MCP Server" in its App Store listing. The claim is accurate. The interesting part is the architecture it describes, because "has MCP" is not a single checkbox.
Per the vendor's own help pages, that server runs on the iPhone. AI clients on your local network connect to an endpoint like http://{LAN_IP}:9000/mcp over HTTP (Streamable MCP is the recommended transport) with a bearer token, or over TCP for Node-bridge setups. The same help page adds the constraint: the iPhone app must stay in the foreground while clients are connected. Nothing leaves your network, but the agent can only reach the data while the app is open, the phone is awake, and both are on the same Wi-Fi.
A zero-dependency local stdio server is the opposite shape. It is a plain Node program the agent launches over standard input and output. No socket, no port, no bearer token on your Wi-Fi. The iOS app writes a small JSON snapshot to a destination you choose; pick iCloud Drive and the OS syncs it to your Mac. The server reads that folder, so it works whether or not the phone is awake. The trade is that a snapshot is a snapshot, so it reports staleness: get_freshness flags the export after 26 hours by default and returns age_hours, as_of and last_data_date, so the agent can say "this is a day old" instead of quietly answering from yesterday. The server ships 16 read-only tools, MIT licensed.
There is also a correctness difference worth knowing. An open issue on the incumbent, #56, describes an app that backfills historical samples stamping them with a recent HealthKit write time, so a snapshot built on "changes since last sync" never recomputes those past days. MetricBridge's 1.10 release recomputes the day a backfilled sample belongs to.
How to check any app's MCP claim in five minutes, without the marketing: where does the server run (phone or computer), how does the agent reach it (network endpoint or local process), and what happens when the phone is locked or backgrounded. If the answer to the third is "it has to be open," that is your real-world failure mode.
Full teardown, with the quoted help-page text and the three-question test, here: https://www.healthexport.dev/blog/health-auto-export-integrated-mcp-vs-local-server?utm_source=devto&utm_medium=social&utm_campaign=exp-20261007-hea189-integratedmcp
Top comments (0)