{
  "markdown": "<!-- delx-wellness header v2 -->\n<h1 align=\"center\">Withings MCP</h1>\n\n<div align=\"center\">\n  <img src=\"assets/banner.png\" alt=\"Withings MCP — Withings MCP for AI agents\" width=\"85%\" />\n</div>\n\n<h3 align=\"center\">\n  Give your AI agent your Withings body measures, sleep, activity and heart data &mdash; locally.<br>\n  Local-first MCP server &mdash; <strong>tokens never leave your machine</strong>.\n</h3>\n\n<p align=\"center\">\n  <a href=\"https://www.npmjs.com/package/withings-mcp-unofficial\"><img src=\"https://img.shields.io/npm/v/withings-mcp-unofficial?style=for-the-badge&labelColor=0F172A&color=10B981&logo=npm&logoColor=white\" alt=\"npm version\" /></a>\n  <a href=\"https://github.com/davidmosiah/withings-mcp/releases/latest\"><img src=\"https://img.shields.io/github/v/release/davidmosiah/withings-mcp?style=for-the-badge&labelColor=0F172A&color=2563EB&logo=github\" alt=\"GitHub release\" /></a>\n  <a href=\"https://www.npmjs.com/package/withings-mcp-unofficial\"><img src=\"https://img.shields.io/npm/dm/withings-mcp-unofficial?style=for-the-badge&labelColor=0F172A&color=0EA5A3&logo=npm&logoColor=white\" alt=\"npm downloads\" /></a>\n  <a href=\"LICENSE\"><img src=\"https://img.shields.io/badge/LICENSE-MIT-22C55E?style=for-the-badge&labelColor=0F172A\" alt=\"License MIT\" /></a>\n  <a href=\"https://wellness.delx.ai/connectors/withings\"><img src=\"https://img.shields.io/badge/SITE-wellness.delx.ai-0EA5A3?style=for-the-badge&labelColor=0F172A\" alt=\"Site\" /></a>\n</p>\n\n<p align=\"center\">\n  <a href=\"https://github.com/davidmosiah/withings-mcp/stargazers\"><img src=\"https://img.shields.io/github/stars/davidmosiah/withings-mcp?style=for-the-badge&labelColor=0F172A&color=FBBF24&logo=github\" alt=\"GitHub stars\" /></a>\n  <a href=\"https://modelcontextprotocol.io\"><img src=\"https://img.shields.io/badge/BUILT_FOR-MCP-7C3AED?style=for-the-badge&labelColor=0F172A\" alt=\"Built for MCP\" /></a>\n  <a href=\"https://github.com/davidmosiah/delx-wellness/blob/main/docs/release-index.md\"><img src=\"https://img.shields.io/badge/VERIFIED-release_index-0EA5A3?style=for-the-badge&labelColor=0F172A\" alt=\"Verified release index\" /></a>\n  <a href=\"https://github.com/davidmosiah/delx-wellness-hermes\"><img src=\"https://img.shields.io/badge/HERMES-one--command_setup-10B981?style=for-the-badge&labelColor=0F172A\" alt=\"Hermes one-command setup\" /></a>\n  <a href=\"https://github.com/davidmosiah/delx-wellness\"><img src=\"https://img.shields.io/badge/Withings-00B6DE?style=for-the-badge&labelColor=0F172A&logoColor=white\" alt=\"Withings\" /></a>\n</p>\n\n> ⚡ **One-command install** with [Delx Wellness for Hermes](https://github.com/davidmosiah/delx-wellness-hermes):\n> `npx -y delx-wellness-hermes setup` &mdash; preconfigures this connector and the other 8 in a dedicated Hermes profile.\n>\n> Or wire it standalone into Claude Desktop / Cursor / ChatGPT Desktop &mdash; see the install section below.\n\n---\n\n## HTTP (v2 stateless)\n\nDefault is **stdio**. Optional Streamable HTTP — no session id, JSON responses, loopback only:\n\n```bash\nnpx -y withings-mcp-unofficial --http\n# GET  http://127.0.0.1:3000/health\n# POST http://127.0.0.1:3000/mcp   (sessionless)\n```\n\nEnv: `WITHINGS_MCP_HOST`, `WITHINGS_MCP_PORT`, `WITHINGS_MCP_TRANSPORT=http`.\n\n\n<!-- /delx-wellness header v2 -->\n\n**Local-first MCP server that connects AI agents to your Withings body, sleep, activity and heart data.**\n\n> **Unofficial project.** Not affiliated with, endorsed by or supported by Withings. Withings is a trademark of its respective owner. Use this only with your own Withings account and in line with the Withings Public API terms.\n\nBuilt by [David Mosiah](https://github.com/davidmosiah) for people who use Claude, Cursor, Hermes, OpenClaw or other MCP-compatible agents to think about body composition, sleep and long-term health trends — without copy-pasting numbers from the Withings app.\n\nPart of [Delx Wellness](https://github.com/davidmosiah/delx-wellness), a registry of local-first wellness MCP connectors.\n\n> If this connector helps your agent workflow, please star the repo. Stars make the project easier for other AI builders to discover and help Delx keep shipping local-first wellness infrastructure.\n\n## Why this exists\n\nWithings has the longest-running consumer body-composition and sleep ecosystem (smart scales, Sleep Analyzer, ScanWatch). The data is rich — punctual weight + body fat + muscle mass measurements, sleep stages, ECG-grade heart records — but the Withings Public API uses a signed-token OAuth flow that's heavier than most consumer APIs.\n\nThis package handles the signed OAuth dance locally, normalizes responses, and exposes Withings through the Model Context Protocol. Tokens never leave your machine. Privacy-mode defaults keep raw payloads opt-in.\n\n## Setup in 60 seconds\n\nYou'll need a Withings app ([create one here](https://account.withings.com/partner/dashboard_oauth2)) with redirect URI `http://127.0.0.1:3000/callback`.\n\n```bash\nnpx -y withings-mcp-unofficial setup    # interactive: paste client id + secret\nnpx -y withings-mcp-unofficial auth     # opens browser, captures the OAuth code\nnpx -y withings-mcp-unofficial doctor   # verifies you're ready\n```\n\nRecommended scopes:\n\n```text\nuser.activity user.metrics\n```\n\nThen add this to your MCP client config:\n\n```json\n{\n  \"mcpServers\": {\n    \"withings\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"withings-mcp-unofficial\"]\n    }\n  }\n}\n```\n\nFor Claude Desktop, run `setup --client claude` and the snippet is written for you.\n\n> **Note:** Withings OAuth authorization codes are short-lived (a few minutes). Don't pause between approving the consent screen and `withings_exchange_code` running.\n\n## Try it with your agent\n\nThree things to ask first:\n\n```text\nUse withings_connection_status to check setup, then run withings_daily_summary.\nGive me a 5-line wellness brief for today.\n```\n\n```text\nCall withings_weekly_summary with response_format=json. Identify my biggest\nsleep/body bottleneck and give me a next-week plan.\n```\n\n```text\nUse the withings_body_sleep_investigation prompt, after=2026-04-01.\nWalk me through what changed in body composition + sleep.\n```\n\n## Data availability\n\nThis package uses the official Withings Public API. When this README says `raw`, it means the upstream Withings JSON for a supported endpoint — not raw device sensor streams.\n\n| Data | Available | Notes |\n|---|:---:|---|\n| Body measures (weight, fat %, muscle, bone, water) | ✓ | Requires `user.metrics` scope |\n| Daily activity (steps, calories, distance, intensity) | ✓ | Requires `user.activity` scope |\n| Workouts + sport metadata | ✓ | Requires `user.activity` scope |\n| Sleep summaries (duration, stages, efficiency, HR) | ✓ | Requires `user.activity` scope |\n| Sleep detail records | ✓ | When the device exposes them |\n| Heart records (ECG, BP, etc.) | ✓ | Requires `user.metrics` scope; varies by device/plan |\n| Continuous sensor telemetry | — | Not exposed by Withings Public API |\n\n## Tools\n\n**Start with these:**\n\n- `withings_connection_status` — verify local setup before calling Withings\n- `withings_data_inventory` — inventory supported data domains, scopes, privacy modes and recommended first calls without calling Withings APIs.\n- `withings_daily_summary` — body, sleep, activity and heart brief for today\n- `withings_weekly_summary` — scorecard, comparison vs prior week, next-week plan\n\n**Auth & diagnostics**\n\n- `withings_capabilities`, `withings_agent_manifest`, `withings_privacy_audit`, `withings_cache_status`\n- `withings_get_auth_url`, `withings_exchange_code`, `withings_revoke_access`\n\n**Body & metrics**\n\n- `withings_list_body_measures` — punctual weight/composition records. Use `after` / `before` as `YYYY-MM-DD` or ISO 8601 for large histories; the server sends Withings `startdate` / `enddate` (Unix seconds) upstream and caps returned records with `limit`.\n- Date filters are action-aware: `getactivity` / `getworkouts` / sleep `getsummary` send civil `startdateymd` / `enddateymd`; `getmeas`, sleep detail, and heart list keep epoch `startdate` / `enddate`. Offset ISO instants keep their exact epoch conversion on epoch-style actions.\n- `withings_list_heart` — heart records when device/plan permit\n\n**Activity**\n\n- `withings_list_activity` — daily activity summaries\n- `withings_list_workouts` — logged workouts\n\n**Sleep**\n\n- `withings_list_sleep_summary` — daily sleep summaries with HR/stage fields\n- `withings_list_sleep` — detailed sleep records\n\n## Prompts\n\n- `withings_daily_checkin` — practical daily health and body check-in\n- `withings_weekly_review` — review trends across body, sleep, activity\n- `withings_body_sleep_investigation` — investigate body measures + sleep together\n\n## Resources\n\n- `withings://capabilities`, `withings://agent-manifest`\n- `withings://latest/activity`, `withings://latest/sleep`\n- `withings://summary/daily`, `withings://summary/weekly`\n\n## Privacy & security\n\n- OAuth tokens are stored in `~/.withings-mcp/tokens.json` with `0600` permissions and are never returned by tools.\n- Withings uses a signed-request OAuth flow — the package handles signing locally; client secrets never reach the MCP client.\n- The server never prints access or refresh tokens.\n- `WITHINGS_PRIVACY_MODE` defaults to `structured`. Raw Withings JSON is opt-in via `raw` mode or per-call override.\n- Structured mode preserves complete upstream physiological fields, including future Withings additions, while removing GPS and secret-bearing values.\n- `withings_revoke_access` clears local tokens; full account-side token revocation depends on your Withings plan.\n- The MCP client never sees access or refresh tokens.\n- This is **not medical advice**. Withings exposes data that may resemble medical signals (ECG, blood pressure) but this server is for personal AI workflows, not diagnosis or treatment.\n\n## Configuration\n\n`setup` writes most of these into `~/.withings-mcp/config.json` (`0600`). Manual env override is supported:\n\n```bash\nWITHINGS_CLIENT_ID=…\nWITHINGS_CLIENT_SECRET=…\nWITHINGS_REDIRECT_URI=http://127.0.0.1:3000/callback\n\n# Optional\nWITHINGS_SCOPES=\"user.activity user.metrics\"\nWITHINGS_PRIVACY_MODE=structured        # summary | structured | raw\nWITHINGS_CACHE=sqlite                   # optional read-through cache\nWITHINGS_TOKEN_PATH=~/.withings-mcp/tokens.json\nWITHINGS_CACHE_PATH=~/.withings-mcp/cache.sqlite\n```\n\n## Hermes / remote setup\n\n```bash\nnpx -y withings-mcp-unofficial setup --client hermes --no-auth\nnpx -y withings-mcp-unofficial auth                      # run locally if browser auth is needed\nnpx -y withings-mcp-unofficial doctor --client hermes\nhermes mcp test withings\n```\n\nAfter Hermes config changes, use `/reload-mcp` or `hermes mcp test withings`. Don't restart the gateway for normal data access.\n\nIf browser OAuth has to happen on a different machine than Hermes, run `auth` locally and copy `~/.withings-mcp/tokens.json` to the server with `chmod 600`.\n\n## Requirements\n\n- Node.js 20+\n- A Withings app at <https://account.withings.com/partner/dashboard_oauth2> with redirect URI `http://127.0.0.1:3000/callback`\n\n## Development\n\n```bash\ngit clone https://github.com/davidmosiah/withings-mcp.git\ncd withings-mcp\nnpm install\nnpm test\nnpm run build\n```\n\nTest with MCP Inspector:\n\n```bash\nnpx @modelcontextprotocol/inspector node dist/index.js\n```\n\n## Links\n\n- npm: <https://www.npmjs.com/package/withings-mcp-unofficial>\n- Docs site: <https://wellness.delx.ai/connectors/withings>\n- Legacy docs: <https://withingsmcp.vercel.app/>\n- GitHub: <https://github.com/davidmosiah/withings-mcp>\n- Delx Wellness registry: <https://github.com/davidmosiah/delx-wellness>\n- Connector quality standard: <https://github.com/davidmosiah/delx-wellness/blob/main/docs/connector-quality-standard.md>\n- Withings Public API docs: <https://developer.withings.com/api-reference/>\n\n<!-- delx-wellness see-also -->\n\n## See also\n\nThe full [Delx Wellness](https://wellness.delx.ai) connector library:\n\n| Provider | Package | Repo |\n|---|---|---|\n| WHOOP | [`whoop-mcp-unofficial`](https://www.npmjs.com/package/whoop-mcp-unofficial) | [whoop-mcp](https://github.com/davidmosiah/whoop-mcp) |\n| Oura | [`oura-mcp-unofficial`](https://www.npmjs.com/package/oura-mcp-unofficial) | [ouramcp](https://github.com/davidmosiah/ouramcp) |\n| Garmin | [`garmin-mcp-unofficial`](https://www.npmjs.com/package/garmin-mcp-unofficial) | [garminmcp](https://github.com/davidmosiah/garminmcp) |\n| Strava | [`strava-mcp-unofficial`](https://www.npmjs.com/package/strava-mcp-unofficial) | [strava-mcp](https://github.com/davidmosiah/strava-mcp) |\n| Fitbit | [`fitbit-mcp-unofficial`](https://www.npmjs.com/package/fitbit-mcp-unofficial) | [fitbitmcp](https://github.com/davidmosiah/fitbitmcp) |\n| Withings | [`withings-mcp-unofficial`](https://www.npmjs.com/package/withings-mcp-unofficial) | [withings-mcp](https://github.com/davidmosiah/withings-mcp) |\n| Apple Health | [`apple-health-mcp-unofficial`](https://www.npmjs.com/package/apple-health-mcp-unofficial) | [apple-health-mcp](https://github.com/davidmosiah/apple-health-mcp) |\n| Polar | [`polar-mcp-unofficial`](https://www.npmjs.com/package/polar-mcp-unofficial) | [polarmcp](https://github.com/davidmosiah/polarmcp) |\n| Nourish (nutrition) | [`wellness-nourish`](https://www.npmjs.com/package/wellness-nourish) | [wellness-nourish](https://github.com/davidmosiah/wellness-nourish) |\n\n**One-command setup for Hermes** — preconfigures every connector above plus wellness skills + onboarding: [`delx-wellness-hermes`](https://github.com/davidmosiah/delx-wellness-hermes).\n\n<!-- /delx-wellness see-also -->\n\n## 📧 Contact & Support\n\n- 📨 **support@delx.ai** — general questions, integration help, partnerships\n- 🐛 **Bug reports / feature requests** — [GitHub Issues](https://github.com/davidmosiah/withings-mcp/issues)\n- 🐦 **Updates** — [@delx369](https://x.com/delx369) on X\n- 🌐 **Site** — [wellness.delx.ai](https://wellness.delx.ai)\n\n\n## License\n\nMIT — see [LICENSE](LICENSE).\n\n## Disclaimer\n\nThis software is provided as-is. It is not a medical device, does not provide medical advice, and should not be used for diagnosis or treatment. Withings exposes data that may resemble medical signals (ECG, blood pressure, body composition) — always consult qualified professionals for medical concerns.\n\n## Skill or MCP\n\nSame package, two doors. MCP registers tools on stdio/HTTP. The [skill](skill/SKILL.md) can drive the **same** tools through the CLI when the client has no MCP:\n\n```bash\nnpx -y withings-mcp-unofficial call withings_connection_status --json '{}'\n```\n\nCopy `skill/SKILL.md` into your agent skills dir.\n",
  "bytes": 14555,
  "sha": "2e14c224f06c5027b363e05208af1de761ecb1096d4c2bb8a8227f04d37dab17",
  "repo_slug": "davidmosiah/withings-mcp",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_io_github_davidmosiah_withingsmcp_6c5efdbd/readme"
}