Skip to main content
Glama
borgels

mcp-server-withings

by borgels

mcp-server-withings

MCP server for the Withings Health API with per-user OAuth2 — each user links their own Withings account and can only ever see their own health data.

How isolation works

Behind an authenticating gateway that forwards the signed-in user as X-MCP-User, every tool is bound to that user. The server keeps an AES-256-GCM encrypted, per-user token store; a user's identity resolves only to their own row. Without a verified identity the server fails closed (no anonymous/shared access). Each user enrolls once via withings_connect, which returns a single-use Withings authorization URL bound to them; after they approve in the browser, /withings/callback stores their (encrypted) tokens.

Related MCP server: fitbit-mcp

Tools

Auth/enrollment: withings_connect, withings_status, withings_disconnect. Read: withings_get_measures, withings_get_activity, withings_get_sleep, withings_get_workouts, withings_get_heart, withings_get_devices, withings_get_goals, withings_search_capabilities. Write (opt-in WITHINGS_ENABLE_WRITES=true): withings_add_measure.

Configuration

See .env.example. Register a Withings app at account.withings.com; the redirect URI must match WITHINGS_REDIRECT_URI exactly and be publicly reachable (route /withings/callback to this container). Set WITHINGS_ENCRYPTION_KEY (never commit) and WITHINGS_TRUST_FORWARDED_USER=true behind the gateway.

Run

npm install
npm run dev:http     # /mcp + /withings/callback on :3000
npm test

Docker images: ghcr.io/borgels/mcp-server-withings.

Install Server
A
license - permissive license
A
quality
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

View all related MCP servers

Related MCP Connectors

  • MCP server for Withings health data — sleep, activity, heart, and body metrics.

  • Self-hosted federated MCP gateway: one OAuth 2.1 MCP server in front of N apps, user-level scopes.

  • Wger MCP — wraps wger Workout Manager REST API (free, no auth for read)

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/borgels/mcp-server-withings'

If you have feedback or need assistance with the MCP directory API, please join our Discord server