Strava MCP
The Strava MCP server connects AI agents to your Strava fitness data locally, keeping OAuth tokens secure on your machine. It provides:
Data Retrieval: Access athlete profiles, heart rate/power zones, aggregate stats, activities (runs, rides, swims, workouts, splits), per-second activity streams (heart rate, power, cadence, altitude, time, distance), routes (geometry redacted by default), clubs, and gear details.
Training Summaries & Context: Generates daily and weekly training summaries including load, intensity, sport mix, and bottlenecks. Provides normalized training context for workout recommendation engines.
Privacy Controls: GPS coordinates and route geometry are redacted by default; opt-in modes for full data (raw or include_gps). Three privacy modes: summary (most redacted), structured (default), raw. Tokens are never returned and never leave your machine; read-only by design.
Setup & Diagnostics: OAuth setup with authorization URL generation, token exchange, and revocation. Connection status checks, quickstart guides, privacy audits, and cache status tools.
AI Agent Integration: Built for MCP-compatible agents, offering capabilities, data inventory, and agent manifest for seamless integration.
Demo & Testing: strava_demo returns realistic synthetic payloads to test workflows without real API calls.
Wellness Profile: Read and update a shared wellness profile (goals, devices, preferences) for cross-connector integration.
Provides tools for accessing Strava activities, routes, streams, and training context, enabling AI agents to retrieve and analyze fitness data from a Strava account.
⚡ One-command install with Delx Wellness for Hermes:
npx -y delx-wellness-hermes setup— preconfigures this connector and the other 8 in a dedicated Hermes profile.Or wire it standalone into Claude Desktop / Cursor / ChatGPT Desktop — see the install section below.
HTTP (v2 stateless)
Default is stdio. Optional Streamable HTTP — no session id, JSON responses, loopback only:
npx -y strava-mcp-unofficial --http
# GET http://127.0.0.1:3000/health
# POST http://127.0.0.1:3000/mcp (sessionless)Env: STRAVA_MCP_HOST, STRAVA_MCP_PORT, STRAVA_MCP_TRANSPORT=http.
Local-first MCP server that connects AI agents to your Strava activities, routes, streams and training context.
Unofficial project. Not affiliated with, endorsed by or supported by Strava, Inc. Strava is a trademark of its respective owner. Use this only with your own Strava account and in line with Strava's API agreement.
Built by David Mosiah for people who use Claude, Cursor, Hermes, OpenClaw or other MCP-compatible agents to think about training, endurance and performance — without copy-pasting numbers from Strava.
Part of Delx Wellness, a registry of local-first wellness MCP connectors.
If this connector helps your agent workflow, please star the repo. Stars make the project easier for other AI builders to discover and help Delx keep shipping local-first wellness infrastructure.
Related MCP server: Strava Planner MCP
Why this exists
Strava holds the long memory of your training — every ride, run, swim, segment, route and stream. But it lives behind an OAuth API with strict rate limits (200 req/15min, 2k/day per app) and GPS data that's privacy-sensitive by default.
This package does the OAuth dance locally, throttles under Strava's per-app limits, redacts GPS lat/lng unless you explicitly opt in, and exposes Strava through the Model Context Protocol. Any MCP-compatible agent gets your training context with one config snippet. Tokens never leave your machine.
Quickstart
From zero to your first agent call in about a minute. You only need a Strava app (create one here) with redirect URI http://127.0.0.1:3000/callback.
1. Paste your app's client id + secret (interactive, stored at ~/.strava-mcp/config.json with 0600):
npx -y strava-mcp-unofficial setup2. Authorize Strava. auth opens your browser; --no-open prints the URL so you can paste it yourself (handy on a headless box). Tokens are saved locally — the command never prints them:
$ npx -y strava-mcp-unofficial auth --no-open
Strava MCP · Authorization
Open this URL manually:
https://www.strava.com/oauth/authorize?client_id=12345&redirect_uri=http%3A%2F%2F127.0.0.1%3A3000%2Fcallback&response_type=code&approval_prompt=auto&scope=read%2Cactivity%3Aread_all%2Cprofile%3Aread_all&state=aa38f29b
Steps
1. Approve access in the browser tab that opens.
2. Strava will redirect to the local callback.
3. Tokens are saved locally; this command never prints them.
Waiting for callback...3. Verify you're ready — doctor confirms scopes and setup without calling Strava:
$ npx -y strava-mcp-unofficial doctor
Strava MCP · Doctor
Status: READY ✓
Checks
✓ Node.js >=20
✓ Env vars
✓ Local config
✓ Automatic auth redirect
✓ Token file
✓ Token permissions
✓ Refresh token
✓ OAuth scopes
· Privacy mode
· Cache
Next steps
1. Ready. Add this MCP server to your agent and start with strava_daily_summary.If OAuth scopes shows a ✗, re-run auth and approve activity:read_all profile:read_all read.
4. Make a first call — no live account required. Ask your agent to run strava_demo. It returns realistic, synthetic payloads (tagged is_demo: true) so you can wire prompts before connecting real data:
> Call strava_demo and summarize my week.
# Strava Demo
- **is_demo**: true
- **recent_sessions**: 3
- **load_classification**: moderate
- **primary_signal**: Recent Strava load is manageable; use intent and consistency as the main lever.
- **recommended_handoff**: exercise_catalog_recommend_sessionCall it with response_format: "json" for the full shapes. The sample block mirrors strava_daily_summary, strava_training_context and strava_list_activities key-for-key — npm run test:demo-contract runs the real builders over fixtures/strava-activities.mjs and fails the build if the demo ever invents a field or omits one. Swap strava_demo for the real tool and the same shape arrives filled with your Strava data.
5. Wire it into your MCP client:
{
"mcpServers": {
"strava": {
"command": "npx",
"args": ["-y", "strava-mcp-unofficial"]
}
}
}For Claude Desktop, run setup --client claude and the snippet is written for you. For Hermes, see Hermes / remote setup below.
Try it with your agent
Three things to ask first:
Use strava_connection_status to check setup, then run strava_daily_summary.
Tell me what my training context looks like in 5 lines.Call strava_weekly_summary with response_format=json. Find my biggest
load/intensity bottleneck and give me a next-week endurance plan.Use the strava_activity_stream_investigator prompt for activity_id=<id>.
Don't expose GPS unless I explicitly ask for it.Data availability
This package uses the official Strava API v3. When this README says raw, it means the upstream Strava JSON for a supported endpoint — not continuous device telemetry.
Data | Available | Notes |
Activities (runs, rides, swims, walks, workouts) | ✓ | All recorded activities |
Activity details + zones + splits | ✓ | HR, power, cadence, elevation, gear |
Activity streams (HR / cadence / watts / altitude) | ✓ | Per-second samples for the activity |
GPS lat/lng streams | opt-in | Hidden by default; requires |
Athlete profile + zones + aggregate stats | ✓ | Authenticated athlete |
Routes + clubs + gear | ✓ | Route geometry redacted in summary/structured modes |
Live device telemetry / continuous HR | — | Not exposed by Strava's public API |
Tools
Start with these:
strava_connection_status— verify local setup, scopes and readiness before calling Stravastrava_data_inventory— inventory supported data domains, scopes, privacy modes and recommended first calls without calling Strava APIs.strava_daily_summary— latest activity, weekly load and intensity context for todaystrava_weekly_summary— scorecard, comparison vs prior week, next-week training plan
Auth & diagnostics
strava_capabilities,strava_agent_manifest,strava_privacy_audit,strava_cache_statusstrava_get_auth_url,strava_exchange_code,strava_revoke_access
Athlete & training
strava_get_athlete,strava_get_zones,strava_get_athlete_stats
Activities & streams
strava_list_activities,strava_get_activity,strava_get_activity_zonesstrava_activity_series,strava_get_activity_streams— GPS lat/lng requiresinclude_gps=trueorrawmode
Routes & context
strava_list_routes,strava_get_route,strava_list_clubs,strava_get_gear
Prompts
strava_daily_training_director— practical daily training briefstrava_weekly_endurance_review— week comparison + next-week endurance planstrava_activity_stream_investigator— investigate one activity using streams (GPS-aware)
Each accepts timezone (IANA, default UTC).
Resources
strava://capabilities,strava://agent-manifeststrava://athletestrava://latest/activitystrava://summary/daily,strava://summary/weekly
Privacy & security
OAuth tokens are stored in
~/.strava-mcp/tokens.jsonwith0600permissions and are never returned by tools.Write/upload scopes are not requested by default — read-only by design.
GPS lat/lng and route geometry are recursively removed in
summaryandstructuredmodes, and only included with explicitinclude_gps=truefor stream calls orrawmode.Structured mode otherwise preserves complete upstream physiological records and future Strava fields.
Activity
after/beforefilters retain instant semantics when converted from timezone-aware ISO date-times to Strava epoch seconds; invalid ranges fail before HTTP.Route geometry is also redacted unless raw mode is explicitly requested.
The MCP client never sees access or refresh tokens.
This is not medical advice. The server exposes user-authorized data for personal AI workflows, not diagnosis or training prescription.
Configuration
setup writes most of these into ~/.strava-mcp/config.json (0600). Manual env override is supported:
STRAVA_CLIENT_ID=…
STRAVA_CLIENT_SECRET=…
STRAVA_REDIRECT_URI=http://127.0.0.1:3000/callback
# Optional
STRAVA_SCOPES="read activity:read_all profile:read_all"
STRAVA_PRIVACY_MODE=structured # summary | structured | raw
STRAVA_CACHE=sqlite # optional read-through cacheHermes / remote setup
npx -y strava-mcp-unofficial setup --client hermes --no-auth
npx -y strava-mcp-unofficial auth # run locally if browser auth is needed
npx -y strava-mcp-unofficial doctor --client hermes
hermes mcp test stravaHermes commonly exposes Strava tools with a prefix:
mcp_strava_strava_agent_manifestmcp_strava_strava_connection_statusmcp_strava_strava_daily_summarymcp_strava_strava_weekly_summarymcp_strava_strava_get_activity_streams
After Hermes config changes, use /reload-mcp or hermes mcp test strava. Don't restart the gateway for normal data access.
If browser OAuth has to happen on a different machine than Hermes, run auth locally and copy ~/.strava-mcp/tokens.json to the server with chmod 600. The token must include activity:read_all profile:read_all read for activity history and streams.
Requirements
Node.js 20+
A Strava app with redirect URI
http://127.0.0.1:3000/callback
Why these scopes:
read— public profile, routes and public Strava resourcesactivity:read_all— your activities, including private activities visible to your appprofile:read_all— fuller authenticated athlete profile fields
No write scope is requested by default.
Development
git clone https://github.com/davidmosiah/strava-mcp.git
cd strava-mcp
npm install
npm test
npm run buildTest with MCP Inspector:
npx @modelcontextprotocol/inspector node dist/index.jsLinks
Docs site: https://wellness.delx.ai/connectors/strava
Legacy docs: https://stravamcp.vercel.app/
GitHub Pages mirror: https://davidmosiah.github.io/strava-mcp/
Delx Wellness registry: https://github.com/davidmosiah/delx-wellness
Connector quality standard: https://github.com/davidmosiah/delx-wellness/blob/main/docs/connector-quality-standard.md
Strava API docs: https://developers.strava.com/docs/reference/
Strava auth docs: https://developers.strava.com/docs/authentication/
See also
The full Delx Wellness connector library:
Provider | Package | Repo |
WHOOP | ||
Oura | ||
Garmin | ||
Strava | ||
Fitbit | ||
Withings | ||
Apple Health | ||
Polar | ||
Nourish (nutrition) |
One-command setup for Hermes — preconfigures every connector above plus wellness skills + onboarding: delx-wellness-hermes.
📧 Contact & Support
📨 support@delx.ai — general questions, integration help, partnerships
🐛 Bug reports / feature requests — GitHub Issues
🐦 Updates — @delx369 on X
🌐 Site — wellness.delx.ai
License
MIT — see LICENSE.
Disclaimer
This software is provided as-is. It is not a medical device, does not provide medical advice, and should not be used for diagnosis, treatment or training prescription. Always consult qualified professionals for medical or training concerns.
Maintenance
Related MCP Servers
- Flicense-qualityBmaintenanceA multi-platform fitness MCP server that syncs data from Garmin, Strava, Google Fit, and Suunto into a local DuckDB database and provides analytics tools via MCP.1
- FlicenseAqualityCmaintenanceExposes Strava training data to Claude for coaching, planning, and analysis via a read-only MCP server with OAuth and Docker support.13
- Alicense-qualityCmaintenanceAn open-source, Strava-first remote MCP server that enables users to authorize with Strava and ask AI about their training data.MIT
- Alicense-qualityAmaintenanceAn MCP server that supplements the official Strava connector with write access, segments, routes, photos, derived analysis, and interactive visualizations.21MIT
Related MCP Connectors
MCP server for Withings health data — sleep, activity, heart, and body metrics.
Streamable HTTP MCP server for Google Calendar and Sheets with OAuth login.
MCP server wrapping the Tesla Fleet API and TeslaMate API
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/davidmosiah/strava-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server