hevy-mcp-server
hevy-mcp-server
A complete, open-source single tenant MCP server for Hevy's public API. Every endpoint Hevy exposes is reachable through one of the tools below -- workouts, routines, routine folders, exercise templates (including custom exercises), per-exercise history, and body measurements.
Runs two ways:
Locally over stdio -- for Claude Desktop / Claude Code, zero hosting required.
Remotely over HTTP -- for claude.ai / Cowork connectors, deployable to Fly.io with the included Dockerfile.
View the full product and technical design here.
Tools
12 tools cover all 21 endpoint paths in Hevy's public API (several are consolidated behind one tool via a view/action parameter to avoid near-duplicate tools). Full list with exact endpoint coverage: docs/tools.md.
Read | Write |
|
|
|
|
|
|
|
|
|
|
| |
|
Quick start (local, stdio)
Requires Node.js 20+ and a Hevy Pro subscription. Grab your Hevy API key first.
npx hevy-mcp-serverPoint your MCP client (Claude Desktop, Claude Code, etc.) at it. For Claude Desktop, add to claude_desktop_config.json:
{
"mcpServers": {
"hevy": {
"command": "npx",
"args": ["hevy-mcp-server"],
"env": {
"HEVY_API_KEY": "your-api-key-here",
"HEVY_READ_ONLY": "false"
}
}
}
}Configuration
Env var | Required | Default | Description |
| yes | -- | Your Hevy API key (a UUID from https://hevy.com/settings?developer). Never logged, never echoed in tool output. |
| no |
| When |
| no |
| Override for testing against a mock server. |
HTTP mode (below) needs three more: PORT, PUBLIC_URL, MCP_HTTP_PASSWORD. See .env.example for all of them with descriptions.
Remote (HTTP) deployment on Fly.io
The HTTP transport is gated by OAuth (required for claude.ai/Cowork connector approval). This is single-tenant OAuth: there's no concept of separate user accounts, it just gates access to your instance behind one shared password. See docs/architecture.md for why and how.
Install flyctl and
fly auth login.fly launch --no-deployfrom this directory (it will readfly.toml; rename theappthere first if you want a specific subdomain).Set secrets (never put these in
fly.toml, which is committed to git):fly secrets set HEVY_API_KEY=your-api-key-here fly secrets set MCP_HTTP_PASSWORD=choose-a-strong-passwordEdit
fly.toml'sPUBLIC_URLto match your actual*.fly.devhostname (or custom domain), then:fly deployIn claude.ai / Cowork, add a custom connector pointing at
https://<your-app>.fly.dev/mcp. You'll be redirected to a login page on your own instance -- enterMCP_HTTP_PASSWORDto approve the connection.
Notes:
Single
shared-cpu-1xmachine, no volume. OAuth session state (registered clients, tokens) lives in memory and is lost on redeploy or restart -- you'll just need to reconnect the connector afterwards. Acceptable trade-off for a low-traffic personal instance; see the TDD.fly.toml's[http_service]is configured to stay always-on (not scaled to zero) for exactly that reason -- a stop/start cycle would otherwise force reconnection too.Hevy's docs ask that scheduled/automated syncs avoid firing exactly on the hour -- stagger any cron-style usage by a random minute.
Development
npm install
npm run dev:stdio # run src/stdio.ts directly with tsx
npm run dev:http # run src/http.ts directly with tsx
npm run typecheck
npm run lint # biome check
npm run lint:fix
npm test
npm run build # bundles dist/stdio.js and dist/http.js with tsupSee docs/architecture.md for the repo layout and request-flow details.
Skills
skills/ bundles ready-made agent workflows on top of these tools (workout logging, routine building, progress reviews, etc.) -- see that folder's README for the full index.
License
MIT -- see LICENSE.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/lukendatigh/hevy-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server