FitTrack MCP
README.md
# FitTrack MCP
A read-only MCP server built with XMCP, Supabase Auth, and HTTP transport.
## Tool
`get-fittrack-info` returns a fixed payload containing the app name, service
status, and sample tracking categories. It does not require authentication and
does not read or write external data.
`get-recent-weight-entries` is a protected, read-only tool that selects the
authenticated user's records from `public.fittrack_weight` using a month, an
exact date, an exact weight in kilograms, or a combination of date and weight.
When both inputs are omitted, it defaults to the current UTC month. It refuses
requests without a verified Supabase OAuth bearer token and relies on Supabase
RLS to enforce `auth.uid() = user_id`.
Results can be sorted by `date` or `weight`, ascending or descending. Without
sorting inputs, the query defaults to `created_at` descending.
`get-recent-waist-entries` applies the same protected, read-only filtering and
sorting behavior to `public.fittrack_waist`. It accepts a month or exact date,
an exact waist measurement in centimeters, and optional sorting by `date` or
`waist`. Without sorting inputs, it defaults to `created_at` descending.
`get-recent-meal-entries` is a protected, read-only tool for
`public.fittrack_meals`. It accepts a month or exact date and a
case-insensitive food-description fragment, and returns each meal's calorie,
protein, and carbohydrate values. When both inputs are omitted, it defaults to
the current UTC month with `created_at` descending.
`add-meal-entry` is a protected write tool for `public.fittrack_meals`. It
accepts a meal description, calories, protein, carbohydrates, and an ISO 8601
timestamp with a timezone, then inserts the entry for the authenticated user.
`get-recent-gym-sessions` is a protected, read-only tool for
`public.fittrack_gym_sessions`. It returns up to ten sessions ordered by newest
date and accepts an optional month, exact date, or case-insensitive partial
exercise/session name. Results include duration, detailed workout notes, start
and end times, and creation and update timestamps.
`get-recent-extra-activities` is a protected, read-only tool for
`public.fittrack_extra_activities`. It returns up to ten activities ordered by
newest date and accepts an optional month, exact date, or case-insensitive
partial activity name. Results include intensity, duration in minutes, notes,
time, calories, and creation and update timestamps.
`get-todays-fittrack-summary` is a protected, read-only, zero-input tool that
returns all records dated today in UTC from the five exposed tracking tables:
meals, gym sessions, extra activities, weight, and waist. Each category is
returned as an array, including when no records exist for that category.
The server publishes OAuth Protected Resource Metadata at
`/.well-known/oauth-protected-resource`. Supabase Auth is the OAuth 2.1
authorization server, while the MCP server remains the resource server.
## Requirements
- Node.js 20 or newer
- npm
## Local development
```bash
npm install
npm run dev
```
The MCP endpoint is available at `http://localhost:3001/mcp`.
## Supabase connectivity safety test
Copy `.env.example` to `.env.local` and provide the project URL, an
`sb_publishable_...` key, and the canonical MCP endpoint URL. Never use a
secret or service-role key.
```bash
npm run test:db-read
```
The test performs an anonymous, read-only request against
`public.fittrack_weight` without returning row data. It passes only when RLS
hides every row from the anonymous role.
## Authentication
Configure Supabase Auth with:
- OAuth 2.1 Server enabled
- Dynamic OAuth application registration enabled
- Site URL `https://fittrack.taimoorahmed.com`
- Authorization path `/oauth/consent`
The web application owns the consent page. The MCP server verifies supplied
access tokens through Supabase Auth before passing them to the read-only
database client. Only OAuth-issued tokens containing a `client_id` are accepted.
Set the production resource URL to the exact endpoint used by MCP clients:
```text
MCP_RESOURCE_URL=https://fittrackmcp.vercel.app/mcp
```
## Build
```bash
npm run build
npm start
```
## Deploy to Vercel
Import this Git repository into Vercel or run:
```bash
vercel deploy
```
After deployment, the public endpoint is `https://<deployment>.vercel.app/mcp`.
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessNo issues