WithingsCAUTION
MCP server for Withings health data integration
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[Help me pay for the servers on Patreon][patreon]
[patreon]: https://patreon.com/akutishevskyi?utmmedium=unknown&utmsource=joinlink&utmcampaign=creatorsharecreator&utmcontent=copyLink
[](https://sonarcloud.io/summary/newcode?id=akutishevskywithings-mcp) [](https://sonarcloud.io/summary/newcode?id=akutishevskywithings-mcp) [](https://sonarcloud.io/summary/newcode?id=akutishevskywithings-mcp) [](https://sonarcloud.io/summary/newcode?id=akutishevskywithings-mcp) [](https://sonarcloud.io/summary/newcode?id=akutishevskywithings-mcp) [](https://sonarcloud.io/summary/newcode?id=akutishevskywithings-mcp) [](https://sonarcloud.io/summary/newcode?id=akutishevskywithings-mcp) [](https://sonarcloud.io/summary/newcode?id=akutishevskywithings-mcp)
A Model Context Protocol (MCP) server that brings your Withings health data into Claude. Access your sleep patterns, body measurements, workouts, heart data, and more through natural conversation.
🔒 Privacy First: This is my personal
d2f5e9963249OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add withings-mcp --env ENCRYPTION_SECRET=${ENCRYPTION_SECRET} -- npx -y [email protected]{
"mcpServers": {
"withings-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ENCRYPTION_SECRET": "${ENCRYPTION_SECRET}"
}
}
}
}Exposed tools (14)
14 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
echo | read | |
get_activity | read | |
get_heart_signal | read | |
get_hrv | read | |
get_intraday_activity | read | |
get_measures | read | |
get_sleep | read | |
get_sleep_summary | read | |
get_stetho_signal | read | |
get_user_devices | read | |
get_user_goals | read | |
get_workouts | read | |
list_heart_records | read | |
list_stetho_records | read |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (8)
logger.warn(`Authentication failed on ${method} ${path}: invalid or expired token`);"Get detailed ECG (electrocardiogram) signal data in micro-volts (μV) for a specific recording. Returns high-frequency waveform data with sampling information. Recording duration: BPM Core (20s), Move
TEST_DATABASE_URL: postgres://postgres:postgres@localhost:5432/postgres
* TEST_DATABASE_URL=postgres://postgres:postgres@localhost:5432/postgres bun test
@cfworker/json-schema, @modelcontextprotocol/hono, @modelcontextprotocol/server, @supabase/supabase-js, hono, zod, @types/bun, typescript
- **NO** tokens, access codes, or authentication credentials
- Nothing else needs restoring: tool handlers close over the MCP token alone and re-read all Withings credentials from Supabase per call
demo/demo.gif
Gates applied: no_behavioural_pass.
d2f5e9963249full audit observations/trust-audit/mcp-server/akutishevsky__withings-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | d2f5e9963249 | CAUTION | B | 86 | first audit |
Questions
What is the Withings MCP server?
MCP server for Withings health data integration
What tools does Withings expose?
14 in total: 14 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Withings safe to connect to an agent?
With care. The audit graded it B (86/100) and found 8 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Withings need?
It reads ENCRYPTION_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Withings run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as withings-mcp at 2.1.0.
How current is this page?
The grade is for one exact copy of the source (d2f5e9963249), read on 2026-10-08. The repository is watched and re-audited when it changes.