Google HealthCAUTION
Local-first MCP server for Google Health API v4 (Fitbit + Pixel Watch) — Claude/Cursor/Hermes
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Google Health MCP
Read user-authorized Google Health API v4 data — Fitbit, Pixel Watch and partners — locally via OAuth. Beta. Local-first MCP server — tokens never leave your machine.
f5f0c1576ec9OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add google-health-mcp-unofficial --env GOOGLE_HEALTH_CLIENT_SECRET=${GOOGLE_HEALTH_CLIENT_SECRET} -- npx -y [email protected]Exposed tools (26)
24 read · 1 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
google_health_agent_manifest | read | |
google_health_cache_status | read | |
google_health_capabilities | read | |
google_health_connection_status | read | |
google_health_daily_rollup | read | |
google_health_daily_summary | read | |
google_health_data_inventory | read | |
google_health_data_type_coverage | read | |
google_health_demo | read | |
google_health_exchange_code | read | |
google_health_get_auth_url | read | |
google_health_get_identity | read | |
google_health_get_profile | read | |
google_health_get_settings | read | |
google_health_list_data_points | read | |
google_health_list_data_types | read | |
google_health_onboarding | read | |
google_health_privacy_audit | read | |
google_health_profile_get | read | |
google_health_profile_update | write | |
google_health_quickstart | read | |
google_health_reconcile_data_points | read | |
google_health_revoke_access | destructive | |
google_health_rollup | read | |
google_health_weekly_summary | read | |
google_health_wellness_context | read |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
console.log(` Token file: ${output.token_path}`);google_health_revoke_access
.nojekyll
# GET http://127.0.0.1:3000/health
# POST http://127.0.0.1:3000/mcp (sessionless)
Create a Google Cloud OAuth client, enable the Google Health API, and add the redirect `http://127.0.0.1:3000/callback`. Then:
http://127.0.0.1:3000/callback
npx -y google-health-mcp-unofficial auth --code "http://127.0.0.1:3000/callback?code=..."
@modelcontextprotocol/sdk, better-sqlite3, cors, delx-mcp-kit, express, zod, @types/better-sqlite3, @types/cors
Gates applied: no_behavioural_pass.
f5f0c1576ec9full audit observations/trust-audit/mcp-server/davidmosiah__google-health.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | f5f0c1576ec9 | CAUTION | B | 89 | first audit |
Questions
What is the Google Health MCP server?
Local-first MCP server for Google Health API v4 (Fitbit + Pixel Watch) — Claude/Cursor/Hermes
What tools does Google Health expose?
26 in total: 24 read-only, 1 that write, and 1 that can delete or overwrite (google_health_revoke_access). Every one is listed on this page with its risk.
Is Google Health safe to connect to an agent?
With care. The audit graded it B (89/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Google Health need?
It reads GOOGLE_HEALTH_AUTH_TIMEOUT_MS and GOOGLE_HEALTH_CLIENT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Google Health run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as google-health-mcp-unofficial at 0.7.8.
How current is this page?
The grade is for one exact copy of the source (f5f0c1576ec9), read on 2026-10-08. The repository is watched and re-audited when it changes.