Garmin ConnectSAFE
Garmin Connect MCP
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/etweisberg/garmin-connect-mcp/actions/workflows/ci.yml) [](https://github.com/etweisberg/garmin-connect-mcp/actions/workflows/release.yml) [](https://www.npmjs.com/package/@etweisberg/garmin-connect-mcp) [](https://www.npmjs.com/package/@etweisberg/garmin-connect-mcp) [](https://www.gnu.org/licenses/agpl-3.0)
MCP server for Garmin Connect. Access your activities, health stats, sleep data, FIT files, and more from Claude Code or any MCP client.
Why This Exists
In March 2026, Garmin changed their authentication API, breaking garth and python-garminconnect — the two most popular libraries for accessing Garmin data programmatically. Garth has been officially deprecated. Garmin added Cloudflare TLS fingerprinting that blocks all non-browser HTTP clients (Node.js fetch, Python requests, curl) from their API endpoints.
This project works around that by routing all API calls through a headless Playwright browser, inheriting a real Chrome TLS fingerprint. Authentication uses browser cookies captured from a manual login session.
Install
npm install -g @etweisberg/garmin-connect-mcp npx playwright install chromium
Then register with Claude Code:
claude mcp add garmin -- npx @etweisberg/garmin-connect-mcp
You also need the Playwright MCP server for the login flow:
claude mcp add playwright -- npx @playwright/mcp@latest
Prerequisites
60407c90b49eOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add garmin-connect-mcp -- npx -y @etweisberg/[email protected]
{
"mcpServers": {
"garmin-connect-mcp": {
"command": "npx",
"args": [
"-y",
"@etweisberg/[email protected]"
]
}
}
}Exposed tools (41)
36 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
check-session | read | Check if the saved Garmin Connect session is still valid. MUST be called after garmin-login to verify authentication worked. |
create-workout | write | Upload a workout from JSON data. Creates a new workout in Garmin Connect from structured workout data. IMPORTANT: Step types must use Garmin |
delete-workout | destructive | Delete a workout from Garmin Connect |
download-fit | read | Download the original FIT file for an activity. Returns the file path. |
download-workout-fit | read | Download a workout as a FIT file |
garmin-login | read | Returns step-by-step instructions for authenticating with Garmin Connect. Requires the Playwright MCP server to be installed. After following these steps, ALWAYS call the check-session tool to verify the login worked. |
get-activity | read | Get full activity summary (name, type, distance, duration, HR, calories, etc.) |
get-activity-details | read | Get time-series metrics for an activity (HR, cadence, elevation, pace over time) |
get-activity-hr-zones | read | Get heart rate time-in-zone breakdown for an activity |
get-activity-polyline | read | Get full-resolution GPS track/polyline for an activity |
get-activity-splits | read | Get lap/split data for an activity |
get-activity-weather | read | Get weather conditions during an activity |
get-badge-leaderboard | read | Get badge leaderboard among your connections |
get-badges | read | Get all earned badges/achievements |
get-body-battery | read | Get today |
get-calendar | read | Get monthly calendar with activities, workouts, and events |
get-daily-heart-rate | read | Get heart rate data throughout the day (resting HR, HR timeline) |
get-daily-intensity-minutes | read | Get intensity minutes earned for a date |
get-daily-movement | read | Get daily movement/activity data |
get-daily-respiration | read | Get respiration rate data for a date |
get-daily-stress | read | Get stress level data throughout the day |
get-daily-summary | read | Get daily summary: steps, calories, distance, intensity minutes, floors, etc. |
get-daily-summary-chart | read | Get daily wellness summary chart data (combined health metrics) |
get-fitness-stats | read | Get aggregated fitness stats by activity type over a date range |
get-goals | read | Get fitness goals |
get-hr-zones-config | read | Get your configured heart rate zone boundaries |
get-hrv | read | Get heart rate variability (HRV) data for a date |
get-hydration | read | Get daily hydration/water intake data |
get-personal-records | write | Get all personal records with history (fastest mile, longest run, etc.) |
get-power-zones | read | Get power zone configuration for all sports |
get-sleep | read | Get sleep data: score, duration, stages, SpO2, HRV during sleep |
get-sleep-stats | read | Get sleep statistics over a date range (averages, trends) |
get-training-readiness | read | Get training readiness score for a date (based on sleep, recovery, training load) |
get-user-profile | read | Get your Garmin Connect user profile and settings |
get-vo2max | read | Get latest VO2 Max / fitness level estimate |
get-weight | read | Get weight measurements over a date range |
get-workout | read | Get a single workout by ID with full step/segment details |
list-activities | read | List your Garmin Connect activities with pagination |
list-workouts | read | List your saved workouts |
run-tests | write | Returns a test plan for verifying all garmin-connect-mcp tools work. Call each tool listed and report results. |
schedule-workout | write | Schedule an existing workout to a date on your calendar. The workout will sync to your device. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
delete-workout
@modelcontextprotocol/sdk, playwright, zod, @eslint/js, @types/node, eslint, eslint-config-prettier, prettier
Gates applied: no_behavioural_pass.
60407c90b49efull audit observations/trust-audit/mcp-server/etweisberg__garmin-connect-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 60407c90b49e | SAFE | B | 89 | first audit |
Questions
What is the Garmin Connect MCP server?
Garmin Connect MCP
What tools does Garmin Connect expose?
41 in total: 36 read-only, 4 that write, and 1 that can delete or overwrite (delete-workout). Every one is listed on this page with its risk.
Is Garmin Connect safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Garmin Connect need?
No credential environment variables were found in its source, so it appears to need none.
How does Garmin Connect run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @etweisberg/garmin-connect-mcp at 0.1.23.
How current is this page?
The grade is for one exact copy of the source (60407c90b49e), read on 2026-10-08. The repository is watched and re-audited when it changes.