Atlas / MCP servers / jamsusmaximus / TrainingPeaks

TrainingPeaksCAUTION

mcp/jamsusmaximus/trainingpeaks

TrainingPeaks MCP server for Claude Desktop, Code and Cowork. No API approval needed - works with any account. Query workouts, CTL/ATL/TSB fitness data, power PRs via natural language.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
52 30r · 17w · 5d
Transport
stdio
License
MIT
Stars
179
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Connect TrainingPeaks to Claude and other AI assistants via the Model Context Protocol (MCP). Query workouts, build structured intervals, manage your calendar, track fitness trends, and control your training through natural conversation.

No API approval required. The official Training Peaks API is approval-gated, but this server uses secure cookie authentication that any user can set up in minutes. Your cookie is stored in your system keyring, never transmitted anywhere except to TrainingPeaks.

What You Can Do

Ask your AI assistant things like:

  • "Build me a 4x8min threshold session for Tuesday with warm-up and cool-down"
  • "Schedule my mobility session for April 14, 2026 at 16:45"
  • "Compare my FTP progression this year vs last year"
  • "Copy last week's long ride to this Saturday"
  • "Log my weight at 74.5kg and sleep at 7.5 hours"
  • "What's my weekly TSS so far? Am I on track for my ATP target?"
  • "Show my race calendar and how many weeks until my A race"
  • "Set my FTP to 310 and update my power zones"
  • "Add a calendar note for next Monday: rest day, travel"

Tools (84)

Workouts

Read from source at commit f40ce421c08aOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add tp-mcp --env TP_AUTH_COOKIE=${TP_AUTH_COOKIE} -- uvx tp-mcp
claude-desktop
{
  "mcpServers": {
    "tp-mcp": {
      "command": "uvx",
      "args": [
        "tp-mcp"
      ],
      "env": {
        "TP_AUTH_COOKIE": "${TP_AUTH_COOKIE}"
      }
    }
  }
}
03

Exposed tools (52)

30 read · 17 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
tp_add_athletes_to_groupwriteAdd one or more athletes to a group. Moving an athlete = add
tp_analyze_workoutreadGet workout analysis: metrics, zones, laps. Saves full time-series to JSON file.
tp_apply_training_planwriteApply a training plan to an athlete
tp_auth_statusreadCheck auth status. Use only when other tools return auth errors.
tp_copy_workoutreadCopy a workout to a new date. Copies structure, description, planned fields.
tp_create_eventwriteCreate a race/event with priority (A/B/C) and CTL target.
tp_create_groupwriteCreate a new athlete group.
tp_create_library_itemwriteSave a workout template to a library.
tp_create_notewriteCreate a calendar note.
tp_delete_equipmentdestructiveDelete equipment.
tp_delete_groupdestructiveDelete an athlete group (the grouping only — athletes are not
tp_delete_strength_workoutdestructiveDelete a strength workout by ID.
tp_delete_workout_filedestructiveDelete a workout file by file_id. Get file_id from tp_get_workout device_files/attachment_files.
tp_get_atpreadGet Annual Training Plan - weekly TSS targets, training periods, races. Max 90 days.
tp_get_availabilityreadGet availability entries for a date range.
tp_get_equipmentreadList equipment (bikes, shoes).
tp_get_eventsreadList events in a date range.
tp_get_fitnessreadGet fitness/fatigue trend (CTL/ATL/TSB). Supports historical date ranges.
tp_get_focus_eventreadGet the A-priority focus event with goals and results.
tp_get_librariesreadList workout library folders.
tp_get_metricsreadGet health metrics for a date range.
tp_get_next_eventreadGet the nearest future planned event.
tp_get_notereadGet a calendar note by ID.
tp_get_note_commentsreadGet all comments on a calendar note.
tp_get_nutritionreadGet nutrition data for a date range.
tp_get_pool_length_settingsreadGet pool length settings.
tp_get_profilereadGet athlete profile. Rarely needed - other tools work without it.
tp_get_strength_summaryreadGet a strength workout
tp_get_training_planreadSummary of one training plan: weeks, per-week duration/distance,
tp_get_training_plan_workoutsreadAll workouts of a training plan laid out by week/day
tp_get_weekly_summaryreadCombined view of workouts + fitness for a week. Totals TSS, duration, end-of-week CTL/ATL/TSB.
tp_get_workoutreadGet workout details by ID. Use after tp_get_workouts.
tp_get_workout_notereadGet the private workout note for a workout.
tp_get_workout_typeswriteList all sport types and subtypes with IDs. Use to find subtype_id for create/update.
tp_list_athletesreadList athletes available to this account (coach accounts).
tp_list_athletes_in_groupreadList the athletes in one athlete group, with names resolved
tp_list_groupsreadList the coach
tp_list_notesreadList calendar notes for a date range.
tp_list_training_plansreadList the coach
tp_log_metricsreadLog health metrics (weight, HRV, sleep, steps, etc.) for a date.
tp_refresh_authreadRefresh auth by extracting cookie from user
tp_remove_athletes_from_groupdestructiveRemove one or more athletes from a group.
tp_rename_groupwriteRename an athlete group. The default group cannot be renamed.
tp_set_workout_notewriteSet or update the private workout note for a workout.
tp_update_equipmentwriteUpdate equipment details.
tp_update_ftpwriteUpdate FTP (power threshold) and rescale the matching power-zone
tp_update_hr_zoneswriteUpdate heart rate zones.
tp_update_library_itemwriteEdit a workout template.
tp_update_notewriteUpdate a calendar note. Provide at least one of: title, description, date, is_hidden.
tp_update_nutritionwriteUpdate daily planned calories.
tp_update_speed_zoneswriteUpdate run/swim pace zones.
tp_upload_workout_filewriteUpload a workout file (.fit, .tcx, .gpx) to an existing workout.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
src/tp_mcp/auth/encrypted.py:69
machine_id_path = Path("/etc/machine-id")
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
tp_delete_equipment, tp_delete_group, tp_delete_strength_workout, tp_delete_workout_file, tp_remove_athletes_from_group
Why it matters. 5 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/tp_mcp/auth/encrypted.py:196
encrypted_data = base64.b64decode(CREDENTIALS_FILE.read_bytes())
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/tp_mcp/tools/workout_files.py:110
raw_bytes = base64.b64decode(file_data_base64 or "", validate=True)
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:249
> **Security note:** the cookie grants full access to your TrainingPeaks account, so treat `TP_AUTH_COOKIE` like a password. Inject it from a secrets manager or your orchestrator's secret mechanism -

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha f40ce421c08afull audit observations/trust-audit/mcp-server/jamsusmaximus__trainingpeaks.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07f40ce421c08aCAUTIONB89first audit
06

Questions

What is the TrainingPeaks MCP server?

TrainingPeaks MCP server for Claude Desktop, Code and Cowork. No API approval needed - works with any account. Query workouts, CTL/ATL/TSB fitness data, power PRs via natural language.

What tools does TrainingPeaks expose?

52 in total: 30 read-only, 17 that write, and 5 that can delete or overwrite (tp_delete_equipment, tp_delete_group, tp_delete_strength_workout, tp_delete_workout_file, tp_remove_athletes_from_group). Every one is listed on this page with its risk.

Is TrainingPeaks safe to connect to an agent?

With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does TrainingPeaks need?

It reads TP_AUTH_COOKIE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does TrainingPeaks run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as tp-mcp.

How current is this page?

The grade is for one exact copy of the source (f40ce421c08a), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement