TrainingPeaksCAUTION
TrainingPeaks MCP server for Claude Desktop, Code and Cowork. No API approval needed - works with any account. Query workouts, CTL/ATL/TSB fitness data, power PRs via natural language.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Connect TrainingPeaks to Claude and other AI assistants via the Model Context Protocol (MCP). Query workouts, build structured intervals, manage your calendar, track fitness trends, and control your training through natural conversation.
No API approval required. The official Training Peaks API is approval-gated, but this server uses secure cookie authentication that any user can set up in minutes. Your cookie is stored in your system keyring, never transmitted anywhere except to TrainingPeaks.
What You Can Do
Ask your AI assistant things like:
- "Build me a 4x8min threshold session for Tuesday with warm-up and cool-down"
- "Schedule my mobility session for April 14, 2026 at 16:45"
- "Compare my FTP progression this year vs last year"
- "Copy last week's long ride to this Saturday"
- "Log my weight at 74.5kg and sleep at 7.5 hours"
- "What's my weekly TSS so far? Am I on track for my ATP target?"
- "Show my race calendar and how many weeks until my A race"
- "Set my FTP to 310 and update my power zones"
- "Add a calendar note for next Monday: rest day, travel"
Tools (84)
Workouts
f40ce421c08aOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add tp-mcp --env TP_AUTH_COOKIE=${TP_AUTH_COOKIE} -- uvx tp-mcp{
"mcpServers": {
"tp-mcp": {
"command": "uvx",
"args": [
"tp-mcp"
],
"env": {
"TP_AUTH_COOKIE": "${TP_AUTH_COOKIE}"
}
}
}
}Exposed tools (52)
30 read · 17 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
tp_add_athletes_to_group | write | Add one or more athletes to a group. Moving an athlete = add |
tp_analyze_workout | read | Get workout analysis: metrics, zones, laps. Saves full time-series to JSON file. |
tp_apply_training_plan | write | Apply a training plan to an athlete |
tp_auth_status | read | Check auth status. Use only when other tools return auth errors. |
tp_copy_workout | read | Copy a workout to a new date. Copies structure, description, planned fields. |
tp_create_event | write | Create a race/event with priority (A/B/C) and CTL target. |
tp_create_group | write | Create a new athlete group. |
tp_create_library_item | write | Save a workout template to a library. |
tp_create_note | write | Create a calendar note. |
tp_delete_equipment | destructive | Delete equipment. |
tp_delete_group | destructive | Delete an athlete group (the grouping only — athletes are not |
tp_delete_strength_workout | destructive | Delete a strength workout by ID. |
tp_delete_workout_file | destructive | Delete a workout file by file_id. Get file_id from tp_get_workout device_files/attachment_files. |
tp_get_atp | read | Get Annual Training Plan - weekly TSS targets, training periods, races. Max 90 days. |
tp_get_availability | read | Get availability entries for a date range. |
tp_get_equipment | read | List equipment (bikes, shoes). |
tp_get_events | read | List events in a date range. |
tp_get_fitness | read | Get fitness/fatigue trend (CTL/ATL/TSB). Supports historical date ranges. |
tp_get_focus_event | read | Get the A-priority focus event with goals and results. |
tp_get_libraries | read | List workout library folders. |
tp_get_metrics | read | Get health metrics for a date range. |
tp_get_next_event | read | Get the nearest future planned event. |
tp_get_note | read | Get a calendar note by ID. |
tp_get_note_comments | read | Get all comments on a calendar note. |
tp_get_nutrition | read | Get nutrition data for a date range. |
tp_get_pool_length_settings | read | Get pool length settings. |
tp_get_profile | read | Get athlete profile. Rarely needed - other tools work without it. |
tp_get_strength_summary | read | Get a strength workout |
tp_get_training_plan | read | Summary of one training plan: weeks, per-week duration/distance, |
tp_get_training_plan_workouts | read | All workouts of a training plan laid out by week/day |
tp_get_weekly_summary | read | Combined view of workouts + fitness for a week. Totals TSS, duration, end-of-week CTL/ATL/TSB. |
tp_get_workout | read | Get workout details by ID. Use after tp_get_workouts. |
tp_get_workout_note | read | Get the private workout note for a workout. |
tp_get_workout_types | write | List all sport types and subtypes with IDs. Use to find subtype_id for create/update. |
tp_list_athletes | read | List athletes available to this account (coach accounts). |
tp_list_athletes_in_group | read | List the athletes in one athlete group, with names resolved |
tp_list_groups | read | List the coach |
tp_list_notes | read | List calendar notes for a date range. |
tp_list_training_plans | read | List the coach |
tp_log_metrics | read | Log health metrics (weight, HRV, sleep, steps, etc.) for a date. |
tp_refresh_auth | read | Refresh auth by extracting cookie from user |
tp_remove_athletes_from_group | destructive | Remove one or more athletes from a group. |
tp_rename_group | write | Rename an athlete group. The default group cannot be renamed. |
tp_set_workout_note | write | Set or update the private workout note for a workout. |
tp_update_equipment | write | Update equipment details. |
tp_update_ftp | write | Update FTP (power threshold) and rescale the matching power-zone |
tp_update_hr_zones | write | Update heart rate zones. |
tp_update_library_item | write | Edit a workout template. |
tp_update_note | write | Update a calendar note. Provide at least one of: title, description, date, is_hidden. |
tp_update_nutrition | write | Update daily planned calories. |
tp_update_speed_zones | write | Update run/swim pace zones. |
tp_upload_workout_file | write | Upload a workout file (.fit, .tcx, .gpx) to an existing workout. |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (5)
machine_id_path = Path("/etc/machine-id")tp_delete_equipment, tp_delete_group, tp_delete_strength_workout, tp_delete_workout_file, tp_remove_athletes_from_group
encrypted_data = base64.b64decode(CREDENTIALS_FILE.read_bytes())
raw_bytes = base64.b64decode(file_data_base64 or "", validate=True)
> **Security note:** the cookie grants full access to your TrainingPeaks account, so treat `TP_AUTH_COOKIE` like a password. Inject it from a secrets manager or your orchestrator's secret mechanism -
Gates applied: no_behavioural_pass.
f40ce421c08afull audit observations/trust-audit/mcp-server/jamsusmaximus__trainingpeaks.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | f40ce421c08a | CAUTION | B | 89 | first audit |
Questions
What is the TrainingPeaks MCP server?
TrainingPeaks MCP server for Claude Desktop, Code and Cowork. No API approval needed - works with any account. Query workouts, CTL/ATL/TSB fitness data, power PRs via natural language.
What tools does TrainingPeaks expose?
52 in total: 30 read-only, 17 that write, and 5 that can delete or overwrite (tp_delete_equipment, tp_delete_group, tp_delete_strength_workout, tp_delete_workout_file, tp_remove_athletes_from_group). Every one is listed on this page with its risk.
Is TrainingPeaks safe to connect to an agent?
With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does TrainingPeaks need?
It reads TP_AUTH_COOKIE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does TrainingPeaks run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as tp-mcp.
How current is this page?
The grade is for one exact copy of the source (f40ce421c08a), read on 2026-10-07. The repository is watched and re-audited when it changes.