Atlas / MCP servers / mvilanova / Intervals.icu

Intervals.icuSAFE

mcp/mvilanova/intervals-icu

Model Context Protocol (MCP) server for connecting Claude and ChatGPT with the Intervals.icu API.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
20 12r · 5w · 3d
Transport
sse · streamable-http
License
GPL-3.0
Stars
364
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Model Context Protocol (MCP) server for connecting Claude and ChatGPT with the Intervals.icu API. It provides tools for authentication and data retrieval for activities, events, wellness data, power curves, and custom items.

If you find the Model Context Protocol (MCP) server useful, please consider supporting its continued development with a donation.

Requirements

Setup

1. Install uv (recommended)

macOS/Linux:

curl -LsSf https://astral.sh/uv/install.sh | sh

Windows (PowerShell):

powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"

After installation, find the full path to uv — you'll need it later when configuring Claude Desktop:

where.exe uv
# Example output: C:\Users\\.local\bin\uv.exe

2. Clone this repository

git clone https://github.com/mvilanova/intervals-mcp-server.git
cd intervals-mcp-server

3. Create and activate a virtual environment

# Create virtual environment with Python 3.12
uv venv --python 3.12

# Activate virtual environment
# On macOS/Linux:
source .venv/bin/activate
# On Windows:
.venv\Scripts\activate

4. Sync project dependencies

uv sync

5. Set up environment variables

Make a copy of .env.example and name it .env by running the following command:

macOS/Linux:

cp .env.example .env

Windows (PowerShell):

Copy-Item .env.example .env

Then edit the .env file and set your Intervals.icu athlete id and API key:

API_KEY=your_intervals_api_key_here
ATHLETE_ID=your_athlete_id_here

Getting your Intervals.icu API Key

  1. Log in to your Intervals.icu account
  2. Go to Settings > API
  3. Generate a new API key

Finding your Athlete ID

Your athlete ID is t

Read from source at commit aa3fb02ea6d6OBSERVED · 2026-10-03
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add intervals-mcp-server --env API_KEY=${API_KEY} -- uvx intervals-mcp-server
claude-desktop
{
  "mcpServers": {
    "intervals-mcp-server": {
      "command": "uvx",
      "args": [
        "intervals-mcp-server"
      ],
      "env": {
        "API_KEY": "${API_KEY}"
      }
    }
  }
}
03

Exposed tools (20)

12 read · 5 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_activity_messagewriteAdd a message (note/comment) to an activity on Intervals.icu
add_or_update_eventwritePost event for an athlete to Intervals.icu this follows the event api from intervals.icu
add_or_update_notewriteAdd or update a plain text note (category NOTE) on the Intervals.icu calendar.
create_custom_itemwriteCreate a new custom item for an athlete on Intervals.icu
delete_custom_itemdestructiveDelete a custom item for an athlete from Intervals.icu
delete_eventdestructiveDelete event for an athlete from Intervals.icu
delete_events_by_date_rangedestructiveDelete events for an athlete from Intervals.icu in the specified date range.
get_activitiesreadGet a list of activities for an athlete from Intervals.icu
get_activity_detailsreadGet detailed information for a specific activity from Intervals.icu
get_activity_intervalsreadGet interval data for a specific activity from Intervals.icu
get_activity_messagesreadGet messages (notes/comments) for a specific activity from Intervals.icu
get_activity_streamsreadGet stream data for a specific activity from Intervals.icu
get_athlete_power_curvesreadGet power curves for an athlete from Intervals.icu.
get_custom_item_by_idreadGet detailed information for a specific custom item from Intervals.icu
get_custom_itemsreadGet custom items (charts, custom fields, zones, etc.) for an athlete from Intervals.icu
get_event_by_idreadGet detailed information for a specific event from Intervals.icu
get_eventsreadGet events for an athlete from Intervals.icu
get_gear_listreadGet the gear catalog (bikes, shoes, etc.) for an athlete from Intervals.icu.
get_wellness_datareadGet wellness data for an athlete from Intervals.icu.
update_custom_itemwriteUpdate an existing custom item for an athlete on Intervals.icu
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (4)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_custom_item, delete_event, delete_events_by_date_range
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:280
The startup log prints the full URLs (for example `http://127.0.0.1:8765/sse`). ChatGPT needs that public URL, so forward the port with a tool such as `ngrok http 8765` if you are not exposing the ser
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:20
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-03 · audit v0.4.1 · source sha aa3fb02ea6d6full audit observations/trust-audit/mcp-server/mvilanova__intervals-icu.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-03aa3fb02ea6d6SAFEB89first audit
06

Questions

What is the Intervals.icu MCP server?

Model Context Protocol (MCP) server for connecting Claude and ChatGPT with the Intervals.icu API.

What tools does Intervals.icu expose?

20 in total: 12 read-only, 5 that write, and 3 that can delete or overwrite (delete_custom_item, delete_event, delete_events_by_date_range). Every one is listed on this page with its risk.

Is Intervals.icu safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Intervals.icu need?

It reads API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Intervals.icu run?

It speaks sse and streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as intervals-mcp-server.

How current is this page?

The grade is for one exact copy of the source (aa3fb02ea6d6), read on 2026-10-03. The repository is watched and re-audited when it changes.

Advertisement