MCPLow riskUnclaimed
whoop-mcp
Full read + write access to your Whoop fitness data via the private iOS API. 48 tools.
briangaoobriangaoo/whoop-mcp
server.json
{
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.briangaoo/whoop-mcp",
"description": "Full read + write access to your Whoop fitness data via the private iOS API. 48 tools.",
"repository": {
"url": "https://github.com/briangaoo/whoop-mcp",
"source": "github"
},
"version": "1.3.0",
"packages": [
{
"registryType": "npm",
"identifier": "@briangaoo/whoop-mcp",
"version": "1.3.0",
"transport": {
"type": "stdio"
},
"environmentVariables": [
{
"description": "Whoop Cognito access token. Obtain via `whoop-mcp auth` from the repo, which prompts for your Whoop email + password + SMS MFA code, then writes both tokens to a local .env. Auto-refreshes every ~24h.",
"isRequired": true,
"format": "string",
"isSecret": true,
"name": "WHOOP_IOS_BEARER_TOKEN"
},
{
"description": "Whoop Cognito refresh token (~30 day lifetime). Obtained alongside the bearer token from `whoop-mcp auth`. When this expires, run `whoop-mcp auth` to get a fresh pair.",
"isRequired": true,
"format": "string",
"isSecret": true,
"name": "WHOOP_COGNITO_REFRESH_TOKEN"
},
{
"description": "Your Whoop account email. Used only by `whoop-mcp auth` — the running server reads tokens, not credentials.",
"isRequired": true,
"format": "string",
"name": "WHOOP_EMAIL"
},
{
"description": "Your numeric Whoop user ID. Optional — used by whoop_profile and whoop_leaderboard. Avoids one redundant bootstrap call per session if set.",
"format": "string",
"name": "WHOOP_USER_ID"
},
{
"description": "IANA timezone (e.g., America/Los_Angeles) for response timestamps. Optional — if unset, the server auto-detects from your Whoop profile's timezone_offset field (refreshed hourly).",
"format": "string",
"name": "WHOOP_TIMEZONE"
}
]
}
]
}Permissions
DeclaredDetected
Runs code—
nodeInstalls—
npm:@briangaoo/whoop-mcp@1.3.0Runs install scripts—None
NetworkNoneNone
Needs credentials
WHOOP_COGNITO_REFRESH_TOKENWHOOP_IOS_BEARER_TOKENWHOOP_COGNITO_REFRESH_TOKENWHOOP_IOS_BEARER_TOKENOutside the workspace—None
Agent tools—None
Checks
Low risk · Nothing worth a warning was found.
Not reviewed by a person · Checked by rules; the model review is not switched on yet.
Versions
- #11.3.0latestOct 7, 2026
whoop-mcpOpen in Codeg