MCPLow riskUnclaimed

withingsmcp

Privacy-first, unofficial Withings MCP server for AI health, sleep, activity and heart-rate agents.

davidmosiahdavidmosiah/withingsmcp★ 5Updated Jul 3, 2026

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "io.github.davidmosiah/withingsmcp",
  "description": "Privacy-first, unofficial Withings MCP server for AI health, sleep, activity and heart-rate agents.",
  "repository": {
    "url": "https://github.com/davidmosiah/withings-mcp",
    "source": "github"
  },
  "version": "0.4.7",
  "websiteUrl": "https://wellness.delx.ai/connectors/withings",
  "packages": [
    {
      "registryType": "npm",
      "identifier": "withings-mcp-unofficial",
      "version": "0.4.7",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "Withings OAuth client ID. Optional when configured with withings-mcp-server setup.",
          "format": "string",
          "name": "WITHINGS_CLIENT_ID"
        },
        {
          "description": "Withings OAuth client secret. Prefer withings-mcp-server setup so this secret is stored in ~/.withings-mcp/config.json instead of MCP client config.",
          "format": "string",
          "isSecret": true,
          "name": "WITHINGS_CLIENT_SECRET"
        },
        {
          "description": "Redirect URI configured in the Withings Developer Dashboard. Optional when configured with withings-mcp-server setup.",
          "format": "string",
          "name": "WITHINGS_REDIRECT_URI"
        },
        {
          "description": "Optional local path for OAuth tokens. Defaults to ~/.withings-mcp/tokens.json.",
          "format": "string",
          "name": "WITHINGS_TOKEN_PATH"
        },
        {
          "description": "Optional payload mode: summary, structured, or raw. Defaults to structured. raw means full Withings API payloads, not continuous 24/7 raw sensor telemetry.",
          "format": "string",
          "name": "WITHINGS_PRIVACY_MODE"
        },
        {
          "description": "Optional SQLite cache toggle. Set to true or sqlite to enable.",
          "format": "string",
          "name": "WITHINGS_CACHE"
        },
        {
          "description": "Optional local SQLite cache path. Defaults to ~/.withings-mcp/cache.sqlite.",
          "format": "string",
          "name": "WITHINGS_CACHE_PATH"
        },
        {
          "description": "Set to true to bypass the in-memory HTTP response cache (60s TTL for GET only). POST/PUT/DELETE and 4xx/5xx responses are never cached regardless. Note: Withings's wbsapi.withings.net is POST-only today, so this is currently a no-op.",
          "format": "string",
          "name": "WITHINGS_NO_CACHE"
        }
      ]
    }
  ]
}

Permissions

DeclaredDetected
Runs code—node
Installs—npm:withings-mcp-unofficial@0.4.7
Runs install scripts—None
NetworkNoneNone
Needs credentialsWITHINGS_CLIENT_SECRETWITHINGS_CLIENT_SECRET
Outside the workspace—None
Agent tools—None

Checks

Low risk · Nothing worth a warning was found.

Not reviewed by a person · Checked by rules; the model review is not switched on yet.

Versions

  1. #10.4.7latestOct 7, 2026