MCPLow riskUnclaimed
withingsmcp
Privacy-first, unofficial Withings MCP server for AI health, sleep, activity and heart-rate agents.
davidmosiahdavidmosiah/withingsmcp
server.json
{
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.davidmosiah/withingsmcp",
"description": "Privacy-first, unofficial Withings MCP server for AI health, sleep, activity and heart-rate agents.",
"repository": {
"url": "https://github.com/davidmosiah/withings-mcp",
"source": "github"
},
"version": "0.4.7",
"websiteUrl": "https://wellness.delx.ai/connectors/withings",
"packages": [
{
"registryType": "npm",
"identifier": "withings-mcp-unofficial",
"version": "0.4.7",
"transport": {
"type": "stdio"
},
"environmentVariables": [
{
"description": "Withings OAuth client ID. Optional when configured with withings-mcp-server setup.",
"format": "string",
"name": "WITHINGS_CLIENT_ID"
},
{
"description": "Withings OAuth client secret. Prefer withings-mcp-server setup so this secret is stored in ~/.withings-mcp/config.json instead of MCP client config.",
"format": "string",
"isSecret": true,
"name": "WITHINGS_CLIENT_SECRET"
},
{
"description": "Redirect URI configured in the Withings Developer Dashboard. Optional when configured with withings-mcp-server setup.",
"format": "string",
"name": "WITHINGS_REDIRECT_URI"
},
{
"description": "Optional local path for OAuth tokens. Defaults to ~/.withings-mcp/tokens.json.",
"format": "string",
"name": "WITHINGS_TOKEN_PATH"
},
{
"description": "Optional payload mode: summary, structured, or raw. Defaults to structured. raw means full Withings API payloads, not continuous 24/7 raw sensor telemetry.",
"format": "string",
"name": "WITHINGS_PRIVACY_MODE"
},
{
"description": "Optional SQLite cache toggle. Set to true or sqlite to enable.",
"format": "string",
"name": "WITHINGS_CACHE"
},
{
"description": "Optional local SQLite cache path. Defaults to ~/.withings-mcp/cache.sqlite.",
"format": "string",
"name": "WITHINGS_CACHE_PATH"
},
{
"description": "Set to true to bypass the in-memory HTTP response cache (60s TTL for GET only). POST/PUT/DELETE and 4xx/5xx responses are never cached regardless. Note: Withings's wbsapi.withings.net is POST-only today, so this is currently a no-op.",
"format": "string",
"name": "WITHINGS_NO_CACHE"
}
]
}
]
}Permissions
DeclaredDetected
Runs code—
nodeInstalls—
npm:withings-mcp-unofficial@0.4.7Runs install scripts—None
NetworkNoneNone
Needs credentials
WITHINGS_CLIENT_SECRETWITHINGS_CLIENT_SECRETOutside the workspace—None
Agent tools—None
Checks
Low risk · Nothing worth a warning was found.
Not reviewed by a person · Checked by rules; the model review is not switched on yet.
Versions
- #10.4.7latestOct 7, 2026
withingsmcpOpen in Codeg