← Back to search

io.github.davidmosiah/fitbitmcp

davidmosiah Scanned 13d ago

Privacy-first, unofficial Fitbit MCP server for AI health, sleep, activity and heart-rate agents.

B
79.3 / 100

Versions

0.4.7latest
Jul 30, 2026
0.4.6
Jul 16, 2026
0.4.5
May 24, 2026
0.4.4
May 24, 2026
0.4.3
May 20, 2026
+ show 7 moreshow less
0.4.2
May 20, 2026
0.4.1
May 11, 2026
0.4.0
May 11, 2026
0.3.0
May 11, 2026
0.2.1
May 6, 2026
0.2.0
May 4, 2026
0.1.0
May 1, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 21

fitbit_data_inventory
annotations: verified low

Inventory supported Fitbit data domains, auth scope requirements, privacy boundary and recommended first calls. Does not call Fitbit APIs or expose user data.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
fitbit_agent_manifest
annotations: verified low

Machine-readable install, runtime and client guidance for AI agents. Does not call Fitbit or expose secrets.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
fitbit_capabilities
annotations: verified low

Explain supported Fitbit data, privacy boundaries, recommended agent workflow and project links.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
fitbit_quickstart
annotations: verified low

Personalized 3-step setup walkthrough for the human user. Adapts to current state (env vars set? token present? what's next?). Call this first when the user asks 'how do I connect Fitbit?'

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
fitbit_demo
annotations: verified low

Returns realistic example payloads of fitbit_daily_summary, fitbit_wellness_context, and fitbit_get_heart_day so agents see the contract before calling real Fitbit APIs.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
fitbit_get_auth_url
annotations: verified low

Generate a Fitbit OAuth authorization URL. Use this first when no local token exists.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
fitbit_exchange_code
annotations: verified low

Exchange a Fitbit OAuth authorization code for local tokens. Tokens are stored locally with 0600 permissions and are never returned. Requires explicit user action: the user must complete browser OAuth and supply the authorization code (agents must not invent codes).

readOnlyHint false openWorldHint true idempotentHint false destructiveHint false
fitbit_get_profile
annotations: verified low

Get the authenticated Fitbit user profile. Requires profile scope.

readOnlyHint true openWorldHint true idempotentHint true destructiveHint false
fitbit_list_devices
annotations: verified low

List devices connected to the authenticated Fitbit account. Requires settings scope.

readOnlyHint true openWorldHint true idempotentHint true destructiveHint false
fitbit_get_heart_intraday
annotations: verified low

Get raw heart-rate intraday samples for a date. For agent work prefer fitbit_heart_series (agent-safe-series/v1 with hard point caps and exact stats).

readOnlyHint true openWorldHint true idempotentHint true destructiveHint false
fitbit_heart_series
annotations: verified low

Bounded heart-rate time-series for one civil day (agent-safe-series/v1).

readOnlyHint true openWorldHint true idempotentHint true destructiveHint false
fitbit_connection_status
annotations: verified low

Check local Fitbit config, token file, Node version, privacy mode, cache readiness and optional MCP client readiness without calling Fitbit or exposing secrets.

response_format enum
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
fitbit_cache_status
annotations: verified low

Show optional local SQLite cache status. Enable with FITBIT_CACHE=sqlite or FITBIT_CACHE=true.

response_format enum
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
fitbit_privacy_audit
annotations: verified low

Return local privacy, cache, token-path and env-presence posture without revealing secret values.

response_format enum
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
fitbit_revoke_access
annotations: verified low

Revoke the current Fitbit OAuth grant and delete the local token file. Use only when the user explicitly wants to disconnect Fitbit. Gated by explicit_user_intent: true (requires explicit user intent).

response_format enum
readOnlyHint false openWorldHint true idempotentHint false destructiveHint true
fitbit_daily_summary
annotations: verified low

Build a practical daily summary from Fitbit activity, sleep, heart-rate, HRV and weight data when available. Read-only and non-medical.

readOnlyHint true openWorldHint true idempotentHint true destructiveHint false
fitbit_weekly_summary
annotations: verified low

Build a weekly Fitbit scorecard with activity, sleep, heart-rate, HRV availability, bottlenecks and actions. Read-only and non-medical.

readOnlyHint true openWorldHint true idempotentHint true destructiveHint false
fitbit_wellness_context
annotations: verified low

Normalize Fitbit sleep and activity load into the shared wellness_context shape for recommendation engines.

readOnlyHint true openWorldHint true idempotentHint true destructiveHint false
fitbit_profile_get
annotations: verified low

Read the canonical Delx Wellness profile shared with the other wellness MCP connectors (Nourish, Cycle Coach, CGM, etc.). Read-only. Profile stores only what the user typed during onboarding — never OAuth tokens, API keys, or biomarkers.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
fitbit_profile_update
annotations: verified low

Persist a partial patch to the canonical Delx Wellness profile. Requires explicit_user_intent=true after the user confirms they want to save. Rejects secret-like fields (oauth, token, api_key, password, cookie, refresh, session).

readOnlyHint false openWorldHint false idempotentHint false destructiveHint false
fitbit_onboarding
annotations: verified low

Read-only. Return the 11-question Delx Wellness onboarding flow (en or pt-BR), the current shared profile, missing critical fields, and a cross-connector hint. Use this when the user starts a fresh wellness session and you need to fill out preferred_name, goals, devices, training context, nutrition, preferences, and safety.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false

Permissions 3

network medium
Server uses network capabilities via: fetch()
shell high
Server uses shell capabilities via: child_process, spawn(), spawnSync()
env_vars low
Server uses env_vars capabilities via: process.env

Scan Findings 57

info
Tool 'fitbit_heart_series' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_connection_status' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_data_inventory' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_agent_manifest' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_capabilities' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_quickstart' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_demo' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_get_auth_url' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_exchange_code' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_get_profile' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_list_devices' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_get_heart_intraday' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_cache_status' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_privacy_audit' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_revoke_access' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_daily_summary' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_weekly_summary' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_wellness_context' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_profile_get' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_profile_update' annotations are consistent annotation_checker · 80%
info
Tool 'fitbit_onboarding' annotations are consistent annotation_checker · 80%
high
Hardcoded OAuth client secret in davidmosiah-fitbit-mcp-c935dcf/scripts/agent-readiness-test.mjs auth_checker · 95%
high
Hardcoded OAuth client secret in davidmosiah-fitbit-mcp-c935dcf/scripts/endpoint-contract-test.mjs auth_checker · 95%
high
Hardcoded OAuth client secret in davidmosiah-fitbit-mcp-c935dcf/scripts/cli-ux-test.mjs auth_checker · 95%
medium
OAuth implementation without PKCE auth_checker · 75%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
info
package.json metadata manifest_parser · 100%
info
Tool: fitbit_data_inventory manifest_parser · 85%
info
Tool: fitbit_agent_manifest manifest_parser · 85%
info
Tool: fitbit_capabilities manifest_parser · 85%
info
Tool: fitbit_quickstart manifest_parser · 85%
info
Tool: fitbit_demo manifest_parser · 85%
info
Tool: fitbit_get_auth_url manifest_parser · 85%
info
Tool: fitbit_exchange_code manifest_parser · 85%
info
Tool: fitbit_get_profile manifest_parser · 85%
info
Tool: fitbit_list_devices manifest_parser · 85%
info
Tool: fitbit_get_heart_intraday manifest_parser · 85%
info
Tool: fitbit_heart_series manifest_parser · 85%
info
Tool: fitbit_connection_status manifest_parser · 85%
info
Tool: fitbit_cache_status manifest_parser · 85%
info
Tool: fitbit_privacy_audit manifest_parser · 85%
info
Tool: fitbit_revoke_access manifest_parser · 85%
info
Tool: fitbit_daily_summary manifest_parser · 85%
info
Tool: fitbit_weekly_summary manifest_parser · 85%
info
Tool: fitbit_wellness_context manifest_parser · 85%
info
Tool: fitbit_profile_get manifest_parser · 85%
info
Tool: fitbit_profile_update manifest_parser · 85%
info
Tool: fitbit_onboarding manifest_parser · 85%
info
Transport: stdio manifest_parser · 90%
info
Required env vars (7) manifest_parser · 80%
medium
OAuth authorization code flow without PKCE oauth_scope_analyzer · 75%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 70%
high
Permission: shell access detected permission_analyzer · 95%
low
Permission: env_vars access detected permission_analyzer · 90%
info
SBOM generated: 170 components sbom_generator · 100%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%