borgels

mcp-server-withings

Community borgels
Updated

MCP server for the Withings Health API with per-user OAuth2

mcp-server-withings

MCP server for the Withings Health API with per-user OAuth2 β€” each user links their own Withings account and can only ever see their own health data.

How isolation works

Behind an authenticating gateway that forwards the signed-in user as X-MCP-User, every tool is bound to that user. The server keeps an AES-256-GCM encrypted, per-user token store; a user's identity resolves only to their own row. Without a verified identity the server fails closed (no anonymous/shared access). Each user enrolls once via withings_connect, which returns a single-use Withings authorization URL bound to them; after they approve in the browser, /withings/callback stores their (encrypted) tokens.

Tools

Auth/enrollment: withings_connect, withings_status, withings_disconnect.Read: withings_get_measures, withings_get_activity, withings_get_sleep, withings_get_workouts, withings_get_heart, withings_get_devices, withings_get_goals, withings_search_capabilities.Write (opt-in WITHINGS_ENABLE_WRITES=true): withings_add_measure.

Configuration

See .env.example. Register a Withings app at account.withings.com; the redirect URI must match WITHINGS_REDIRECT_URI exactly and be publicly reachable (route /withings/callback to this container). Set WITHINGS_ENCRYPTION_KEY (never commit) and WITHINGS_TRUST_FORWARDED_USER=true behind the gateway.

Run

npm install
npm run dev:http     # /mcp + /withings/callback on :3000
npm test

Docker images: ghcr.io/borgels/mcp-server-withings.

MCP Server Β· Populars

MCP Server Β· New

    talivia-group

    Talivia Agent Kit

    Revenue-first website analytics installed and verified by AI agents through MCP

    Community talivia-group
    gura105

    Operational Ontology

    A minimal, readable reference implementation of the Operational Ontology pattern. Palantir Foundry is one implementation; this is the concept, minimized.

    Community gura105
    EllisMorrow

    Caelune

    Caelune (ζ˜Ÿι‡Ž) β€” Local-first retrieval for private Markdown, PDF, and Tika documents, with a Windows desktop app and read-only MCP server.ο½œζœ¬εœ°δΌ˜ε…ˆηš„η§δΊΊηŸ₯θ―†ζ£€η΄’ε·₯具。

    Community EllisMorrow
    vmware-skills

    VMware AIops

    VMware vCenter/ESXi AI-powered monitoring and operations. Two skills: vmware-monitor (read-only, safe) and vmware-aiops (full operations) | Claude Code Skill

    Community vmware-skills
    asdecided

    AsDecided

    Native deterministic requirements-as-code engine and read-only MCP server.

    Community asdecided