Hevy MCP
The Hevy MCP server enables AI assistants to interact with the Hevy fitness tracking app API for comprehensive fitness data management:
Workout Management: Fetch, create, update, and track workouts with detailed exercise data
Routine Management: Access, create, update, and organize workout routines
Exercise Templates: Browse and retrieve both standard and custom exercise templates
Folder Organization: Create and manage folders to categorize routines effectively
Utilized for code formatting and linting in the development process of the MCP server.
Used for environment variable configuration to store the Hevy API key.
Used for version control of the MCP server codebase.
Hosts the repository for the MCP server codebase.
Provides tools for accessing and managing workout data, routines, exercise templates, and folders through the Hevy fitness app API, enabling workout tracking and fitness management capabilities.
Required as a runtime environment (v20 or higher) for running the MCP server.
Used as a package manager for installing and managing dependencies of the MCP server.
Provides badge for license information in the README.
Supported as an alternative package manager for installing and managing dependencies.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Hevy MCPshow me my last 3 workouts"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Hevy MCP Server
Talk to your Hevy workout data from Claude, Cursor, Codex, and other MCP clients.
Connect to the hosted MCP · Use the Hevy CLI · Watch the 18-second demo · Explore all 26 tools
Hevy CLI
Prefer the terminal? The separate
@chrisdoc/hevy-cli
package reads workouts, routines, exercises, and body measurements directly
from the Hevy API, and can create or update those resources with explicit
confirmation. Deletion is not supported.
npm install -g @chrisdoc/hevy-cli
export HEVY_API_KEY=your-hevy-api-key
hevy workouts list --page-size 10
hevy summary --weeks 4Add --json to any command for scripts and pipelines. The CLI is a standalone
Hevy API client, not an MCP wrapper. See
packages/cli/README.md for the full command
reference, pagination behavior, and exit codes.
hevy-mcp is an open-source Model Context Protocol (MCP)
server for the Hevy fitness and workout tracking
app. It lets AI assistants read, analyze, create, and update your Hevy workouts,
routines, exercise templates, and body measurements through authenticated Hevy
API requests.
The repository is organized as a private workspace with explicit runtime
boundaries: @hevy-mcp/hevy-client owns the web-safe Hevy client,
@hevy-mcp/core owns MCP tools and server construction, hevy-mcp is the
published Node.js stdio adapter, and @hevy-mcp/worker is the private
Cloudflare HTTP/OAuth adapter. Only the Node workspace is publishable.
A Hevy API key, available with Hevy PRO, is required.
Related MCP server: hevy-mcp
See it in action

In the demo, the assistant retrieves real Hevy data and answers a multi-part training question with evidence from the user's workout history.
What can you do with it?
Analyze training progress: summarize 1-12 weeks of workouts and body measurements in one tool call.
Ask questions in plain language: find recent sessions, frequently trained exercises, consistency gaps, routine details, or exercise history.
Plan and log training: create or update workouts, routines, routine folders, custom exercises, and body measurements.
Search without huge responses: discover routines and exercise templates with compact, AI-friendly results.
Connect from your preferred MCP client: use the hosted Streamable HTTP endpoint or run locally with Codex, Claude Desktop, Cursor, and other clients.
Start without installing anything: connect directly to the production Cloudflare Worker—no Node.js, package download, or Docker container required.
Keep local control when you want it: run the same server with
npx,bunx, or the official Docker image.
Try asking:
Analyze my training over the last six weeks. Show workouts per week, my most frequently trained exercises, any obvious gaps or inconsistencies, and cite the workout evidence you used.
Find my push-day routine and show its exercises and sets.
Compare my recent body measurements with my training consistency.
Create a completed workout from my saved routine. Ask me for any missing set results before writing it to Hevy.
Quick start
1. Get your Hevy API key
Create an API key in Hevy, then keep it somewhere secure. API access currently requires a Hevy PRO subscription.
2. Connect hevy-mcp to your client
The hosted Cloudflare endpoint is the fastest way to start. It runs remotely, so your client does not need Node.js, Bun, Docker, or a local server process.
Connect to the hosted endpoint
Production URL:
https://mcp.hevy-mcp.dev/mcpThe endpoint uses Streamable HTTP. Send your Hevy API key as a bearer token on every request.
Codex
Codex CLI, the Codex desktop app, and the IDE extension share the same MCP configuration. Make your Hevy API key available in the environment that starts Codex, then add the hosted server:
export HEVY_API_KEY=your-hevy-api-key
codex mcp add hevy \
--url https://mcp.hevy-mcp.dev/mcp \
--bearer-token-env-var HEVY_API_KEYCodex stores the environment variable name, not the key itself, in its MCP
configuration. Restart Codex or begin a new session, then run codex mcp list
to verify the server is configured.
Other Streamable HTTP clients
Clients that accept a remote MCP URL and fixed headers commonly use this shape:
{
"mcpServers": {
"hevy": {
"url": "https://mcp.hevy-mcp.dev/mcp",
"headers": {
"Authorization": "Bearer your-hevy-api-key"
}
}
}
}Exact configuration keys vary by client. The hosted server requires support for
Streamable HTTP and a fixed Authorization header.
Treat the bearer value like a password. The Worker validates it with Hevy for
each request, does not store it, and forwards it to Hevy only as the requiredapi-key header.
Run locally instead
Choose local stdio if you prefer to run the server on your own machine or your client cannot attach a fixed authorization header to remote MCP requests.
Codex
codex mcp add hevy \
--env HEVY_API_KEY=your-hevy-api-key \
-- npx -y hevy-mcpClaude Desktop or Cursor
Add this mcpServers entry to your client configuration:
{
"mcpServers": {
"hevy": {
"command": "npx",
"args": ["-y", "hevy-mcp"],
"env": {
"HEVY_API_KEY": "your-hevy-api-key"
}
}
}
}Google Antigravity
There are two ways to configure the Hevy MCP server for Google Antigravity (agy):
Option A: Automatic Plugin Installation (Recommended)
This utilizes the built-in plugin system:
Install the plugin:
agy plugin install https://github.com/chrisdoc/hevy-mcpProvide the
HEVY_API_KEYin your host shell environment so the CLI child process can inherit it:Persistent: Save the environment variable
HEVY_API_KEYin your system/shell configurations:macOS / Linux: Add it to your shell profile configurations (e.g.,
~/.zshrcor~/.bashrc):export HEVY_API_KEY="your-actual-api-key"Windows: Add it to your User or System Environment Variables. In PowerShell, you can run:
[Environment]::SetEnvironmentVariable("HEVY_API_KEY", "your-actual-api-key", "User")
Temporary (Session-only): If you do not want to persist the key, export it in your active terminal session before running
agy:export HEVY_API_KEY="your-actual-api-key"
Option B: Manual Configuration (No Plugin)
If you prefer configuring it statically via the global configuration file:
Open your global MCP configuration file:
Location:
~/.gemini/config/mcp_config.json
Add the
hevyconfiguration block under themcpServerskey. Make sure to merge this entry with any existing servers you have configured rather than replacing the entire file contents:{ "mcpServers": { "hevy": { "command": "npx", "args": ["-y", "hevy-mcp"], "env": { "HEVY_API_KEY": "your-actual-api-key" } } } }
Common local configuration locations:
Claude Desktop on macOS:
~/Library/Application Support/Claude/claude_desktop_config.jsonClaude Desktop on Windows:
%APPDATA%\Claude\claude_desktop_config.jsonCursor:
~/.cursor/mcp.json
Restart or reconnect the client after saving the file.
Any stdio MCP client
Configure your client to launch this command with HEVY_API_KEY in the child
process environment:
npx -y hevy-mcpnpx requires Node.js 20 or newer. Restart or reconnect your client after
saving its configuration.
Requires Bun:
{
"mcpServers": {
"hevy": {
"command": "bunx",
"args": ["hevy-mcp@latest"],
"env": {
"HEVY_API_KEY": "your-hevy-api-key"
}
}
}
}Official images support linux/amd64 and linux/arm64. Keep stdin open with
-i because the container runs the stdio MCP server:
export HEVY_API_KEY=your-hevy-api-key
docker run -i --rm -e HEVY_API_KEY ghcr.io/chrisdoc/hevy-mcp:latestFor an MCP client, store the key in a protected environment file and configure the client to launch Docker:
{
"mcpServers": {
"hevy": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"--env-file",
"/absolute/path/to/hevy-mcp.env",
"ghcr.io/chrisdoc/hevy-mcp:latest"
]
}
}
}Pin an exact image tag such as ghcr.io/chrisdoc/hevy-mcp:X.Y.Z when you need
reproducible upgrades.
You can also add the npm server to supported clients with
add-mcp:
npx add-mcp hevy-mcp --env "HEVY_API_KEY=your-hevy-api-key"3. Ask your first question
Try one of these after restarting or reconnecting your MCP client:
“Give me a training summary for the last four weeks.”
“What routines do I have saved on Hevy?”
“Show my three most recent workouts.”
“Find exercise templates containing squat.”
“Which Hevy account is connected?”
Your assistant should ask for approval before mutation tools when the client supports tool confirmations.
How it works
Hosted: Your AI assistant → Streamable HTTP → Cloudflare Worker → Hevy API
Local: Your AI assistant → MCP over stdio → local hevy-mcp → Hevy APIThe hosted endpoint creates a fresh MCP server and Hevy client for each request. It validates the supplied key with Hevy, keeps no shared user session, and does not persist the key. The local server follows the same tool contract but runs on your machine and receives the key through its child-process environment.
In either mode, read tools retrieve data; mutation tools create or replace data only when your assistant calls them.
Guided prompts
These server-provided MCP prompts coordinate common multi-step workflows:
Prompt | Arguments | Workflow |
| Optional | Calls |
| Required | Loads a routine, collects actual completed-set data and an end time, then creates a workout without inventing results. |
With MCP SDK v1.29.0, clients invokinganalyze-workout-progress with its
default value must send arguments: {}. Omitting the entire arguments
object is rejected by that SDK version before the default is applied.
Tools
hevy-mcp registers 26 tools. Read-only tools are safe for exploration; create
and update tools are exposed with MCP mutation annotations so compatible clients
can request confirmation.
Category | Tool | Description |
Training analysis |
| Summarize 1-12 weeks of workout activity and body-measurement trends in one call. |
Workouts |
| List workouts from newest to oldest with exercise and timing details. |
Workouts |
| Get complete details for one workout by ID. |
Workouts |
| Return the account's total workout count. |
Workouts |
| List workout update and delete events since a timestamp. |
Workouts |
| Create a completed workout in Hevy. |
Workouts |
| Patch workout metadata by ID; omitted fields and all exercises remain unchanged. |
Workouts |
| Replace all exercises and sets while preserving workout metadata. |
Routines |
| Search routine titles and return compact metadata for discovery. |
Routines |
| List custom and default workout routines. |
Routines |
| Get one routine and its exercise configuration by ID. |
Routines |
| Create a reusable workout routine. |
Routines |
| Replace an existing routine's content. |
Routine folders |
| List default and custom routine folders. |
Routine folders |
| Get one routine folder's metadata by ID. |
Routine folders |
| Create a routine folder. |
Exercise templates |
| List exercise templates with equipment and muscle metadata. |
Exercise templates |
| Get complete metadata for one exercise template by ID. |
Exercise templates |
| Search the full exercise catalog by title substring. |
Exercise templates |
| Create a custom exercise template. |
Exercise history |
| Get past performed sets for one exercise template. |
Body measurements |
| List dated body measurements. |
Body measurements |
| Get the body measurement entry for one date. |
Body measurements |
| Create a dated body measurement. |
Body measurements |
| Update the body measurement for an existing date. |
Account |
| Return the user's ID, display name, and public profile URL. |
The Hevy API currently exposes no delete endpoints for workouts, routines, routine folders, exercise templates, or body measurements, so there are no corresponding delete tools.
Resources
Name | URI | Description |
|
| Authenticated Hevy user profile. |
|
| Total number of workouts in the account. |
|
| Full formatted exercise template catalog. |
|
| Full formatted list of Hevy routine folders. |
Hosted Cloudflare endpoint
The production MCP server is live at:
https://mcp.hevy-mcp.dev/mcpIt is the quickest way to use hevy-mcp: there is nothing to install or keep
running locally, and it exposes the same 26 tools as the npm package and Docker
image.
The Cloudflare Worker uses stateless Streamable HTTP at POST /mcp.
Clients must send their Hevy API key as a fixed authorization header:
{
"mcpServers": {
"hevy": {
"url": "https://mcp.hevy-mcp.dev/mcp",
"headers": {
"Authorization": "Bearer your-hevy-api-key"
}
}
}
}The bearer value is your Hevy API key, not an OAuth token. The Worker validates
the key with Hevy on each request, does not store it, and forwards it upstream
only as Hevy's required api-key header.
OAuth for Claude.ai and other remote MCP clients
The hosted production Worker is deployed with an OAUTH_KV namespace binding,
so it exposes a full OAuth 2.1 layer for clients that cannot send a fixed
header, such as Claude.ai custom connectors. Self-hosted Workers can opt in by
following the OAUTH_KV setup in CONTRIBUTING.md:
RFC 8414 / RFC 9728 discovery metadata under
/.well-known/Dynamic client registration (
/register) and PKCE token exchange (/token)An
/authorizepage where you paste your Hevy API key once; the key is validated with Hevy and stored encrypted inside the OAuth grant
Add the Worker URL ending in /mcp as a Claude.ai custom connector and
complete the authorization flow in the browser. Direct
Authorization: Bearer <hevy-api-key> requests keep working unchanged — the
OAuth layer is purely additive — and rotating your Hevy API key invalidates
every OAuth grant created with it.
OAuth access tokens last seven days and refresh tokens last 30 days. This reduces KV writes from frequent hourly refreshes while preserving automatic refresh for supported clients.
The endpoint does not expose legacy SSE or a GET event stream. Without the
opt-in OAuth layer, clients that require OAuth discovery, dynamic
registration, or token refresh are not compatible unless they can send the
fixed custom header above.
Self-host the Worker
A clean clone can deploy the portable TypeScript Wrangler configuration with
npx wrangler deploy --x-new-config and receive a workers.dev URL. OAuth
requires your own OAUTH_KV namespace; custom domains, routes, and
observability destinations are optional account-owned settings. See
CONTRIBUTING.md for setup and
for the distinction between self-hosting and the maintainer-only named
environments.
See CONTRIBUTING.md to deploy the Cloudflare Worker for self-hosted Streamable HTTP.
Advanced configuration
Setting | Default | Scope | Notes |
| None; required | Local stdio or HTTP | Hevy API key from the Hevy app. Never pass it in a URL. |
|
| Local stdio | Positive Hevy API timeout in milliseconds. Invalid values fall back to 30 seconds. |
| Disabled | Local Node | Set to exactly |
| None | Non-loopback HTTP | Required when |
| Enabled | Local Node | Set to exactly |
|
| Local stdio | Changes the root for the npm update-check cache at |
| Packaged project DSN | Optional local Node telemetry | Sentry-only override for the destination. An empty value disables Sentry export. The Worker does not import Node telemetry. |
|
| Optional local Node telemetry | Overrides the release label attached to local Sentry events and traces. |
| N/A | Local stdio CLI | Print supported options and exit. |
| N/A | Local stdio CLI | Print the installed version and exit. |
The local Node executable uses stdio by default. Opt into local Streamable HTTP with:
HEVY_API_KEY=your-hevy-api-key npx hevy-mcp --transport http --host 127.0.0.1 --port 3000The local MCP endpoint is http://127.0.0.1:3000/mcp; non-loopback binds
require the separate HEVY_MCP_HTTP_BEARER_TOKEN environment variable. A
Docker deployment must publish the port explicitly:
docker run --rm -p 3000:3000 -e HEVY_API_KEY -e HEVY_MCP_HTTP_BEARER_TOKEN \\
ghcr.io/chrisdoc/hevy-mcp:latest --transport http --host 0.0.0.0 --port 3000This Node HTTP mode is distinct from the stateless Cloudflare Worker HTTP endpoint described above: the Node server owns stateful client sessions, while the Worker is designed for hosted deployment and does not import Node code.
Cache behavior
search-exercise-templates and hevy://exercise-templates share a
server-scoped in-memory catalog cache:
Entries live for five minutes, and the cache holds at most one catalog.
Concurrent catalog requests share an in-flight fetch when possible.
search-exercise-templatesacceptsrefresh: trueto invalidate the cache.Paginated
get-exercise-templatescalls always fetch their requested page.Each hosted Worker request gets a fresh cache, preventing cross-key sharing.
Local Node telemetry and privacy
The local Node package enables project telemetry by default. It is local Node
behavior only; the Cloudflare Worker does not import Node telemetry. Set
HEVY_MCP_TELEMETRY=0 before startup or import to disable all project
telemetry. Only the literal value 0 opts out: an unset value, an empty value,
1, false, and every other value remain enabled. The master setting takes
precedence over SENTRY_DSN and packaged or runtime OTEL_COLLECTOR_TOKEN
credentials, so the disabled path creates no telemetry exporters or periodic
metric readers and makes no telemetry network requests. SENTRY_DSN remains a
Sentry-only setting; when telemetry is enabled, an empty value disables only
Sentry export.
When enabled, errors and traces are sent to the packaged Sentry project at https://o4508975499575296.ingest.de.sentry.io/4509049671647312. Traces and metrics are sent to the collector at https://otel.chrisdoc.dev/v1/traces and https://otel.chrisdoc.dev/v1/metrics, which forward to Honeycomb. Metrics export every 10 seconds.
The API key is never exported. Enabled telemetry derives a deterministic ten-character HMAC-SHA-256 pseudonym from it solely for cross-span correlation. The pseudonym is attached to spans only, never used as a metric dimension, and is not intended for per-user behavior histories.
The privacy allowlist contains service/version/transport; fixed tool feature, read/write kind, operation, and short-lived tool name; bounded outcome/error/count/retry/duration/session/cache/workflow values; normalized API method/endpoint/status; shape-only key names, presence, count, and boolean fields; sanitized client/protocol tokens; and the span-only pseudonym. It explicitly prohibits raw prompts, tool argument values, tool result content, request bodies, API keys, raw identifiers/queries/exact dates, workout/routine/folder/template/body-measurement content, names/titles/ descriptions/notes, measurement values, arbitrary client metadata, and unnormalized endpoint paths.
Security and mutations
Keep
HEVY_API_KEYout of source control, URLs, logs, and screenshots.Local clients provide the key through the child process environment.
Hosted clients send the key only in the
Authorization: Bearerheader. The Worker validates each key with Hevy, does not store it, and sends it upstream only as Hevy'sapi-keyheader.Browser requests must come from an exact allowlisted origin. The default allowlist includes Claude.ai, ChatGPT, VS Code for the Web, and github.dev; self-hosted deployments can override it with
MCP_ALLOWED_ORIGINS.Local development can copy
.dev.vars.exampleto.dev.varsto disable Origin validation for MCP Inspector. PR preview Workers use the same development-only setting because their browser origins are dynamic. Never setMCP_DISABLE_ORIGIN_CHECK=trueon a production Worker.Create operations can produce duplicates when retried. Update operations replace existing records. Review tool inputs and use client confirmations.
Troubleshooting
The server does not appear: restart or reconnect your MCP client after changing its configuration.
npxfails: confirm that Node.js 20 or newer is installed, then runnpx -y hevy-mcp --versionin a terminal.Codex cannot see the server: run
codex mcp list, then start a new Codex session after confirming thehevyentry exists.Hosted authentication fails: confirm the key is active, belongs to a Hevy PRO account, and is sent as
Authorization: Bearer <HEVY_API_KEY>.Local authentication fails: confirm the key is active and available to the MCP child process as
HEVY_API_KEY.Need diagnostics: set
HEVY_MCP_DEBUG=1. Diagnostic output goes to stderr and does not interfere with MCP messages on stdout.
If you find a bug or have a feature request, open an issue.
Contributing
Contributions are welcome. Developer setup, testing lanes, generated-client workflows, Cloudflare Worker deployment, and pull request rules are documented in CONTRIBUTING.md.
License and acknowledgements
License: MIT
Credits: Model Context Protocol and Hevy Fitness
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityCmaintenancePython MCP server for the Hevy fitness app. Gives Claude full access to your Hevy data. Log workouts, manage routines, track body measurements, browse exercises, and more. Covers all 25 endpoints of the official Hevy API.Last updatedMIT
- AlicenseAqualityBmaintenanceAn MCP server that interfaces with the Hevy fitness tracking API, enabling AI assistants to manage workouts, routines, exercise templates, and more via natural language.Last updated264,871MIT
- Alicense-qualityCmaintenanceA Model Context Protocol (MCP) server that provides AI assistants with access to the Hevy fitness tracking API. This allows you to log workouts, manage routines, browse exercises, and track your fitness progress directly through AI chat interfaces.Last updated4MIT
Related MCP Connectors
Create Hevy routines and analyze your training from chat. Unofficial; BYO Hevy PRO API key.
A comprehensive Model Context Protocol (MCP) server that enables AI assistants to interact with yo…
MCP (Model Context Protocol) server for Appwrite
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/chrisdoc/hevy-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server