Back to Home
chrisdoc icon

hevy-mcp

Verified Safe

by chrisdoc

Overview

This server acts as a Model Context Protocol (MCP) interface, enabling AI assistants to interact with the Hevy fitness tracking app's API to manage workout data, routines, exercise templates, folders, and webhook subscriptions.

Installation

Run Command
HEVY_API_KEY=your_hevy_api_key_here npx -y hevy-mcp

Environment Variables

  • HEVY_API_KEY

Security Notes

The server securely handles the Hevy API key via environment variables or CLI arguments. Webhook URL validation is implemented to prevent common SSRF vulnerabilities (e.g., disallowing localhost/loopback addresses). A Sentry DSN is hardcoded for observability of the tool itself, but PII collection is explicitly disabled, mitigating direct user data exposure risks. Users who wish to fully disable telemetry would need to fork the repository.

Similar Servers

Stats

Interest Score51
Security Score8
Cost ClassMedium
Avg Tokens2000
Stars103
Forks25
Last Update2026-01-19

Tags

mcphevyfitnessapiworkoutroutineexercisewebhook