Mcp Hevy Pro — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp Hevy Pro (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A production-ready Model Context Protocol server for the Hevy fitness API. Exposes 27 tools for reading, writing, and analyzing your workout data — designed for "personal trainer via LLM" workflows in Claude Desktop, Claude Code, and Cursor.
Compared to the existing community Hevy MCP server, hevy-mcp-pro adds:
/exercise_history endpoint (one call, full history) instead of paginating all workouts.Retry-After, and never logs your API key.duplicate_workout, routine_from_workout, compare_workouts.Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):
{
"mcpServers": {
"hevy": {
"command": "npx",
"args": ["-y", "@cdorneles/hevy-mcp-pro"],
"env": {
"HEVY_API_KEY": "your-key-here"
}
}
}
}Restart Claude Desktop and you should see "hevy" in the MCP tool picker.
Add to ~/.cursor/mcp.json:
{
"mcpServers": {
"hevy": {
"command": "npx",
"args": ["-y", "@cdorneles/hevy-mcp-pro"],
"env": { "HEVY_API_KEY": "your-key-here" }
}
}
}claude mcp add hevy npx -- -y @cdorneles/hevy-mcp-pro
# then set HEVY_API_KEY in the resulting config| Tool | Purpose |
|---|---|
list_workouts | Paginate workouts (max pageSize 10 — Hevy API limit) |
get_workout | Fetch a single workout with all sets |
get_workout_count | Total workout count for the account |
get_workout_events | Sync incremental updates/deletes since a timestamp |
list_routines | Paginate routines |
get_routine | Fetch a single routine |
list_exercise_templates | Paginate exercise templates |
get_exercise_template | Fetch one template |
search_exercise_templates | Local fuzzy search across all templates (cached) |
get_exercise_history | Flat history of every set for one exercise |
list_routine_folders | Paginate folders |
get_routine_folder | Fetch one folder |
get_user_info | Authenticated user profile |
| Tool | Purpose |
|---|---|
create_workout | Log a new workout |
update_workout | Modify an existing workout |
create_routine | Create a routine template |
update_routine | Modify an existing routine |
create_routine_folder | Create a new folder |
create_exercise_template | Create a custom exercise |
| Tool | Purpose |
|---|---|
get_exercise_progression | Time series of best set per session for one exercise |
get_personal_records | PRs (heaviest weight, best set, top estimated 1RM) |
get_volume_summary | Volume grouped by exercise / muscle group / week |
get_workout_frequency | Workouts/week, current streak, longest gap |
detect_stagnation | Exercises whose 1RM has plateaued in the last N weeks |
| Tool | Purpose |
|---|---|
duplicate_workout | Re-log a past workout starting now (or at a given time) |
routine_from_workout | Convert a logged workout into a reusable routine |
compare_workouts | Side-by-side diff of two workouts |
All configuration is via environment variables.
| Variable | Required | Default | Description | |||
|---|---|---|---|---|---|---|
HEVY_API_KEY | yes | — | Your Hevy API key | |||
LOG_LEVEL | no | info | error \ | warn \ | info \ | debug |
HEVY_RATE_LIMIT_CAPACITY | no | 10 | Token bucket capacity (max burst) | |||
HEVY_RATE_LIMIT_REFILL_PER_SEC | no | 10 | Token refill rate (requests/sec) | |||
HEVY_ANALYTICS_MAX_PAGES | no | 50 | Soft cap for analytics pagination (50 pages = 500 workouts) | |||
HEVY_CACHE_TTL_MS | no | 3600000 | Exercise template cache TTL (default 1h) |
Once installed, you can ask your LLM things like:
"Show me my bench press progression over the last 3 months."
"What are my current personal records on squats, deadlifts, and bench?"
"Detect any exercises where I've stagnated in the last 8 weeks."
"Duplicate yesterday's workout and start it now."
"Compare my last two leg days."
"How many times did I train chest in March?"
Invalid API key or Hevy PRO subscription requiredConfirm you have a Hevy PRO subscription and that the key from hevy.com/settings?p=developer is correctly set in HEVY_API_KEY. The key never appears in logs, so a typo is the most common cause.
Rate limited by Hevy API (retries exhausted)The default client-side throttle is 10 req/s. If you're running heavy analytics queries against a long workout history, lower HEVY_RATE_LIMIT_REFILL_PER_SEC to e.g. 5 to slow down further.
Analysis limited to first 500 workoutsAnalytics tools paginate workouts with a soft cap. Raise HEVY_ANALYTICS_MAX_PAGES if you need to analyze deeper history. Each page is up to 10 workouts.
This server writes structured JSON logs to stderr (stdout is reserved for the MCP protocol). To debug, set LOG_LEVEL=debug and check your MCP client's server log view.
git clone https://github.com/cbotworks/mcp-hevy-pro.git
cd hevy-mcp-pro
pnpm install
pnpm test # 41+ unit tests, no network
pnpm typecheck
pnpm lint
pnpm build # produces dist/ (ESM + CJS + .d.ts)To regenerate the vendored OpenAPI snapshot:
pnpm fetch-openapisrc/
├── client/ HTTP layer (rate limiter, retry, error mapping, paginator)
├── schemas/ Zod schemas for API requests + responses
├── tools/ Tool implementations grouped by domain
│ └── analytics/ Pure analyzers (progression, PRs, volume, frequency, stagnation)
├── utils/ Logger, errors, TTL cache
├── server.ts MCP server: registers tools, wires stdio transport
└── index.ts CLI entry: parses env, fails fast on missing API keyThe HTTP client owns all network I/O. Tools never call fetch directly. Analytics tools are pure functions over data fetched via the client, which makes them trivially fixture-testable.
Issues and PRs welcome. Please run pnpm typecheck && pnpm lint && pnpm test before submitting.
MIT — see LICENSE.
The Hevy team for the public API. The community chrisdoc/hevy-mcp server informed early API exploration but no code was reused.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.