Oura Ring Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Oura Ring Mcp (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP server that connects your Oura Ring to Claude and other AI assistants. Get human-readable insights about your sleep, readiness, and activity—not just raw JSON.
<img src="docs/outputs/demo.gif" width="500" alt="Demo">
See example outputs — what Claude returns for sleep, readiness, weekly summaries, and smart analysis
npm install -g oura-ring-mcpOr use directly with npx (no install needed):
npx oura-ring-mcpOption A: Personal Access Token (simpler)
OURA_ACCESS_TOKEN in your Claude Desktop config (see below)Option B: OAuth CLI Flow
http://localhost:3000/callback export OURA_CLIENT_ID=your_client_id
export OURA_CLIENT_SECRET=your_client_secret
npx oura-ring-mcp auth~/.oura-mcp/credentials.jsonAdd to claude_desktop_config.json:
With Personal Access Token:
{
"mcpServers": {
"oura": {
"command": "npx",
"args": ["oura-ring-mcp"],
"env": {
"OURA_ACCESS_TOKEN": "your_token_here"
}
}
}
}With OAuth (after running `npx oura-ring-mcp auth`):
{
"mcpServers": {
"oura": {
"command": "npx",
"args": ["oura-ring-mcp"]
}
}
}The server reads credentials from ~/.oura-mcp/credentials.json. To enable automatic token refresh, add your OAuth credentials:
{
"mcpServers": {
"oura": {
"command": "npx",
"args": ["oura-ring-mcp"],
"env": {
"OURA_CLIENT_ID": "your_client_id",
"OURA_CLIENT_SECRET": "your_client_secret"
}
}
}
}Restart Claude Desktop. Requires Node >=18.
Daily check-ins:
Patterns & trends:
Correlations & insights:
Comparisons:
Anomalies:
| Tool | Description |
|---|---|
get_sleep | Sleep data with stages, efficiency, HR, HRV |
get_daily_sleep | Daily sleep scores with contributors |
get_readiness | Readiness scores and recovery metrics |
get_activity | Steps, calories, intensity breakdown |
get_workouts | Workout sessions with type and intensity |
get_sessions | Meditation and relaxation sessions |
get_heart_rate | HR readings throughout the day |
get_stress | Stress levels and recovery time |
get_spo2 | Blood oxygen and breathing disturbance |
get_tags | User-created tags and notes |
| Tool | Description |
|---|---|
detect_anomalies | Find unusual readings using outlier detection |
analyze_sleep_quality | Sleep analysis with trends, patterns, debt |
correlate_metrics | Find correlations between health metrics |
compare_periods | Compare this week vs last week |
compare_conditions | Compare metrics with/without a tag |
best_sleep_conditions | What predicts your good vs poor sleep |
analyze_hrv_trend | HRV trend with rolling averages |
| Resource | Description |
|---|---|
oura://today | Today's health summary |
oura://weekly-summary | Last 7 days with averages |
oura://baseline | Your 30-day averages and normal ranges |
oura://monthly-insights | 30-day analysis with trends and anomalies |
oura://tag-summary | Your tags and usage frequency |
| Prompt | Description |
|---|---|
weekly-review | Comprehensive weekly health review |
sleep-optimization | Identify what leads to your best sleep |
recovery-check | Should you train hard or rest today? |
compare-weeks | This week vs last week comparison |
tag-analysis | How a specific tag affects your health |
Deploy the MCP server for remote access. The server proxies OAuth through Oura, so users authenticate directly with their Oura account — no PAT needed.
https://your-app.railway.app/oauth/callback# Install Railway CLI
npm install -g @railway/cli
# Login, init, and deploy
railway login
railway init
railway upIn the Railway dashboard, add:
| Variable | Description |
|---|---|
OURA_CLIENT_ID | From your Oura OAuth app |
OURA_CLIENT_SECRET | From your Oura OAuth app |
NODE_ENV | production |
MCP_SECRET | (Optional) Static bearer token for Claude Desktop (openssl rand -base64 32) |
OURA_ACCESS_TOKEN | (Optional) PAT fallback if not using OAuth (MCP_SECRET required) |
Railway automatically sets PORT and RAILWAY_PUBLIC_DOMAIN.
Use the connector in Claude.ai:
https://your-app.railway.app (without /mcp)For Claude Desktop, use MCP_SECRET + OURA_ACCESS_TOKEN:
{
"mcpServers": {
"oura-remote": {
"url": "https://your-app.railway.app/mcp",
"headers": {
"Authorization": "Bearer your_mcp_secret_here"
}
}
}
}# With Oura OAuth (full flow)
OURA_CLIENT_ID=your_id OURA_CLIENT_SECRET=your_secret pnpm start:http
# With static secret only (requires OURA_ACCESS_TOKEN)
OURA_ACCESS_TOKEN=your_pat MCP_SECRET=test-secret pnpm start:http
# Verify health endpoint
curl http://localhost:3000/health
# Check OAuth metadata (only available when OURA_CLIENT_ID is set)
curl http://localhost:3000/.well-known/oauth-authorization-server
# Test authenticated request (with static secret)
curl -X POST http://localhost:3000/mcp \
-H "Authorization: Bearer test-secret" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","method":"initialize","params":{"capabilities":{}},"id":1}'See CLAUDE.md for architecture details and development guidelines.
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.