Whoop Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Whoop Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Model Context Protocol (MCP) server that gives Claude access to your WHOOP biometric data — recovery, sleep, strain, and workouts.
Ask Claude things like:
This app accesses your WHOOP data locally on your device. No data is sent to any third-party server.
| Tool | What it returns |
|---|---|
get_recovery | Recovery score, HRV, resting HR, SpO2 |
get_sleep | Sleep duration, stages (light/deep/REM), efficiency, respiratory rate |
get_strain | Day strain score, avg/max HR, calories |
get_latest_workout | Most recent workout — sport, duration, strain, HR zones |
get_recovery_trend | Recovery scores over N days (default 7) |
get_sleep_trend | Sleep data over N days (default 7) |
get_workout_history | Recent workout history (default 5) |
get_profile | Profile + body measurements |
whoop-mcp (or anything)http://localhost:8080/callbackofflinenpm install -g @souravpn/whoop-mcpThis opens your browser, you log into WHOOP, and your tokens are saved to ~/.whoop-mcp-tokens.json:
WHOOP_CLIENT_ID=your_id WHOOP_CLIENT_SECRET=your_secret whoop-mcp-auth-setupYou only need to do this once. The server will auto-refresh tokens after that.
Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS):
{
"mcpServers": {
"whoop": {
"command": "@souravpn/whoop-mcp",
"env": {
"WHOOP_CLIENT_ID": "your_client_id",
"WHOOP_CLIENT_SECRET": "your_client_secret"
}
}
}
}Restart Claude Desktop. You should see a green "running" badge in Settings → Developer.
Open a new chat and ask:
How's my recovery today?Daily check-in:
What's my recovery, sleep, and strain for today?Trend analysis:
How has my HRV trended over the past 7 days?Workout correlation:
Look at my workouts this week and my recovery scores
the day after each one. Is there a pattern?Full briefing:
Give me a complete health briefing — recovery, last
night's sleep breakdown, and any workouts from yesterdayIf you also use Oura Ring, you can run both MCP servers together and ask Claude to cross-reference:
{
"mcpServers": {
"whoop": {
"command": "/path/to/whoop-mcp",
"env": { "WHOOP_ACCESS_TOKEN": "your_whoop_token" }
},
"oura": {
"command": "/path/to/oura-mcp",
"env": { "OURA_ACCESS_TOKEN": "your_oura_token" }
}
}
}Then ask:
Compare my WHOOP and Oura HRV readings for this week.
Do they agree? Which is trending higher?git clone https://github.com/yourusername/whoop-mcp
cd whoop-mcp
npm install
npm run build
# Test locally
WHOOP_ACCESS_TOKEN=your_token node dist/index.jswhoop-mcp/
├── src/
│ ├── index.ts # MCP server + tool definitions
│ └── whoop.ts # WHOOP API client + formatters
├── package.json
├── tsconfig.json
└── README.mdPRs welcome. Some ideas for extension:
MIT
Built with the MCP TypeScript SDK and the WHOOP Developer API.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.