cronometer-api-mcp
MCP server for Cronometer nutrition tracking using the mobile API. Enables food logging, nutrition data retrieval, diary management, and fasting tracking.
README
cronometer-api-mcp
<!-- mcp-name: io.github.rwestergren/cronometer-api-mcp -->
Hosted version for Claude.ai, ChatGPT, and Grok coming soon. Join the waitlist →
An MCP (Model Context Protocol) server for Cronometer nutrition tracking, built on the reverse-engineered mobile REST API.
Unlike cronometer-mcp, which takes a comprehensive GWT-RPC approach against Cronometer's web backend, this server talks to the same JSON REST API used by the Cronometer Android app -- with clean payloads and stable, versioned endpoints.
Features
- Food log -- diary entries with food names, amounts, meal groups
- Nutrition data -- daily macro/micro totals and nutrition scores with per-nutrient confidence
- Food search -- search the Cronometer food database, get detailed nutrition info
- Diary management -- add/remove entries, copy days, mark days complete
- Custom foods -- create foods with custom nutrition data
- Macro targets -- read weekly schedule and saved templates
- Fasting -- view history and aggregate statistics
- Biometrics -- weight, body fat, heart rate, and other tracked metrics over a date range
Quick Start
1. Install uv
curl -LsSf https://astral.sh/uv/install.sh | sh
2. Set credentials
export CRONOMETER_USERNAME="your@email.com"
export CRONOMETER_PASSWORD="your-password"
3. Configure your MCP client
uvx downloads and runs the server on demand -- no separate install step.
OpenCode (opencode.json)
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"cronometer": {
"type": "local",
"command": ["uvx", "cronometer-api-mcp"],
"environment": {
"CRONOMETER_USERNAME": "{env:CRONOMETER_USERNAME}",
"CRONOMETER_PASSWORD": "{env:CRONOMETER_PASSWORD}"
},
"enabled": true
}
}
}
Claude Desktop (claude_desktop_config.json)
{
"mcpServers": {
"cronometer": {
"command": "uvx",
"args": ["cronometer-api-mcp"],
"env": {
"CRONOMETER_USERNAME": "your@email.com",
"CRONOMETER_PASSWORD": "your-password"
}
}
}
}
Available Tools
Food Log & Nutrition
| Tool | Description |
|---|---|
get_food_log |
Diary entries for a date, each enriched with food name, source, serving measure/count, and that food's per-entry nutrient contribution, plus an energy_summary (target/consumed/remaining kcal) and a nutrition_summary of consumed totals for every tracked nutrient |
get_daily_nutrition |
Consumed macro and micronutrient totals for every nutrient tracked in Cronometer |
get_nutrition_scores |
Category scores (Vitamins, Minerals, etc.) with per-nutrient consumed amounts and confidence levels |
Food Search & Details
| Tool | Description |
|---|---|
search_foods |
Search the Cronometer food database by name |
get_food_details |
Full nutrition profile and serving sizes for a food |
Targets & Tracking
| Tool | Description |
|---|---|
get_macro_targets |
Weekly macro schedule and saved target templates |
get_fasting_history |
Fasting history within a date range |
get_fasting_stats |
Aggregate fasting statistics |
All date parameters use YYYY-MM-DD format and default to today when omitted.
Diary Management
| Tool | Description |
|---|---|
add_food_entry |
Log a food serving to the diary |
remove_food_entry |
Permanently delete diary entries — no undo |
add_custom_food |
Create a custom food with specified nutrition |
copy_day |
Copy all entries from the previous day |
mark_day_complete |
Mark a diary day as complete or incomplete |
FORK: hardened fork, read/write. This fork ran read-only through its first eight phases; the owner enabled writes on 2026-07-27. Write tools carry
readOnlyHint: Falseandremove_food_entrycarriesdestructiveHint: True, so clients can warn before mutating. Every tool — read and write — is rate-limited and audited. The biometrics tools (list_biometrics,get_biometrics) remain removed, holding the surface at exactly 13.tests/test_tool_surface.pypins that surface in both directions.Date ranges are capped at 90 days per call, calls are rate-limited to 60/hour, and every call is logged (shapes and counts only, never contents). See
CLAUDE.mdfor the constraints,AUDIT.mdfor the upstream security review, andRUNBOOK.mdfor operations.
Remote Deployment
The server supports remote deployment with OAuth 2.1 authorization (PKCE) for use with Claude.ai and other remote MCP clients.
Environment Variables
| Variable | Required | Description |
|---|---|---|
CRONOMETER_USERNAME |
Yes | Cronometer account email |
CRONOMETER_PASSWORD |
Yes | Cronometer account password |
MCP_TRANSPORT |
No | Transport mode: stdio (default), sse, or streamable-http |
MCP_AUTH_TOKEN |
Remote | HMAC key used to sign and verify access tokens |
MCP_OAUTH_CLIENT_ID |
Remote | OAuth client ID, verified at /token |
MCP_OAUTH_CLIENT_SECRET |
Remote | OAuth client secret, verified at /token |
MCP_AUTHORIZE_PASSPHRASE |
Remote | FORK: required to complete /authorize |
MCP_BASE_URL |
Remote | Public base URL; must match the deployed URL exactly |
MCP_ALLOWED_REDIRECT_ORIGINS |
No | FORK: allowed OAuth redirect origins (default https://claude.ai,https://claude.com) |
PORT |
No | Listen port for remote transports (default 8000) |
FORK: the four variables marked Remote are mandatory whenever
MCP_TRANSPORTissseorstreamable-http— the server refuses to start without them. Upstream treated them as optional and served the diary unauthenticated when they were absent, so a forgotten secret was a silent downgrade to no authentication at all.
Dokku / Heroku Deployment
The project includes a Procfile and .python-version for direct deployment with the Heroku Python buildpack:
# Create app
dokku apps:create cronometer-api-mcp
# Set environment
dokku config:set cronometer-api-mcp \
MCP_TRANSPORT=streamable-http \
MCP_AUTH_TOKEN=$(openssl rand -hex 32) \
MCP_OAUTH_CLIENT_ID=my-client \
MCP_OAUTH_CLIENT_SECRET=$(openssl rand -hex 32) \
MCP_BASE_URL=https://your-domain.com \
CRONOMETER_USERNAME=your@email.com \
CRONOMETER_PASSWORD=your-password
# Deploy
git push dokku main
Claude.ai Remote Connection
When deployed remotely with OAuth configured, connect from Claude.ai using:
- Server URL:
https://your-domain.com/mcp - OAuth Client ID: Value of
MCP_OAUTH_CLIENT_ID - OAuth Client Secret: Value of
MCP_OAUTH_CLIENT_SECRET
Claude.ai will open a browser tab for authorization. Click Authorize to complete the connection.
Development
For local development, copy .env.example to .env and fill in your credentials:
cp .env.example .env
# edit .env
uv run cronometer-api-mcp
The CLI auto-loads .env on startup (dev convenience only). Real environment variables always win over .env, so production deployments and MCP client env blocks are unaffected.
How It Works
This server communicates with mobile.cronometer.com -- the same REST API used by the Cronometer Android/Flutter app. The API was reverse-engineered through:
- Static analysis of
libapp.so(Dart AOT snapshot) from the APK to discover endpoint names - Traffic interception via Frida + mitmproxy to capture exact request/response formats
- Trial-and-error against the live API to confirm payload shapes
The API uses two protocols:
- v2 (
POST /api/v2/*) -- JSON-body auth, used for most operations (food search, diary read/write, nutrition, fasting, macros, biometrics) - v3 (
DELETE /api/v3/user/{id}/*) -- Header-based auth (x-crono-session), used for diary entry deletion
Python API
You can use the client directly:
from cronometer_api_mcp.client import CronometerClient
from datetime import date
client = CronometerClient()
# Search for foods
results = client.search_food("chicken breast")
# Get food details
food = client.get_food(results[0]["id"])
# Log a serving
client.add_serving(
food_id=food["id"],
measure_id=food["defaultMeasureId"],
grams=200,
)
# Get today's diary
diary = client.get_diary()
# Get nutrition scores
scores = client.get_nutrition_scores()
License
MIT
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。