Withings MCP Server

Withings MCP Server

Enables reading Withings smart-scale data (weight, body composition, etc.) through MCP tools, with OAuth2 authentication and automatic token refresh.

Category
访问服务器

README

Withings MCP Server

A Model Context Protocol server that wraps the Withings Health API — including the full OAuth2 handshake and token refresh — so an MCP client (Claude, etc.) can read your smart-scale data: weight, body fat, muscle mass, bone mass, water, and more.

It runs as a remote, hosted server on AWS Lambda (Streamable-HTTP transport), with:

  • Withings credentials in SSM Parameter Store SecureString parameters (KMS-encrypted).
  • OAuth tokens in DynamoDB (encrypted at rest), refreshed automatically.
  • A server-side /callback route that completes the OAuth code exchange for you.
  • A bearer-key guard on the MCP endpoint so only you can reach it.

It also runs locally (single process, JSON-file token cache) for development.


Architecture

  MCP client ──Bearer key──▶  Lambda Function URL
                                   │
                    ┌──────────────┴───────────────┐
                    │  Starlette ASGI app (Mangum)  │
                    │   /mcp       Streamable-HTTP  │──▶ tools
                    │   /callback  OAuth code→token │
                    │   /health                     │
                    └───────┬───────────────┬───────┘
                            │               │
                  SSM SecureString     DynamoDB
                (client_id/secret/key)  (tokens + oauth state)
                            │
                            └──▶ Withings API (account.withings.com, wbsapi.withings.net)

Why Lambda + Streamable-HTTP: the transport runs stateless (one self-contained JSON request/response per call), which maps cleanly onto Lambda — no long-lived SSE connection to hold open. Tokens live in DynamoDB precisely because Lambda containers are ephemeral.


Tools

Tool Description
withings_connection_status Whether an account is linked and when the token expires.
withings_start_authorization Returns an authorization_url to open in a browser to grant access.
withings_get_measurements Weight + body-composition groups, filterable by meastypes, start_date/end_date, days, limit.
withings_get_latest_weight The most recent weigh-in with full body composition.
withings_list_measure_types All Withings measurement type codes with names/units.
withings_disconnect Delete the stored tokens.

Measurement values are returned already decoded (Withings sends value + unit exponent; the server computes value × 10^unit), e.g. {"weight": {"value": 70.5, "unit": "kg"}}.


Prerequisites

  1. A Withings developer account and application: developer.withings.com → Dashboard → create an app. Note the Client ID and Client Secret. You will add a Callback URL after the first deploy (step 5).
  2. AWS account with credentials configured (aws configure).
  3. AWS SAM CLI (brew install aws-sam-cli or install docs) and Python 3.12.

Deploy to AWS (Lambda)

1. Store secrets in SSM Parameter Store

These are KMS-encrypted SecureStrings (default aws/ssm key — no extra cost) and are never placed in the CloudFormation template or Lambda env vars.

WITHINGS_CLIENT_ID=xxxxxxxx \
WITHINGS_CLIENT_SECRET=yyyyyyyy \
./scripts/setup-ssm.sh

The script generates a random MCP API key and prints it — save it, your MCP client sends it as Authorization: Bearer <key>. (Override with MCP_API_KEY=... , or change the SSM prefix with SSM_PREFIX=....)

2. Build

sam build

3. First deploy (redirect URL not known yet)

cp samconfig.toml.example samconfig.toml   # edit region if needed
sam deploy --guided                        # accept defaults; leave PublicBaseUrl empty

When it finishes, note the stack Outputs:

  • FunctionUrl — e.g. https://abc123.lambda-url.eu-west-1.on.aws/
  • McpEndpoint — that URL + mcp
  • RedirectUri — that URL + callback

4. Register the callback in Withings

In your Withings app settings, add the RedirectUri from the outputs (exactly, including https:// and /callback) to the app's Callback URLs.

5. Redeploy with the public base URL

The server needs to know its own address to build the OAuth redirect_uri. Pass the FunctionUrl without a trailing slash:

sam deploy --parameter-overrides \
  "SsmPrefix=/withings-mcp PublicBaseUrl=https://abc123.lambda-url.eu-west-1.on.aws"

That's it — the server is live.


Connect an MCP client

Point your client at the McpEndpoint (.../mcp) with the bearer header.

For a client that supports remote HTTP MCP servers with headers, e.g.:

{
  "mcpServers": {
    "withings": {
      "type": "streamable-http",
      "url": "https://abc123.lambda-url.eu-west-1.on.aws/mcp",
      "headers": { "Authorization": "Bearer YOUR_MCP_API_KEY" }
    }
  }
}

Claude Desktop's stdio config doesn't send custom headers directly. If your client can't attach an Authorization header, use a local bridge such as mcp-remote: npx mcp-remote https://.../mcp --header "Authorization: Bearer YOUR_MCP_API_KEY".

First-run authorization

  1. Ask the client to call withings_start_authorization.
  2. Open the returned authorization_url, sign in to Withings, approve.
  3. You're redirected to /callback, which stores your tokens and shows a success page.
  4. Call withings_connection_status to confirm, then withings_get_latest_weight or withings_get_measurements.

Access tokens are refreshed automatically using the stored refresh token, so this is a one-time step.


Local development

python -m venv .venv && source .venv/bin/activate
pip install -r requirements-dev.txt
cp .env.example .env          # fill in Withings client id/secret
python scripts/run_local.py   # serves http://localhost:8000

Register http://localhost:8000/callback as a callback URL in your Withings app and set PUBLIC_BASE_URL=http://localhost:8000 in .env. Tokens are cached to ~/.withings-mcp/tokens.json. The MCP endpoint is http://localhost:8000/mcp.

Run the tests (no network/AWS needed):

pytest

Security notes

  • Secrets never leave SSM except as decrypted values inside the Lambda execution environment. The IAM role grants ssm:GetParameter* scoped to <prefix>/* and kms:Decrypt only ViaService ssm.
  • The MCP endpoint is bearer-protected. The Function URL is AuthType: NONE (so Withings can reach /callback), but /mcp requires your key, compared in constant time. Rotate it by re-running setup-ssm.sh with a new MCP_API_KEY.
  • /callback is public but CSRF-protected: it only accepts an OAuth state that this server issued (stored in DynamoDB with a 10-minute TTL) and consumes it once.
  • Tokens sit in DynamoDB with encryption at rest (AWS-owned KMS key by default). For a customer-managed key, add an SSESpecification with SSEType: KMS and your key ARN in template.yaml.
  • This is a single-user server ("my scale data"). To support multiple Withings accounts, key the token store by the Withings userid returned in the token response instead of the fixed tokens partition key.

Measurement type reference (common scale metrics)

Code Metric Unit
1 Weight kg
5 Fat-free mass kg
6 Fat ratio %
8 Fat mass weight kg
76 Muscle mass kg
77 Hydration kg
88 Bone mass kg
170 Visceral fat —

Call withings_list_measure_types for the full set (blood pressure, heart rate, SpO₂, temperature, pulse wave velocity, etc.).


License

MIT

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选