Strava Mcp Unofficial

by davidmosiah

293 downloads
Not rated
GitHub

About

Unofficial local-first MCP server for Strava. Activity history, streams (HR/power/cadence/GPS), athlete zones, routes, weekly training summaries. Privacy modes (summary/structured/raw) with GPS protection by default, SQLite cache, doctor CLI for setup. Works with Claude Desktop,

Details

Author
davidmosiah
Downloads
293
Categories
Other, AI

- Local‑first OAuth – tokens never leave your machine
- Read‑only by default – no write scopes requested
- GPS lat/lng hidden unless explicitly opted in
- Rate‑limited under Strava’s per‑app limits (200 req/15min)
- Compatible with any MCP‑supporting agent
- Provides prompts, tools, and resources for training context

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Strava Mcp Unofficial
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

Create a Strava app with redirect URI http://127.0.0.1:3000/callback, then run npx -y strava-mcp-unofficial setup, npx -y strava-mcp-unofficial auth, and npx -y strava-mcp-unofficial doctor. Add the server to your MCP client config with command: "npx", args: ["-y", "strava-mcp-unofficial"].

strava_data_inventory

Inventory supported Strava data domains, auth scope requirements, privacy boundary and recommended first calls. Does not call Strava APIs or expose user data.

strava_agent_manifest

Machine-readable install, runtime and client guidance for AI agents. Includes Hermes direct tool names and anti-gateway-restart guidance. Does not call Strava or expose secrets.

strava_capabilities

Explain supported Strava data, privacy boundaries, GPS handling, recommended agent workflow and project links. Does not call Strava or expose secrets.

strava_quickstart

Personalized 3-step setup walkthrough for the human user. Adapts to current state (env vars set? token present? what's next?). Call this first when the user asks 'how do I connect Strava?'

strava_demo

Returns realistic example payloads of strava_daily_summary, strava_training_context, and strava_list_activities so agents see the contract before calling real Strava APIs.

strava_get_auth_url

Generate a Strava OAuth authorization URL. Use this first when no local token exists.

strava_exchange_code

Exchange a Strava OAuth authorization code for local tokens. Tokens are stored locally with 0600 permissions and are never returned. Requires explicit user action: the user must complete browser OAuth and supply the authorization code (agents must not invent codes).

strava_get_athlete

Get the authenticated Strava athlete profile. Requires read/profile scope depending on requested fields.

strava_get_zones

Get the authenticated athlete heart-rate and power zones when available.

strava_get_athlete_stats

Get public-visible aggregate Strava stats for the authenticated athlete.

strava_list_activities

List authenticated athlete activities. Supports after/before filters and Strava pagination. Requires activity:read or activity:read_all.

strava_list_routes

List authenticated athlete routes. GPS/map geometry is redacted unless raw mode is requested.

strava_list_clubs

List clubs joined by the authenticated athlete.

strava_get_activity

Get detailed activity data by id. Summary/structured modes protect raw GPS details.

strava_get_activity_zones

Get heart-rate/power zones for an activity when available.

strava_get_route

Get route details by id. Summary/structured modes avoid full route geometry.

strava_get_gear

Get gear/equipment details by id.

strava_get_activity_streams

Get raw Strava activity streams (time, distance, heartrate, cadence, watts, altitude). For agent work prefer strava_activity_series — it returns agent-safe-series/v1 with hard point caps and exact stats. GPS latlng is withheld unless include_gps=true or privacy_mode=raw (both require explicit_user_intent=true).

strava_activity_series

Bounded time-series for one activity metric (agent-safe-series/v1). Returns exact stats on full-resolution samples plus a downsampled series capped at 500 points, so a multi-hour ride never blows the context window. Prefer strava_get_activity / zones first; reach for this when you need the shape of the effort. GPS is never returned here. Shared contract with garmin_activity_series / Kindred workout_series.

strava_connection_status

Check local Strava config, token file, Node version, privacy mode, cache readiness and optional MCP client readiness without calling Strava or exposing secrets.

strava_cache_status

Show optional local SQLite cache status. Enable with STRAVA_CACHE=sqlite or STRAVA_CACHE=true.

strava_privacy_audit

Return local privacy, cache, token-path, GPS redaction and env-presence posture without revealing secret values.

strava_revoke_access

Revoke the current Strava OAuth access grant and delete the local token file. Use only when the user explicitly wants to disconnect Strava. Gated by explicit_user_intent: true (requires explicit user intent).

strava_daily_summary

Build a practical daily training/load summary from recent Strava activities. Read-only and non-medical.

strava_weekly_summary

Build a weekly Strava scorecard with volume, intensity, sport mix, bottlenecks and next-week actions. Read-only and non-medical.

strava_training_context

Normalize recent Strava activity load into a compact training_context for workout recommendation engines. Includes fallback guidance when recent Strava activity is missing.

strava_profile_get

Read the canonical Delx Wellness profile shared with the other wellness MCP connectors (Nourish, Cycle Coach, CGM, etc.). Read-only. Profile stores only what the user typed during onboarding — never OAuth tokens, API keys, or biomarkers. Note: this profile does NOT change Strava's GPS-redaction default; Strava continues to redact latlng and route geometry unless STRAVA_GPS_INCLUDE=true or include_gps=true is explicitly passed.

strava_profile_update

Persist a partial patch to the canonical Delx Wellness profile. Requires explicit_user_intent=true after the user confirms they want to save. Rejects secret-like fields (oauth, token, api_key, password, cookie, refresh, session). Strava's GPS-redaction default is unaffected by profile changes.

strava_onboarding

Read-only. Return the 11-question Delx Wellness onboarding flow (en or pt-BR), the current shared profile, missing critical fields, and a cross-connector hint. Use this when the user starts a fresh wellness session and you need to fill out preferred_name, goals, devices, training context, nutrition, preferences, and safety. Strava continues to redact GPS by default — onboarding does not change that.

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "strava mcp unofficial": {
            "strava": {
                "command": "npx",
                "args": [
                    "-y",
                    "strava-mcp-unofficial"
                ]
            }
        }
    }
}

McpServers

{
    "strava": {
        "command": "npx",
        "args": [
            "-y",
            "strava-mcp-unofficial"
        ]
    }
}

strava-mcp-server

MCP Compatible
License: MIT
TypeScript
Provider: Strava
npm version
GitHub stars
npm downloads
CI
Delx Wellness
Agent-ready MCP

Local-first MCP server that connects AI agents to your Strava activities, routes, streams and training context.

> Unofficial project. Not affiliated with, endorsed by or supported by Strava, Inc. Strava is a trademark of its respective owner. Use this only with your own Strava account and in line with Strava's API agreement.

Built by David Mosiah for people who use Claude, Cursor, Hermes, OpenClaw or other MCP-compatible agents to think about training, endurance and performance — without copy-pasting numbers from Strava.

Part of Delx Wellness, a registry of local-first wellness MCP connectors.

> If this connector helps your agent workflow, please star the repo. Stars make the project easier for other AI builders to discover and help Delx keep shipping local-first wellness infrastructure.

Why this exists

Strava holds the long memory of your training — every ride, run, swim, segment, route and stream. But it lives behind an OAuth API with strict rate limits (200 req/15min, 2k/day per app) and GPS data that's privacy-sensitive by default.

This package does the OAuth dance locally, throttles under Strava's per-app limits, redacts GPS lat/lng unless you explicitly opt in, and exposes Strava through the Model Context Protocol. Any MCP-compatible agent gets your training context with one config snippet. Tokens never leave your machine.

Setup in 60 seconds

You'll need a Strava app (create one here) with redirect URI http://127.0.0.1:3000/callback.

npx -y strava-mcp-unofficial setup    # interactive: paste client id + secret
npx -y strava-mcp-unofficial auth     # opens browser, captures the OAuth code
npx -y strava-mcp-unofficial doctor   # verifies you're ready

doctor should report these scopes as granted:

read activity:read_all profile:read_all

If only read is granted, re-run auth. Then add this to your MCP client config:

{
  "mcpServers": {
    "strava": {
      "command": "npx",
      "args": ["-y", "strava-mcp-unofficial"]
    }
  }
}

For Claude Desktop, run setup --client claude and the snippet is written for you.

Try it with your agent

Three things to ask first:

Use strava_connection_status to check setup, then run strava_daily_summary.
Tell me what my training context looks like in 5 lines.
Call strava_weekly_summary with response_format=json. Find my biggest
load/intensity bottleneck and give me a next-week endurance plan.
Use the strava_activity_stream_investigator prompt for activity_id=<id>.
Don't expose GPS unless I explicitly ask for it.

Data availability

This package uses the official Strava API v3. When this README says raw, it means the upstream Strava JSON for a supported endpoint — not continuous device telemetry.

| Data | Available | Notes |
|---|:---:|---|
| Activities (runs, rides, swims, walks, workouts) | ✓ | All recorded activities |
| Activity details + zones + splits | ✓ | HR, power, cadence, elevation, gear |
| Activity streams (HR / cadence / watts / altitude) | ✓ | Per-second samples for the activity |
| GPS lat/lng streams | opt-in | Hidden by default; requires include_gps=true or raw mode |
| Athlete profile + zones + aggregate stats | ✓ | Authenticated athlete |
| Routes + clubs + gear | ✓ | Route geometry redacted in summary/structured modes |
| Live device telemetry / continuous HR | — | Not exposed by Strava's public API |

Tools

Start with these:

- strava_connection_status — verify local setup, scopes and readiness before calling Strava
- strava_daily_summary — latest activity, weekly load and intensity context for today
- strava_weekly_summary — scorecard, comparison vs prior week, next-week training plan

Auth & diagnostics

- strava_capabilities, strava_agent_manifest, strava_privacy_audit, strava_cache_status
- strava_get_auth_url, strava_exchange_code, strava_revoke_access

Athlete & training

- strava_get_athlete, strava_get_zones, strava_get_athlete_stats

Activities & streams

- strava_list_activities, strava_get_activity, strava_get_activity_zones
- strava_get_activity_streams — GPS lat/lng requires include_gps=true or raw mode

Routes & context

- strava_list_routes, strava_get_route, strava_list_clubs, strava_get_gear

Prompts

- strava_daily_training_director — practical daily training brief
- strava_weekly_endurance_review — week comparison + next-week endurance plan
- strava_activity_stream_investigator — investigate one activity using streams (GPS-aware)

Each accepts timezone (IANA, default UTC).

Resources

- strava://capabilities, strava://agent-manifest
- strava://athlete
- strava://latest/activity
- strava://summary/daily, strava://summary/weekly

Privacy & security

- OAuth tokens are stored in ~/.strava-mcp/tokens.json with 0600 permissions and are never returned by tools.
- Write/upload scopes are not requested by default — read-only by design.
- GPS lat/lng is removed in summary mode, limited in structured mode, and only included with explicit include_gps=true or raw mode.
- Route geometry is also redacted unless raw mode is explicitly requested.
- The MCP client never sees access or refresh tokens.
- This is not medical advice. The server exposes user-authorized data for personal AI workflows, not diagnosis or training prescription.

Configuration

setup writes most of these into ~/.strava-mcp/config.json (0600). Manual env override is supported:

STRAVA_CLIENT_ID=…
STRAVA_CLIENT_SECRET=…
STRAVA_REDIRECT_URI=http://127.0.0.1:3000/callback

Optional

STRAVA_SCOPES="read activity:read_all profile:read_all" STRAVA_PRIVACY_MODE=structured # summary | structured | raw STRAVA_CACHE=sqlite # optional read-through cache

Hermes / remote setup

npx -y strava-mcp-unofficial setup --client hermes --no-auth
npx -y strava-mcp-unofficial auth                       # run locally if browser auth is needed
npx -y strava-mcp-unofficial doctor --client hermes
hermes mcp test strava

Hermes commonly exposes Strava tools with a prefix:

- mcp_strava_strava_agent_manifest
- mcp_strava_strava_connection_status
- mcp_strava_strava_daily_summary
- mcp_strava_strava_weekly_summary
- mcp_strava_strava_get_activity_streams

After Hermes config changes, use /reload-mcp or hermes mcp test strava. Don't restart the gateway for normal data access.

If browser OAuth has to happen on a different machine than Hermes, run auth locally and copy ~/.strava-mcp/tokens.json to the server with chmod 600. The token must include activity:read_all profile:read_all read for activity history and streams.

Requirements

- Node.js 20+
- A Strava app with redirect URI http://127.0.0.1:3000/callback

Why these scopes:

- read — public profile, routes and public Strava resources
- activity:read_all — your activities, including private activities visible to your app
- profile:read_all — fuller authenticated athlete profile fields

No write scope is requested by default.

Development

git clone https://github.com/davidmosiah/strava-mcp.git
cd strava-mcp
npm install
npm test
npm run build

Test with MCP Inspector:

npx @modelcontextprotocol/inspector node dist/index.js

Links

- npm: <https://www.npmjs.com/package/strava-mcp-unofficial>
- Docs site: <https://wellness.delx.ai/connectors/strava>
- Legacy docs: <https://stravamcp.vercel.app/>
- GitHub Pages mirror: <https://davidmosiah.github.io/strava-mcp/>
- Delx Wellness registry: <https://github.com/davidmosiah/delx-wellness>
- Connector quality standard: <https://github.com/davidmosiah/delx-wellness/blob/main/docs/connector-quality-standard.md>
- Strava API docs: <https://developers.strava.com/docs/reference/>
- Strava auth docs: <https://developers.strava.com/docs/authentication/>

License

MIT — see LICENSE.

Disclaimer

This software is provided as-is. It is not a medical device, does not provide medical advice, and should not be used for diagnosis, treatment or training prescription. Always consult qualified professionals for medical or training concerns.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.