Strava Mcp Unofficial
About
Unofficial local-first MCP server for Strava. Activity history, streams (HR/power/cadence/GPS), athlete zones, routes, weekly training summaries. Privacy modes (summary/structured/raw) with GPS protection by default, SQLite cache, doctor CLI for setup. Works with Claude Desktop,
Details
- Author
- davidmosiah
- Downloads
- 293
- Categories
- Other, AI
Jump to
- Local‑first OAuth – tokens never leave your machine
- Read‑only by default – no write scopes requested
- GPS lat/lng hidden unless explicitly opted in
- Rate‑limited under Strava’s per‑app limits (200 req/15min)
- Compatible with any MCP‑supporting agent
- Provides prompts, tools, and resources for training context
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
Strava Mcp UnofficialCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
Create a Strava app with redirect URI http://127.0.0.1:3000/callback, then run npx -y strava-mcp-unofficial setup, npx -y strava-mcp-unofficial auth, and npx -y strava-mcp-unofficial doctor. Add the server to your MCP client config with command: "npx", args: ["-y", "strava-mcp-unofficial"].
strava_data_inventory
Inventory supported Strava data domains, auth scope requirements, privacy boundary and recommended first calls. Does not call Strava APIs or expose user data.
strava_agent_manifest
Machine-readable install, runtime and client guidance for AI agents. Includes Hermes direct tool names and anti-gateway-restart guidance. Does not call Strava or expose secrets.
strava_capabilities
Explain supported Strava data, privacy boundaries, GPS handling, recommended agent workflow and project links. Does not call Strava or expose secrets.
strava_quickstart
Personalized 3-step setup walkthrough for the human user. Adapts to current state (env vars set? token present? what's next?). Call this first when the user asks 'how do I connect Strava?'
strava_demo
Returns realistic example payloads of strava_daily_summary, strava_training_context, and strava_list_activities so agents see the contract before calling real Strava APIs.
strava_get_auth_url
Generate a Strava OAuth authorization URL. Use this first when no local token exists.
strava_exchange_code
Exchange a Strava OAuth authorization code for local tokens. Tokens are stored locally with 0600 permissions and are never returned. Requires explicit user action: the user must complete browser OAuth and supply the authorization code (agents must not invent codes).
strava_get_athlete
Get the authenticated Strava athlete profile. Requires read/profile scope depending on requested fields.
strava_get_zones
Get the authenticated athlete heart-rate and power zones when available.
strava_get_athlete_stats
Get public-visible aggregate Strava stats for the authenticated athlete.
strava_list_activities
List authenticated athlete activities. Supports after/before filters and Strava pagination. Requires activity:read or activity:read_all.
strava_list_routes
List authenticated athlete routes. GPS/map geometry is redacted unless raw mode is requested.
strava_list_clubs
List clubs joined by the authenticated athlete.
strava_get_activity
Get detailed activity data by id. Summary/structured modes protect raw GPS details.
strava_get_activity_zones
Get heart-rate/power zones for an activity when available.
strava_get_route
Get route details by id. Summary/structured modes avoid full route geometry.
strava_get_gear
Get gear/equipment details by id.
strava_get_activity_streams
Get raw Strava activity streams (time, distance, heartrate, cadence, watts, altitude). For agent work prefer strava_activity_series — it returns agent-safe-series/v1 with hard point caps and exact stats. GPS latlng is withheld unless include_gps=true or privacy_mode=raw (both require explicit_user_intent=true).
strava_activity_series
Bounded time-series for one activity metric (agent-safe-series/v1). Returns exact stats on full-resolution samples plus a downsampled series capped at 500 points, so a multi-hour ride never blows the context window. Prefer strava_get_activity / zones first; reach for this when you need the shape of the effort. GPS is never returned here. Shared contract with garmin_activity_series / Kindred workout_series.
strava_connection_status
Check local Strava config, token file, Node version, privacy mode, cache readiness and optional MCP client readiness without calling Strava or exposing secrets.
strava_cache_status
Show optional local SQLite cache status. Enable with STRAVA_CACHE=sqlite or STRAVA_CACHE=true.
strava_privacy_audit
Return local privacy, cache, token-path, GPS redaction and env-presence posture without revealing secret values.
strava_revoke_access
Revoke the current Strava OAuth access grant and delete the local token file. Use only when the user explicitly wants to disconnect Strava. Gated by explicit_user_intent: true (requires explicit user intent).
strava_daily_summary
Build a practical daily training/load summary from recent Strava activities. Read-only and non-medical.
strava_weekly_summary
Build a weekly Strava scorecard with volume, intensity, sport mix, bottlenecks and next-week actions. Read-only and non-medical.
strava_training_context
Normalize recent Strava activity load into a compact training_context for workout recommendation engines. Includes fallback guidance when recent Strava activity is missing.
strava_profile_get
Read the canonical Delx Wellness profile shared with the other wellness MCP connectors (Nourish, Cycle Coach, CGM, etc.). Read-only. Profile stores only what the user typed during onboarding — never OAuth tokens, API keys, or biomarkers. Note: this profile does NOT change Strava's GPS-redaction default; Strava continues to redact latlng and route geometry unless STRAVA_GPS_INCLUDE=true or include_gps=true is explicitly passed.
strava_profile_update
Persist a partial patch to the canonical Delx Wellness profile. Requires explicit_user_intent=true after the user confirms they want to save. Rejects secret-like fields (oauth, token, api_key, password, cookie, refresh, session). Strava's GPS-redaction default is unaffected by profile changes.
strava_onboarding
Read-only. Return the 11-question Delx Wellness onboarding flow (en or pt-BR), the current shared profile, missing critical fields, and a cross-connector hint. Use this when the user starts a fresh wellness session and you need to fill out preferred_name, goals, devices, training context, nutrition, preferences, and safety. Strava continues to redact GPS by default — onboarding does not change that.
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"strava mcp unofficial": {
"strava": {
"command": "npx",
"args": [
"-y",
"strava-mcp-unofficial"
]
}
}
}
}
McpServers
{
"strava": {
"command": "npx",
"args": [
"-y",
"strava-mcp-unofficial"
]
}
}
strava-mcp-server
Local-first MCP server that connects AI agents to your Strava activities, routes, streams and training context.
> Unofficial project. Not affiliated with, endorsed by or supported by Strava, Inc. Strava is a trademark of its respective owner. Use this only with your own Strava account and in line with Strava's API agreement.
Built by David Mosiah for people who use Claude, Cursor, Hermes, OpenClaw or other MCP-compatible agents to think about training, endurance and performance — without copy-pasting numbers from Strava.
Part of Delx Wellness, a registry of local-first wellness MCP connectors.
> If this connector helps your agent workflow, please star the repo. Stars make the project easier for other AI builders to discover and help Delx keep shipping local-first wellness infrastructure.
Why this exists
Strava holds the long memory of your training — every ride, run, swim, segment, route and stream. But it lives behind an OAuth API with strict rate limits (200 req/15min, 2k/day per app) and GPS data that's privacy-sensitive by default.
This package does the OAuth dance locally, throttles under Strava's per-app limits, redacts GPS lat/lng unless you explicitly opt in, and exposes Strava through the Model Context Protocol. Any MCP-compatible agent gets your training context with one config snippet. Tokens never leave your machine.
Setup in 60 seconds
You'll need a Strava app (create one here) with redirect URI http://127.0.0.1:3000/callback.
npx -y strava-mcp-unofficial setup # interactive: paste client id + secret
npx -y strava-mcp-unofficial auth # opens browser, captures the OAuth code
npx -y strava-mcp-unofficial doctor # verifies you're ready
doctor should report these scopes as granted:
read activity:read_all profile:read_all
If only read is granted, re-run auth. Then add this to your MCP client config:
{
"mcpServers": {
"strava": {
"command": "npx",
"args": ["-y", "strava-mcp-unofficial"]
}
}
}
For Claude Desktop, run setup --client claude and the snippet is written for you.
Try it with your agent
Three things to ask first:
Use strava_connection_status to check setup, then run strava_daily_summary.
Tell me what my training context looks like in 5 lines.
Call strava_weekly_summary with response_format=json. Find my biggest
load/intensity bottleneck and give me a next-week endurance plan.
Use the strava_activity_stream_investigator prompt for activity_id=<id>.
Don't expose GPS unless I explicitly ask for it.
Data availability
This package uses the official Strava API v3. When this README says raw, it means the upstream Strava JSON for a supported endpoint — not continuous device telemetry.
| Data | Available | Notes |
|---|:---:|---|
| Activities (runs, rides, swims, walks, workouts) | ✓ | All recorded activities |
| Activity details + zones + splits | ✓ | HR, power, cadence, elevation, gear |
| Activity streams (HR / cadence / watts / altitude) | ✓ | Per-second samples for the activity |
| GPS lat/lng streams | opt-in | Hidden by default; requires include_gps=true or raw mode |
| Athlete profile + zones + aggregate stats | ✓ | Authenticated athlete |
| Routes + clubs + gear | ✓ | Route geometry redacted in summary/structured modes |
| Live device telemetry / continuous HR | — | Not exposed by Strava's public API |
Tools
Start with these:
- strava_connection_status — verify local setup, scopes and readiness before calling Strava
- strava_daily_summary — latest activity, weekly load and intensity context for today
- strava_weekly_summary — scorecard, comparison vs prior week, next-week training plan
Auth & diagnostics
- strava_capabilities, strava_agent_manifest, strava_privacy_audit, strava_cache_status
- strava_get_auth_url, strava_exchange_code, strava_revoke_access
Athlete & training
- strava_get_athlete, strava_get_zones, strava_get_athlete_stats
Activities & streams
- strava_list_activities, strava_get_activity, strava_get_activity_zones
- strava_get_activity_streams — GPS lat/lng requires include_gps=true or raw mode
Routes & context
- strava_list_routes, strava_get_route, strava_list_clubs, strava_get_gear
Prompts
- strava_daily_training_director — practical daily training brief
- strava_weekly_endurance_review — week comparison + next-week endurance plan
- strava_activity_stream_investigator — investigate one activity using streams (GPS-aware)
Each accepts timezone (IANA, default UTC).
Resources
- strava://capabilities, strava://agent-manifest
- strava://athlete
- strava://latest/activity
- strava://summary/daily, strava://summary/weekly
Privacy & security
- OAuth tokens are stored in ~/.strava-mcp/tokens.json with 0600 permissions and are never returned by tools.
- Write/upload scopes are not requested by default — read-only by design.
- GPS lat/lng is removed in summary mode, limited in structured mode, and only included with explicit include_gps=true or raw mode.
- Route geometry is also redacted unless raw mode is explicitly requested.
- The MCP client never sees access or refresh tokens.
- This is not medical advice. The server exposes user-authorized data for personal AI workflows, not diagnosis or training prescription.
Configuration
setup writes most of these into ~/.strava-mcp/config.json (0600). Manual env override is supported:
STRAVA_CLIENT_ID=…
STRAVA_CLIENT_SECRET=…
STRAVA_REDIRECT_URI=http://127.0.0.1:3000/callback
Optional
STRAVA_SCOPES="read activity:read_all profile:read_all"
STRAVA_PRIVACY_MODE=structured # summary | structured | raw
STRAVA_CACHE=sqlite # optional read-through cache
Hermes / remote setup
npx -y strava-mcp-unofficial setup --client hermes --no-auth
npx -y strava-mcp-unofficial auth # run locally if browser auth is needed
npx -y strava-mcp-unofficial doctor --client hermes
hermes mcp test strava
Hermes commonly exposes Strava tools with a prefix:
- mcp_strava_strava_agent_manifest
- mcp_strava_strava_connection_status
- mcp_strava_strava_daily_summary
- mcp_strava_strava_weekly_summary
- mcp_strava_strava_get_activity_streams
After Hermes config changes, use /reload-mcp or hermes mcp test strava. Don't restart the gateway for normal data access.
If browser OAuth has to happen on a different machine than Hermes, run auth locally and copy ~/.strava-mcp/tokens.json to the server with chmod 600. The token must include activity:read_all profile:read_all read for activity history and streams.
Requirements
- Node.js 20+
- A Strava app with redirect URI http://127.0.0.1:3000/callback
Why these scopes:
- read — public profile, routes and public Strava resources
- activity:read_all — your activities, including private activities visible to your app
- profile:read_all — fuller authenticated athlete profile fields
No write scope is requested by default.
Development
git clone https://github.com/davidmosiah/strava-mcp.git
cd strava-mcp
npm install
npm test
npm run build
Test with MCP Inspector:
npx @modelcontextprotocol/inspector node dist/index.js
Links
- npm: <https://www.npmjs.com/package/strava-mcp-unofficial>
- Docs site: <https://wellness.delx.ai/connectors/strava>
- Legacy docs: <https://stravamcp.vercel.app/>
- GitHub Pages mirror: <https://davidmosiah.github.io/strava-mcp/>
- Delx Wellness registry: <https://github.com/davidmosiah/delx-wellness>
- Connector quality standard: <https://github.com/davidmosiah/delx-wellness/blob/main/docs/connector-quality-standard.md>
- Strava API docs: <https://developers.strava.com/docs/reference/>
- Strava auth docs: <https://developers.strava.com/docs/authentication/>
License
MIT — see LICENSE.
Disclaimer
This software is provided as-is. It is not a medical device, does not provide medical advice, and should not be used for diagnosis, treatment or training prescription. Always consult qualified professionals for medical or training concerns.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.




