Lifestyle MCP Gym
Enables agents to track workouts, body metrics, and training stats for registered users through a JSON-RPC MCP endpoint, with scoped agent permissions and a web dashboard.
README
Lifestyle MCP Gym
Lifestyle MCP Gym is an agent-ready gym and personal-trainer data layer: humans manage nutrition, user-entered food, workouts, body metrics, and deterministic wellness estimates through a responsive dashboard and scoped JSON-RPC MCP tools.
Capabilities
- Human registration and login with password hashing, secure HTTP-only session cookies, goals, experience, timezone, and consent.
- Agent registration with scoped capabilities, optional HTTPS webhook, owner metadata, and a one-time secret response. Only a hash is stored.
- Workout tracking: exercises, sets, reps, weight, duration, notes, and recent activity.
- Body metrics: weight, body fat, waist, date, and notes.
- Nutrition profiles and bounded food logs. Nutrition values are always user-entered and are never fabricated.
- Deterministic Mifflin-St Jeor BMR, activity-factor TDEE, goal calories, and weight-based macro estimates with versioned assumptions, missing-input guidance, safety floors, and wellness disclaimers.
- One-call coaching context with the nutrition profile, calculated targets, today's nutrition, recent training stats, latest body metrics, and explicit next actions.
- MCP JSON-RPC endpoint at
/api/mcpwithinitialize,tools/list, andtools/call. - Scoped MCP tools for workouts, metrics, nutrition, coaching context, agent registration, and dashboard access links.
Run locally
Requirements: Node.js 20+ and npm.
npm install
cp .env.example .env.local
npm run dev
Open http://localhost:3000.
The default local storage driver is a JSON file at .data/lifestyle-gym.json. It is useful for local development and is ignored by git. To use explicit demo storage instead:
LIFESTYLE_STORAGE_DRIVER=memory npm run dev
Memory storage resets when the server process restarts.
Environment
See .env.example:
SUPABASE_URL: project URL from the Supabase API settings.SUPABASE_SERVICE_ROLE_KEY: service-role secret from the Supabase API settings.LIFESTYLE_STORAGE_DRIVER: local fallback, eitherfileormemory.LIFESTYLE_DATA_FILE: optional path for local JSON storage.
When both Supabase variables are present, the server automatically selects SupabaseStorage; otherwise the existing file/memory behavior remains. On Vercel, the fallback is process-local memory unless the file driver is explicitly selected.
Security: SUPABASE_SERVICE_ROLE_KEY is server-only. Never prefix it with NEXT_PUBLIC_, import the storage adapter into client code, print the key, or commit it. The app stores password hashes, session-token hashes, and agent-secret hashes; raw agent secrets are returned only once.
Supabase setup
-
Create a Supabase project.
-
Link the Supabase CLI to the project and apply the checked-in migration:
npx supabase@latest link --project-ref YOUR_PROJECT_REF npx supabase@latest db pushThe checked-in migrations are idempotent and safe to rerun.
-
Copy the project URL and service-role key into
.env.localfor a local Supabase-backed server. -
Restart the Next.js server and confirm
/api/statusreports storage modesupabase.
The migrations create normalized humans, sessions, agents, workouts, workout exercises/sets, body metrics, nutrition profiles, and nutrition entries. Row Level Security is enabled on every table. There are intentionally no public policies: all data access uses the server-side service-role client.
MCP quickstart
Register a human in the dashboard, then create an agent. The agent secret is shown once. Send it as a bearer token:
curl -s https://YOUR_DEPLOYMENT/api/mcp \
-H 'content-type: application/json' \
-H 'authorization: Bearer YOUR_AGENT_SECRET' \
--data '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{}}'
curl -s https://YOUR_DEPLOYMENT/api/mcp \
-H 'content-type: application/json' \
-H 'authorization: Bearer YOUR_AGENT_SECRET' \
--data '{"jsonrpc":"2.0","id":2,"method":"tools/list","params":{}}'
Human browser sessions may call the endpoint from the same origin. Agent tool calls require the relevant scopes. Existing workout and metric scopes are unchanged. Nutrition tools use nutrition:read or nutrition:write; get_coaching_context uses only coaching:read, which authorizes the aggregate read without granting separate nutrition, workout, or metric tools.
LLM-ready coaching context
An agent with coaching:read can retrieve every grounded coaching input in one call:
curl -s https://YOUR_DEPLOYMENT/api/mcp \
-H 'content-type: application/json' \
-H 'authorization: Bearer YOUR_AGENT_SECRET' \
--data '{
"jsonrpc":"2.0",
"id":"coach-context",
"method":"tools/call",
"params":{"name":"get_coaching_context","arguments":{}}
}'
The response includes concise text in result.content and machine-readable JSON in result.structuredContent. Calculated targets include the formula version, exact inputs and assumptions, missing inputs, clamp explanations, and a safety note.
Log user-entered food
log_food never looks up or invents nutrients. Supply totals for the complete log entry, including all servings:
curl -s https://YOUR_DEPLOYMENT/api/mcp \
-H 'content-type: application/json' \
-H 'authorization: Bearer YOUR_AGENT_SECRET' \
--data '{
"jsonrpc":"2.0",
"id":"food-1",
"method":"tools/call",
"params":{
"name":"log_food",
"arguments":{
"eatenAt":"2026-08-20T12:30:00Z",
"mealType":"lunch",
"foodName":"Tofu rice bowl",
"servingSize":"1 bowl",
"servings":1,
"caloriesKcal":640,
"proteinG":31,
"carbohydratesG":82,
"fatG":19,
"fiberG":11,
"notes":"Totals entered from the recipe"
}
}
}'
Validate
npm test
npm run lint
npm run build
Deploy to Vercel
Set these Vercel environment variables for every environment that should use persistent storage:
SUPABASE_URLSUPABASE_SERVICE_ROLE_KEY
Use the Vercel dashboard or vercel env add; keep the service-role value out of command history and deployment logs. Do not create a NEXT_PUBLIC_ copy.
Then deploy a preview:
npx vercel@latest --token "$VERCEL_TOKEN" --yes
Use --prod only for an intentional production deployment. Verify the returned deployment with npx vercel@latest inspect <deployment-url> --token "$VERCEL_TOKEN".
Architecture
src/components/: client dashboard, auth, forms, and API guide.src/app/api/: Next.js route handlers for auth, workouts, metrics, stats, agents, status, and MCP.src/lib/domain.ts: validated domain input schemas and stat calculations.src/lib/service.ts: auth, authorization, and application operations.src/lib/storage/: storage interface plus Supabase, local JSON, and in-memory adapters.src/lib/mcp.ts: JSON-RPC/MCP request validation, tools, auth, and scope enforcement.
LifestyleStorage keeps domain, service, UI, and MCP behavior independent of the selected persistence adapter.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.