Oura MCP Server
An MCP server that enables access to Oura Ring data, including sleep, activity, readiness, and other health metrics, through local stdio or remote HTTP with OAuth.
README
Oura MCP Server
A Model Context Protocol (MCP) server for accessing Oura Ring data.
It runs in two modes from the same codebase:
| Mode | Entrypoint | Transport | Use it for |
|---|---|---|---|
| Local | npm run start:stdio |
stdio | Claude Code and Claude Desktop on your own machine |
| Hosted | npm start |
Streamable HTTP + OAuth | claude.ai in the browser and the Claude mobile apps |
Prerequisites
- Node.js 20+
- An Oura account
Installation
npm install
npm run build
Oura credentials
- Log in to the Oura Cloud Console
- Create a Personal Access Token
Set it as OURA_PERSONAL_ACCESS_TOKEN. See .env.example for the full list of
variables. Set OURA_TIMEZONE to your IANA zone (e.g. America/Phoenix) — it
decides what "the last 7 days" means for the resource defaults. It falls back to
UTC, which shifts the window by a day for part of every day anywhere west of
Greenwich, so it is worth setting explicitly.
Personal access tokens are the only supported credential. Earlier versions also accepted OAuth2 client id/secret, but nothing ever ran the authorization-code flow against Oura, so that path could only fail at request time; it has been removed rather than left as a trap.
Local mode (stdio)
Claude Code
claude mcp add oura -s user \
-e OURA_PERSONAL_ACCESS_TOKEN=your_token \
-- "$(command -v node)" /absolute/path/to/oura-mcp/build/index.js
Claude Desktop
Settings → Developer → Edit Config:
{
"mcpServers": {
"oura": {
"command": "/absolute/path/to/node",
"args": ["/absolute/path/to/oura-mcp/build/index.js"],
"env": { "OURA_PERSONAL_ACCESS_TOKEN": "your_token" }
}
}
}
Pass the token in env rather than relying on a .env file. dotenv resolves
.env against the current working directory, which for a client-launched
server is wherever the client happened to start — not this repo.
Testing
npm test # builds first, then runs the suite
22 tests across two suites, none of which need a live Oura token: oauth.test.ts
drives the real OAuth flow over HTTP (discovery, dynamic registration, PKCE,
single-use codes, refresh, bearer rejection), and tools.test.ts checks the tool
and resource surface over stdio — including a regression test that stdout carries
nothing but JSON-RPC.
For a manual probe against real data:
node test.js get_daily_sleep 2026-08-01
Hosted mode (HTTP + OAuth)
claude.ai and the mobile apps only talk to remote MCP servers over HTTPS, so reaching your data from a phone means deploying this somewhere.
What the auth actually does
The server is its own OAuth 2.1 authorization server. Your Oura token stays in
server-side env and is never handed to the client; the OAuth flow exists only to
prove that whoever is calling /mcp knows MCP_AUTH_PASSWORD.
Client ids, authorization codes, and tokens are all HMAC-signed payloads rather than database rows, so a redeploy doesn't sign you out and no storage needs provisioning. Clients are registered as public clients and authenticate with PKCE. Authorization codes are single-use.
Deploying to Railway
-
Create a new Railway project from this repo.
railway.jsonpins the build and start commands and points the healthcheck at/healthz. -
Generate a signing secret:
openssl rand -hex 32 -
Set these variables in the Railway service:
Variable Value OURA_PERSONAL_ACCESS_TOKENyour Oura token OAUTH_SIGNING_SECRETthe hex string from step 2 MCP_AUTH_PASSWORDthe password you'll type when connecting You do not need to set
PUBLIC_URLon Railway. The server falls back toRAILWAY_PUBLIC_DOMAIN, which Railway injects once the service has a domain (Settings → Networking → Public Networking → Generate Domain). SetPUBLIC_URLexplicitly only when hosting elsewhere, or to override the advertised origin — it must then match the real origin exactly, since it's what the server publishes in its OAuth metadata. -
Confirm the deploy:
curl https://your-app.up.railway.app/healthz
PORT is injected by Railway; don't set it yourself.
Connecting Claude
In claude.ai → Settings → Connectors → Add custom connector, use:
https://your-app.up.railway.app/mcp
Leave the OAuth client fields blank — the server supports dynamic client
registration, so Claude registers itself. You'll be redirected to a sign-in page
asking for MCP_AUTH_PASSWORD, and after that the connector is available in the
browser and on the mobile apps under the same account.
Endpoints
| Path | Purpose |
|---|---|
POST /mcp |
The MCP endpoint. Requires a bearer token and the oura:read scope. |
/authorize, /token, /register, /revoke |
OAuth, mounted by the MCP SDK |
POST /login |
Password form posted from the authorize page |
/.well-known/oauth-authorization-server |
AS metadata |
/.well-known/oauth-protected-resource/mcp |
Protected-resource metadata |
GET /healthz |
Healthcheck |
GET and DELETE on /mcp return 405: the server runs the transport in
stateless mode, so there's no long-lived SSE stream or session to tear down.
Every request gets a fresh server instance, which is what lets a redeploy or a
second replica pick up mid-conversation.
Available resources
personal_info, daily_activity, daily_readiness, daily_sleep, sleep,
sleep_time, workout, session, daily_spo2, rest_mode_period,
ring_configuration, daily_stress, daily_resilience,
daily_cardiovascular_age, vO2_max
Date-based resources default to the last 7 days, bounded by OURA_TIMEZONE.
Response shape
Results are paginated by Oura via next_token; the server follows it to
completion, so a wide date range returns every record rather than the first page.
It stops after 25 pages and marks the response truncated rather than looping.
Interval-sample fields — the per-30-second and per-5-minute arrays on sleep
(heart_rate, hrv, movement_30_sec, sleep_phase_5_min) and
daily_activity (class_5_min, met) — are stripped by default, since a month
of them runs to megabytes and crowds out the conversation. Pass
includeIntervalSamples: true on a narrow range when you need them.
Available tools
Every date-based resource above has a matching get_<name> tool taking
startDate and endDate in YYYY-MM-DD form — 13 in total.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
E2B
Using MCP to run code via e2b.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.