Connects WHOOP fitness and recovery data to Claude Desktop, enabling users to query workouts, sleep, recovery, and trends through natural language.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Next.js is vulnerable to RCE in React flight protocol
Authorization Bypass in Next.js Middleware
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
Next.js Vulnerable to Denial of Service with Server Components
Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
process.env. You'll be asked to provide them before it can run.NEXT_PUBLIC_WHOOP_DASHBOARD_API_URLWHOOP_DASHBOARD_API_URLWHOOP_CLIENT_SECRET— If is not set, setup prompts for it securely.WHOOP_CLIENT_IDWHOOP_EXPORT_DIRLOG_LEVEL— Logs: use and optional LOG_FILE environment variables.LOG_FILE— Logs: use LOG_LEVEL and optional environment variables.WHOOP_MCP_TRANSPORTMCP_TRANSPORTFASTMCP_HOSTFASTMCP_PORTPORT[](https://m8ven.ai/mcp/arpitarunkumaar-whoop-mcp-server-rhstht)