Tecnologia6 de julho de 2026Atualizado em 7 de julho de 202612 min de leitura

Health MCP: Connect Your Health & Fitness Data to Any AI

Josh Passell
Josh Passell

Cofundador da Cora (YC W24). Cornell University, Economia. Baseado em São Francisco.

Health MCP: Connect Your Health & Fitness Data to Any AI

A health MCP is a secure server that lets an AI assistant like Claude or ChatGPT read and act on your real fitness data — recovery, sleep, workouts, nutrition — directly inside a normal chat conversation, instead of you switching to an app. Cora's MCP server is live in production today, with 47 tools and OAuth-secured, scoped consent, at https://api.purplepill.ai/api/mcp/. This guide explains what MCP actually is in plain language, how Cora's implementation works end to end, what you can genuinely do with it right now, and what's still missing.

If you've spent any time around AI tools in the last year, you've probably typed something like "based on my last two weeks, should I train hard today?" into ChatGPT, only to realize it has no idea what your last two weeks looked like. It can talk about recovery science in general terms, but it cannot see your actual HRV trend, your actual sleep debt, or the workout you logged this morning. That gap — a smart model with no access to your real data — is exactly what MCP was built to close.

This is not a hypothetical. Cora has built and deployed a real, working MCP server, and it's live in production — not a mockup, a roadmap slide, or a "coming Q3" placeholder. Any existing, onboarded Cora account can connect it today. This guide walks through what that actually means, in plain terms, for anyone who trains, eats, sleeps, and wants their AI assistant to actually know about it.

What is MCP, in plain language?

MCP stands for Model Context Protocol. It's an open standard, originally published by Anthropic and now used broadly across the AI industry, that defines a common way for an AI assistant to connect to outside systems and use them as tools. Think of it as a universal plug: instead of every app building its own custom, one-off integration with every AI model, an app builds one MCP server, and any MCP-compatible AI client (Claude, ChatGPT, and a growing list of others) can talk to it the same way.

For a non-developer, the useful mental model is this: an MCP server is a menu of specific actions an AI is allowed to take on your behalf — "get my sleep data for the last 30 days," "log this meal," "build me a training week" — each one clearly defined, each one requiring your permission. The AI doesn't get some vague, unrestricted window into your life. It gets a specific, named set of tools, each scoped to a specific type of data, that you explicitly approve.

This is a meaningfully different relationship than "the AI has access to your account." It's closer to handing someone a set of labeled keys — one for reading your sleep data, one for logging workouts, one for talking to your coach — rather than handing over your whole house key.

Why your real health data changes what AI coaching can do

General-purpose AI is already good at fitness and nutrition advice in the abstract. Ask Claude or ChatGPT how to structure a training week around poor sleep, and you'll get a reasonable, textbook answer. What it can't do without a connection like MCP is apply that reasoning to your actual sleep, your actual training history, and your actual recovery trend.

That distinction matters more than it sounds like on paper. A generic answer treats every input as hypothetical. A grounded answer can say something like: "Your resting heart rate has been 4 beats above baseline for three days and you slept 5h40m last night — that's consistent with under-recovery, not illness, so I'd cut today's session to Zone 2 and keep the volume." That's the difference between advice and coaching, and it depends entirely on the AI having your real numbers, not a description of them.

This is also why Cora built its own AI coaching system around recovery data in the first place — see our deeper explanation in how an AI fitness coach actually works. MCP extends that same grounded reasoning into whatever chat interface you already spend time in, rather than requiring you to open a separate app to get it.

How Cora's MCP server actually works

Here's the real setup flow, not a marketing simplification:

  1. Get a Cora account first. The MCP server connects to an existing, onboarded Cora account — it doesn't create one. If you don't have Cora yet, download it on iPhone and complete onboarding before you connect an AI client.
  2. Add the connector. In Claude, go to Settings → Connectors → Add custom connector, or in ChatGPT, Settings → Apps & Connectors → Add, and paste Cora's MCP server URL: https://api.purplepill.ai/api/mcp/.
  3. Sign in. The client redirects you to a consent page hosted by Cora, where you sign in with Google, Apple, or email — the same login you already use for the Cora app. This step is what determines whose data the connection reaches: whoever signs in is whose data gets connected, so this only works if you already have an onboarded Cora account.
  4. Choose what to grant. You'll see three plain-language permission bundles as checkboxes, not a wall of technical scopes:
    • "Read my data" — checked by default. Covers all read access: recovery, sleep, training history, nutrition, body weight, habits.
    • "Log & edit my data" — unchecked by default. Lets the AI log workouts and meals, record body weight or measurements, build training plans, and manage habits and reminders.
    • "Talk to my coach" — unchecked by default. Lets the AI ask your Cora coach a question on your behalf, grounded in your real data.
  5. Approve. Once you approve, the connection is live. Reconnecting later skips this screen entirely — it's remembered.
  6. Manage it anytime. You can remove the connector from Claude's or ChatGPT's own connector settings whenever you like. An in-app "Connected Apps" screen inside Cora, for managing connections without leaving the app, is coming soon.

Why the default matters: "Read my data" is checked by default, and both write access and coach access are opt-in. Cora built the consent screen so the safest option — look-but-don't-touch — is what happens if you don't think about it at all. You have to actively choose to let an AI change anything.

Under the hood, this is real OAuth 2.1 with PKCE and dynamic client registration, not a simplified home-grown login. Every request an AI makes afterward carries a token that's checked against exactly the scopes you granted — if you never checked "Log & edit my data," any attempt by the AI to log a workout is rejected at the server, not just discouraged by a prompt.

Live now — in production

Cora's MCP server is live at https://api.purplepill.ai/api/mcp/. Add it as a custom connector in Claude or a new app in ChatGPT, sign in with your existing Cora account, and choose your scopes. It's not yet listed in the Claude Connectors Directory or ChatGPT's app directory, so add it manually for now — full copy-paste setup lives on the Cora MCP page.

What 47 tools actually means in practice

Queres que o Cora te ajude com isto?

Experimenta o Cora Grátis

"47 tools" sounds like an engineering brag until you translate it into what you can actually ask for. Roughly, the tools break down into six areas:

  • Nutrition (10 tools). Get a day's logged meals and macros, search past entries and templates, see planned future meals, get a quick macro estimate for a meal you describe, log a meal from free text, edit or delete an entry, duplicate a past meal onto a new day, plan a future meal, and set day notes. See our dedicated guide on nutrition tracking with MCP.
  • Training and workouts (9 tools). Get your current plan, your completed workout history, full details on any single workout, saved workout templates, and cardio goals; log a completed workout from a description; add, move, or remove workouts in your plan; generate a full new plan from a freeform description; and schedule a saved template onto a date. Full breakdown in our workout MCP guide.
  • Sleep, recovery, stats, and body (8 tools). Get sleep summaries over a chosen window, recovery score and HRV trends, summary stats for any tracked metric, a merged day-by-day table of your scores, raw metric time series for trend analysis, your logged body-weight history, the ability to log a new weight entry, and log body-circumference measurements like waist, chest, and neck. See our sleep MCP guide for the sleep-specific detail.
  • Habits, routines, and journals (15 tools). Get your active habits and routines, check progress and streaks on any one of them, create or delete a habit, log a check-off event, pause and resume habits, and create, update, or delete routines and journal entries, plus mark a routine complete for the day.
  • Reminders (3 tools). Schedule a one-time push notification, list your scheduled reminders, and cancel one.
  • Coach and help (2 tools). Ask your Cora coach a question grounded in your real data, and search Cora's in-app help content for how a feature works.

That's the honest inventory: 47 named, individually scoped tools, each with clear metadata about whether it reads or writes, and whether it can delete something. Nothing on that list reaches outside your own Cora account, and nothing operates on the open internet — every tool is explicitly marked as touching only your own data.

What it's genuinely good for

  • Asking questions your app dashboard can't answer directly. "Why has my resting heart rate crept up this week?" is a question a chart can't answer on its own; an AI that can pull your sleep, training load, and recovery data together can actually reason about it.
  • Logging by voice or text, fast. "Log a 45-minute upper-body push session, moderate effort" is quicker than opening an app and tapping through a workout builder, especially right after a session when you just want it recorded.
  • Multi-week analysis in a format you can question. Instead of squinting at a graph, you can ask "what changed between my best training block and my worst" and get a written comparison you can follow up on.
  • Planning that blends multiple data sources at once. A training plan that actually accounts for your sleep debt and your nutrition intake in the same reasoning pass is exactly the kind of cross-domain synthesis chat-based AI is well suited to.

Honest limitations

This guide exists to be useful, not to oversell a feature that's still growing. Here's what MCP genuinely cannot do yet:

  • There's no in-app entry point yet. The backend is live in production, but there's no button inside the Cora app to start this flow — you add the connector URL yourself in Claude or ChatGPT, and it's not yet listed in either AI client's connector directory.
  • Calorie and macro goals aren't queryable yet. If you ask an AI what your daily calorie target is, it can't answer from a tool call today — your targets live on-device and the server doesn't store them yet. It can still see what you've logged and estimate macros for a described meal.
  • No photo-based logging through chat. Meal logging over MCP works from a text description you type or dictate, not a photo you snap. If you want photo-based food logging, that's an in-app feature, not something MCP does today.
  • No persistent AI memory across sessions. Asking your Cora coach a question through MCP is a one-off, grounded answer — it doesn't create a running memory the way a dedicated coaching relationship might. Every dedicated write action (logging, planning) goes through its own specific tool, not through the coach conversation itself.
  • Rate limits exist, and matter for heavy automation. Cora's server allows roughly 120 requests per minute per connected app, with a smaller allowance for unauthenticated probing. That's generous for normal chat use, but worth knowing if you're scripting something.
  • No recurring, scheduled AI tasks. You can't currently ask an AI to "check my recovery every morning and text me a plan" as an automated recurring job — every interaction today is something you initiate in the moment.

None of these are secret. They're the actual, current shape of a product still being hardened before a wider release, and we'd rather tell you what's missing than let you find out the hard way.

Where this is headed

The near-term roadmap is mostly about closing the app-side gap: shipping an in-app entry point so you don't have to paste a URL by hand, and submitting to the Claude Connectors Directory and ChatGPT's app directory so discovery doesn't require a support doc.

Queres que o Cora te ajude com isto?

Experimenta o Cora Grátis

The longer-term shift is more interesting than any individual feature. Once an AI can reliably read your recovery, training, and nutrition data and write back into your plan with your consent, the AI stops being a chat window you visit occasionally and starts becoming something closer to a standing collaborator on your training — one that can be asked to reconsider a plan the moment new data comes in, rather than waiting for you to open an app and notice something changed. Cora's AI & API page goes deeper on that vision, and the MCP page has the live endpoint and setup steps.

Key Takeaways

  • MCP (Model Context Protocol) is an open standard that lets an AI assistant call specific, permissioned tools on outside data — in Cora's case, your real fitness and health data — instead of just talking about it in the abstract.
  • Cora's MCP server is real and live today: 47 tools across nutrition, training, sleep/recovery/body, habits, reminders, and coaching, secured with OAuth 2.1 and three plain-language consent bundles you control.
  • It's live in production for any existing, onboarded Cora account — no waitlist. There's no in-app button and no connector-directory listing yet, so you add the endpoint yourself; full setup is at corahealth.app/mcp.
  • Read access is the default and covers most useful questions; write access and coach access are separate, opt-in permissions you grant explicitly and can remove anytime from your AI client's own connector settings.
  • Real limitations exist today — no photo logging, no stored macro goals via MCP yet, no recurring automated tasks — and are worth knowing before you build a workflow around it.

Frequently Asked Questions

What is a health MCP, and is it different from a fitness app?

A health MCP (Model Context Protocol server) is not an app you open — it's a secure connection that lets an AI assistant like Claude or ChatGPT read and act on your health and fitness data directly inside a normal chat. Instead of tapping through screens, you type a question or a request in plain English, and the AI calls specific tools (like "get my sleep data" or "log this workout") on your behalf. Cora's app is still where you view dashboards, get push notifications, and see your day at a glance. The MCP server is a second way to reach the exact same data, through whatever AI you already talk to.

Is it safe to connect my health data to Claude or ChatGPT?

Cora's MCP server uses OAuth 2.1, the same authorization standard behind "Sign in with Google" buttons, plus scoped consent bundles you approve explicitly (read-only by default). You choose exactly what an AI client can see and do — read-only access, write access, or coaching access. The AI itself never sees your password or account credentials; it only receives a token limited to the scopes you granted. You can remove the connection anytime from Claude's or ChatGPT's own connector settings — an in-app management screen inside Cora is coming soon.

Can I use Cora's MCP server today?

Yes — it's live in production, not a preview. Cora's MCP server is real and fully functional: 47 tools, OAuth-secured, running on our production infrastructure right now. Any existing, onboarded Cora account can connect it today by adding the endpoint to Claude or ChatGPT as a custom connector — there's no waitlist. It isn't yet listed in the Claude or ChatGPT connector directories, and there's no button inside the Cora app for this yet, so you add the connector URL yourself. Full setup steps are at /mcp.

Do I need to already have a Cora account to use the MCP server?

Yes. The MCP server is not a new way to sign up for Cora — it's a new way to reach your existing Cora account. When you connect Claude or ChatGPT, you sign in with the same Google, Apple, or email login you already use in the app, and the AI gets access to that same data. If you don't have a Cora account yet, download the app and complete onboarding first.

What can an AI actually do with my fitness data through MCP?

With read access, an AI can pull your recovery score, HRV, sleep, training history, nutrition logs, and body-weight trends and reason over them in plain language — explaining patterns a dashboard just shows you as a number. With write access, it can log a workout or meal from a text description, build or adjust a training plan, or plan a future meal. With coaching access, it can ask your Cora coach a question grounded in your real data. What it cannot do: see anything outside those granted scopes, act on someone else's account, or bypass Cora's normal safety and consent logic.

Which AI assistants work with Cora's MCP server right now?

Claude (including Claude Code and Claude Desktop) and ChatGPT are the two clients Cora has actually tested end-to-end, including the full OAuth login and consent flow. The server also works with the standard MCP Inspector tool used to test any MCP server. Because Cora's server follows the open Model Context Protocol spec, other compliant clients should work in principle, but we can only vouch for what we've verified.

Acompanha o teu dados de fitness com o Cora

O Cora cria planos de treino com IA que se adaptam à tua recuperação, acompanha o teu progresso em todas as métricas e treina-te em tempo real.