streamable-httpupdated 1mo ago
A local MCP server that lets an MCP client (Claude Desktop, Claude Code, Cursor, โฆ) act as a Trainzilla coach. It wraps the existing GraphQL API at api.tzilla.live โ no direct DB access โ so all auth and business rules stay enforced by the backend.
What can you do with Trainzilla Coach MCP?
tzilla-mcp (MVP, local only)
A local MCP server that lets an MCP client
(Claude Desktop, Claude Code, Cursor, โฆ) act as a Trainzilla coach. It wraps
the existing GraphQL API at api.tzilla.live โ no direct DB access โ so all
auth and business rules stay enforced by the backend.
Status: Local MVP โ read tools, offline calculators, and confirm-gated write tools, plus a resource + a prompt. Not deployed anywhere. Runs entirely on your machine against your own coach login.
What it can do today (23 tools, 1 resource, 1 prompt)
Read (live data):
whoami,list_clients,get_client_profilelist_client_habits,get_habit_compliance,recent_habit_activity,master_habitslist_workout_plans,list_diet_planslist_checkins,list_sessions,list_subscriptions,billing_summary
Calculators (offline, no network):
calc_tdeeโ BMR / TDEE / recommended caloriescalc_macrosโ macro split by strategy (Standard 40/30/30, Pro g/kg, Keto)calc_1rmโ 1-rep-max (Epley) + %1RM weight suggestions
Write (confirm-gated): every write tool returns a preview unless called
with confirm: true, so nothing changes by accident:
create_habit,create_master_habit,assign_master_habitcreate_checkin(with questions),schedule_sessioncreate_workout_plan,create_diet_plan
Still not exposed: deletes, payment execution/refunds, messaging, permission changes โ by design.
Resource: tzilla://client/{clientId}/profile โ a client's profile as JSON.
Prompt: weekly_client_review โ pulls profile/habits/compliance/sessions and
writes a read-only weekly review.
Setup
npm install
npm run build
Create .env (see .env.example) with a coach's tokens. Easiest source โ log in
to the coach web app, then in the browser console:
localStorage.getItem("token") // -> TZ_ACCESS_TOKEN
localStorage.getItem("refreshToken") // -> TZ_REFRESH_TOKEN
The server auto-refreshes the access token via refreshAccessToken when it expires.
Run
Local (stdio) โ for Claude Desktop etc.:
- Dev:
npm run dev - Built:
npm start - Smoke:
node scripts/smoke.mjs
Remote (Streamable HTTP) โ localhost only, multi-coach:
- Dev:
npm run httpยท Built:npm run start:http - Listens on
http://127.0.0.1:8787/mcp(setMCP_HTTP_PORT/MCP_HTTP_HOST). - Smoke:
node scripts/smoke-http.mjs
Auth modes
- stdio: uses
TZ_ACCESS_TOKEN(+TZ_REFRESH_TOKEN) from env; auto-refreshes. - Endpoint selection:
TZ_API_URLwins when set.- Otherwise
TZ_ENVIRONMENT=staginguseshttps://qa-be2.tzilla.live/graphql. - All other cases default to
https://api.tzilla.live/graphql.
- HTTP: pass-through โ each request must send the coach's API key
(
Authorization: Bearer tz_...orx-api-key). The server never stores tokens; it forwards the caller's key to the GraphQL API, so the backend enforces scope (multi-coach safe). API keys are minted by the backend feature below.
Backend: trainer API keys (built in tzilla-be, local โ not deployed yet)
createApiKey(name)โ returns the plaintexttz_โฆkey once + infoapiKeys(list, no secret) ยทrevokeApiKey(id)- Auth middleware accepts
tz_keys (headerx-api-keyorBearer), resolves the owning coach, and stampslastUsedAt. Only a SHA-256 hash is stored.
Use from Claude Desktop
Add to claude_desktop_config.json (Settings โ Developer โ Edit Config):
{
"mcpServers": {
"tzilla-coach": {
"command": "node",
"args": ["C:/New folder/tzilla-mcp/dist/index.js"],
"env": {
"TZ_API_URL": "https://api.tzilla.live/graphql",
"TZ_ACCESS_TOKEN": "<paste>",
"TZ_REFRESH_TOKEN": "<paste>"
}
}
}
}
Restart Claude Desktop, then try: "Use tzilla-coach: who am I, and list my clients."
Roadmap
- Write tools (habits, check-ins, sessions, plans) โ confirm-gated
- Resource (client profile) + prompt (weekly review)
- Wider read coverage (plans, check-ins, sessions, billing)
- Backend trainer API keys / PAT (built in
tzilla-be, local โ needs PR + deploy) - Remote Streamable-HTTP transport (localhost, API-key pass-through auth)
- Deploy the backend API-key feature; host the HTTP server (TLS) for real remote use
- Full MCP OAuth 2.1 (replace pass-through) for a public connector
- More resources (plans / check-in history) + prompts (e.g. "draft a plan")
Layout
src/
config.ts # env + tiny .env loader
client.ts # GraphQL client: bearer auth + refresh-on-401 + role header
calc.ts # offline coach math (ported from HealthMath/WorkoutMath)
index.ts # MCP server + tool definitions (stdio)
scripts/
smoke.mjs # spawns the server and lists tools (handshake check)
Install
Add Trainzilla Coach MCP to your client. Pick the one you use.
claude mcp add --transport http trainzilla-coach-mcp https://api.tzilla.live/mcpcodex mcp add trainzilla-coach-mcp --url https://api.tzilla.live/mcp{
"mcpServers": {
"trainzilla-coach-mcp": {
"url": "https://api.tzilla.live/mcp"
}
}
}Add to `~/.cursor/mcp.json`, or `.cursor/mcp.json` for a single project.
{
"servers": {
"trainzilla-coach-mcp": {
"type": "http",
"url": "https://api.tzilla.live/mcp"
}
}
}Add to `.vscode/mcp.json` in your workspace.
{
"mcpServers": {
"trainzilla-coach-mcp": {
"url": "https://api.tzilla.live/mcp"
}
}
}Add to `claude_desktop_config.json`, then restart Claude Desktop.
{
"mcpServers": {
"trainzilla-coach-mcp": {
"serverUrl": "https://api.tzilla.live/mcp"
}
}
}Add to `~/.codeium/windsurf/mcp_config.json`.
Score
39 / 100
Incomplete
- Documentation25/25
- Maintenance16/25
- Trust6/20
- Capability0/15
- Install experience12/15
- Documents what it does and how to connect
- Has a resolvable package or endpoint
- Exposes at least one tool, prompt or resource
- README has substantive content
- Includes a code example
- Documents its configuration
- Mentions credentials or security posture
- Last commit 33 days ago
- Has a release history
- Repository is not archived
- No licence detected
- Namespace verified in the official MCP registry
- Claimed by its owner
- Published under an organisation
- 0 tool(s) documented
- Provides prompt templates
- Provides resources
- 6 documented install method(s)
- Published to a package registry
- Offers a hosted endpoint โ no local install
Version history
| Versions | Published |
|---|---|
| 1.0.0Latest | Jun 13, 2026 |