
List WHOOP physiological cycles with cursor pagination. Use next_token from response for subsequent pages. Filter by start/end (ISO 8601).
Get a specific WHOOP physiological cycle by ID. Use list_cycles to find valid cycle IDs.
Get sleep activity linked to a specific WHOOP cycle. Returns the sleep record associated with the given cycle ID. Use list_cycles to find valid cycle IDs.
List WHOOP recovery records with cursor pagination. Includes recovery score, HRV, resting heart rate, and SpO2. Filter by start/end (ISO 8601). Use next_token for subsequent pages.
List WHOOP sleep activities with cursor pagination. Use next_token from response for subsequent pages. Filter by start/end (ISO 8601).
Get a specific WHOOP sleep activity by ID, including stage breakdown, respiratory rate, and performance scores. Use listsleepactivities to find valid IDs.
Get the current user's WHOOP profile including first name, last name, email, and user ID.
Get the current user's WHOOP body measurements including height (meters), weight (kg), and max heart rate.
Validate WHOOP credentials by fetching the current user profile. Returns {success, message}.
List WHOOP workout activities with cursor pagination. Use next_token from response for subsequent pages. Filter by start/end (ISO 8601).
Get a specific WHOOP workout by ID, including strain score, heart rate zones, distance, and kilojoules. Use list_workouts to find valid IDs.

In an mcp.json file, add the configuration below, and restart Cursor.
Learn more in the official documentation ↗
1{
2 "mcpServers": {
3 "agent-handler": {
4 "url": "https://ah-api-develop.merge.dev/api/v1/tool-packs/{TOOL_PACK_ID}/registered-users/{REGISTERED_USER_ID}/mcp",
5 "headers": {
6 "Authorization": "Bearer yMt*****"
7 }
8 }
9 }
10}
11Open your Claude Desktop configuration file and add the server configuration below. You'll also need to restart the application for the changes to take effect.
Make sure Claude is using the Node v20+.
Learn more in the official documentation ↗
1{
2 "mcpServers": {
3 "agent-handler": {
4 "command": "npx",
5 "args": [
6 "-y",
7 "mcp-remote@latest",
8 "https://ah-api-develop.merge.dev/api/v1/tool-packs/{TOOL_PACK_ID}/registered-users/{REGISTERED_USER_ID}/mcp",
9 "--header",
10 "Authorization: Bearer ${AUTH_TOKEN}"
11 ],
12 "env": {
13 "AUTH_TOKEN": "yMt*****"
14 }
15 }
16 }
17}Open your Windsurf MCP configuration file and add the server configuration below.
Click on the refresh button in the top right of the Manage MCP server page or in the top right of the chat box in the box icon.
Learn more in the official documentation ↗
1{
2 "mcpServers": {
3 "agent-handler": {
4 "command": "npx",
5 "args": [
6 "-y",
7 "mcp-remote@latest",
8 "https://ah-api.merge.dev/api/v1/tool-packs/<tool-pack-id>/registered-users/<registered-user-id>/mcp",
9 "--header",
10 "Authorization: Bearer ${AUTH_TOKEN}"
11 ],
12 "env": {
13 "AUTH_TOKEN": "<ah-production-access-key>"
14 }
15 }
16 }
17 }In Command Palette (Cmd+Shift+P on macOS, Ctrl+Shift+P on Windows), run "MCP: Open User Configuration".
You can then add the configuration below and press "start" right under servers. Enter the auth token when prompted.
Learn more in the official documentation ↗
1{
2 "inputs": [
3 {
4 "type": "promptString",
5 "id": "agent-handler-auth",
6 "description": "Agent Handler AUTH_TOKEN", // "yMt*****" when prompt
7 "password": true
8 }
9 ],
10 "servers": {
11 "agent-handler": {
12 "type": "stdio",
13 "command": "npx",
14 "args": [
15 "-y",
16 "mcp-remote@latest",
17 "https://ah-api-develop.merge.dev/api/v1/tool-packs/{TOOL_PACK_ID}/registered-users/{REGISTERED_USER_ID}/mcp",
18 "--header",
19 "Authorization: Bearer ${input:agent-handler-auth}"
20 ]
21 }
22 }
23}It’s an MCP server that lets you access data and functionality from a specific Whoop device via tools. Your agents can invoke these tools to retrieve recovery records, get specific sleep activity, fetch a workout, and more.
WHOOP doesn’t currently support an official MCP server. But you can use one from a 3rd-party platform, like Merge Agent Handler.
Here are some popular use cases:
Here are some widely-used tools:
Here are just a few reasons:
Yes, Merge Agent Handler includes a security gateway with DLP that allows you to define custom rules to block, redact, or mask sensitive data in tool inputs and outputs.
You can implement the following custom rules:
You can follow these steps:
1. Create/sign in to your Merge Agent Handler account (pick Sandbox vs Production). You’ll do the initial setup in the Agent Handler dashboard for the environment you plan to test in first.[1]
2. Create a Tool Pack for your WHOOP use case. Tool Packs are the container that defines which connectors + specific tools your agent can access (start least-privilege; typically read-only first).
3. Add the WHOOP connector to that Tool Pack (and select the tools). This is where you explicitly enable WHOOP and choose which WHOOP actions are exposed via MCP through that Tool Pack.
4. Create a Registered User (the identity boundary for tool execution). This represents “who” the agent is acting on behalf of; Agent Handler uses it to scope credentials and audit logs.
5. Authenticate WHOOP for that Registered User via Link (if not already connected). When credentials are missing, Agent Handler will prompt connection through the Link flow; once completed, tool calls can run authenticated.
6. Copy the MCP endpoint URL for your Tool Pack + Registered User. The MCP URL is generated per Tool Pack + Registered User pair (it includes both IDs).
7. Generate an Agent Handler API key and connect your MCP client. Configure your MCP client (Claude Desktop/Cursor/VS Code/Windsurf, etc.) with:
<code class="blog_inline-code">Authorization: Bearer <your Agent Handler API key></code> (Agent Handler uses a Merge-issued API key for the MCP endpoint auth)8. Test safely, then expand. Start with a couple of “read” WHOOP pulls, confirm logs look right, then add write/high-risk tools only after you’re confident—using rules/alerts/logs as guardrails.
Yes, Agent Handler for Employees lets your employees connect Claude, ChatGPT, Microsoft Copilot, Cursor, and other MCP-compatible AI tools to Whoop without bypassing IT governance.
Instead of setting up direct connections with personal credentials that IT can't monitor or revoke, each employee authenticates through Agent Handler and gets individual credentials tied to their identity.
IT also provisions access by role or group via SCIM. A wellness coordinator, for example, gets Whoop access to monitor team recovery trends, Slack to share wellness updates, and Google Sheets to track program metrics; while an HR manager gets Whoop access to review aggregate wellness data, Workday to manage employee records, and BambooHR to track leave and org data.
Every tool call an employee's AI makes to Whoop is also inspected against your DLP rules and logged to a searchable audit trail, giving security teams full visibility into what data was accessed and by whom.
Whether you're an engineer experimenting with agents or a product manager looking to add tools, you can get started for free now