Connected agents
Your data. Your agents.
Last updated · September 4, 2026
NAFA supports authenticated Model Context Protocol (MCP) connections for ChatGPT, Codex, and other personal agents. You decide what each agent may read or edit, and you can revoke access at any time.
MCP endpoint:
https://nafa.fitness/api/agent/mcpConnect your AI assistant
- In ChatGPT, Claude, Grok, or another MCP client, add the NAFA MCP endpoint above.
- Choose Connect when your assistant asks you to authorize NAFA.
- Sign in on the web or open the NAFA app, then approve the exact requested permissions.
Available permissions
- Read or edit workout programs and review workout history.
- Read or edit food logs, calories, macros, and fibre.
- Read health metrics and biomarkers, or edit manual biomarkers.
Safety boundaries
- Every edit requires a separate explicit confirmation in the conversation.
- Meal photos, progress photos, and imported report files are never available to agents.
- Responses omit database and sync metadata, except for purpose-named record handles needed for an edit you request.
- Tokens are revocable and stored only as one-way hashes.
- Agent audit records contain tool names and outcomes, never health or fitness values.
Agents without OAuth can use a manually created bearer token from Profile → Agent Access. OAuth-capable clients should use the discovery metadata exposed by the MCP server.