Skip to content

Cloud OAuth

Fitbit API integration

Connectable nowYour end-users can connect this provider today through the hosted flow.

Fitbit device illustration

Fitbit has the largest installed base of any dedicated wearable, which makes it the provider most consumer health products need first. It is also the API with the most historical baggage — the surface has accreted since 2011 and it shows in inconsistent date handling and endpoint shapes.

The single biggest constraint is intraday data. Second- and minute-level heart rate is not available to a standard application; it requires a separate approval from Fitbit for your specific use case. Plenty of teams design a feature around intraday heart rate before discovering they cannot have it.

WearLink normalises Fitbit's daily summaries and sleep logs into the shared schema and manages the Subscriptions API registration for you, including re-registration when a subscription is dropped on Fitbit's side.

Connect a Fitbit user

Two calls. The first mints a hosted connect URL for your end-user; the second reads the normalised summaries once they have authorised with Fitbit. Subscribe a webhook to receive the same objects as they land.

connect + read — fitbit
# 1. Create a connect session for your end-user
#    The API key goes in X-WearLink-API-Key, not in Authorization.
curl -X POST https://wearlink.io/api/v1/connections/session \
  -H "X-WearLink-API-Key: $WEARLINK_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"user_id": "'"$USER_ID"'", "provider": "fitbit", "redirect_uri": "https://yourapp.com/connected"}'

# → { "connect_url": "https://wearlink.io/widget/connect?token=...", "expires_in": 3600 }
# Redirect the user there; they authorise fitbit and land back on your redirect_uri.
# The token is scoped to that one user — it is safe to put in a browser URL.

# 2. Pull normalised data whenever you want
curl -H "X-WearLink-API-Key: $WEARLINK_API_KEY" \
  "https://wearlink.io/api/v1/users/$USER_ID/summaries?provider=fitbit&days=7"

Fitbit data available through WearLink

  • Steps
  • Sleep stages
  • Heart rate (intraday where granted)
  • Calories
  • SpO2
  • Activities & workouts
  • Weight

Webhook events you can subscribe to

  • steps.created
  • sleep.created
  • heart_rate.created
  • workout.created

Normalised families this provider feeds: Sleep, Heart Rate Variability, Heart Rate, Workouts, Steps & Daily Activity, Calories & Energy, Body Composition, Respiratory Rate & SpO2, Stress, VO2 Max & Fitness Metrics.

What makes the Fitbit API hard to integrate directly

These are the things that turn an estimated one-week integration into a one-month one.

Intraday data needs separate approval

Standard OAuth access gives you daily and activity-level summaries. Minute-level heart rate requires Fitbit to approve your application for intraday access, and consumer products are frequently declined.

Subscriptions tell you nothing useful on their own

The subscription notification says "collection X changed for user Y". You still fetch the data yourself. Budget for the second round trip.

Timezones are per-user and mutable

Fitbit reports in the user's device timezone, which changes when they travel. Storing raw local timestamps without the offset produces duplicate or missing days.

FAQ

Fitbit API — frequently asked questions

Is the Fitbit API free?
Yes for standard access — you register an application and use OAuth 2.0. Intraday access is free but gated behind a separate manual approval from Fitbit.
Can I get minute-by-minute Fitbit heart rate?
Only if Fitbit grants your application intraday access. WearLink will surface whatever your credentials are approved for; we cannot grant access Fitbit has not given you.
Does Fitbit work alongside Google Health Connect?
Yes, and many Android users have both. WearLink deduplicates overlapping records using your configured provider priority so a single walk does not count twice.

Related

Other cloud integrations

Oura Ring API

Connectable now

The Oura Ring API (v2) is one of the cleaner wearable APIs to work with — the documentation is accurate and the daily-summary endpoints are stable. The complexity is not in reading it, it is in keeping it read: Oura backfills and revises data after the fact, so a sleep record you fetched this morning can legitimately change by this evening.

WHOOP API

Connectable now

WHOOP's developer API exposes the four objects the product is built around — cycles, recovery, sleep and workouts. The data is high quality and the model is coherent, which makes WHOOP a favourite for recovery and readiness products.

Strava API

Connectable now

Strava is the best-instrumented activity API in the consumer space and the only provider in the WearLink catalogue with a true push model — an activity upload triggers a webhook within seconds, not on a poll cycle. If your product cares about workouts rather than sleep or recovery, Strava is usually the fastest path to a working demo.

Withings API

Connectable now

Withings is the connected-scale and blood-pressure provider, which makes it the one that matters most for clinical-adjacent products — weight management, hypertension programmes, GLP-1 follow-up and remote patient monitoring. Its data is measurement-shaped rather than continuous: discrete readings taken when a user steps on a scale or straps on a cuff.

Garmin API

Provider onboarding

Garmin has the broadest data surface of any provider in the catalogue — if a metric exists in consumer wearables, a Garmin device probably measures it. For endurance, military, occupational-health and research use cases it is frequently non-negotiable.

Polar AccessLink API

Provider onboarding

Polar's AccessLink API serves a smaller but committed base — endurance athletes, coaching platforms and sports-science teams. Heart rate quality is the reason people choose it; Polar's chest straps remain a reference standard.

Start with Fitbit — free for up to 3 users

No credit card. Your API key is issued at sign-up, and the hosted connect flow works from the first request.