Skip to content

Cloud OAuth

WHOOP API integration

Connectable nowYour end-users can connect this provider today through the hosted flow.

WHOOP device illustration

WHOOP's developer API exposes the four objects the product is built around — cycles, recovery, sleep and workouts. The data is high quality and the model is coherent, which makes WHOOP a favourite for recovery and readiness products.

The friction is in access and in the cycle model. WHOOP organises a day around a physiological cycle rather than a calendar date, so a "day" can start at 22:40 and the recovery score attaches to the cycle, not to the date your product probably keys on. WearLink resolves cycles to local calendar days during normalisation so your daily rollups line up with what the user expects.

Scopes matter more here than with most providers: each data family needs its own scope at authorisation time, and adding a scope later means re-consenting the user. WearLink requests the full set your plan permits up front so you are not forced through a second consent screen when you ship a new feature.

Connect a WHOOP user

Two calls. The first mints a hosted connect URL for your end-user; the second reads the normalised summaries once they have authorised with WHOOP. Subscribe a webhook to receive the same objects as they land.

connect + read — whoop
# 1. Create a connect session for your end-user
#    The API key goes in X-WearLink-API-Key, not in Authorization.
curl -X POST https://wearlink.io/api/v1/connections/session \
  -H "X-WearLink-API-Key: $WEARLINK_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"user_id": "'"$USER_ID"'", "provider": "whoop", "redirect_uri": "https://yourapp.com/connected"}'

# → { "connect_url": "https://wearlink.io/widget/connect?token=...", "expires_in": 3600 }
# Redirect the user there; they authorise whoop and land back on your redirect_uri.
# The token is scoped to that one user — it is safe to put in a browser URL.

# 2. Pull normalised data whenever you want
curl -H "X-WearLink-API-Key: $WEARLINK_API_KEY" \
  "https://wearlink.io/api/v1/users/$USER_ID/summaries?provider=whoop&days=7"

WHOOP data available through WearLink

  • Recovery score
  • Strain
  • Sleep stages & sleep performance
  • HRV
  • Resting heart rate
  • Respiratory rate
  • SpO2
  • Workouts

Webhook events you can subscribe to

  • recovery_score.created
  • sleep.created
  • workout.created
  • series.heart_rate_variability.created

Normalised families this provider feeds: Sleep, Heart Rate Variability, Heart Rate, Workouts, Calories & Energy, Recovery & Readiness, Body & Skin Temperature, Respiratory Rate & SpO2.

What makes the WHOOP API hard to integrate directly

These are the things that turn an estimated one-week integration into a one-month one.

Cycles are not days

A WHOOP cycle boundary is physiological, not midnight. Naively grouping by cycle start date produces off-by-one-day recovery scores for anyone who sleeps past midnight — which is most people.

Scopes are consent-time, not request-time

If you did not ask for the sleep scope during authorisation you cannot read sleep later without sending the user back through the consent flow.

Rate limits punish backfill

Pulling long histories for many users at once will hit limits. WearLink queues and paces historical backfill per connection rather than fanning out.

FAQ

WHOOP API — frequently asked questions

How do I get access to the WHOOP API?
You register an application in the WHOOP developer portal and request OAuth credentials. Access to production and the breadth of available scopes depends on WHOOP's review of your use case.
Does the WHOOP API give real-time strain?
No. WHOOP publishes strain and recovery once the band syncs and the cycle is scored, not as a live stream. WearLink notifies your webhook endpoint as soon as a scored record is available.
Can I combine WHOOP recovery with Oura readiness?
Yes — both normalise into the recovery_score category, so you can compare or fall back between them without provider-specific code. Provider priority settings decide which wins when a user has both.

Related

Other cloud integrations

Oura Ring API

Connectable now

The Oura Ring API (v2) is one of the cleaner wearable APIs to work with — the documentation is accurate and the daily-summary endpoints are stable. The complexity is not in reading it, it is in keeping it read: Oura backfills and revises data after the fact, so a sleep record you fetched this morning can legitimately change by this evening.

Fitbit API

Connectable now

Fitbit has the largest installed base of any dedicated wearable, which makes it the provider most consumer health products need first. It is also the API with the most historical baggage — the surface has accreted since 2011 and it shows in inconsistent date handling and endpoint shapes.

Strava API

Connectable now

Strava is the best-instrumented activity API in the consumer space and the only provider in the WearLink catalogue with a true push model — an activity upload triggers a webhook within seconds, not on a poll cycle. If your product cares about workouts rather than sleep or recovery, Strava is usually the fastest path to a working demo.

Withings API

Connectable now

Withings is the connected-scale and blood-pressure provider, which makes it the one that matters most for clinical-adjacent products — weight management, hypertension programmes, GLP-1 follow-up and remote patient monitoring. Its data is measurement-shaped rather than continuous: discrete readings taken when a user steps on a scale or straps on a cuff.

Garmin API

Provider onboarding

Garmin has the broadest data surface of any provider in the catalogue — if a metric exists in consumer wearables, a Garmin device probably measures it. For endurance, military, occupational-health and research use cases it is frequently non-negotiable.

Polar AccessLink API

Provider onboarding

Polar's AccessLink API serves a smaller but committed base — endurance athletes, coaching platforms and sports-science teams. Heart rate quality is the reason people choose it; Polar's chest straps remain a reference standard.

Start with WHOOP — free for up to 3 users

No credit card. Your API key is issued at sign-up, and the hosted connect flow works from the first request.