Skip to content

Cloud OAuth

Withings API integration

Connectable nowYour end-users can connect this provider today through the hosted flow.OAuth configured; provider-side production tier not yet confirmed

Withings device illustration

Withings is the connected-scale and blood-pressure provider, which makes it the one that matters most for clinical-adjacent products — weight management, hypertension programmes, GLP-1 follow-up and remote patient monitoring. Its data is measurement-shaped rather than continuous: discrete readings taken when a user steps on a scale or straps on a cuff.

That measurement model interacts badly with naive daily-summary logic. A user might weigh themselves three times in a morning or skip four days. WearLink normalises each reading as a discrete timestamped record rather than forcing it into a daily bucket, so you can apply your own smoothing.

Withings also distinguishes between developer sandbox and production tiers. Sandbox works for building; you need the production tier before real users can connect, and promotion is a manual review on Withings' side.

Connect a Withings user

Two calls. The first mints a hosted connect URL for your end-user; the second reads the normalised summaries once they have authorised with Withings. Subscribe a webhook to receive the same objects as they land.

connect + read — withings
# 1. Create a connect session for your end-user
#    The API key goes in X-WearLink-API-Key, not in Authorization.
curl -X POST https://wearlink.io/api/v1/connections/session \
  -H "X-WearLink-API-Key: $WEARLINK_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"user_id": "'"$USER_ID"'", "provider": "withings", "redirect_uri": "https://yourapp.com/connected"}'

# → { "connect_url": "https://wearlink.io/widget/connect?token=...", "expires_in": 3600 }
# Redirect the user there; they authorise withings and land back on your redirect_uri.
# The token is scoped to that one user — it is safe to put in a browser URL.

# 2. Pull normalised data whenever you want
curl -H "X-WearLink-API-Key: $WEARLINK_API_KEY" \
  "https://wearlink.io/api/v1/users/$USER_ID/summaries?provider=withings&days=7"

Withings data available through WearLink

  • Weight & body composition
  • Blood pressure
  • Sleep
  • Heart rate
  • Body temperature

Webhook events you can subscribe to

  • body_composition.created
  • blood_pressure.created
  • sleep.created

Normalised families this provider feeds: Sleep, Heart Rate, Steps & Daily Activity, Blood Pressure, Body Composition, Respiratory Rate & SpO2.

What makes the Withings API hard to integrate directly

These are the things that turn an estimated one-week integration into a one-month one.

Sandbox and production are different worlds

An integration that works perfectly against sandbox credentials will not serve real users until Withings promotes your application. Plan for that review in your launch timeline.

Multi-user scales attribute by guesswork

A shared household scale assigns readings to whichever profile the weight most closely matches. Misattributed readings are a real data-quality problem, not an edge case.

The API is measurement-typed, not metric-typed

Withings returns a measurement group containing typed values. Mapping those type codes to meaningful fields is a lookup table you have to maintain — WearLink maintains it for you.

FAQ

Withings API — frequently asked questions

Does Withings give continuous heart rate?
Not in the way a wrist wearable does. Withings heart rate comes from discrete measurements taken by its devices, plus sleep-tracking hardware where the user owns it.
Is Withings suitable for remote patient monitoring?
It is one of the more common choices, because connected scales and blood-pressure cuffs are the two device categories clinical programmes most often need. Your own regulatory obligations still apply.
How do I handle duplicate weigh-ins?
WearLink stores every reading as its own record with a timestamp. Deduplication and smoothing are left to you, since the correct policy differs between a weight-loss product and a clinical trial.

Related

Other cloud integrations

Oura Ring API

Connectable now

The Oura Ring API (v2) is one of the cleaner wearable APIs to work with — the documentation is accurate and the daily-summary endpoints are stable. The complexity is not in reading it, it is in keeping it read: Oura backfills and revises data after the fact, so a sleep record you fetched this morning can legitimately change by this evening.

WHOOP API

Connectable now

WHOOP's developer API exposes the four objects the product is built around — cycles, recovery, sleep and workouts. The data is high quality and the model is coherent, which makes WHOOP a favourite for recovery and readiness products.

Fitbit API

Connectable now

Fitbit has the largest installed base of any dedicated wearable, which makes it the provider most consumer health products need first. It is also the API with the most historical baggage — the surface has accreted since 2011 and it shows in inconsistent date handling and endpoint shapes.

Strava API

Connectable now

Strava is the best-instrumented activity API in the consumer space and the only provider in the WearLink catalogue with a true push model — an activity upload triggers a webhook within seconds, not on a poll cycle. If your product cares about workouts rather than sleep or recovery, Strava is usually the fastest path to a working demo.

Garmin API

Provider onboarding

Garmin has the broadest data surface of any provider in the catalogue — if a metric exists in consumer wearables, a Garmin device probably measures it. For endurance, military, occupational-health and research use cases it is frequently non-negotiable.

Polar AccessLink API

Provider onboarding

Polar's AccessLink API serves a smaller but committed base — endurance athletes, coaching platforms and sports-science teams. Heart rate quality is the reason people choose it; Polar's chest straps remain a reference standard.

Start with Withings — free for up to 3 users

No credit card. Your API key is issued at sign-up, and the hosted connect flow works from the first request.