Metal Strength ← Back to the app
Developers

Developer API

Version 1 · Last updated: October 8, 2026

The short version: a read-only HTTPS API to your own Metal Strength data — workouts, sets, heart rate, weigh-ins, body fat and tape measurements — for your own scripts, spreadsheets and dashboards. Part of Premium. You create a personal access token in the app under Settings → Developer API, and every request carries it.

1. Authentication

Send your token in the Authorization header. Tokens start with ms_live_, are shown once when you create them, and are stored by us only as a SHA-256 hash — a lost token cannot be recovered, only revoked and replaced. You can hold up to five, and revoke any of them at any time in the same screen.

curl https://metalstrength.fit/api/v1/me \
  -H "Authorization: Bearer ms_live_YOUR_TOKEN"

Treat a token like a password: it reads your training history. Never put it in a page other people can open, a public repository, or a shared spreadsheet.

2. Basics

Base URLhttps://metalstrength.fit/api/v1
FormatJSON, UTF-8. Dates are YYYY-MM-DD (your own calendar day); instants are ISO 8601 UTC.
UnitsBody data is always metric (kg, cm, %). A workout's weights are in the workout's own unit (kg or lb).
AccessRead-only. Premium accounts only; when Premium ends, tokens stop working until it is renewed.
Rate limit120 requests per minute per token.
CORSAllowed from any origin (the token, not a cookie, is the credential).

3. Errors

Every error has an HTTP status and the same body:

{ "error": { "code": "premium_required", "message": "The API is part of Metal Strength Premium." } }
StatuscodeMeaning
401unauthorizedMissing, unknown or revoked token.
403premium_requiredThe account has no active Premium.
404not_foundNo such workout on this account.
429rate_limitedOver 120 requests a minute. Wait and retry.
500server_errorOur side. Retry with a short backoff.

4. GET /me

Who the token belongs to, and the profile numbers your data is read against.

{
  "data": {
    "id": "5f1c…",
    "displayName": "Sam",
    "sex": "male",
    "age": 31,
    "heightCm": 180,
    "bodyweightKg": 82.4
  }
}

5. GET /workouts

Your saved workouts, newest first.

ParameterMeaning
sinceOnly workouts trained on or after this day (YYYY-MM-DD).
untilOnly workouts trained on or before this day.
limit1–100, default 50.
offsetSkip this many. paging.next gives the next offset, or null at the end.
{
  "data": [
    {
      "id": "9a0e…",
      "performedOn": "2026-10-08",
      "savedAt": "2026-10-08T18:52:11.204Z",
      "name": "Push A",
      "program": "Push Pull Legs",
      "unit": "kg",
      "durationSec": 3120,
      "exercises": [
        {
          "exerciseId": "barbell-bench-press",
          "name": "Barbell Bench Press",
          "supersetId": null,
          "sets": [
            { "kind": "warmup", "done": true, "reps": 5, "seconds": null, "weight": 40, "rpe": null, "note": null },
            { "kind": "working", "done": true, "reps": 8, "seconds": null, "weight": 80, "rpe": 8, "note": null }
          ]
        }
      ],
      "heartRate": {
        "avg": 124, "max": 168, "min": 82, "maxHr": 186,
        "zoneSeconds": [840, 1260, 690, 300, 30],
        "series": [96, 101, 118, 0, 131],
        "seriesStepSec": 30
      }
    }
  ],
  "paging": { "limit": 50, "offset": 0, "next": 50 }
}
FieldMeaning
sets[].kindwarmup, working, drop or failure.
sets[].doneWhether the set was ticked off. Only done sets count as work.
sets[].secondsSet for timed sets (holds, intervals) instead of reps; otherwise null.
sets[].rpeEffort, 5–10 in half steps, or null. Sets logged as RIR are stored as RPE = 10 − RIR.
heartRateFrom the watch, via the phone's health app; null when none was recorded. zoneSeconds are zones 1–5 by share of maxHr (<60, 60–70, 70–80, 80–90, ≥90%). series is one reading per seriesStepSec from the start, 0 where there was none.

6. GET /workouts/{id}

One workout, in the same shape, under data.

7. GET /body

Weigh-ins, body-fat readings and tape measurements, oldest first. Accepts since and until.

{
  "data": {
    "weight": [ { "date": "2026-10-07", "kg": 82.4 } ],
    "bodyFat": [ { "date": "2026-10-01", "percent": 15.2 } ],
    "measurements": [ { "date": "2026-10-05", "site": "waist", "cm": 84.5 } ]
  }
}

site is one of neck, shoulders, chest, waist, hips, arm_left, arm_right, forearm_left, forearm_right, thigh_left, thigh_right, calf_left, calf_right.

8. Terms of use

9. Privacy

The API returns only what your account already holds, to whoever holds your token. We keep the token's hash, its name, and when it was created and last used — listed in Download my data and deleted with your account. See the Privacy Policy.