# Fitbit

**Canonical:** https://apis.io/providers/fitbit/  
**Website:** https://www.fitbit.com  
**APIs profiled:** 3

Fitbit is a wearable health and fitness platform — devices (trackers, smartwatches, smart scales) plus a companion mobile app and cloud data services. Founded in 2007 and acquired by Google in January 2021, Fitbit is now operated as part of Google's hardware portfolio alongside the Pixel Watch. The Fitbit Web API exposes user activity, exercise, heart rate (including intraday and HRV), sleep with stage breakdowns, body and weight, nutrition and water, devices, friends and leaderboards, and advanced sensor metrics — SpO2, breathing rate, skin and core temperature, ECG, Irregular Rhythm Notifications, and Cardio Fitness Score (VO2 Max). Authentication is OAuth 2.0 Authorization Code Grant with PKCE; default quota is 150 requests per hour per authorized user per app. A webhook subscription system streams sync notifications for the activities, body, foods, sleep, and userRevokedAccess collections. The Fitbit OS SDK lets developers ship apps and clock faces directly to Versa, Sense, and other Fitbit devices using JavaScript/CSS/SVG. The legacy Fitbit Web API is scheduled for deprecation in September 2026; new and migrated integrations should target the successor Google Health API at developers.google.com/health, which uses Google OAuth 2.0 and Google's modern infrastructure.

## Kin Score — 67.5 / 100 (exemplar)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 67.5).

| Facet | Score |
|---|---|
| Discoverability | 64.8 |
| Contract Quality | 78.6 |
| Governance | 13.6 |
| Contract Governance | 13.6 |
| Operational Transparency | 42.1 |
| Developer Ergonomics | 61.9 |
| Commercial Clarity | 84.2 |
| Access Clarity | 84.2 |

Regulatory layer — **Health**: 52.5 (matched via tags).

## Agent readiness — 35.3 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | documented |
| Rate Limit Signal | documented |
| Event Surface Described | derived |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (3)

- **Fitbit User API** — Read and update the authorized Fitbit user's profile including display name, gender, birthday, height, weight, locale, timezone, and unit preferences (distance, weight, water, g...
- **Fitbit Foods API** — The Foods API from Fitbit — 1 operation(s) for foods.
- **Fitbit Oauth2 API** — The Oauth2 API from Fitbit — 4 operation(s) for oauth2.

## Agentic access (1)

- **Fitbit Agentic Access** — 55 operations · 18 acting · 1 human-in-the-loop

## Security (2)

- **Fitbit Authentication** — oauth2 · 1 scheme
- **Fitbit Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC

## Plans (1)

- **Fitbit Plans Pricing**

## Tags

Wearable, Health, Fitness, Activity Tracking, Heart Rate, Sleep, Google, IoT

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/fitbit/). Scores are computed from the provider's own public artifacts under a published rubric.
