# VITLS

> VITLS is an AI health and longevity coach that runs the user's whole body: it reads their vitals
> (HRV, sleep, resting heart rate, weight, workouts), remembers their story, and tells them what to do
> today. One coach for nutrition, training, recovery and body composition. Coaching, not medical advice.

This site (the marketing site) has no API. The product is the VITLS app at https://app.vitls.ai, built on
agent-native. Agents interact with it in two ways:

- **MCP** — call the app's actions directly as tools, on behalf of a signed-in user. Use this to read
  health data, update the coach profile or edit the dashboard.
- **A2A** — hand a task to the VITLS coach agent, which reasons over it with its own tools and replies.
  Use this when the coach should think (interpret a readout, plan a training day).

## A2A (agent-to-agent)

- Agent card: https://app.vitls.ai/.well-known/agent-card.json (also served at /.well-known/agent-card.json on this site)
- JSON-RPC 2.0 endpoint: POST https://app.vitls.ai/_agent-native/a2a
- Methods: `message/send`, `message/stream` (SSE), `tasks/get`, `tasks/cancel`
- Always send `"async": true` with `message/send`, then poll `tasks/get` until the task is
  `completed`, `failed` or `canceled`. Coach turns can outlast serverless gateway timeouts.
- Auth: `Authorization: Bearer <token>` using a scheme listed in the agent card's `securitySchemes`
  (JWT signed with the deployment's shared A2A secret for agent-native peers). Production refuses
  unauthenticated calls.
- Message parts: `{ "type": "text" }` for instructions, `{ "type": "data" }` for structured input.
  Reuse `contextId` to continue the same conversation.

Example:

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "message/send",
  "params": {
    "message": {
      "role": "user",
      "parts": [{ "type": "text", "text": "Give me today's morning readout and training directive." }]
    },
    "async": true
  }
}
```

## MCP (tools)

- Server URL: https://app.vitls.ai/mcp (streamable HTTP)
- Setup page with per-host instructions: https://app.vitls.ai/mcp/connect
- Auth: OAuth 2.1 with PKCE and dynamic client registration. Discovery:
  https://app.vitls.ai/.well-known/oauth-authorization-server. Scopes: `mcp:read`, `mcp:write`, `mcp:apps`,
  `offline_access`. The user signs in and approves; you act only as that user, inside their workspace.
- Local coding agents (Claude Code, Codex, Cursor, VS Code): `npx @agent-native/core@latest connect https://app.vitls.ai`

## Coach capabilities

- `get-coach-profile` / `update-coach-profile`: persona, goals, language, timezone, units, morning readout time, onboarding stage
- `get-health`: daily metrics with trend and baseline summaries, weigh-ins with the water-vs-fat check, sleep, workouts
- `get-dashboard` / `save-dashboard`: the user's goal-driven dashboard; revisions allow undo
  (`list-dashboard-revisions`, `restore-dashboard-revision`)
- `save-memory`: injuries, conditions, life events, coaching preferences
- `create-device-pairing`: pairing code for the companion app (needs the user's explicit approval)
- `manage-notifications`: deliver the morning readout (inbox and push)

The live list of tools is whatever the MCP server returns from `tools/list`; prefer it over this file.

## Rules for agents

- Health data is sensitive. Request only what the task needs, and never send it to third parties
  without the user's consent.
- Never invent or estimate numbers. Read them with `get-health`; if data is missing, say so.
- Trend over raw: one day (a weight jump, a bad HRV night) is noise until the trend moves.
- VITLS is a coach, not a doctor. Route medical questions to a professional.
- Verify a write by reading it back before reporting it done.

## Links

- App: https://app.vitls.ai
- Website: /en (also /sk, /cs, /es, /it, /ru)
