openGym: Open-Source Self-Hosted Fitness Tracker with Passkey Authentication and Local Storage
Deployable via Docker without subscriptions or telemetry, openGym is a self-hosted workout tracker featuring WebAuthn passkey profiles, 1,324 exercises, 3-way m
Developer Duarte Santos (DuarteSantos8) has released openGym, an open-source, self-hosted gym and body-weight tracking web application designed to break free from aggressive mobile app subscription models and proprietary cloud data lock-in. Distributed under the AGPL-3.0 license, openGym operates entirely without third-party cloud accounts, ads, or telemetry, storing all workout logs and body measurements directly on the user's own server within a local ./data directory of lightweight JSON files.
![]()
Image source: DuarteSantos8/openGym
As mainstream fitness apps such as Hevy, Strong, and JEFIT continue to move core features behind recurring paywalls and silo workout histories on remote servers, homelab enthusiasts and privacy-conscious athletes are turning toward self-hosted alternatives. Since its open-source release, openGym has quickly gained traction, surpassing 3,200 GitHub stars as a practical, privacy-first community alternative.
Passkey-Based Passwordless Authentication and Local Data Sovereignty
The primary architectural highlight of openGym is its complete departure from traditional email-password schemes and third-party social logins in favor of standard WebAuthn passkey authentication.
- Native Biometric Hardware Integration: Authenticate seamlessly using Face ID, Touch ID, or fingerprint sensors built into smartphones and computers, eliminating password leakage and credential fatigue.
- Multi-Profile Privacy Isolation: Multiple household members or training partners can maintain distinct, private workout logs on a single server instance. Passkey private keys remain in device hardware modules, and optional AI coach queries route through opaque handles so instance owners see query counts rather than question contents.
- One-Time Pairing Codes: Sessions across smartphones, tablets, and desktop workstations can be linked securely and synced using disposable one-time pairing codes without complex configuration steps.
- Pure File-Based Storage: By organizing training data as structured JSON files inside
./datarather than requiring a heavyweight database engine, system backups, migrations, and disaster recovery remain trivial.
1,324 Exercise Library and 3-Way Muscle Map Visualization
Engineered directly from real training floor feedback, openGym incorporates a focused workflow to minimize screen friction during active sets.
- Guided Routine Creation and Evidence-Based Reviews: Users can establish a weekly routine by answering basic parameters regarding goals, training days, session length, and available equipment. The review engine reads logged performance, stalls, perceived effort (RPE), and body weight trends to propose structured routine adjustments. Automatic weight pre-fills, pre-set body weight logging rituals, superset pairing, and configurable rest timers are built in.
- 1,324 Exercises with Animated Demonstrations: A comprehensive built-in library provides animated movement demos and execution guides for proper form verification.
- Three-Perspective Anatomical Muscle Map:
- Balance: Shows where training volume was distributed and highlights muscle groups that were neglected.
- Fatigue: Weights set intensity and volume to show which muscles are actively recovering in real time.
- Strength: Tracks how long since each muscle group was stimulated, detailing the lifts behind it along with their estimated 1RM.
- Four Progressive Overload Rules: Built-in support for four proven progression rules, including linear progression and Greyskull LP, automates methodical strength gains.
- Universal Data Migration: Seamlessly imports existing workout histories from FitNotes, Strong, and Hevy CSV exports, as well as Apple Health data, allowing users to transition without losing years of tracked progress.
One-Click Docker Deployment and Local MCP Server for AI Integration
Under the hood, openGym couples a lightweight Node.js backend with a responsive React and Vite frontend, architected as a Progressive Web App (PWA) deployable through a single Docker Compose command:
# Launch openGym in the background
docker compose up -d
When saved to a mobile home screen via Safari or Chrome, openGym functions as a native application, retaining offline logging capabilities so lifters can record sets even inside basement gyms with no cellular connectivity.
In addition, openGym ships with an optional, read-only local Model Context Protocol (MCP) server. By connecting openGym to AI clients like Claude Desktop, an assistant can securely inspect real-time workout logs, strength trajectories, and muscle fatigue state in plain language to analyze training history and answer workout questions directly from local data.
Deployment Flavors and Practical Operational Considerations
Depending on user requirements, openGym supports three distinct operational flavors:
- Self-Hosted Docker Instance: The full-featured setup providing passkey profiles, multi-device synchronization, web push notifications, and an optional administrator dashboard.
- Standalone Android APK (Device-Only Mode): A sideloadable APK that stores data exclusively in the phone's private internal storage with native notification support. This mode operates entirely offline without server sync.
- In-Browser Demo: An unauthenticated web demo running on sample data entirely within the browser's local sandbox, ideal for evaluating features before server deployment.
Homelab administrators planning a deployment should account for two essential operational prerequisites:
- Mandatory HTTPS for WebAuthn: The WebAuthn passkey standard strictly requires a valid SSL/TLS (HTTPS) connection when accessed outside of
localhost. Deployments intended for remote smartphone access must be placed behind a reverse proxy (such as Caddy or Nginx) or exposed through a Cloudflare Tunnel with an active domain. - iOS Platform Installation: Due to iOS platform restrictions on sideloading binaries, Apple users should access their self-hosted instance through Safari and select 'Add to Home Screen' (PWA) or compile the source code via Xcode.
Sources
- GitHub Repository: DuarteSantos8/openGym
- Official Web & Live Demo: openGym Live Demo
- Documentation: openGym Docs