Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.cyanheads/medical-codes-mcp-server

REMOTE · MEDICAL-CODES.CASEYJHAND.COM · 2 COMPONENTS · SCANNED SEP 28

Offline US medical code lookup and crosswalk — ICD-10-CM/PCS, HCPCS Level II, RxNorm. Keyless.

+6 this week 86 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security83
Transport & Reachability100
Schema Quality & AI Usability61
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 3302 tokens (~550/item across 6 items; 6 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
  • No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 6 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 7 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the io.github.cyanheads/medical-codes-mcp-server server?

io.github.cyanheads/medical-codes-mcp-server is a hosted endpoint at https://medical-codes.caseyjhand.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · medical-codes.caseyjhand.com

# add to Claude Code
claude mcp add --transport http cyanheads-medical-codes-mcp-server 'https://medical-codes.caseyjhand.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "cyanheads-medical-codes-mcp-server": {
      "url": "https://medical-codes.caseyjhand.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "cyanheads-medical-codes-mcp-server": {
      "type": "http",
      "url": "https://medical-codes.caseyjhand.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.cyanheads-medical-codes-mcp-server]
url = "https://medical-codes.caseyjhand.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "cyanheads-medical-codes-mcp-server": {
      "type": "remote",
      "url": "https://medical-codes.caseyjhand.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add cyanheads-medical-codes-mcp-server --url 'https://medical-codes.caseyjhand.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  cyanheads-medical-codes-mcp-server:
    url: "https://medical-codes.caseyjhand.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "cyanheads-medical-codes-mcp-server": {
      "Transport": "http",
      "Url": "https://medical-codes.caseyjhand.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add cyanheads-medical-codes-mcp-server -t streamable-http -u 'https://medical-codes.caseyjhand.com/mcp'
// mcp.json
{
  "mcpServers": {
    "cyanheads-medical-codes-mcp-server": {
      "type": "http",
      "url": "https://medical-codes.caseyjhand.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 +7
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 −1
    • The server rewrote its instructions, which are the text every model session reads security
    • Tool “medcode_list_systems” rewrote its description, which is the text the model reads security
    • Tool “medcode_search_codes” rewrote its description, which is the text the model reads security
    • Tool “medcode_check_code” rewrote its description, which is the text the model reads security
    • Tool “medcode_get_code” rewrote its description, which is the text the model reads security
    • Tool “medcode_map_codes” rewrote its description, which is the text the model reads security
    • Schema quality: 415 → 550 ▼ functional
    • Schema quality: 415 → 460 ▼ functional
    • Server version: 0.3.0 → 0.4.0 functional
    • Server version: 0.2.9 → 0.3.0 functional
    • “medcode_map_codes” added an optional parameter “classType” cosmetic
    • “medcode_map_codes” reworded the description of “direction” cosmetic
    • “medcode_map_codes” reworded the description of “from” cosmetic
    • “medcode_map_codes” reworded the description of “limit” cosmetic
    • “medcode_search_codes” reworded the description of “billableOnly” cosmetic
    • “medcode_get_code” reworded the description of “system” cosmetic
    • “medcode_map_codes” reworded the description of “cursor” cosmetic
    • “medcode_map_codes” reworded the description of “system” cosmetic
    • Tool “medcode_search_codes” changed its title: medical-codes-mcp-server → Search Medical Codes cosmetic
    • Tool “medcode_browse_hierarchy” changed its title: medical-codes-mcp-server → Browse Code Hierarchy cosmetic
    • Tool “medcode_check_code” changed its title: medical-codes-mcp-server → Check Medical Code cosmetic
    • Tool “medcode_get_code” changed its title: medical-codes-mcp-server → Get Medical Code cosmetic
    • Tool “medcode_list_systems” changed its title: medical-codes-mcp-server → List Code Systems cosmetic
    • Tool “medcode_map_codes” changed its title: medical-codes-mcp-server → Map Medical Codes cosmetic
  • 19 Sept 26 0
    • Server version: 0.2.8 → 0.2.9 functional
  • 9 Sept 26 0
    • Stability: 0.97 → pass security
  • 8 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.

  • 7 Sept 26 −1
    • Stability: pass → 0.93 functional
  • 26 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 28 Sept 2026 · Probed https://medical-codes.caseyjhand.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=caseyjhand.com CN=WE1,O=Google Trust Services,C=US 4 Sept 2026 3 Dec 2026 ECDSA 256 ECDSA-SHA256 a6985204ed51ae050e7738aa6be668e9
SANs: caseyjhand.com, *.caseyjhand.com
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC secure

Validation of medical-codes.caseyjhand.com. — Secure

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
caseyjhand.com. present 2371 13 Verified
medical-codes.caseyjhand.com. Verified address RRset verified with the apex keys
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=63072000; includeSubDomains; preload
x-content-type-options nosniff

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://medical-codes.caseyjhand.com/mcp Verified 200
http (plaintext) http://medical-codes.caseyjhand.com/mcp HTTPS enforced 301 https://medical-codes.caseyjhand.com/mcp
MCP tools · 6 exposed · ~2,921 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
medcode_browse_hierarchy ~351

Walk a US medical code system's hierarchy for discovery without a search term. With no `node`, returns the top-level entries (ICD-10-CM categories, HCPCS range buckets, or ICD-10-PCS first-axis values). With a `node`, returns its immediate children. ICD-10-CM and HCPCS use a prefix hierarchy (a shorter code is the parent of a longer one); ICD-10-PCS is axis-based — each of its 7 characters is an independent axis (section, body system, root operation, body part, approach, device, qualifier), but only the top-level Section axis is browsable (omit `node`): positions 2–7 are context-dependent on the preceding axis path and are not enumerable from a flat partial code. Lets an agent orient in an unfamiliar system or enumerate a category's specific codes. A large child set paginates: when the response carries a `nextCursor`, pass it back as `cursor` to fetch the next page.

NameTypeReqDescription
cursorstring–Opaque continuation token from a previous response's `nextCursor`, to fetch the next page of children/entries. Omit for the top of the list.
limitinteger–Max entries per page. Defaults to MEDCODE_MAX_RESULTS (50), ceiling 200.
node––A node to expand — or omit / pass an empty string for the top level. For ICD-10-CM/HCPCS, a code whose children to list; ICD-10-PCS supports only top-level Section browsing. Must not be blank or whit…
systemstringyesThe code system to browse.
NameTypeReqDescription
axesarray–The top-level ICD-10-PCS Section axis values (only the Section axis is enumerable). Empty when kind is "codes".
capnumber–The page size that was applied.
codesarray–Child codes under the requested node or top level. Empty when kind is "axes".
errorobject–Present when the call failed. Absent on success.
kindstring–"codes" for prefix-hierarchy children (ICD-10-CM/HCPCS); "axes" for ICD-10-PCS axis values.
nextCursorstring–Opaque token to pass back as `cursor` for the next page. Present only when more entries exist beyond this page.
noticestring–Guidance when a node has no children/axes — suggests the top level or a valid node.
shownnumber–Number of entries returned on this page (codes or axes).
truncatedboolean–True when more entries exist beyond this page.

No examples provided.

medcode_check_code ~282

Validate whether a US medical code exists, is current, and is billable in the active bundled release. Returns a discriminated status — valid_billable, valid_not_billable, valid_header, valid, or terminated — with a `whyNot` explaining non-billable and terminated cases (e.g. "valid ICD-10-CM category but not billable — submit a more specific child code"). This is the detail a coder needs before submitting a claim. RxNorm has no billing concept, so a current RxNorm concept is `valid` with `billable: null` and no billing verdict. Auto-detects the system from the code's shape; pass an explicit `system` to disambiguate. A non-billable or terminated code is a successful result with a whyNot, not an error — only a code absent from the named or detected system raises unknown_code, which names the other bundled system when one holds the code. A code string that also exists in another bundled system carries `alsoInSystems` naming it, since the verdict applies only to the system that answered.

NameTypeReqDescription
codestringyesThe code to validate, with or without dots. Must not be blank or whitespace-only.
systemstring–Force the lookup into this system. Omit to auto-detect from the code's shape.
NameTypeReqDescription
alsoInSystemsarray–Other bundled systems holding this same code string, present only when there is at least one. The verdict above is for the system this code resolved in; the code is a DIFFERENT code in each system li…
billableboolean|null–True only when status is valid_billable. Null when status is valid — the system has no billing concept.
codestring–The code in display form (ICD-10-CM carries the dot).
errorobject–Present when the call failed. Absent on success.
statusstring–Validity status. valid_billable = submit as-is; valid_header/valid_not_billable = needs a more specific code; valid = exists and is current in a system with no billing concept (RxNorm), so there is n…
systemstring–The system the code was resolved in, echoed for chaining.
whyNotstring|null–Explanation for non-billable/terminated statuses, or null when valid_billable or valid.

No examples provided.

medcode_get_code ~511

Decode one or more US medical codes to their official descriptions across ICD-10-CM (diagnoses), ICD-10-PCS (inpatient procedures), HCPCS Level II (supplies/drugs/services), and RxNorm (drugs, by RXCUI). Also decodes a National Drug Code (NDC) directly to its RxNorm product offline, tagged `source: "NDC"` — hyphenated in an FDA segment configuration (4-4-2, 5-3-2, 5-4-1, or the 11-digit 5-4-2) or as bare 10/11 digits; any other segment widths are malformed and stay unresolved. Auto-detects the system from each code's shape; pass an explicit `system` only when a value is genuinely ambiguous. Accepts 1–50 codes and returns partial success: resolved codes in `found`, unresolved in `notFound` with a per-code reason, so one bad code never fails the batch. Set `includeHierarchy` to attach each code's parent and immediate children (with a `childrenTruncated` flag when a code has more children than the cap returns — walk the full set via medcode_browse_hierarchy or medcode_map_codes). The resolved `system` is echoed on every result for chaining into a billability check or a medcode_map_codes parents/children walk; a bare integer that resolves nowhere is named as a possible CPT / HCPCS Level I code, which is out of scope, except a bare 10/11-digit one, which is named as an NDC no bundled drug maps to; a code string that also exists in another bundled system carries `alsoInSystems` naming it, so a single answer to a colliding code is never mistaken for the only one.

NameTypeReqDescription
codesarrayyesCodes to decode (1–50). Mixed systems are fine — each is detected independently. An NDC decodes to its RxNorm product: hyphenated as 4-4-2, 5-3-2, 5-4-1, or 5-4-2, or as bare 10/11 digits.
includeHierarchyboolean–When true, attach each found code's parent and immediate children.
systemstring–Force every code to be looked up in this system, which also skips the NDC decode. Omit to auto-detect per code.
NameTypeReqDescription
errorobject–Present when the call failed. Absent on success.
foundarray–Successfully decoded codes, in request order.
notFoundarray–Codes that did not resolve, with per-code reasons.

No examples provided.

medcode_list_systems ~148

List the bundled US medical code systems with their release identifiers, effective dates, and code counts, and the RxClass drug-class layer the class crosswalks read, with each source’s version. Confirms which ICD-10-CM fiscal year, ICD-10-PCS fiscal year, HCPCS Level II release, RxNorm normalized set, and RxClass sources are active before acting on any decode, search, or crosswalk result. The corpus is offline and built at package-build time — this call reports exactly which release is baked into the running server. ICD-10-CM/PCS are the US clinical modifications, not the ICD-10/ICD-11 base.

Input schema present but exposes no named parameters.

NameTypeReqDescription
classLayer––The RxClass drug-class layer the rxcui_to_classes and class_to_rxcuis directions of medcode_map_codes read — not a code system, so it has no entry in `systems`. Null when this build carries no class…
errorobject–Present when the call failed. Absent on success.
systemsarray–One entry per bundled code system, in canonical order — the systems the `system` inputs of the other tools accept.

No examples provided.

medcode_map_codes ~1,150

Crosswalk a US medical code or drug across systems and within a hierarchy. Hierarchy directions: `parents` and `children` walk a code's prefix hierarchy one level per call — immediate parent/children only (depth-1); call iteratively for the full ancestor or descendant path (ICD-10-CM/HCPCS; ICD-10-PCS codes have no prefix parent, and RxNorm concepts no code hierarchy). A resolvable source with no edge in the requested direction is a successful empty result with a notice, not an error. A source code string that also exists in another bundled system carries `alsoInSystems` naming it, since only the resolved system's hierarchy was walked. Drug directions (RxNorm): `name_to_rxcui` (drug name → RXCUI), `ndc_to_rxcui` and `rxcui_to_ndc` (NDC ↔ RXCUI; NDCs accepted hyphenated in an FDA segment configuration — 4-4-2, 5-3-2, 5-4-1, or the 11-digit 5-4-2 — or as bare 10/11 digits; `ndc_to_rxcui` names the product it decoded to), `rxcui_to_ingredients` and `rxcui_to_brands` (RXCUI → ingredient/brand RXCUIs, each with the target's RxNorm name and its `conceptType` — read that before counting a combination product's ingredients). Drug-class directions (RxClass): `rxcui_to_classes` (RXCUI → its classes: pharmacologic class, mechanism of action, physiologic effect, pharmacokinetics, therapeutic category, chemical structure, the diseases it may treat, prevent, diagnose, or induce or is contraindicated with, VA class, DEA controlled-substance schedule, CDC vaccine code; a drug product also carries its ingredients' classes, naming the ingredient in `via`, while DEA schedules are recorded only on drug products and VA classes almost only there, so map a product for those) and `class_to_rxcuis` (class ID → its direct member RXCUIs, each with its RxNorm name and `conceptType`). Each class hit carries `classType`, `source` (the RxClass source asserting it), and `relation` — a `ci_` relation is a contraindication, not an indication; narrow either direction with `classType`. Every result c…

NameTypeReqDescription
classTypestring–For rxcui_to_classes and class_to_rxcuis only: keep only classes of this RxClass type — EPC (FDA established pharmacologic class), MOA (mechanism of action), PE (physiologic effect), PK (pharmacokine…
cursorstring–Opaque continuation token from a previous response's `nextCursor`, for the paginated directions only (children, name_to_rxcui, rxcui_to_ndc, rxcui_to_classes, class_to_rxcuis). Omit for the first pag…
directionstringyesWhat to map to. parents/children return the immediate parent or children only (depth-1) — call iteratively to walk a full path; the rxcui/ndc/name directions are RxNorm drug crosswalks; rxcui_to_clas…
fromstringyesThe source value: a code (for parents/children), a drug name, an NDC, an RXCUI, or an RxClass class ID (for class_to_rxcuis). Must not be blank or whitespace-only.
limitinteger–Max results per page, for the paginated directions only (children, name_to_rxcui, rxcui_to_ndc, rxcui_to_classes, class_to_rxcuis). Defaults to MEDCODE_MAX_RESULTS (50), ceiling 200. Rejected on ever…
systemstring–For parents/children, force the source code into this system. Omit to auto-detect. The drug and class directions resolve in RxNorm and accept only "RXNORM" (no effect); any other value there is rejec…
NameTypeReqDescription
alsoInSystemsarray–Other bundled systems holding the same `from` code string, present only when there is at least one (hierarchy directions only — a drug name, NDC, or RXCUI is not system-scoped). The hits above were w…
capnumber–Paginated directions only: the page size that was applied.
directionstring–The mapping direction that was applied.
errorobject–Present when the call failed. Absent on success.
fromstring–The source value, echoed back.
hitsarray–Crosswalk results, each tagged with the edge that produced it.
nextCursorstring–Paginated directions only: opaque token to pass back as `cursor` for the next page. Present only when more results exist beyond this page.
noticestring–Guidance whenever a resolvable source returns no hits, naming which of the two causes applies: it has no edge in the requested direction (a top-level code has no parent; a leaf has no children; ICD-1…
resolvedSystemstring|null–The system the source resolved in, or null when not system-scoped.
shownnumber–Paginated directions only: number of hits returned on this page.
truncatedboolean–Paginated directions (children, name_to_rxcui, rxcui_to_ndc, rxcui_to_classes, class_to_rxcuis) only: true when more results exist beyond this page.

No examples provided.

medcode_search_codes ~479

Find US medical codes whose official descriptions match a described concept, via full-text search over the bundled index. Every search term must appear — matched first as a token prefix, then as a substring so inflected and compound forms are also found (a "neuropathy" search surfaces "mononeuropathy"/"polyneuropathy" siblings too, not only a standalone "neuropathy" token). An RxNorm concept matches on its drug name alone, never its term type (SBD, IN, …) — narrow by type with `chapter`. Filter by `system` (ICD10CM/ICD10PCS/HCPCS/RXNORM), `billableOnly` to exclude headers/categories, and `chapter`. Use when you have a clinical description and need the code — the reverse of medcode_get_code. Results echo the resolved system per row for chaining, rank exact prefix matches ahead of substring-only matches with a deterministic tie-break, and disclose truncation with a `nextCursor`: pass it back as `cursor` to page through the full ranked set.

NameTypeReqDescription
billableOnlyboolean–When true, return only billable leaf codes (exclude headers/categories). RxNorm has no billing concept, so this excludes every RxNorm concept.
chapterstring–Restrict to a chapter/range bucket (the value from a code's `chapter` field). Case-insensitive: surrounding whitespace is trimmed and the value is upper-cased to match how chapters are stored, and `a…
cursorstring–Opaque continuation token from a previous response's `nextCursor`, to fetch the next page of the same ranked result set. Omit for the first page.
limitinteger–Max codes per page. Defaults to the server's MEDCODE_MAX_RESULTS (50), ceiling 200.
querystringyesClinical description to match, e.g. "type 2 diabetes with neuropathy". Must not be blank or whitespace-only.
systemstring–Restrict results to one system. Omit to search all bundled systems.
NameTypeReqDescription
appliedFiltersobject–Filters the server applied to the search.
capnumber–The page size that was applied.
codesarray–Matching codes, ranked by full-text relevance.
effectiveQuerystring–The query as the server parsed it for matching.
errorobject–Present when the call failed. Absent on success.
nextCursorstring–Opaque token to pass back as `cursor` for the next page. Present only when more matches exist beyond this page.
noticestring–Guidance when nothing matched — echoes the query and suggests how to broaden, or names `billableOnly` as the cause when the searched system has no billing concept.
shownnumber–Number of codes returned on this page.
truncatedboolean–True when more matches exist beyond this page.

No examples provided.

Common questions

What is the io.github.cyanheads/medical-codes-mcp-server server?

io.github.cyanheads/medical-codes-mcp-server is listed in the public MCP registry as io.github.cyanheads/medical-codes-mcp-server. Offline US medical code lookup and crosswalk, ICD-10-CM/PCS, HCPCS Level II, RxNorm. Keyless. This page covers its hosted endpoint (https://medical-codes.caseyjhand.com/mcp).

Is the io.github.cyanheads/medical-codes-mcp-server server safe to use?

io.github.cyanheads/medical-codes-mcp-server scores 86 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.cyanheads/medical-codes-mcp-server server expose?

io.github.cyanheads/medical-codes-mcp-server exposes 6 tools: medcode_get_code, medcode_search_codes, medcode_check_code, medcode_map_codes, medcode_browse_hierarchy, medcode_list_systems. Their descriptions and schemas cost roughly 2,921 tokens of context every time the server is loaded.

Does the io.github.cyanheads/medical-codes-mcp-server server require authentication?

No. We connected to io.github.cyanheads/medical-codes-mcp-server without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the io.github.cyanheads/medical-codes-mcp-server server still maintained?

io.github.cyanheads/medical-codes-mcp-server is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.