MedRates
REMOTE · MCP.MEDRATES.FYI · SCANNED SEP 27
Search US hospital prices, compare costs, and find insurance-negotiated rates.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 6 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability59
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2674 tokens (~445/item across 6 items; 6 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage71
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 0% of tool parameters carry a description.Fail
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 6 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 7 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the MedRates MCP server?
MedRates is a hosted endpoint at https://mcp.medrates.fyi/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.medrates.fyi
claude mcp add --transport http fyi-medrates-mcp 'https://mcp.medrates.fyi/mcp'
{
"mcpServers": {
"fyi-medrates-mcp": {
"url": "https://mcp.medrates.fyi/mcp"
}
}
} {
"servers": {
"fyi-medrates-mcp": {
"type": "http",
"url": "https://mcp.medrates.fyi/mcp"
}
}
} [mcp_servers.fyi-medrates-mcp] url = "https://mcp.medrates.fyi/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"fyi-medrates-mcp": {
"type": "remote",
"url": "https://mcp.medrates.fyi/mcp",
"enabled": true
}
}
} openclaw mcp add fyi-medrates-mcp --url 'https://mcp.medrates.fyi/mcp' --transport streamable-http
mcp_servers:
fyi-medrates-mcp:
url: "https://mcp.medrates.fyi/mcp" {
"McpServers": {
"fyi-medrates-mcp": {
"Transport": "http",
"Url": "https://mcp.medrates.fyi/mcp"
}
}
} assistant mcp add fyi-medrates-mcp -t streamable-http -u 'https://mcp.medrates.fyi/mcp'
{
"mcpServers": {
"fyi-medrates-mcp": {
"type": "http",
"url": "https://mcp.medrates.fyi/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 16 Sept 26 0
- HSTS header: unverified → fail ▼ security
- Authorization: Authorisation not fully verified: no authorisation is required to call this server, and 6 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. security
- The server rewrote its instructions, which are the text every model session reads security
- Tool “price_quote” rewrote its description, which is the text the model reads security
- Tool “search” rewrote its description, which is the text the model reads security
- “price_quote” added an optional parameter “provider_type” cosmetic
- “search” added an optional parameter “provider_type” cosmetic
- 15 Sept 26 0
- HSTS header: fail → unverified ▼ security
- Authorization: Authorisation not yet verified: we couldn't confirm whether this endpoint requires it. security
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
- 15 Aug 26 0
- HSTS header: unverified → fail ▼ security
- Authorization: Authorisation not fully verified: no authorisation is required to call this server, and 6 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. security
- 14 Aug 26 0
- HSTS header: fail → unverified ▼ security
- Authorization: Authorisation not yet verified: we couldn't confirm whether this endpoint requires it. security
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 27 Sept 2026 · Probed https://mcp.medrates.fyi/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=medrates.fyi | CN=WE1,O=Google Trust Services,C=US | 12 Aug 2026 | 10 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | b1b3bc29cfb336cb13fe2d6d5a663818 |
| SANs: medrates.fyi, *.medrates.fyi | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.medrates.fyi. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| fyi. | present | 24340 | 8 | Verified |
| medrates.fyi. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.medrates.fyi/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.medrates.fyi/mcp | HTTPS enforced | 301 | https://mcp.medrates.fyi/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
hospitals ~210
Find hospitals by name/city/state, or list a sample of hospitals. Returns hospital names, IDs, EINs, NPIs, and per-campus locations with addresses and coordinates. Use hospital IDs to filter other search tools. The result is capped (~100 hospitals) for performance, so the unfiltered list is only a sample. To locate a SPECIFIC hospital, pass ``search`` (a name/city/state substring) — it filters server-side and returns the matches. NOTE: This lists US HOSPITALS only — not non-US providers, independent imaging centers, ambulatory surgery centers, clinics, or other freestanding facilities. Args: search: Optional name/city/state substring to find a specific hospital. Returns: JSON array of hospitals with id, name, display_name, ein, npi, cms_certification_number, and locations (address, city, state, lat/lng).
| Name | Type | Req | Description |
|---|---|---|---|
| search | – | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
payer_network_info ~208
Look up network-geography facts for a named insurance payer. Call this whenever an AI agent or user asks whether a plan covers out-of-state care, whether an insurer has nationwide coverage, or what BlueCard / PPO network mechanism the payer uses. Returns JSON with network_scope ('national', 'state', etc.), nationwide_via ('bluecard_ppo', 'national_ppo', 'none'), and a source_url to cite. Returns {"network_scope": "unknown"} when the payer is not in the database. Args: payer_name: Insurance payer name as the user stated it (e.g. 'Blue Cross Blue Shield of Texas', 'UnitedHealthcare Choice Plus', 'Aetna PPO', 'Medicare'). Returns: JSON object with network_scope, home_state, nationwide_via, source_url, match_pattern, and notes fields.
| Name | Type | Req | Description |
|---|---|---|---|
| payer_name | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
payers ~151
List available insurance payers and plan types. Returns all payer + plan combinations found in the hospital price data. Optionally filter to payers available at a specific hospital. Use the payer names and plan types from this list as inputs to the search_nlp and price_quote tools for insurance-specific rates. NOTE: These are payers with negotiated rates at US HOSPITALS in the database. The same payers may have different rates at non-hospital facilities. Args: hospital_id: Optional hospital ID to filter payers for that hospital. Returns: JSON array of {name, plan_type, display_name} objects.
| Name | Type | Req | Description |
|---|---|---|---|
| hospital_id | – | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
price_quote ~715
Get price quotes for specific procedure codes, grouped by hospital. This is the most detailed pricing tool. Provide exact CPT/HCPCS codes and get per-hospital price estimates with totals. Supports insurance filtering and geographic search. Default location is San Jose, CA if no coordinates provided — always pass the user's location for best results. NOTE: Hospital results come from US hospital price files. Doctors' offices and clinics are included when provider_type is practice or any and a payer with contract files is given; practice rates are payer-product contract rates for one visit or service. Args: codes: Comma-separated CPT/HCPCS codes (e.g. "70551,70552,70553"). lat: Patient latitude — always provide the user's location for best results. lng: Patient longitude — always provide the user's location for best results. radius_miles: Search radius in miles (default 25). payer: Insurance company name to filter rates (e.g. "Blue Cross", "Aetna"). plan_type: Insurance plan type (e.g. "PPO", "HMO", "Indemnity"). plan_category: Plan category filter (e.g. "Commercial", "Medicare", "Medicaid"). plan_name: Specific plan name for exact matching. drg_codes: Comma-separated MS-DRG codes for inpatient bundled pricing. include_bundle: If true, also include ancillary procedure codes (anesthesia, facility fees, etc.) in the total estimate. limit: Max hospitals to return (default 5). zip_code: Optional 5-digit ZIP the user gave, used ONLY to build a localized deep link to the search page — does NOT affect pricing (pricing uses lat/lng). provider_type: "hospital", "practice", or "any" (default). "practice" adds doctors' offices and clinics; office prices always need a payer. Returns: JSON with hospitals sorted by total estimated cost. Each hospital…
| Name | Type | Req | Description |
|---|---|---|---|
| codes | string | yes | – |
| drg_codes | – | – | – |
| include_bundle | boolean | – | – |
| lat | number | – | – |
| limit | integer | – | – |
| lng | number | – | – |
| payer | – | – | – |
| plan_category | – | – | – |
| plan_name | – | – | – |
| plan_type | – | – | – |
| provider_type | string | – | – |
| radius_miles | number | – | – |
| zip_code | – | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
search ~644
Search for medical procedure prices by code or description. Use this for direct lookups when you know a CPT/HCPCS code (e.g. "70551") or want to search by keyword (e.g. "MRI", "knee replacement"). For code-like queries → exact match on procedure code. For text queries → searches code, description, and code_type fields. Supports filtering by insurance payer, clinical setting, and location (via zip code or lat/lng coordinates with a radius). NOTE: Hospital results come from US hospital price files. Doctors' offices and clinics are included when provider_type is practice or any and a payer with contract files is given; practice rates are payer-product contract rates for one visit or service. Args: query: CPT/HCPCS code (e.g. "70551") or text search (e.g. "MRI brain"). Must be at least 2 characters. code_type: Filter by code type: "CPT", "HCPCS", "MS-DRG", "RC", etc. hospital_id: Filter to a specific hospital (use the hospitals tool to find IDs). payer_name: Filter by insurance payer name (e.g. "Blue Cross", "Aetna"). plan_name: Filter by plan name (e.g. "PPO", "HMO"). setting: Filter by clinical setting: "inpatient" or "outpatient". zip_code: US zip code for geographic filtering (alternative to lat/lng). lat: Latitude for geographic filtering (use with lng and radius_miles). lng: Longitude for geographic filtering (use with lat and radius_miles). radius_miles: Search radius in miles from the zip code or lat/lng location. page: Page number (default 1). page_size: Results per page (default 25, max 100). provider_type: "hospital", "practice", or "any" (default). "practice" adds doctors' offices and clinics; office prices always need a payer. Returns: JSON with matching charge items including procedure codes, descriptions, gross charges, cash prices, and negotiated rate rang…
| Name | Type | Req | Description |
|---|---|---|---|
| code_type | – | – | – |
| hospital_id | – | – | – |
| lat | – | – | – |
| lng | – | – | – |
| page | integer | – | – |
| page_size | integer | – | – |
| payer_name | – | – | – |
| plan_name | – | – | – |
| provider_type | string | – | – |
| query | string | yes | – |
| radius_miles | – | – | – |
| setting | – | – | – |
| zip_code | – | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
search_nlp ~546
Natural language search for medical procedure prices. Understands free-text queries like: - "MRI brain near San Jose with Blue Cross PPO" - "How much does a colonoscopy cost in Palo Alto?" - "knee replacement, no insurance, Mountain View" Extracts procedure, location, and insurance from the query, resolves CPT/DRG codes (using static synonyms + LLM), geocodes the city, and searches with optional geo-filtering and payer matching. You can provide structured fields (lat/lng, payer, setting) to override or supplement what the NLP extraction detects from the query text. NOTE: Results are from US HOSPITALS only — not non-US providers, independent imaging centers, ambulatory surgery centers (ASCs), or other freestanding facilities. For outpatient procedures (MRIs, CTs, minor surgeries), independent facilities may offer lower prices than hospitals. Args: query: Natural language query describing what you're looking for. radius_miles: Search radius from the detected city (default 25 miles). code_type: Filter by code type: "CPT", "HCPCS", "MS-DRG". setting: Filter by clinical setting: "inpatient" or "outpatient". lat: Override latitude (e.g. from browser geolocation). Skips geocoding. lng: Override longitude (e.g. from browser geolocation). Skips geocoding. zip_code: 5-digit ZIP to search near — alternative to lat/lng. payer: Insurance payer name (e.g. "Blue Cross"). Overrides NLP extraction. plan_type: Plan type (e.g. "PPO", "HMO"). Overrides NLP extraction. limit: Max results (default 25). Returns: JSON with extracted entities (procedure, city, insurance), resolved codes, and matching charge items with prices and hospital info. Only high-confidence results (with at least one usable price) are included. Each result includes last_updated (ISO date of the per-hospital MRF ingest) and mrf_…
| Name | Type | Req | Description |
|---|---|---|---|
| code_type | – | – | – |
| lat | – | – | – |
| limit | integer | – | – |
| lng | – | – | – |
| payer | – | – | – |
| plan_type | – | – | – |
| query | string | yes | – |
| radius_miles | number | – | – |
| setting | – | – | – |
| zip_code | – | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
What is the MedRates MCP server?
MedRates is an MCP server listed in the public MCP registry as fyi.medrates/mcp. Search US hospital prices, compare costs, and find insurance-negotiated rates. This page covers its hosted endpoint (https://mcp.medrates.fyi/mcp).
Is the MedRates MCP server safe to use?
MedRates scores 73 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the MedRates MCP server expose?
MedRates exposes 6 tools: search, search_nlp, price_quote, hospitals, payer_network_info, payers. Their descriptions and schemas cost roughly 2,474 tokens of context every time the server is loaded.
Does the MedRates MCP server require authentication?
No. We connected to MedRates without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the MedRates MCP server still maintained?
MedRates is still listed as active in the MCP registry. We last reached this channel on 27 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.