Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

MedRates

REMOTE · MCP.MEDRATES.FYI · SCANNED SEP 27

Search US hospital prices, compare costs, and find insurance-negotiated rates.

Available components

0 this week 73 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security57
Transport & Reachability100
Schema Quality & AI Usability59
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 2674 tokens (~445/item across 6 items; 6 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
  • No destabilizing schema changes in the last 30 days.Pass
Tool Coverage71
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 0% of tool parameters carry a description.Fail
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 6 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 7 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the MedRates MCP server?

MedRates is a hosted endpoint at https://mcp.medrates.fyi/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcp.medrates.fyi

# add to Claude Code
claude mcp add --transport http fyi-medrates-mcp 'https://mcp.medrates.fyi/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "fyi-medrates-mcp": {
      "url": "https://mcp.medrates.fyi/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "fyi-medrates-mcp": {
      "type": "http",
      "url": "https://mcp.medrates.fyi/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.fyi-medrates-mcp]
url = "https://mcp.medrates.fyi/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "fyi-medrates-mcp": {
      "type": "remote",
      "url": "https://mcp.medrates.fyi/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add fyi-medrates-mcp --url 'https://mcp.medrates.fyi/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  fyi-medrates-mcp:
    url: "https://mcp.medrates.fyi/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "fyi-medrates-mcp": {
      "Transport": "http",
      "Url": "https://mcp.medrates.fyi/mcp"
    }
  }
}
# add to Vellum
assistant mcp add fyi-medrates-mcp -t streamable-http -u 'https://mcp.medrates.fyi/mcp'
// mcp.json
{
  "mcpServers": {
    "fyi-medrates-mcp": {
      "type": "http",
      "url": "https://mcp.medrates.fyi/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 16 Sept 26 0
    • HSTS header: unverified → fail ▼ security
    • Authorization: Authorisation not fully verified: no authorisation is required to call this server, and 6 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. security
    • The server rewrote its instructions, which are the text every model session reads security
    • Tool “price_quote” rewrote its description, which is the text the model reads security
    • Tool “search” rewrote its description, which is the text the model reads security
    • “price_quote” added an optional parameter “provider_type” cosmetic
    • “search” added an optional parameter “provider_type” cosmetic
  • 15 Sept 26 0
    • HSTS header: fail → unverified ▼ security
    • Authorization: Authorisation not yet verified: we couldn't confirm whether this endpoint requires it. security
  • 26 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Aug 26 0
    • Stability: 0.97 → pass security
  • 15 Aug 26 0
    • HSTS header: unverified → fail ▼ security
    • Authorization: Authorisation not fully verified: no authorisation is required to call this server, and 6 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. security
  • 14 Aug 26 0
    • HSTS header: fail → unverified ▼ security
    • Authorization: Authorisation not yet verified: we couldn't confirm whether this endpoint requires it. security
  • 11 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 27 Sept 2026 · Probed https://mcp.medrates.fyi/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=medrates.fyi CN=WE1,O=Google Trust Services,C=US 12 Aug 2026 10 Nov 2026 ECDSA 256 ECDSA-SHA256 b1b3bc29cfb336cb13fe2d6d5a663818
SANs: medrates.fyi, *.medrates.fyi
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcp.medrates.fyi. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
fyi. present 24340 8 Verified
medrates.fyi. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
x-content-type-options nosniff
x-frame-options SAMEORIGIN
referrer-policy strict-origin-when-cross-origin

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.medrates.fyi/mcp Verified 200
http (plaintext) http://mcp.medrates.fyi/mcp HTTPS enforced 301 https://mcp.medrates.fyi/mcp
MCP tools · 6 exposed · ~2,474 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
hospitals ~210

Find hospitals by name/city/state, or list a sample of hospitals. Returns hospital names, IDs, EINs, NPIs, and per-campus locations with addresses and coordinates. Use hospital IDs to filter other search tools. The result is capped (~100 hospitals) for performance, so the unfiltered list is only a sample. To locate a SPECIFIC hospital, pass ``search`` (a name/city/state substring) — it filters server-side and returns the matches. NOTE: This lists US HOSPITALS only — not non-US providers, independent imaging centers, ambulatory surgery centers, clinics, or other freestanding facilities. Args: search: Optional name/city/state substring to find a specific hospital. Returns: JSON array of hospitals with id, name, display_name, ein, npi, cms_certification_number, and locations (address, city, state, lat/lng).

NameTypeReqDescription
search–––
NameTypeReqDescription
resultstringyes–

No examples provided.

payer_network_info ~208

Look up network-geography facts for a named insurance payer. Call this whenever an AI agent or user asks whether a plan covers out-of-state care, whether an insurer has nationwide coverage, or what BlueCard / PPO network mechanism the payer uses. Returns JSON with network_scope ('national', 'state', etc.), nationwide_via ('bluecard_ppo', 'national_ppo', 'none'), and a source_url to cite. Returns {"network_scope": "unknown"} when the payer is not in the database. Args: payer_name: Insurance payer name as the user stated it (e.g. 'Blue Cross Blue Shield of Texas', 'UnitedHealthcare Choice Plus', 'Aetna PPO', 'Medicare'). Returns: JSON object with network_scope, home_state, nationwide_via, source_url, match_pattern, and notes fields.

NameTypeReqDescription
payer_namestringyes–
NameTypeReqDescription
resultstringyes–

No examples provided.

payers ~151

List available insurance payers and plan types. Returns all payer + plan combinations found in the hospital price data. Optionally filter to payers available at a specific hospital. Use the payer names and plan types from this list as inputs to the search_nlp and price_quote tools for insurance-specific rates. NOTE: These are payers with negotiated rates at US HOSPITALS in the database. The same payers may have different rates at non-hospital facilities. Args: hospital_id: Optional hospital ID to filter payers for that hospital. Returns: JSON array of {name, plan_type, display_name} objects.

NameTypeReqDescription
hospital_id–––
NameTypeReqDescription
resultstringyes–

No examples provided.

price_quote ~715

Get price quotes for specific procedure codes, grouped by hospital. This is the most detailed pricing tool. Provide exact CPT/HCPCS codes and get per-hospital price estimates with totals. Supports insurance filtering and geographic search. Default location is San Jose, CA if no coordinates provided — always pass the user's location for best results. NOTE: Hospital results come from US hospital price files. Doctors' offices and clinics are included when provider_type is practice or any and a payer with contract files is given; practice rates are payer-product contract rates for one visit or service. Args: codes: Comma-separated CPT/HCPCS codes (e.g. "70551,70552,70553"). lat: Patient latitude — always provide the user's location for best results. lng: Patient longitude — always provide the user's location for best results. radius_miles: Search radius in miles (default 25). payer: Insurance company name to filter rates (e.g. "Blue Cross", "Aetna"). plan_type: Insurance plan type (e.g. "PPO", "HMO", "Indemnity"). plan_category: Plan category filter (e.g. "Commercial", "Medicare", "Medicaid"). plan_name: Specific plan name for exact matching. drg_codes: Comma-separated MS-DRG codes for inpatient bundled pricing. include_bundle: If true, also include ancillary procedure codes (anesthesia, facility fees, etc.) in the total estimate. limit: Max hospitals to return (default 5). zip_code: Optional 5-digit ZIP the user gave, used ONLY to build a localized deep link to the search page — does NOT affect pricing (pricing uses lat/lng). provider_type: "hospital", "practice", or "any" (default). "practice" adds doctors' offices and clinics; office prices always need a payer. Returns: JSON with hospitals sorted by total estimated cost. Each hospital…

NameTypeReqDescription
codesstringyes–
drg_codes–––
include_bundleboolean––
latnumber––
limitinteger––
lngnumber––
payer–––
plan_category–––
plan_name–––
plan_type–––
provider_typestring––
radius_milesnumber––
zip_code–––
NameTypeReqDescription
resultstringyes–

No examples provided.

search ~644

Search for medical procedure prices by code or description. Use this for direct lookups when you know a CPT/HCPCS code (e.g. "70551") or want to search by keyword (e.g. "MRI", "knee replacement"). For code-like queries → exact match on procedure code. For text queries → searches code, description, and code_type fields. Supports filtering by insurance payer, clinical setting, and location (via zip code or lat/lng coordinates with a radius). NOTE: Hospital results come from US hospital price files. Doctors' offices and clinics are included when provider_type is practice or any and a payer with contract files is given; practice rates are payer-product contract rates for one visit or service. Args: query: CPT/HCPCS code (e.g. "70551") or text search (e.g. "MRI brain"). Must be at least 2 characters. code_type: Filter by code type: "CPT", "HCPCS", "MS-DRG", "RC", etc. hospital_id: Filter to a specific hospital (use the hospitals tool to find IDs). payer_name: Filter by insurance payer name (e.g. "Blue Cross", "Aetna"). plan_name: Filter by plan name (e.g. "PPO", "HMO"). setting: Filter by clinical setting: "inpatient" or "outpatient". zip_code: US zip code for geographic filtering (alternative to lat/lng). lat: Latitude for geographic filtering (use with lng and radius_miles). lng: Longitude for geographic filtering (use with lat and radius_miles). radius_miles: Search radius in miles from the zip code or lat/lng location. page: Page number (default 1). page_size: Results per page (default 25, max 100). provider_type: "hospital", "practice", or "any" (default). "practice" adds doctors' offices and clinics; office prices always need a payer. Returns: JSON with matching charge items including procedure codes, descriptions, gross charges, cash prices, and negotiated rate rang…

NameTypeReqDescription
code_type–––
hospital_id–––
lat–––
lng–––
pageinteger––
page_sizeinteger––
payer_name–––
plan_name–––
provider_typestring––
querystringyes–
radius_miles–––
setting–––
zip_code–––
NameTypeReqDescription
resultstringyes–

No examples provided.

search_nlp ~546

Natural language search for medical procedure prices. Understands free-text queries like: - "MRI brain near San Jose with Blue Cross PPO" - "How much does a colonoscopy cost in Palo Alto?" - "knee replacement, no insurance, Mountain View" Extracts procedure, location, and insurance from the query, resolves CPT/DRG codes (using static synonyms + LLM), geocodes the city, and searches with optional geo-filtering and payer matching. You can provide structured fields (lat/lng, payer, setting) to override or supplement what the NLP extraction detects from the query text. NOTE: Results are from US HOSPITALS only — not non-US providers, independent imaging centers, ambulatory surgery centers (ASCs), or other freestanding facilities. For outpatient procedures (MRIs, CTs, minor surgeries), independent facilities may offer lower prices than hospitals. Args: query: Natural language query describing what you're looking for. radius_miles: Search radius from the detected city (default 25 miles). code_type: Filter by code type: "CPT", "HCPCS", "MS-DRG". setting: Filter by clinical setting: "inpatient" or "outpatient". lat: Override latitude (e.g. from browser geolocation). Skips geocoding. lng: Override longitude (e.g. from browser geolocation). Skips geocoding. zip_code: 5-digit ZIP to search near — alternative to lat/lng. payer: Insurance payer name (e.g. "Blue Cross"). Overrides NLP extraction. plan_type: Plan type (e.g. "PPO", "HMO"). Overrides NLP extraction. limit: Max results (default 25). Returns: JSON with extracted entities (procedure, city, insurance), resolved codes, and matching charge items with prices and hospital info. Only high-confidence results (with at least one usable price) are included. Each result includes last_updated (ISO date of the per-hospital MRF ingest) and mrf_…

NameTypeReqDescription
code_type–––
lat–––
limitinteger––
lng–––
payer–––
plan_type–––
querystringyes–
radius_milesnumber––
setting–––
zip_code–––
NameTypeReqDescription
resultstringyes–

No examples provided.

Common questions

What is the MedRates MCP server?

MedRates is an MCP server listed in the public MCP registry as fyi.medrates/mcp. Search US hospital prices, compare costs, and find insurance-negotiated rates. This page covers its hosted endpoint (https://mcp.medrates.fyi/mcp).

Is the MedRates MCP server safe to use?

MedRates scores 73 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the MedRates MCP server expose?

MedRates exposes 6 tools: search, search_nlp, price_quote, hospitals, payer_network_info, payers. Their descriptions and schemas cost roughly 2,474 tokens of context every time the server is loaded.

Does the MedRates MCP server require authentication?

No. We connected to MedRates without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the MedRates MCP server still maintained?

MedRates is still listed as active in the MCP registry. We last reached this channel on 27 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.