MediMo
REMOTE · MEDIMO.CO.UK · SCANNED SEP 20
Find and book UK private physiotherapy, osteopathy and chiropractic clinics, with live availability.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability64
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1977 tokens (~329/item across 6 items; 6 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management17
- Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 6 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 7 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the MediMo MCP server?
MediMo is a hosted endpoint at https://medimo.co.uk/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · medimo.co.uk
claude mcp add --transport http uk-co-medimo-mcp 'https://medimo.co.uk/mcp'
{
"mcpServers": {
"uk-co-medimo-mcp": {
"url": "https://medimo.co.uk/mcp"
}
}
} {
"servers": {
"uk-co-medimo-mcp": {
"type": "http",
"url": "https://medimo.co.uk/mcp"
}
}
} [mcp_servers.uk-co-medimo-mcp] url = "https://medimo.co.uk/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"uk-co-medimo-mcp": {
"type": "remote",
"url": "https://medimo.co.uk/mcp",
"enabled": true
}
}
} openclaw mcp add uk-co-medimo-mcp --url 'https://medimo.co.uk/mcp' --transport streamable-http
mcp_servers:
uk-co-medimo-mcp:
url: "https://medimo.co.uk/mcp" {
"McpServers": {
"uk-co-medimo-mcp": {
"Transport": "http",
"Url": "https://medimo.co.uk/mcp"
}
}
} assistant mcp add uk-co-medimo-mcp -t streamable-http -u 'https://medimo.co.uk/mcp'
{
"mcpServers": {
"uk-co-medimo-mcp": {
"type": "http",
"url": "https://medimo.co.uk/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 16 Sept 26 +7
- Authorization: unverified → partial ▲ security
- Stability: unverified → 0.03 ▲ functional
- Tool “get_availability” now declares an output schema ▲ functional
- Tool “get_clinic” now declares an output schema ▲ functional
- Tool “get_nhs_wait” now declares an output schema ▲ functional
- Tool “get_practitioner” now declares an output schema ▲ functional
- Tool “search_clinics” now declares an output schema ▲ functional
- Tool “start_booking” now declares an output schema ▲ functional
- First check of Tool coverage: 100 functional
- 15 Sept 26 65
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://medimo.co.uk/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=medimo.co.uk | CN=WE1,O=Google Trust Services,C=US | 17 Sept 2026 | 16 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | b9fba55ce81dc3a70eb166e6326eb977 |
| SANs: medimo.co.uk, *.medimo.co.uk | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of medimo.co.uk. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| uk. | present | 43876 | 8 | Verified |
| co.uk. | present | 11810 | 8 | Verified |
| medimo.co.uk. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.tailwindcss.com https://cdn.jsdelivr.net https://player.vimeo.com https://www.googletagmanager.com https://www.googleadservices.com https://*.doubleclick.net https://*.clarity.ms https://connect.facebook.net https://static.cloudflareinsights.com https://snap.licdn.com https://js.hs-scripts.com https://js.hs-banner.com https://js.hs-analytics.net https://js.hscollectedforms.net https://js.hsadspixel.net https://js.usemessages.com https://static.hsappstatic.net https://api.mapbox.com https://js.stripe.com https://checkout.stripe.com; style-src 'self' 'unsafe-inline' https://fonts.bunny.net https://api.mapbox.com https://cdn.tailwindcss.com; font-src 'self' https://fonts.bunny.net; img-src 'self' https: data: blob:; connect-src 'self' https://fonts.bunny.net https://api.mapbox.com https://events.mapbox.com https://*.google-analytics.com https://google-analytics.com https://*.analytics.google.com https://analytics.google.com https://w |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=(self) |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://medimo.co.uk/mcp | Verified | 200 | |
| http (plaintext) | http://medimo.co.uk/mcp | HTTPS enforced | 301 | https://medimo.co.uk/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
get_availability Check clinic availability ~313
Return current bookable availability for one clinic, read from the clinic's own diary. Gives the soonest appointment and how many are free today, tomorrow and in the next 48 hours, per treatment type. Pass a date or a date range to get that day's appointment times, each carrying the ids start_booking needs to open the checkout on that exact slot. Every response says how old its reading is, and every date carries its own age, because the next few days are re-read every ten minutes and later dates far less often. Says plainly when a date has not been read rather than reporting it as having nothing. Covers self-pay first appointments booked online; the checkout page shows every live slot.
| Name | Type | Req | Description |
|---|---|---|---|
| clinic_id | string | yes | The clinic id from search_clinics. Accepts the slug or the ULID. |
| date | string | – | Optional single date, ISO format (2026-09-22). Returns that day's appointment times. |
| date_from | string | – | Optional start of a date range, ISO format. Use with date_to. |
| date_to | string | – | Optional end of a date range, ISO format. At most 14 days from date_from. |
| service | string | – | Optional. Narrow to one treatment, e.g. "physiotherapy", "osteopathy", "chiropractic". |
| time_of_day | string | – | Optional. Narrow the times to morning (before noon), afternoon (noon to 5pm) or evening (5pm on). |
| Name | Type | Req | Description |
|---|---|---|---|
| about | string | yes | What MediMo is. |
| booking_rule | string | yes | Where bookings and payment complete. |
| data | object | yes | – |
| data_as_of | string|null | – | Age of the underlying reading, when different from generated_at. |
| generated_at | string | yes | When this response was produced. ISO 8601, Europe/London. |
| price_promise | string | yes | – |
No examples provided.
get_clinic Get clinic details ~122
Return the full public profile of one MediMo clinic: description, address, the treatments it offers with prices and durations, its practitioners with profession and regulator registration, and current availability. Prices are the clinic's own — booking through MediMo costs the same as booking direct. Contains no phone numbers, emails or review text. Use it after search_clinics when someone wants detail on a specific clinic; call start_booking when they have chosen.
| Name | Type | Req | Description |
|---|---|---|---|
| clinic_id | string | yes | The clinic id from search_clinics. Accepts the slug or the ULID. |
| Name | Type | Req | Description |
|---|---|---|---|
| about | string | yes | What MediMo is. |
| booking_rule | string | yes | Where bookings and payment complete. |
| data | object | yes | – |
| data_as_of | string|null | – | Age of the underlying reading, when different from generated_at. |
| generated_at | string | yes | When this response was produced. ISO 8601, Europe/London. |
| price_promise | string | yes | – |
No examples provided.
get_nhs_wait NHS waiting times ~182
Return the latest published NHS waiting-time figures for the Integrated Care Board covering a UK postcode, or for a named board: the median wait, how many people are waiting, the wait bands, and how that compares with the national average. Figures are NHS England's own published statistics, with the reporting period stated. Useful context when someone is deciding whether to wait or to go private; pair it with search_clinics for what is bookable privately nearby.
| Name | Type | Req | Description |
|---|---|---|---|
| icb | string | – | Alternative to postcode: an Integrated Care Board by name, slug or code, e.g. "Greater Manchester". |
| postcode | string | – | A UK postcode. The Integrated Care Board covering it is looked up locally, with no external call. |
| specialty | string | – | Optional. Defaults to MSK physiotherapy, the waiting list private physiotherapy is an alternative to. |
| Name | Type | Req | Description |
|---|---|---|---|
| about | string | yes | What MediMo is. |
| booking_rule | string | yes | Where bookings and payment complete. |
| data | object | yes | – |
| data_as_of | string|null | – | Age of the underlying reading, when different from generated_at. |
| generated_at | string | yes | When this response was produced. ISO 8601, Europe/London. |
| price_promise | string | yes | – |
No examples provided.
get_practitioner Get practitioner details ~103
Return one practitioner's public profile: name, profession, the regulator they are registered with and their registration number where MediMo holds it, their bio, and the clinics they can be booked at. Only registrations MediMo has verified are included. Contains no contact details. Use it when someone asks about a named clinician; call get_availability on their clinic for appointment times.
| Name | Type | Req | Description |
|---|---|---|---|
| practitioner_id | string | yes | The practitioner id (ULID) from get_clinic. |
| Name | Type | Req | Description |
|---|---|---|---|
| about | string | yes | What MediMo is. |
| booking_rule | string | yes | Where bookings and payment complete. |
| data | object | yes | – |
| data_as_of | string|null | – | Age of the underlying reading, when different from generated_at. |
| generated_at | string | yes | When this response was produced. ISO 8601, Europe/London. |
| price_promise | string | yes | – |
No examples provided.
search_clinics Search clinics ~444
Find private physiotherapy, osteopathy or chiropractic clinics near a UK postcode or town that can be booked online through MediMo. Each result carries the clinic's next available first appointment, read from its own diary and refreshed every ten minutes, plus distance, Google rating and the treatments it offers. Returns no appointment times beyond the next available slot and does not book. Pass a date, a date range and/or a time of day to get only the clinics free then, with that day's appointment times — "a chiropractic appointment next Tuesday afternoon within 5 miles of WA14". Start here; use get_clinic for detail on one result and start_booking when the person has chosen.
| Name | Type | Req | Description |
|---|---|---|---|
| date | string | – | Optional single date, ISO format (2026-09-22). Returns only clinics with an appointment that day, and that day's times. |
| date_from | string | – | Optional start of a date range, ISO format. Use with date_to. |
| date_to | string | – | Optional end of a date range, ISO format. At most 7 days from date_from. |
| limit | integer | – | Maximum clinics to return, 1–20. Default 10. |
| location | string | yes | A UK postcode ("M33 7XS"), postcode district ("SK8") or town ("Altrincham"). A full postcode gives the most accurate distances. |
| radius_miles | integer | – | Search radius, 1–20 miles. Default 10. Widens once to 20 if fewer than 3 clinics are found. |
| service | string | – | Optional treatment: "physiotherapy", "osteopathy", "chiropractic" (short forms like "physio" are fine). Leave empty to search all treatments. |
| sort | string | – | Order of results. "nearest" (default) lists clinics with an appointment first, then by distance; "soonest" by next available appointment; "rating" by Google rating. |
| time_of_day | string | – | Optional. Only clinics with a slot in the morning (before noon), afternoon (noon to 5pm) or evening (5pm on). |
| Name | Type | Req | Description |
|---|---|---|---|
| about | string | yes | What MediMo is. |
| booking_rule | string | yes | Where bookings and payment complete. |
| data | object | yes | – |
| data_as_of | string|null | – | Age of the underlying reading, when different from generated_at. |
| generated_at | string | yes | When this response was produced. ISO 8601, Europe/London. |
| price_promise | string | yes | – |
No examples provided.
start_booking Start a booking ~192
Build the MediMo checkout link for a chosen clinic and treatment, so the person can complete their booking and payment on medimo.co.uk. Returns the URL and a summary of what they are booking and what it costs. Call it once they have chosen. It holds no appointment, creates no booking, takes no payment and needs no personal details — all of that happens on the MediMo page. Safe to call more than once.
| Name | Type | Req | Description |
|---|---|---|---|
| clinic_id | string | yes | The clinic id from search_clinics or get_clinic. |
| practitioner_id | string | – | Optional. The practitioner id from get_clinic, if they asked for someone specific. |
| service_id | string | – | Optional. The service id from get_clinic, to open the checkout on that treatment. |
| starts_at | string | – | Optional ISO 8601 time, from get_availability next_available_at. Requires service_id and practitioner_id. |
| Name | Type | Req | Description |
|---|---|---|---|
| about | string | yes | What MediMo is. |
| booking_rule | string | yes | Where bookings and payment complete. |
| data | object | yes | – |
| data_as_of | string|null | – | Age of the underlying reading, when different from generated_at. |
| generated_at | string | yes | When this response was produced. ISO 8601, Europe/London. |
| price_promise | string | yes | – |
No examples provided.
What is the MediMo MCP server?
MediMo is an MCP server listed in the public MCP registry as uk.co.medimo/mcp. Find and book UK private physiotherapy, osteopathy and chiropractic clinics, with live availability. This page covers its hosted endpoint (https://medimo.co.uk/mcp).
Is the MediMo MCP server safe to use?
MediMo scores 74 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the MediMo MCP server expose?
MediMo exposes 6 tools: search_clinics, get_clinic, get_availability, get_practitioner, start_booking, get_nhs_wait. Their descriptions and schemas cost roughly 1,356 tokens of context every time the server is loaded.
Does the MediMo MCP server require authentication?
No. We connected to MediMo without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the MediMo MCP server still maintained?
MediMo is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.