Server data from the Official MCP Registry
Valida ICD-10-CM contra catalogo real FY2026 (NCHS/CDC) y CPT por estructura/categoria.
About
Valida ICD-10-CM contra catalogo real FY2026 (NCHS/CDC) y CPT por estructura/categoria.
Remote endpoints: streamable-http: https://validar-codigo-medico.encodari.workers.dev/mcp
Security Report
This is a Cloudflare Workers-based MCP server that validates medical codes (ICD-10-CM and CPT) against official databases. The server implements proper x402 payment authentication for API access and uses environment-based credential storage. However, there are moderate concerns around error handling in payment logic, insufficient input validation on code parameters, and a lack of rate limiting mechanisms that could expose the service to abuse. Supply chain analysis found 1 known vulnerability in dependencies (1 critical, 0 high severity).
3 files analyzed · 8 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install & Connect
Available as Local & Remote
This plugin can run on your machine or connect to a hosted endpoint. during install.
Documentation
View on GitHubFrom the project's GitHub README.
validar-codigo-medico
Remote MCP server (Cloudflare Workers) with one tool that validates medical codes against real data:
validate_medical_code—system: "icd10"does a real lookup against the official billable ICD-10-CM code catalog (FY2026, NCHS/CDC, public domain as a work of the U.S. government) and returns the official short description.system: "cpt"validates the real structure of a CPT code (Category I: 5 digits; Category II: 4 digits +F; Category III: 4 digits +T) and estimates its area by public numeric range — it doesn't include per-code descriptions, because the CPT catalog is owned by the AMA and requires a paid license (it can't be redistributed).
No database, no persistent state between calls: each call builds a fresh McpServer (see createServer() in src/index.ts). The ICD-10-CM catalog (~6MB, 74,719 codes) is bundled into the Worker itself as static data (src/tools/data/icd10cm.ts) and parsed once per isolate into an in-memory Map — see src/tools/codigoMedico.ts.
Why CPT has no descriptions
The CPT (Current Procedural Terminology) description catalog is owned by the American Medical Association and requires a paid license to redistribute its content — unlike ICD-10-CM, which is a work of the U.S. government and therefore public domain. That's why this tool validates a CPT code's real format (regex + numeric range, publicly available information about the code's structure) but doesn't offer the procedure's description: that requires an AMA-licensed codebook.
Billing (x402)
Charges per call via x402 — real USDC payment on Base mainnet, against the Coinbase Developer Platform (CDP) facilitator. The payment travels inside the MCP JSON-RPC itself (_meta), not as an HTTP header; see src/payments.ts.
| Tool | Price |
|---|---|
validate_medical_code | $0.02 USDC |
An unpaid tools/call returns isError: true with the accepts (network, amount, payTo) the client needs to pay and retry — not an unexplained exception.
Structure
src/
index.ts # registers the tool in the McpServer and exposes the MCP HTTP handler
payments.ts # x402 billing on Base mainnet via the CDP facilitator
tools/
codigoMedico.ts # pure logic for validate_medical_code (testable without Workers)
codigoMedico.test.ts
data/
icd10cm.ts # bundled FY2026 ICD-10-CM catalog (generated, do not edit by hand)
scripts/
dev-node.ts # dev server that runs the handler in plain Node, no wrangler
gen-icd10-data.mjs # regenerates tools/data/icd10cm.ts from a new CMS/NCHS order file
Updating the ICD-10-CM catalog
When NCHS publishes a new version (new fiscal year or addenda):
- Download the "Code Descriptions" zip from
https://ftp.cdc.gov/pub/health_statistics/nchs/publications/ICD10CM/<YEAR>/. - Unzip it and locate
icd10cm-codes-<YEAR>.txt. node scripts/gen-icd10-data.mjs <path-to-txt> src/tools/data/icd10cm.ts.
Running it locally
⚠️ Note on wrangler dev: the real Cloudflare Workers runtime (workerd) requires macOS 13.5+. If your Mac has an older version, wrangler dev (and npm run dev) will fail. This project includes a plain-Node shim that runs the exact same fetch() handler without needing workerd.
1. Install dependencies
npm install
2. Run the unit tests
npm test
3a. If your wrangler dev works (macOS 13.5+, Linux, Windows)
npm run dev
3b. If wrangler dev fails because of the macOS version
npm run dev:node
Starts at http://localhost:8787/mcp, reading CDP credentials from ~/.mcp-tools-factory-credentials.env (shared across all tools in this factory).
4. Test with curl
# 1) initialize
curl -s -X POST http://localhost:8787/mcp \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"curl-test","version":"0.0.1"}}}'
# 2) tools/list
curl -s -X POST http://localhost:8787/mcp \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":2,"method":"tools/list","params":{}}'
# 3) tools/call — validate_medical_code (ICD-10-CM)
curl -s -X POST http://localhost:8787/mcp \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":3,"method":"tools/call","params":{"name":"validate_medical_code","arguments":{"system":"icd10","codes":["A00.0","Z21","does-not-exist"]}}}'
Responses come as Server-Sent Events (event: message + data: {...}); the data: line is the usual JSON-RPC response.
Deploy and listings
Deployed at https://validar-codigo-medico.encodari.workers.dev/mcp (Cloudflare Workers). Published on the official MCP registry, Smithery, mcp.so, and with an open PR to awesome-mcp-servers.
What it doesn't do (yet)
- Doesn't include per-code CPT descriptions (see "Why CPT has no descriptions" above).
- Charges on Base mainnet with real money. To switch back to testnet (Base Sepolia,
eip155:84532) during development, changeNETWORKinsrc/payments.ts. - No database or persistent state between calls (beyond the billing config and the ICD-10-CM catalog Map, cached in memory per isolate).
- Not medical or billing advice: this is a structural/catalog validation, not a substitute for a certified professional coder.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
FinAgent
Freeby mcp-marketplace · Finance
Free stock data and market news for any MCP-compatible AI assistant.
