Back to Browse

Mychart MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Connects to Epic MyChart patient portals: interactive login, list and download your own test results

About

Connects to Epic MyChart patient portals: interactive login, list and download your own test results

Security Report

4.2
Use Caution4.2High Risk

This MyChart MCP server has a well-designed architecture with appropriate authentication controls and proper credential handling. Login credentials are never passed through the MCP protocol or server code — users type them directly into a visible browser window. The main concerns are moderate-severity issues: optional credential pre-filling via environment variables (acceptable when documented), potential for timing-based session race conditions in a multi-call scenario, and informational code quality items. Permissions are appropriately scoped to the server's purpose of automating a patient portal. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

7 files analyzed · 10 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

process_spawn

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Default MyChart provider URL (alternative to the mychart_set_provider tool)Optional

Environment variable: MYCHART_URL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-kriskraw80-mychart": {
      "env": {
        "MYCHART_URL": "your-mychart-url-here"
      },
      "args": [
        "-y",
        "mychart-mcp-server"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

MyChart MCP Server

An MCP (Model Context Protocol) server that connects to any Epic MyChart patient portal to log in, list your test results, and download them as PDFs — so an AI assistant can help you understand your own lab work.

Epic offers no simple public login API (the official FHIR route requires per-organization app registration), so this server drives the MyChart website with Playwright:

  • Login is interactive and private — a visible browser window opens; you type your username/password and complete MFA yourself. Credentials never pass through the AI, the MCP protocol, or this server's tool arguments.
  • Session persists — cookies (including MyChart's session-scoped auth cookie) are exported to disk after login and replayed on every launch, so subsequent operations run headless until the portal expires the session server-side.
  • Works across MyChart versions — scraping tries the modern SPA routes (/app/test-results) first, then classic routes, with permissive selectors.

Tools

ToolPurpose
mychart_set_providerSet your health system's MyChart URL (one-time). Paste any URL from their MyChart site.
mychart_loginOpens a visible browser window; you sign in + complete MFA there.
mychart_session_statusCheck provider config + whether the saved session is still valid.
mychart_list_test_resultsList ALL test results (auto-expands "Show more"), with ids r1, r2, ....
mychart_get_test_resultFull readable content of one result (values, ranges, comments).
mychart_download_test_resultSave a result as PDF to ~/.mychart-mcp/downloads.
mychart_screenshotDebug: full-page PNG of what the automation browser sees.
mychart_close_browserClose the browser process (session stays saved on disk).

Installation

npm install -g mychart-mcp-server
npx playwright install chromium

Or from source:

git clone https://github.com/kriskraw80/mychart-mcp-server.git
cd mychart-mcp-server
npm install
npx playwright install chromium
npm run build

Register with Claude Code / Claude Desktop

{
  "mcpServers": {
    "mychart": {
      "command": "npx",
      "args": ["mychart-mcp-server"]
    }
  }
}

(Or point command at node with args: ["<path>/dist/index.js"] for a source checkout.) Restart your MCP client after config changes.

Optional environment variables

VariablePurpose
MYCHART_URLDefault provider URL (alternative to mychart_set_provider).
MYCHART_USERNAME / MYCHART_PASSWORDIf set on the server process, the login form is pre-filled (MFA is still completed by you in the window). Optional — typing in the window is the default and safest.

Typical flow

  1. mychart_set_provider with your portal URL (e.g. https://mychart.example-health.org/MyChart)
  2. mychart_login → sign in + MFA in the window that opens (check "Remember this device")
  3. mychart_list_test_results → returns r1, r2, ...
  4. mychart_get_test_result r1 or mychart_download_test_result r1

Data locations

Everything lives in ~/.mychart-mcp/ — keep it out of synced folders (the Chromium profile does not tolerate file sync):

  • config.json — provider URL
  • browser-profile/ — persistent Chromium profile
  • storage-state.json — exported session cookies (replayed on each launch)
  • results-cache.json — id → result-URL map from the last list call
  • downloads/ — PDFs and screenshots

Notes & limitations

  • Personal use, no warranty. This tool automates the MyChart web portal to access your own health records — a right you have under HIPAA — but portal scraping is not officially sanctioned by Epic. Use at your own discretion.
  • MyChart's DOM varies by health system and Epic version. If listing finds nothing, use mychart_screenshot to see the rendered page; selectors may need a tweak for your provider. Some systems host MyChart on non-obvious domains (e.g. secure.<org>.org rather than mychart.<org>.org) — paste the URL straight from your browser.
  • The server prefers your system-installed Chrome (then Edge, then Playwright's bundled Chromium) — real Chrome's app-bound cookie encryption requires the whole profile to stay on one browser brand, and some Windows machines can't run the bundled build.
  • PDF download renders the result detail page via headless Chrome (page.pdf), which is version-independent, rather than hunting for per-version "Download" buttons.
  • Sessions expire server-side after idle time; just run mychart_login again.
  • login-helper.mjs, run-direct.mjs, and run-batch.mjs drive the built dist/ code directly — handy for re-login or batch fetching without an MCP client in the loop.

License

MIT

Reviews

No reviews yet

Be the first to review this server!

Mychart MCP Server - Connects to Epic MyChart patient portals: interactive | MCP Marketplace