Back to Home
wso2 icon

fhir-mcp-server

Verified Safe

by wso2

Overview

The FHIR MCP Server acts as a bridge between AI/LLM tools and FHIR APIs, enabling seamless search, retrieval, and analysis of clinical information.

Installation

Run Command
uvx fhir-mcp-server --transport stdio

Environment Variables

  • FHIR_MCP_HOST
  • FHIR_MCP_PORT
  • FHIR_MCP_SERVER_URL
  • FHIR_MCP_REQUEST_TIMEOUT
  • FHIR_SERVER_CLIENT_ID
  • FHIR_SERVER_CLIENT_SECRET
  • FHIR_SERVER_SCOPES
  • FHIR_SERVER_BASE_URL
  • FHIR_SERVER_ACCESS_TOKEN
  • FHIR_SERVER_DISABLE_AUTHORIZATION

Security Notes

The server correctly uses environment variables for sensitive configurations like client IDs, secrets, and access tokens, rather than hardcoding them. It also supports OAuth 2.0 Authorization Code Grant flow. The `docker-compose.yml` uses a default password for PostgreSQL, which is only for a local development setup and not a vulnerability in the application itself. A notable configuration aspect is the `FHIR_SERVER_DISABLE_AUTHORIZATION: True` setting for local Docker runs, which disables authentication and should be set to `False` for production deployments requiring secure access.

Similar Servers

Stats

Interest Score50
Security Score9
Cost ClassLow
Stars78
Forks30
Last Update2026-01-09

Tags

fhirhealthcaremcpmodel-context-protocolllmapi-gateway