openfda-mcp-server
Query FDA data on drugs, food, devices, and recalls via openFDA. STDIO or Streamable HTTP.
The record the registry holds
It also ships as a package you run yourself.
{
"server": {
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.cyanheads/openfda-mcp-server",
"description": "Query FDA data on drugs, food, devices, and recalls via openFDA. STDIO or Streamable HTTP.",
"repository": {
"url": "https://github.com/cyanheads/openfda-mcp-server",
"source": "github"
},
"version": "0.7.3",
"packages": [
{
"registryType": "npm",
"registryBaseUrl": "https://registry.npmjs.org",
"identifier": "@cyanheads/openfda-mcp-server",
"version": "0.7.3",
"runtimeHint": "bun",
"transport": {
"type": "stdio"
},
"environmentVariables": [
{
"description": "Free API key from open.fda.gov — increases daily limit from 1K to 120K requests.",
"format": "string",
"name": "OPENFDA_API_KEY"
},
{
"description": "Serve exact-key lookups for drug/label, drug/ndc, drug/enforcement, and drug/drugsfda from a local bulk mirror instead of the API. Off by default; the initial harvest runs out-of-band via the mirror:init script.",
"format": "string",
"default": "false",
"name": "OPENFDA_MIRROR_ENABLED"
},
{
"description": "Directory holding one SQLite file per mirrored dataset.",
"format": "string",
"default": "./data/openfda-mirror",
"name": "OPENFDA_MIRROR_PATH"
},
{
"description": "Cron expression for the in-process mirror refresh. HTTP transport only; stdio operators run mirror:refresh from the host. Requires the optional node-cron peer dependency.",
"format": "string",
"name": "OPENFDA_MIRROR_REFRESH_CRON"
},
{
"description": "Fall back to the live API when the mirror is cold, missing the record, or failing. Disable to fail loudly instead.",
"format": "string",
"default": "true",
"name": "OPENFDA_MIRROR_FALLBACK_LIVE"
},
{
"description": "Wall-clock budget for one scheduled refresh before it is aborted. Raise it for drug/label, the only multi-partition dataset.",
"format": "string",
"default": "21600000",
"name": "OPENFDA_MIRROR_REFRESH_TIMEOUT_MS"
},
{
"description": "Host serving the openFDA bulk download manifest. Override only to harvest from a private mirror of the dumps.",
"format": "string",
"default": "https://api.fda.gov",
"name": "OPENFDA_MIRROR_BASE_URL"
},
{
"description": "Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').",
"format": "string",
"default": "info",
"name": "MCP_LOG_LEVEL"
}
]
},
{
"registryType": "npm",
"registryBaseUrl": "https://registry.npmjs.org",
"identifier": "@cyanheads/openfda-mcp-server",
"version": "0.7.3",
"runtimeHint": "bun",
"transport": {
"type": "streamable-http",
"url": "http://localhost:3010/mcp"
},
"environmentVariables": [
{
"description": "Free API key from open.fda.gov — increases daily limit from 1K to 120K requests.",
"format": "string",
"name": "OPENFDA_API_KEY"
},
{
"description": "Must be set to 'http' for streamable HTTP transport.",
"isRequired": true,
"format": "string",
"default": "http",
"name": "MCP_TRANSPORT_TYPE"
},
{
"description": "The hostname for the HTTP server.",
"format": "string",
"default": "127.0.0.1",
"name": "MCP_HTTP_HOST"
},
{
"description": "The port to run the HTTP server on.",
"format": "string",
"default": "3010",
"name": "MCP_HTTP_PORT"
},
{
"description": "The endpoint path for the MCP server.",
"format": "string",
"default": "/mcp",
"name": "MCP_HTTP_ENDPOINT_PATH"
},
{
"description": "Authentication mode to use: 'none', 'jwt', or 'oauth'.",
"format": "string",
"default": "none",
"name": "MCP_AUTH_MODE"
},
{
"description": "Serve exact-key lookups for drug/label, drug/ndc, drug/enforcement, and drug/drugsfda from a local bulk mirror instead of the API. Off by default; the initial harvest runs out-of-band via the mirror:init script.",
"format": "string",
"default": "false",
"name": "OPENFDA_MIRROR_ENABLED"
},
{
"description": "Directory holding one SQLite file per mirrored dataset.",
"format": "string",
"default": "./data/openfda-mirror",
"name": "OPENFDA_MIRROR_PATH"
},
{
"description": "Cron expression for the in-process mirror refresh. HTTP transport only; stdio operators run mirror:refresh from the host. Requires the optional node-cron peer dependency.",
"format": "string",
"name": "OPENFDA_MIRROR_REFRESH_CRON"
},
{
"description": "Fall back to the live API when the mirror is cold, missing the record, or failing. Disable to fail loudly instead.",
"format": "string",
"default": "true",
"name": "OPENFDA_MIRROR_FALLBACK_LIVE"
},
{
"description": "Wall-clock budget for one scheduled refresh before it is aborted. Raise it for drug/label, the only multi-partition dataset.",
"format": "string",
"default": "21600000",
"name": "OPENFDA_MIRROR_REFRESH_TIMEOUT_MS"
},
{
"description": "Host serving the openFDA bulk download manifest. Override only to harvest from a private mirror of the dumps.",
"format": "string",
"default": "https://api.fda.gov",
"name": "OPENFDA_MIRROR_BASE_URL"
},
{
"description": "Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').",
"format": "string",
"default": "info",
"name": "MCP_LOG_LEVEL"
}
]
}
],
"remotes": [
{
"type": "streamable-http",
"url": "https://openfda.caseyjhand.com/mcp"
}
]
},
"_meta": {
"io.modelcontextprotocol.registry/official": {
"status": "active",
"statusChangedAt": "2026-08-07T09:46:36.641927Z",
"publishedAt": "2026-08-07T09:46:36.641927Z",
"updatedAt": "2026-08-07T09:46:36.641927Z",
"isLatest": true
}
}
}
Draft an Agent Plugin from this
An MCP server is raw capability: some tools, wired to something. An Agent Plugin is the packaging that says what job it does, what it leaves behind and where it stops. The prompt below carries this record and asks for the packaging; your own assistant writes it, and nothing here is sent anywhere.
MCP server
These are the publisher's own words, filed by them with the official MCP registry and mirrored here. This catalog did not read them from the publisher and has not run, called or installed anything.
The publisher's own address
https://github.com/cyanheads/openfda-mcp-server
The address the publisher put in their registry record, printed as they wrote it. Nobody here has opened it.