PubMed MCP Server

Remote MCP server from Casey Hand for searching, reviewing, and citing biomedical literature.

Description

PubMed MCP Server is, according to the provider, an independent MCP product from Casey Hand and the cyanheads project. The official repository at https://github.com/cyanheads/pubmed-mcp-server describes the Apache-2.0 licensed software, its STDIO and Streamable HTTP deployments, and the public product endpoint https://pubmed.caseyjhand.com/mcp. The submitted address https://pubmed.caseyhand.com/mcp is not the same host and did not resolve during review; the canonical URL documented by the provider repository uses caseyjhand.com. Smithery lists cyanheads/pubmed-mcp-server as a remote deployment and names https://pubmed-mcp-server--cyanheads.run.tools as its deployment endpoint. That endpoint returned HTTP 401 with a missing-authorization response when probed without credentials. This demonstrates an access boundary, not that the service is absent. The repository, documented product endpoint, and Smithery mapping therefore establish a separate and durable product identity. This catalog stores no credentials, tokens, API keys, secrets, or personal health data.

Purpose, tools, and source quality

According to the provider, the server supports searching PubMed and Europe PMC, retrieving bibliographic metadata, abstracts, and available full text, generating formatted citations, finding related or citing works, searching MeSH terms, correcting search terms, and converting DOI, PMID, and PMCID identifiers. The repository describes NCBI E-utilities as the primary PubMed integration. PubMed is a National Library of Medicine bibliographic database containing citations and abstracts; PubMed does not automatically contain the complete journal article. For full text, the documented chain uses PubMed Central, Europe PMC, and, where applicable, Unpaywall. These sources are not interchangeable: PubMed and PMC are NLM services, Europe PMC expands coverage, and Unpaywall points to open copies hosted by other providers. Always inspect the original source, publication type, journal, version, date, license, and currency. Preprints, patents, and open copies must not be presented as peer-reviewed PubMed literature without clear labeling.

The distinction from the published Medical Terminologies MCP is explicit. Medical Terminologies MCP supports searching and mapping medical terminologies such as codes and classifications through a different provider, product page, repository, and remote endpoint. PubMed MCP Server researches literature and citations through NCBI, PMC, and Europe PMC paths. They are not the same product source, feature scope, or remote deployment. Overlap in the medical domain alone does not make this entry a duplicate.

Authorization, privacy, and data sharing

The public product endpoint is described by the provider without a visible key in the repository, while the Smithery deployment requires authorization. Operators must verify current authentication, permissions, availability, terms, and rate limits before use. NCBI documents a limited default rate for E-utilities; an API key may be needed for higher rates and belongs only in protected client configuration, never in this catalog. Medical literature queries can create sensitive inferences when combined with cases, people, institutions, or timestamps. Use data minimization, TLS, endpoint allowlisting, separated roles, short retention, and controlled log access. A remote server processes the request at its deployment; the MCP client may additionally pass results to a model provider, logs, or telemetry. That sharing must be reviewed organizationally and legally.

Access restrictions, write access, and safety

The documented tools are primarily read-oriented and do not modify PubMed or PMC. Writes can still happen outside the server when a client saves citations, abstracts, or full text into files, knowledge bases, databases, or reports. Such actions require an approved destination, least privilege, validation, and human approval. Full text is subject to individual copyright and license terms. Search results and tool responses are untrusted input and may be stale, incomplete, incorrect, or prompt-injected. Bound queries, respect rate limits, validate identifiers and sources, and check citations against NLM or the original publisher. Literature research is not a diagnosis or treatment and must not replace either; clinical decisions remain the responsibility of qualified professionals. The E-E-A-T basis of this entry is, according to the provider, the official repository and its documented product URL, Smithery deployment information, and official NLM, PubMed, PMC, and E-utilities references. These sources support identity, mapping, and documented scope, not the correctness of every automatically generated answer.

Requirements

An MCP client with Streamable HTTP support or a local STDIO configuration, plus network access to the provider-documented endpoint. NCBI rate rules and source licenses must be respected.

Installation instructions

Add the provider-documented remote endpoint https://pubmed.caseyjhand.com/mcp using current MCP client guidance, or use the official repository for a local STDIO deployment. Verify endpoint, tool schema, authentication, data sharing, and source terms first.

https://pubmed-mcp-server--cyanheads.run.tools

Authentication

The provider documents a public product endpoint; Smithery returns HTTP 401 to an unauthenticated request. Verify current authentication and rate limits. Never store secrets or NCBI keys.

Required access permissions

Literature queries are read-oriented according to the documentation. NCBI, PMC, Europe PMC, and Unpaywall access have their own terms, rates, and licenses. Client-side writes require separate approval.

Transmitted or stored data

Queries reach external literature services or the remote deployment. Responses may contain abstracts, full text, citations, and metadata and may be passed by the client to models, logs, or telemetry.

Security risks

Prompt injection, stale or incorrect literature claims, sensitive inferences, copyright violations, rate-limit failures, and unintended writes. Mitigate with TLS, allowlisting, source review, and human approval.

License and costs

License
Apache-2.0
Cost
free

The repository is Apache-2.0 licensed. Check current operating terms, availability, rate limits, and possible usage limits for the remote service directly with the provider.

Alternatives

Not recorded yet.

At a glance

Provider
Casey Hand
Status
Official server
Deployment
Remote
Current version
2.10.8
GitHub stars
148
Last reviewed
09.09.2026

Repository and documentation

Categories

Supported clients

Not recorded yet.