Using the API
MCP server: the API as tools.
The same API as 17 tools your agent can call directly — attach the hosted endpoint by URL, or run the MIT-licensed npm package over stdio. No data on disk, no local copy of the catalogue.
Install
Add it to your client's MCP config. Claude Desktop uses claude_desktop_config.json; Cursor and Windsurf take the same JSON shape under their own config keys.
{
"mcpServers": {
"drug-database": {
"command": "npx",
"args": ["-y", "@drug-database/mcp-server"],
"env": {
"DRUG_DATABASE_API_KEY": "dd_live_YOUR_KEY"
}
}
}
}Node 20 or newer. The binary is also on your path as drug-database-mcp if you install the package globally.
Hosted endpoint
For agents that attach to a URL instead of launching a process, the same tools are served at https://drug-database.com/v1/mcp over Streamable HTTP, with your key as a Bearer token. The handshake and the tool list are free; each tool call counts as one request against your plan, exactly like the API call behind it, and the list shows only the tools your plan can run.
POST https://drug-database.com/v1/mcp
Authorization: Bearer dd_live_YOUR_KEY
Content-Type: application/json
{"jsonrpc":"2.0","id":1,"method":"tools/list"}You need a key
Read this before wiring it up
Every tool except schema_docs calls a /v1 endpoint, and every one of those endpoints requires a bearer token. Four tools — search_drug, atc_lookup, browse_therapeutic_classes and compare_market_prices — do not check for the key locally before making the call, so with no key configured they fail with a 401 from the API rather than a clear local message. That is a rough edge, not a free tier: set DRUG_DATABASE_API_KEY.
Tools whose endpoint needs a scope your tier does not carry return the API's 403 with missing_scope — see Authentication for the tier table. check_interactions and validate_prescription need interactions:write (Growth and up); ask needs chat:write.
The tools
All sixteen are namespaced drug-database.<name> — so search_drug is exposed to your agent as drug-database.search_drug.
| Tool | Scope | Calls | What it does |
|---|---|---|---|
| search_drug | drugs:read | GET /v1/drugs | Typeahead across the catalogue. Its country parameter accepts only CH and FR — other markets need the HTTP endpoint. |
| get_drug | drugs:read | GET /v1/drugs/{id} · /v1/drugs/lookup | One full record — identifiers, ATC chain, dispensing category. |
| get_drug_profile | drugs:read | GET /v1/drugs/{id}/profile | The everything view: label texts, pricing, interactions, availability. |
| find_equivalents | drugs:read | GET /v1/drugs/{id}/equivalents | The same medicine in every other country: same substance, strength and form, grouped by country. |
| atc_lookup | atc:read | GET /v1/atc/{code} | One ATC node with its parents, children and DDD. |
| browse_therapeutic_classes | atc:read | GET /v1/classes and sub-paths | Multi-axis class registry — ATC plus the FDA pharmacologic axes. |
| check_interactions | drugs:read | POST /v1/interactions/check | Pairwise and N-way screening across a list of drugs. |
| validate_prescription | interactions:write | POST /v1/prescriptions/validate | Screening over non-identifying context only. Processes no PHI. |
| compare_market_prices | drugs:read | GET /v1/markets/overview | One comparable price per market for the same substance. |
| check_pharmacogenomics | drugs:read | GET /v1/pgx | CPIC pharmacogenomic guidance for a substance. |
| find_drug_targets | drugs:read | GET /v1/targets | Molecular targets for a substance, from Open Targets. |
| list_changes | changes:read | GET /v1/changes | The diff feed since a timestamp. |
| assess_feasibility | drugs:read | GET /v1/assessment | The composed assessment — targets, genetics, concordance, repurposing, guidelines, HTA — in one call. |
| assess_target_genetics | drugs:read | GET /v1/targets/genetics | Human-genetics support for a target×disease plus a concordance verdict. |
| find_repurposing_candidates | drugs:read | GET /v1/signatures | Compounds that most reverse a curated disease signature. |
| ask | chat:write | POST /v1/chat | A question in plain language, answered with sources. Draws on your plan’s monthly AI answers. |
| schema_docs | local | — local — | Field reference for the Drug, Interaction and AtcCode types. Never leaves the process. |
Configuration
| Variable | Default | Effect |
|---|---|---|
| DRUG_DATABASE_API_KEY | unset | Your dd_live_ or dd_test_ key. Required in practice. |
| DRUG_DATABASE_API_BASE | https://drug-database.com | Ignored unless the override flag below is also set. |
| DRUG_DATABASE_ALLOW_BASE_OVERRIDE | 0 | Set to 1 to permit an API base override. Off by default so a hostile MCP config cannot silently redirect your key to somebody else’s server. |
| DRUG_DATABASE_MCP_TELEMETRY | 1 | Set to 0 to stop the client attempting a telemetry post. There is currently no endpoint behind it — see below. |
| DRUG_DATABASE_MCP_TRANSPORT | stdio | stdio or sse. |
Why the base URL is pinned
An MCP config is a file an agent can be talked into editing. If the API base were freely overridable, a prompt-injected config change could point the server at an attacker's host and your API key would be sent there on the next tool call. The override exists for local development and is opt-in by a second, separate variable.
What the server does not do
- No data on disk. An in-memory ETag cache scoped to the process lifetime, and nothing else. Drug names, identifiers and ATC codes are never written locally.
- No catalogue ships with the package. Every answer is a live call. The npm package is the shim; the data stays behind the API.
- No telemetry reaches us. The client is built to post
{ tool, ok, http_status, ms }— which tool ran, whether it worked, the status and the latency; never a query, never a result, never patient context. In practice even that goes nowhere: the path it posts to is not a route that exists, so every attempt 404s. SetDRUG_DATABASE_MCP_TELEMETRY=0if you would rather it did not try at all.
Localisation
Tool descriptions and error strings ship in English, German, French and Italian, selected from LC_ALL / LANG; anything else falls back to English. The data itself comes back in whatever language the source register publishes — Swiss monographs in German, French and Italian, for instance — and is not translated.
Clinical framing
Tell your agent, not just yourself
Interaction and prescription tools return informational data, not clinical decisions. Every response carries the disclaimer verbatim: informational only, not a medical device, not a substitute for professional clinical judgment, verify against primary sources before clinical use. If you are building an agent that surfaces this to a clinician, pass that line through rather than summarising it away.