Connect Claude, ChatGPT or Gemini to EMS, legal and health data

One MCP endpoint, OAuth or a key, the full tool list and what to check before trusting a result.

Add https://thefiredev.com/mcp to an MCP-capable client. MeshVault Connectors exposes 18 read-only tools for published EMS protocols, judges and courts, public health data and local-model sizing.

MCP is the Model Context Protocol: the assistant discovers tool names and arguments on a server, then requests a lookup. This service searches public reference sources. It does not connect to an electronic health record, a private case file or patient records.

The server was tested from Claude Code, Codex and the official MCP SDK against production on October 6, 2026. ChatGPT and Claude web connection steps require custom-connector access on your account. Gemini support here is a CLI extension; Gemini web accounts were not tested.

Connect a client

Claude and ChatGPT custom connectors

  1. Open connector or app settings in the client. Choose to add a custom remote MCP server.
  2. Enter https://thefiredev.com/mcp. Choose OAuth when the client offers an authentication method.
  3. On the MeshVault sign-in page, use your existing key or create a Free key. Read the consent screen before authorizing.
  4. Return to the assistant and ask it to list the MeshVault tools. Check that you see the expected tool names before making a lookup.

If your account has no custom-server option, upgrading MeshVault Connectors will not enable that client feature. Check the client plan and administrator restrictions first. MeshVault OAuth authorizes its own tools; it does not grant access to your Google, Apple or healthcare accounts.

Claude Code with an API key

Create a key on the Connectors page. Store it outside source code and keep it out of screenshots. Set MESHVAULT_API_KEY in the environment before starting the client. On a shell that supports read -s, this avoids typing the key into command history:

read -r -s -p "MeshVault key: " MESHVAULT_API_KEY
export MESHVAULT_API_KEY
printf '\n'
claude mcp add --transport http meshvault https://thefiredev.com/mcp \
  --header 'Authorization: Bearer ${MESHVAULT_API_KEY}'
claude mcp list

The single quotes preserve the variable reference in client configuration instead of embedding a key. Claude Code 2.1.284 produced this production status on October 6:

meshvault: https://thefiredev.com/mcp (HTTP) - Connected

In Claude Code, ask: Use ems_list_agencies for CA, then show the agency IDs and the source. Do not give clinical advice. Follow with an agency-scoped search. A broad state search can return a book for another county.

Codex CLI with an API key

codex mcp add meshvault --url https://thefiredev.com/mcp \
  --bearer-token-env-var MESHVAULT_API_KEY
codex mcp get meshvault

Codex CLI 0.159.0 reported Streamable HTTP transport and the production URL on October 6. It successfully called one tool from each of the four groups. The environment-variable name is configuration; the key itself stays in your environment.

Gemini CLI

gemini extensions install https://github.com/thefiredev-cloud/meshvault-connectors

The extension manifest declares the remote endpoint and a sensitive MESHVAULT_API_KEY setting. Review the extension permissions and enter your own key when prompted. The manifest passed extension validation in the October 6 release checks. An end-to-end Gemini conversation was not exercised in these tests.

What happens during OAuth

You do not need to implement this when your client handles MCP OAuth. The discovery sequence is useful when a connection fails:

  1. An unauthenticated request to /mcp returns HTTP 401 and a WWW-Authenticate header naming protected-resource metadata.
  2. The client reads /.well-known/oauth-protected-resource and the authorization-server metadata. Those name the authorize, registration and token URLs.
  3. The client registers and starts an authorization-code flow with PKCE S256. You inspect and approve the consent screen.
  4. The client exchanges the code for an access token. Access tokens last one hour. Refresh tokens rotate; replay of a used refresh token revokes that token family.

This is the production response to an unauthenticated initialize request, checked October 6:

HTTP 401
WWW-Authenticate: Bearer resource_metadata="https://thefiredev.com/.well-known/oauth-protected-resource", scope="mcp"

{"error":"authentication_required","error_description":"Authentication required. Use OAuth or an API key."}

The production SDK test completed discovery, dynamic registration, PKCE authorization and token exchange, then listed 18 tools and called models_gpu_catalog. A successful metadata fetch alone would not prove the consent or token exchange.

The actual tool list

A production tools/list request on October 6 returned the 18 tools below. Every tool had readOnlyHint: true and destructiveHint: false. Arguments here are a short reference; the client receives the full schema, required fields and accepted values.

EMS protocols

Source: Protocol Guide's published protocol books.

ems_search_protocols
Cited excerpts, section IDs and source PDF links.
Arguments: query, state or agency_id, limit.
ems_get_protocol
One full protocol section returned by search.
Arguments: id.
ems_list_agencies
Agency IDs and loaded section counts.
Arguments: state.
ems_coverage
Local, state or national-model coverage.
Arguments: state (optional).

Judges and courts

Source: JudgeFinder's public court-record API.

legal_search_judges
Names, courts and profile slugs.
Arguments: query, state, limit.
legal_get_judge
A judge profile and public-case activity.
Arguments: slug.
legal_judge_recent_cases
Recent public cases.
Arguments: judge_id, limit.
legal_search_courts
Court IDs and available contact data.
Arguments: query, state, county, type, limit.
legal_court_judges
Judges assigned to a court.
Arguments: court_id, limit.

Public health data

Source: CMS NPPES NPI Registry and FDA openFDA.

health_npi_lookup
Provider identity, status, taxonomy and registry link.
Arguments: npi, or provider/organization name and location.
health_drug_label
FDA labeling text and DailyMed links.
Arguments: name, sections, limit.
health_drug_recalls
Recall number, reason and report date.
Arguments: query, classification, status, limit.
health_drug_adverse_events
FAERS spontaneous-report counts.
Arguments: drug, top.

Model sizing

Source: Hugging Face configuration/files and a GPU catalog.

models_fit_check
Memory fit verdicts and estimated speed ceilings.
Arguments: model_id, hardware, context_tokens, quants.
models_estimate_vram
Weights, KV cache and runtime overhead estimates.
Arguments: model_id or params_b, quant, context_tokens, kv_cache, batch.
models_gguf_files
Exact GGUF download sizes.
Arguments: repo_id, memory_gb.
models_search_hf
Public Hugging Face model search.
Arguments: query, task, gguf_only, sort, limit.
models_gpu_catalog
Memory and bandwidth specifications.
Arguments: query (optional).

Use a result without losing its source

For EMS reference, first call ems_list_agencies, select the agency, search with that agency_id, then fetch the chosen section with ems_get_protocol. Ask the assistant to retain the agency, protocol year and source PDF link. Verify the current official book separately.

A production search for epinephrine anaphylaxis adult, scoped to CA with a limit of two, returned Alameda and Stanislaus County sections on October 6. The first result had DRAFT in its source URL. Inspect the source before relying on the excerpt. A search match is not current medical direction.

{
  "id": 254195,
  "protocol_number": "32",
  "title": "ANAPHYLAXIS / ALLERGIC REACTION",
  "agency": "Alameda County EMS Agency",
  "state": "CA",
  "protocol_year": 2025
}

For legal lookups, use the court ID or judge slug from search in the follow-up call. A zero judge_count means the dataset contains no associated judges for that result; it does not prove the court has no judges. The production test returned 65 California state-court matches, but this remains partial public-record data.

For drug labels, use specific products and routes. A local test against real openFDA data on October 6 searched naloxone and returned an oral pentazocine/naloxone combination first. A broad ingredient search can find the wrong formulation. Ask for the brand, generic name, route, effective date and DailyMed link before reading label text.

The health_drug_label section argument uses FDA field names such as indications_and_usage, not indications. FAERS report counts are spontaneous reports, not incidence or proof of causation. NPI registration does not establish that a provider is suitable for your needs.

Free versus Pro

Connector plans checked October 6, 2026
PlanTool calls / UTC dayPrice
Anonymous at /mcp/try10 per networkFree
Free key100Free
Pro5,000$19 / month

Only tools/call counts. Discovery and listing tools do not consume calls. Bad-input errors and upstream failures are refunded. The quota resets at 00:00 UTC, not your local midnight. All plans expose the same tool groups; Pro raises usage.

This production trial error arrived inside an MCP response with HTTP 200 and isError: true, after the anonymous allowance for the shared network was consumed:

Daily quota reached for the Anonymous (no key) plan (10/10 calls). Resets 2026-10-07T00:00:00.000Z. Upgrade or get a key: https://thefiredev.com/connectors#pricing

The authenticated /api/usage response includes your plan, limit, used calls and next reset. A fresh Free key in the local October 6 test returned:

{"plan":"free","daily_calls":100,"used_today":0,"resets_at":"2026-10-07T00:00:00.000Z"}

Subscribe through Connectors pricing. An existing Free key is upgraded when provided at checkout. A purchase without a key issues a new Pro key. Cancellation downgrades an upgraded Free key; a key issued with the subscription is revoked when Pro ends. Save the key when shown and never put it into a prompt.

Errors to diagnose first

  • HTTP 401 authentication_required: use OAuth or a valid key at /mcp. The keyless trial is the different URL /mcp/try.
  • HTTP 429 too_many_keys_today: the daily free-key issuance limit for your network is reached. Use an existing key or wait. Repeated requests will not fix it.
  • MCP input error -32602: compare arguments with the full tool schema. A label section such as indications is not accepted.
  • A tool returns no results: broaden the query or try a structured filter. An empty dataset match is not an authoritative negative answer.
  • OAuth stops working after refresh: reconnect rather than replaying a refresh token. Do not copy credentials from another user.

Never enter patient-identifying information, confidential legal facts or private health history. These are public reference tools. EMS responses are education and reference, not medical direction; legal results are not legal advice; health results are not medical advice.

Sources and test dates