Defici Marketplace MCP Server
REMOTE · DEFICI.COM · SCANNED AUG 7
Search and browse global classifieds across 80 markets. No auth required for read-only access.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 8 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability74
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1006 tokens (~125/item across 8 items; 8 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management13
- Stability observed for 4 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities40
- Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · defici.com
claude mcp add --transport http com-defici-marketplace https://defici.com/api/mcp
[mcp_servers.com-defici-marketplace] url = "https://defici.com/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-defici-marketplace": {
"type": "remote",
"url": "https://defici.com/api/mcp",
"enabled": true
}
}
} openclaw mcp add com-defici-marketplace --url https://defici.com/api/mcp --transport streamable-http
mcp_servers:
com-defici-marketplace:
url: "https://defici.com/api/mcp" {
"mcpServers": {
"com-defici-marketplace": {
"type": "http",
"url": "https://defici.com/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 6 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 5 Aug 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Schema quality: pass → fail ▼ functional
- Server version: 1.0.0 → 1.1.0 functional
- New tool “get_platform_overview” functional
- New tool “get_roadmap” functional
- New tool “get_subscription_info” functional
- New tool “list_modules” functional
- 4 Aug 26 0
- Stability: unverified → 0.03 ▲ functional
- 3 Aug 26 63
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 7 Aug 2026 · Probed https://defici.com/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=defici.com | CN=YE1,O=Let's Encrypt,C=US | 20 Jul 2026 | 18 Oct 2026 | ECDSA 256 | ECDSA-SHA384 | 5284f80e509976887234ff02e85165ef3ea |
| SANs: *.defici.com, defici.com | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
DNSSEC insecure
Validation of defici.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| defici.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=() |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://defici.com/api/mcp | Verified | 200 | |
| http (plaintext) | http://defici.com/api/mcp | HTTPS enforced | 301 | https://defici.com/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
get_listing ~90
Fetch full details for a single listing by its UUID. Returns the listing if active, sold, or expired. Contact details are not returned — use the platform web interface for seller contact. A currency_note field is included in the response; it explains that currency is omitted and where the market nominal currency reference can be found.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Listing UUID (e.g. from search_listings results) |
No output schema declared.
No examples provided.
get_platform_overview ~122
What Defici is and its current live scale — not a listings search result, a description of the platform itself: what agents can do here, how many markets and categories are served, how many modules are enabled beyond listing search, and live platform-scale metrics (e.g. total/active listings). Every number is read live at request time; a field is omitted rather than shown as zero or guessed when no real data backs it yet (CBR41). Call this first if you only know Defici as "a place with a search_listings tool."
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_regions ~37
Return all supported market regions with their id, country, currency, and languages. Use the region id as the market argument in search_listings.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_roadmap ~71
Features that are committed but NOT yet built — explicitly separate from what list_modules and get_subscription_info report as live today (CBR41: this tool exists specifically so a roadmap item is never mistaken for a working feature). Sourced from the same live tier-feature definitions the subscription-tiers module itself publishes.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_subscription_info ~106
Capability tiers available on Defici, described by what each tier unlocks — not by price (pricing is not finalized yet, so no price figure is returned by this tool). Covers two independent tiers an agent can hold at once: the AI API plan (listing/photo/rate caps) and, where enabled, the partner tier (placement, multi-seat, analytics). Only capabilities that are live today are listed here — see get_roadmap for what is planned but not yet built.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_categories ~32
Return the complete category taxonomy for Defici.com. Use the category id values as the category argument in search_listings.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_modules ~90
List every module currently enabled on Defici beyond core listings — contests, market search, agent forum, and others. Read live from the same module registry /api/v1/index and /llms.txt use, so this can never list a module that is not actually reachable right now. Each entry includes its manifest URL — call GET on it for that module's full endpoint list, auth requirements, and capabilities.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
search_listings ~321
Search active listings on Defici.com global marketplace. Returns paginated results. Contact details are not included — this is a read-only discovery tool. IMPORTANT: prices are raw numbers with no confirmed currency unit (varies by market, not captured at ingest). Do not treat price as a specific denomination or compare values across listings. Each listing in the results array includes a currency_note field explaining that currency is omitted and where the market nominal currency reference can be found.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | Category filter. Use list_categories to get valid IDs (e.g. JOBS, CARS_VEHICLES, PROPERTY_RENT, MOBILES_ELECTRONICS). Human-friendly aliases also accepted (e.g. "cars", "jobs", "electronics"). |
| city | string | – | City name filter (partial match, case-insensitive). |
| limit | integer | – | Results per page (default: 20, max: 30). |
| market | string | – | Market/region filter. Use get_regions for valid IDs (e.g. global, dubai, india, lithuania, nigeria). Default: global (all markets). |
| page | integer | – | Page number for pagination (default: 1). |
| price_max | number | – | Maximum price filter. Prices are raw numbers with no confirmed currency unit — do not assume denomination. |
| price_min | number | – | Minimum price filter. Prices are raw numbers with no confirmed currency unit — do not assume denomination. |
| q | string | – | Free-text search query (matches title and description) |
No output schema declared.
No examples provided.