Licita
REMOTE · EUTENDERS.DUCKDNS.ORG · SCANNED AUG 20
Spanish/EU procurement intelligence for agents; x402 or prepaid credits.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 11 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability64
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 2011 tokens (~182/item across 11 items; 11 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management10
- Stability observed for 3 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage89
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 67% of tool parameters carry a description.Partial
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · eutenders.duckdns.org
claude mcp add --transport http gastonrey-licita-app https://eutenders.duckdns.org/mcp
[mcp_servers.gastonrey-licita-app] url = "https://eutenders.duckdns.org/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"gastonrey-licita-app": {
"type": "remote",
"url": "https://eutenders.duckdns.org/mcp",
"enabled": true
}
}
} openclaw mcp add gastonrey-licita-app --url https://eutenders.duckdns.org/mcp --transport streamable-http
mcp_servers:
gastonrey-licita-app:
url: "https://eutenders.duckdns.org/mcp" {
"mcpServers": {
"gastonrey-licita-app": {
"type": "http",
"url": "https://eutenders.duckdns.org/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 19 Aug 26 +1
- The server changed its declared name: licita-agent → licita security
- Schema quality: 155 → 182 ▼ functional
- Tool coverage: 52% → 67% ▲ functional
- New tool “billing_get_balance” functional
- New tool “billing_purchase_credits” functional
- New tool “research” functional
- “get_buyer_history” added an optional parameter “client_key” cosmetic
- “get_company” added an optional parameter “client_key” cosmetic
- “get_company_awards” added an optional parameter “client_key” cosmetic
- “get_company_opportunities” added an optional parameter “client_key” cosmetic
- “get_renewals” added an optional parameter “client_key” cosmetic
- “get_tender” added an optional parameter “client_key” cosmetic
- “search_tenders” added an optional parameter “client_key” cosmetic
- 18 Aug 26 0
- Stability: unverified → 0.03 ▲ functional
- 17 Aug 26 60
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Aug 2026 · Probed https://eutenders.duckdns.org/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=eutenders.duckdns.org | CN=YE1,O=Let's Encrypt,C=US | 17 Aug 2026 | 15 Nov 2026 | ECDSA 256 | ECDSA-SHA384 | 6b670fbef19b9c32267263bf12c37b9b4e3 |
| SANs: eutenders.duckdns.org | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
DNSSEC insecure
Validation of eutenders.duckdns.org. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| org. | present | 26974 | 8 | Verified |
| duckdns.org. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://eutenders.duckdns.org/mcp | Verified | 200 | |
| http (plaintext) | http://eutenders.duckdns.org/mcp | HTTPS enforced | 308 | https://eutenders.duckdns.org/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
billing_get_balance ~129
[GET /v1/billing — $0.00] Check the prepaid credit balance for a client key (in cents and USD). Always free. Returns not_found when no account exists yet — buy credits via billing_purchase_credits to create one.
| Name | Type | Req | Description |
|---|---|---|---|
| client_key | string | yes | prepaid credit account key (must match the key used when buying credits) |
| payment_token | string | – | Payment proof: dev mode → single-use token from POST /v1/dev-faucet; x402 mode → base64 payment payload (the PAYMENT-SIGNATURE / X-PAYMENT header value) |
No output schema declared.
No examples provided.
billing_purchase_credits ~196
[POST /v1/billing/credits/5 — $5.00] Buy a prepaid credit bundle (5, 10 or 25 USD) paid per-endpoint via x402 (mirrors REST POST /v1/billing/credits/:amount). Set amount to the bundle you pay for with payment_token; the proof is verified against that exact bundle, then the account is credited and the balance returned. Afterwards send client_key on every paid tool to pay from balance instead of per-call proofs.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number|string | yes | bundle amount in USD: 5, 10 or 25 |
| client_key | string | yes | prepaid credit account key to credit |
| payment_token | string | – | Payment proof: dev mode → single-use token from POST /v1/dev-faucet; x402 mode → base64 payment payload (the PAYMENT-SIGNATURE / X-PAYMENT header value) |
No output schema declared.
No examples provided.
get_buyer_history ~149
[GET /v1/buyers/:id/history — $0.05] Buyer profile by id: award history, supplier concentration (top-supplier share) and per-CPV-division recurrence (median months between awards).
| Name | Type | Req | Description |
|---|---|---|---|
| client_key | string | – | Prepaid credit balance key: when set, paid calls first try to debit this account instead of requiring a per-call proof. |
| id | integer | yes | numeric id from search results |
| payment_token | string | – | Payment proof: dev mode → single-use token from POST /v1/dev-faucet; x402 mode → base64 payment payload (the PAYMENT-SIGNATURE / X-PAYMENT header value) |
No output schema declared.
No examples provided.
get_company ~153
[GET /v1/companies/:id — $0.05] Company profile by id: name, country, NIF, aliases and source identifiers (cross-source identity), plus aggregate stats (wins, total awarded value, top CPVs, top buyers).
| Name | Type | Req | Description |
|---|---|---|---|
| client_key | string | – | Prepaid credit balance key: when set, paid calls first try to debit this account instead of requiring a per-call proof. |
| id | integer | yes | numeric id from search results |
| payment_token | string | – | Payment proof: dev mode → single-use token from POST /v1/dev-faucet; x402 mode → base64 payment payload (the PAYMENT-SIGNATURE / X-PAYMENT header value) |
No output schema declared.
No examples provided.
get_company_awards ~153
[GET /v1/companies/:id/awards — $0.05] Paginated award history for a company: dates, lots, values, tender + buyer context.
| Name | Type | Req | Description |
|---|---|---|---|
| client_key | string | – | Prepaid credit balance key: when set, paid calls first try to debit this account instead of requiring a per-call proof. |
| id | integer | yes | numeric id from search results |
| page | integer | – | – |
| payment_token | string | – | Payment proof: dev mode → single-use token from POST /v1/dev-faucet; x402 mode → base64 payment payload (the PAYMENT-SIGNATURE / X-PAYMENT header value) |
| size | integer | – | – |
No output schema declared.
No examples provided.
get_company_opportunities ~161
[GET /v1/companies/:id/opportunities — $0.10] Active/recent tenders matching a company's historical CPV/buyer profile, with a deterministic similarity score (explained in score_explanation).
| Name | Type | Req | Description |
|---|---|---|---|
| client_key | string | – | Prepaid credit balance key: when set, paid calls first try to debit this account instead of requiring a per-call proof. |
| id | integer | yes | numeric id from search results |
| page | integer | – | – |
| payment_token | string | – | Payment proof: dev mode → single-use token from POST /v1/dev-faucet; x402 mode → base64 payment payload (the PAYMENT-SIGNATURE / X-PAYMENT header value) |
| size | integer | – | – |
No output schema declared.
No examples provided.
get_pricing ~86
[GET /v1/pricing — $0.00] Machine-readable price ladder for all endpoints/tools plus the payment flow. Always free.
| Name | Type | Req | Description |
|---|---|---|---|
| payment_token | string | – | Payment proof: dev mode → single-use token from POST /v1/dev-faucet; x402 mode → base64 payment payload (the PAYMENT-SIGNATURE / X-PAYMENT header value) |
No output schema declared.
No examples provided.
get_renewals ~196
[GET /v1/renewals — $0.25] Forecast signals for likely re-tenders: contracts/frameworks approaching renewal. Filters: cpv (prefix), buyer, window_months (default 12, max 36), min_confidence=low|medium|high.
| Name | Type | Req | Description |
|---|---|---|---|
| buyer | string | – | – |
| client_key | string | – | Prepaid credit balance key: when set, paid calls first try to debit this account instead of requiring a per-call proof. |
| cpv | string | – | – |
| min_confidence | string | – | – |
| page | integer | – | – |
| payment_token | string | – | Payment proof: dev mode → single-use token from POST /v1/dev-faucet; x402 mode → base64 payment payload (the PAYMENT-SIGNATURE / X-PAYMENT header value) |
| size | integer | – | – |
| window_months | integer | – | – |
No output schema declared.
No examples provided.
get_tender ~147
[GET /v1/tenders/:id — $0.02] Full tender detail by id: buyer, CPVs, deadline, estimated value, all awards/lots with winners, plus provenance (source + TED url).
| Name | Type | Req | Description |
|---|---|---|---|
| client_key | string | – | Prepaid credit balance key: when set, paid calls first try to debit this account instead of requiring a per-call proof. |
| id | integer | yes | numeric id from search results |
| payment_token | string | – | Payment proof: dev mode → single-use token from POST /v1/dev-faucet; x402 mode → base64 payment payload (the PAYMENT-SIGNATURE / X-PAYMENT header value) |
No output schema declared.
No examples provided.
research ~218
[POST /v1/research — $0.50] High-level EU public procurement intelligence for a topic: recent tenders, relevant renewal signals, company opportunities and active buyers, each with evidence and an evidence-strength confidence label. Deterministic over the licita database (no LLM). Costs $0.50 USDC per call (x402). Use when an agent needs a research brief on a topic rather than raw rows from search_tenders/get_renewals.
| Name | Type | Req | Description |
|---|---|---|---|
| client_key | string | – | Prepaid credit balance key: when set, paid calls first try to debit this account instead of requiring a per-call proof. |
| limit | integer | – | max findings to return |
| payment_token | string | – | Payment proof: dev mode → single-use token from POST /v1/dev-faucet; x402 mode → base64 payment payload (the PAYMENT-SIGNATURE / X-PAYMENT header value) |
| query | string | yes | topic to research (matches tender full-text, company/buyer names, renewal signals) |
No output schema declared.
No examples provided.
search_tenders ~268
[GET /v1/search — $0.02] Search Spanish public-sector IT/software/cyber procurement: awards, tenders and contracts. Filters: q (full-text), cpv (prefix), buyer, company, region (NUTS), from/to (YYYY-MM-DD), type=award|tender|contract. Returns compact rows with ids for the other tools.
| Name | Type | Req | Description |
|---|---|---|---|
| buyer | string | – | – |
| client_key | string | – | Prepaid credit balance key: when set, paid calls first try to debit this account instead of requiring a per-call proof. |
| company | string | – | – |
| cpv | string | – | CPV code or prefix, e.g. "72" |
| from | string | – | YYYY-MM-DD |
| page | integer | – | – |
| payment_token | string | – | Payment proof: dev mode → single-use token from POST /v1/dev-faucet; x402 mode → base64 payment payload (the PAYMENT-SIGNATURE / X-PAYMENT header value) |
| q | string | – | – |
| region | string | – | NUTS code or prefix, e.g. "ES61" |
| size | integer | – | – |
| to | string | – | YYYY-MM-DD |
| type | string | – | – |
No output schema declared.
No examples provided.