Diavgis — Greek Public Procurement
REMOTE · MCP.DIAVGIS.GR · SCANNED SEP 21
Greek public procurement: tenders, awards, contracts, payments, suppliers, expiring contracts.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security83
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability76
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2894 tokens (~289/item across 10 items; 10 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage98
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 94% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 10 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 11 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the Diavgis — Greek Public Procurement MCP server?
Diavgis — Greek Public Procurement is a hosted endpoint at https://mcp.diavgis.gr/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.diavgis.gr
claude mcp add --transport http gr-diavgis-procurement 'https://mcp.diavgis.gr/mcp'
{
"mcpServers": {
"gr-diavgis-procurement": {
"url": "https://mcp.diavgis.gr/mcp"
}
}
} {
"servers": {
"gr-diavgis-procurement": {
"type": "http",
"url": "https://mcp.diavgis.gr/mcp"
}
}
} [mcp_servers.gr-diavgis-procurement] url = "https://mcp.diavgis.gr/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"gr-diavgis-procurement": {
"type": "remote",
"url": "https://mcp.diavgis.gr/mcp",
"enabled": true
}
}
} openclaw mcp add gr-diavgis-procurement --url 'https://mcp.diavgis.gr/mcp' --transport streamable-http
mcp_servers:
gr-diavgis-procurement:
url: "https://mcp.diavgis.gr/mcp" {
"McpServers": {
"gr-diavgis-procurement": {
"Transport": "http",
"Url": "https://mcp.diavgis.gr/mcp"
}
}
} assistant mcp add gr-diavgis-procurement -t streamable-http -u 'https://mcp.diavgis.gr/mcp'
{
"mcpServers": {
"gr-diavgis-procurement": {
"type": "http",
"url": "https://mcp.diavgis.gr/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 2 Sept 26 0
- Tool “get_act” rewrote its description, which is the text the model reads security
- Tool “get_chain” rewrote its description, which is the text the model reads security
- 1 Sept 26 +1
- Stability: 0.97 → pass security
- 29 Aug 26 +1
- The server rewrote its instructions, which are the text every model session reads security
- Schema quality: 303 → 272 ▲ functional
- Tool coverage: 88% → 100% ▲ functional
- Tool “expiring_contracts” now declares an output schema ▲ functional
- Server version: 1.2.0 → 1.3.0 functional
- New tool “find_entity” functional
- New tool “get_quota” functional
- 28 Aug 26 +8
- Judged manipulation: unverified → pass ▲ security
- Tool “search_tenders” rewrote its description, which is the text the model reads security
- Schema quality: unverified → excellent ▲ functional
- “search_tenders” added an optional parameter “deadline_after” cosmetic
- “search_tenders” added an optional parameter “region” cosmetic
- 27 Aug 26 −7
- Judged manipulation: pass → unverified ▼ security
- The server rewrote its instructions, which are the text every model session reads security
- Schema quality: 249 → 288 ▼ functional
- Schema quality: excellent → unverified ▼ functional
- 26 Aug 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Aug 26 +1
- Server version: 1.0.2 → 1.2.0 functional
- 12 Aug 26 0
- Tool coverage: 100% → 88% ▼ functional
- Schema quality: 1506 → 1835 ▼ functional
- New tool “expiring_contracts” functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 21 Sept 2026 · Probed https://mcp.diavgis.gr/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=diavgis.gr | CN=WE1,O=Google Trust Services,C=US | 11 Aug 2026 | 9 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | d3e041bb9096d4280e10f5f1dc1aab5c |
| SANs: diavgis.gr, mcp.diavgis.gr, *.mcp.diavgis.gr | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of mcp.diavgis.gr. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| gr. | present | 13987 | 8 | Verified |
| diavgis.gr. | present | 2371 | 13 | Verified |
| mcp.diavgis.gr. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=15552000; includeSubDomains; preload |
| x-content-type-options | nosniff |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.diavgis.gr/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.diavgis.gr/mcp | HTTPS enforced | 301 | https://mcp.diavgis.gr/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
entity_counterparties Entity Counterparties ~89
Top counterparties of an entity (ΑΦΜ): for a buyer, the suppliers it pays most; for a supplier, its top public buyers — with act counts and EUR totals. The 'who does business with whom' due-diligence view.
| Name | Type | Req | Description |
|---|---|---|---|
| afm | string | yes | 9-digit ΑΦΜ |
| limit | number | – | max 30, default 10 |
| Name | Type | Req | Description |
|---|---|---|---|
| afm | string | yes | – |
| counterparties | array | yes | – |
No examples provided.
expiring_contracts Greek Public Contracts About to Expire ~329
Greek public contracts that are RUNNING NOW and expire within a horizon of 0, 7, 30 or 180 days — the renewal pipeline. Each row carries who currently holds the contract and HOW it was awarded (direct award vs competitive tender, and the number of bids where the source reports it), which is what tells you whether the re-tender is worth chasing. One procurement is counted ONCE: Greek sources publish the duration on the award record as well as the contract, so award records are dropped when a contract in the same lifecycle chain already defines the expiry. ⚠ `expiry_basis` on every row states how the date was obtained — `published` (the buyer published an end date), `computed_from_start` (start date + declared duration) or `computed_from_publication` (no start date published, so the publication date was substituted; systematically early). Do not present a computed date as a published one. ACCESS: horizon 0 (expiring today) is free on every plan and returns the complete record. Horizons 7/30/180 require a paid plan — lead time is the paid product.
| Name | Type | Req | Description |
|---|---|---|---|
| cpv | string | – | CPV division, 2 digits (e.g. 33 for medical equipment) |
| h | number | – | horizon in days; 0 = expiring today (free on every plan). Default 180. |
| page_size | number | – | rows to return, 1-200 (default 50) |
| region | string | – | NUTS code, e.g. EL30 for Attica |
| Name | Type | Req | Description |
|---|---|---|---|
| data | array | yes | – |
| horizon_days | number | – | – |
| next | number|null | yes | next page NUMBER, or null at the end |
| page | number | yes | – |
| page_size | number | yes | – |
| total | number | yes | – |
No examples provided.
find_entity Find Entity by Name ~158
Resolve a Greek buyer or supplier NAME to its ΑΦΜ. Use this first whenever you have a name but no ΑΦΜ — get_entity, entity_counterparties and the buyer_afm/supplier_afm filters all need the 9-digit number. Matching is accent- and case-insensitive; returns the closest names with their ΑΦΜ, so pick the right one before calling anything else.
| Name | Type | Req | Description |
|---|---|---|---|
| kind | string | – | Restrict to public bodies (buyer) or companies (supplier). Omit for all. |
| limit | number | – | 1-20, default 8 |
| name | string | yes | Full or partial name, e.g. "Δήμος Αθηναίων". Accents and case are ignored. |
| Name | Type | Req | Description |
|---|---|---|---|
| matches | array | yes | – |
| query | string | yes | – |
No examples provided.
get_act Get One Act ~190
Full detail of one act by its id (Διαύγεια ΑΔΑ, ΚΗΜΔΗΣ 'kimdis:<ΑΔΑΜ>', or TED 'ted:<number>'): canonical fields, resolved buyer/supplier entities, CPV codes with labels, and its cross-source lifecycle chain if linked. On ΚΗΜΔΗΣ contracts, `commitment_ada` carries the Διαύγεια ΑΔΑ of the budget-commitment decision the source declares (comma-separated when more than one). It is a pointer INTO Διαύγεια, not an act we necessarily hold — resolve it at diavgeia.gov.gr, not through this API — and it is deliberately NOT a chain edge: one annual commitment funds many unrelated contracts.
| Name | Type | Req | Description |
|---|---|---|---|
| ada | string | yes | act id — ΑΔΑ, 'kimdis:<ΑΔΑΜ>' or 'ted:<number>' |
| Name | Type | Req | Description |
|---|---|---|---|
| act | object | yes | – |
| buyer | object|null | yes | – |
| chain | object|null | yes | – |
| cpvs | array | yes | CPV classifications with their official Greek labels |
| supplier | object|null | yes | – |
No examples provided.
get_chain Get Procurement Lifecycle Chain ~143
A reconstructed procurement lifecycle chain by chain_id: the linked sequence of related acts (e.g. commitment → award → contract → payments) with confidence and link method. Get a chain_id from the chain_id field of any act. A chain is ONE procurement's lifecycle, not everything an act references: an administrative umbrella cited by more than 25 acts (e.g. one annual expense-approval decision referenced by thousands of a buyer's acts) is deliberately NOT merged, so a chain never swallows a year of unrelated activity. Those references are still published — see the act's own references — they simply do not form a chain.
| Name | Type | Req | Description |
|---|---|---|---|
| chain_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| chain_id | string | yes | – |
| members | array | yes | – |
No examples provided.
get_entity Get Entity Profile ~117
Profile of a legal entity (company or public body) by 9-digit ΑΦΜ: name, role, and spend/receipt statistics as buyer and as supplier. EUR totals = the COMMITTED procurement value counted ONCE per procurement (deduplicated across ΚΗΜΔΗΣ/Διαύγεια sources and the award→contract→payment lifecycle; tenders/budgets excluded), so it reflects real committed spend, not a sum of every published act.
| Name | Type | Req | Description |
|---|---|---|---|
| afm | string | yes | 9-digit ΑΦΜ |
| Name | Type | Req | Description |
|---|---|---|---|
| afm | string | yes | – |
| first_seen | string|null | – | – |
| kind | string | – | buyer | supplier |
| last_seen | string|null | – | – |
| name | string | yes | – |
| stats | object|null | yes | – |
No examples provided.
get_quota Plan, Usage and Remaining Calls ~78
What this API key is allowed to do right now: plan, calls used this period, calls remaining, per-minute rate, page-size and pagination caps, and when the period resets. Free — this call is not counted against the quota. Check it before starting a long job so you can size the work instead of hitting a wall mid-task.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number|null | – | monthly quota, null if unlimited |
| max_page_size | number | yes | – |
| max_pages | number | yes | pagination depth cap; deeper pages return an error, narrow with filters instead |
| period_reset | string | yes | ISO date when used resets to 0 |
| plan | string | yes | – |
| pricing_url | string | – | – |
| rate_per_min | number | yes | – |
| remaining | number|null | – | – |
| used | number | yes | calls consumed this period (REST + MCP share one counter) |
No examples provided.
rank_entities Rank Buyers or Suppliers ~175
Rank top Greek public-procurement entities. role=buyer (default) or supplier; by=spend (default — COMMITTED procurement value in EUR, counted ONCE per procurement: deduplicated across sources and lifecycle stages, tenders excluded), single_bidder (count of ≤1-bid awards/contracts) or direct_award (count of απευθείας ανάθεση). Answers 'top 10 suppliers by public revenue', 'which buyers award most without competition'. Returns afm, name, metric, total. Precomputed and refreshed every 6 hours, so it is instant and always the top 15.
| Name | Type | Req | Description |
|---|---|---|---|
| by | string | – | default spend |
| limit | number | – | max 15, default 15 — the published ranking holds the top 15 |
| role | string | – | default buyer |
| Name | Type | Req | Description |
|---|---|---|---|
| by | string | yes | – |
| results | array | yes | – |
| role | string | yes | – |
No examples provided.
search_tenders Search Greek Procurement Acts ~624
Search Greek public-procurement acts across THREE cross-linked sources — Διαύγεια, ΚΗΜΔΗΣ (Central Electronic Public Procurement Registry) and EU TED. Filter by source (diavgeia|kimdis|ted), lifecycle status (request|tender|award|contract|payment), buyer or supplier ΑΦΜ (9-digit tax id), CPV code, EUR budget range, NUTS region, submission deadline (deadline_after=TODAY + status=tender ⇒ the OPEN tenders a supplier can still bid on), free-text q over the act title, and procurement signals (published facts from ΚΗΜΔΗΣ): direct_award (απευθείας ανάθεση), single_bidder (≤1 bid on the contract), cancelled. Returns a paginated envelope; 'next' is the next PAGE NUMBER or null. Natural-person counterparties are redacted. Do NOT sum amount_net across results to get spend — use rank_entities or spend_by_cpv, which count each procurement once.
| Name | Type | Req | Description |
|---|---|---|---|
| budget_max | number | – | maximum amount_net in EUR |
| budget_min | number | – | minimum amount_net in EUR |
| buyer_afm | string | – | 9-digit buyer ΑΦΜ |
| cancelled | boolean | – | only acts the source marked as cancelled |
| cpv | string | – | CPV code (e.g. 79710000) |
| deadline_after | string | – | ISO date (YYYY-MM-DD). Only acts whose submission deadline is on/after this date. Pass TODAY to get OPEN tenders — the ones a supplier can still bid on. Combine with status="tender". |
| direct_award | boolean | – | only direct awards (procedure = απευθείας ανάθεση) — a published ΚΗΜΔΗΣ fact |
| has_chain | boolean | – | only acts linked into a reconstructed lifecycle chain (request→tender→award→contract→payment) |
| page | number | – | 1-based page number; pagination DEPTH is capped per plan |
| page_size | number | – | max 200 |
| price_only | boolean | – | only awards/contracts decided on lowest-price alone (award_criteria = Βάσει τιμής / Χαμηλότερη Τιμή), excluding most-economically-advantageous (MEAT) criteria |
| q | string | – | free-text search over the act title |
| region | string | – | NUTS region code prefix, e.g. EL30 (Attica), EL52 (Central Macedonia). Matches by prefix, so EL3 covers all of Attica. |
| single_bidder | boolean | – | only contracts where ≤1 bid was submitted (maxBidsSubmitted; single bidder) |
| source | string | – | filter by data source |
| status | string | – | – |
| supplier_afm | string | – | 9-digit supplier ΑΦΜ |
| year | string | – | 4-digit issue year, e.g. 2026 — restricts to acts issued that year |
| Name | Type | Req | Description |
|---|---|---|---|
| data | array | yes | – |
| next | number|null | yes | next page NUMBER, or null when there are no more pages — not a URL |
| page | number | yes | – |
| page_size | number | yes | – |
| total | number | yes | total acts matching the filters |
No examples provided.
spend_by_cpv Spend by CPV Category ~124
Committed public procurement value by CPV category (2-digit division), optionally for one year. Value = counted ONCE per procurement (deduplicated across sources and award/contract/payment stages; tenders excluded). Answers 'what does the Greek state spend the most on'. Returns cpv_division, acts, spend (EUR) for the top divisions by spend — precomputed nightly, so it is instant. Use search_tenders with cpv= for divisions outside the top list.
| Name | Type | Req | Description |
|---|---|---|---|
| year | string | – | 4-digit year; omit for all-time |
| Name | Type | Req | Description |
|---|---|---|---|
| divisions | array | yes | – |
| year | string | yes | the year filtered on, or 'all' |
No examples provided.
What is the Diavgis — Greek Public Procurement MCP server?
Diavgis — Greek Public Procurement is an MCP server listed in the public MCP registry as gr.diavgis/procurement. Greek public procurement: tenders, awards, contracts, payments, suppliers, expiring contracts. This page covers its hosted endpoint (https://mcp.diavgis.gr/mcp).
Is the Diavgis — Greek Public Procurement MCP server safe to use?
Diavgis — Greek Public Procurement scores 89 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Diavgis — Greek Public Procurement MCP server expose?
Diavgis — Greek Public Procurement exposes 10 tools: search_tenders, expiring_contracts, get_act, get_entity, get_chain, and 5 more. Their descriptions and schemas cost roughly 2,027 tokens of context every time the server is loaded.
Does the Diavgis — Greek Public Procurement MCP server require authentication?
No. We connected to Diavgis — Greek Public Procurement without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Diavgis — Greek Public Procurement MCP server still maintained?
Diavgis — Greek Public Procurement is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.