Back to Browse

Vergabe Api MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

German public tenders as normalised JSON (CPV, NUTS, deadlines). Free sample; search paid via x402.

About

German public tenders as normalised JSON (CPV, NUTS, deadlines). Free sample; search paid via x402.

Remote endpoints: streamable-http: https://vergabe-api.applehorsefrog.workers.dev/mcp

Security Report

4.2
Use Caution4.2High Risk

This is a well-structured procurement data API with proper authentication via x402 (USDC payments on Base) and appropriate permission scoping. The codebase demonstrates good security practices with input validation, no hardcoded credentials, and clean separation of free vs. paid endpoints. Minor code quality issues around error handling and a truncated ETL file prevent a higher score, but the core architecture is sound. Supply chain analysis found 7 known vulnerabilities in dependencies (0 critical, 2 high severity).

5 files analyzed · 12 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

database

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

vergabe-api

German public procurement notices, above and below the EU thresholds, as a normalised JSON API for software agents and procurement tools. Paid per call with x402 (HTTP 402, USDC). No account, no API key, no subscription.

Base URL: https://vergabe-api.applehorsefrog.workers.dev (a branded domain under viono-insights.de will follow). Payments settle on Base mainnet in USDC since 2026-09-14; the facilitator is PayAI.

What you get

Every day roughly 1,000 notices are published on the official German notification service (Datenservice Öffentlicher Einkauf, eForms-DE). The raw feed is a ZIP of XML files, 20 MB per day, with organisation contacts, lots, deadlines and classifications scattered over UBL extensions. This API turns each notice into one flat record:

fieldmeaning
id, notice_id, versionnotice UUID and version
published, issue_datepublication day of the export, issue date from the notice
kindcompetition (calls for tenders), result (awards), planning, change
notice_type, subtype, procedure, legal_basis, natureeForms codes (cn-standard, open, vgv, works ...)
title, descriptionGerman text, personal contact data removed
cpv_main, cpv_additionalCPV codes without check digit
buyer_name, buyer_type, buyer_city, buyer_postal, buyer_nuts, buyer_websitecontracting authority (organisation level only)
place_nuts, place_cityplace of performance
estimated_value, currencyif stated
deadline_date, deadline_time, deadline_kindearliest lot deadline; tender or participation
documents_url, submission_urlwhere the tender documents live
lotsarray of lots with title, CPV, NUTS, value, deadline, period
winners, total_awardedfor award notices, organisation names only
source_urlthe original notice at oeffentlichevergabe.de

Coverage on a sample day (2026-09-10): 1,067 notices, 589 calls for tenders, 569 of them with a submission deadline, 1,036 with CPV, 985 with NUTS.

Endpoints

endpointpricenotes
GET /freeservice descriptor
GET /openapi.jsonfreeOpenAPI 3.1
GET /v1/statsfreenotices per day, last 30 days
GET /v1/sample?cpv=72free5 latest calls for tenders, compact fields
GET /v1/notices$0.01filtered list, up to 100 records
GET /v1/notice/{id}$0.002one full record
POST /mcpfreeremote MCP server (Streamable HTTP), free tools
GET /.well-known/x402freex402 discovery manifest

Filters for /v1/notices

kind (default competition; result, planning, change, all), cpv (codes or prefixes, comma separated: 45,7131), nuts (prefixes: DE2,DE1), q (substring in title, description, buyer), since / until (publication day), deadline_after / deadline_before, nature, procedure, legal_basis, buyer_type, min_value, limit (max 100), offset (max 5000), fields=full (all columns incl. lots), sort=deadline.

GET /v1/notices?cpv=45,71&nuts=DE2&deadline_after=2026-09-20&limit=20
GET /v1/notices?q=Photovoltaik&since=2026-09-01&fields=full
GET /v1/notices?kind=result&cpv=72&since=2026-09-01

Paying with x402

A request without payment returns 402 with a PAYMENT-REQUIRED header describing the amount (USDC), network and receiving address. Any x402 client handles this automatically, for example @x402/fetch:

import { wrapFetchWithPaymentFromConfig } from "@x402/fetch";
import { ExactEvmScheme } from "@x402/evm";
import { privateKeyToAccount } from "viem/accounts";

const account = privateKeyToAccount(process.env.PRIVATE_KEY as `0x${string}`); // holds USDC on Base
const fetchWithPay = wrapFetchWithPaymentFromConfig(fetch, {
  schemes: [{ network: "eip155:8453", client: new ExactEvmScheme(account) }],
});
const r = await fetchWithPay("https://vergabe-api.applehorsefrog.workers.dev/v1/notices?cpv=72");
console.log(await r.json());

Prices are in USD and settled in USDC on Base (eip155:8453); there are no other fees on our side. The same code runs against Base Sepolia by setting X402_NETWORK=eip155:84532 and X402_FACILITATOR=https://x402.org/facilitator in wrangler.jsonc.

MCP server

Two ways to use the data from an MCP client (Claude Desktop, Claude Code, Cursor, any MCP host):

Remote, free tools only (no install): Streamable HTTP endpoint https://vergabe-api.applehorsefrog.workers.dev/mcp with sample_tenders, tender_stats, describe_api. The paid tools are listed there too but only return the payment requirements, because the remote server has no wallet.

Local, with paid tools (stdio, Node 20+): the client pays per call from a wallet you control.

{
  "mcpServers": {
    "vergabe": {
      "command": "npx",
      "args": ["-y", "github:applehorsefrog/vergabe-api"],
      "env": { "VERGABE_PAYER_KEY": "0x<private key of a wallet holding USDC on Base>" }
    }
  }
}

Tools: search_tenders ($0.01 per call, all filters of /v1/notices), get_tender ($0.002), sample_tenders, tender_stats, describe_api (free). Without VERGABE_PAYER_KEY the paid tools return the x402 payment requirements and the HTTP URL instead of data. Use a dedicated low-balance wallet for the key; the server never sends it anywhere, it only signs USDC transfer authorisations (EIP-3009) for the exact price of each call. Source: mcp/server.mjs.

Data source, licence, privacy

Data: Datenservice Öffentlicher Einkauf, https://oeffentlichevergabe.de, published under CC0 1.0. Every response carries X-Data-Source and X-Data-License headers. Code in this repository: MIT.

Contact persons, e-mail addresses, phone and fax numbers are removed during import (etl/etl.py), both from structured fields and from free text. Only organisation-level data is served. If you find personal data that slipped through, open an issue and it will be removed.

This is a technical data service, not legal advice. Deadlines and conditions must be verified at the source before bidding.

How it runs

  • src/index.ts: Cloudflare Worker (Hono) with @x402/hono payment middleware, a D1 (SQLite) database and the remote MCP endpoint.
  • mcp/server.mjs: local MCP server (stdio) that pays for the paid endpoints with @x402/fetch.
  • etl/etl.py: downloads the daily eForms ZIP, parses it with lxml, scrubs personal data, writes INSERT statements.
  • .github/workflows/daily-etl.yml: runs the ETL twice a day (06:30 and 14:00 UTC), re-imports the last three days and loads the rows with wrangler d1 execute.

Local development:

npm install
npx wrangler d1 execute vergabe --local --file=schema.sql
python etl/etl.py --day 2026-09-10 --out etl/out/d.sql && for f in etl/out/d*.sql; do npx wrangler d1 execute vergabe --local --file=$f; done
npx wrangler dev

Provider, legal notice, privacy

Operated by Dr. Josua Decker, Viono Insights (https://viono-insights.de). Legal notice (Impressum, § 5 DDG): https://viono-insights.de/impressum.html, also served at GET /impressum. Privacy notice for this API (Art. 13 GDPR): GET /datenschutz. Contact: kontakt@viono-insights.de. The GitHub account that publishes this repository is an automated account operated with Claude on behalf of the provider.

Disclosure

This service was built with substantial AI assistance (Claude); the provider reviews and is responsible for it. Issues and pull requests are welcome; automated contributions are labelled as such.

Reviews

No reviews yet

Be the first to review this server!