Build on TenderLock
Connect your finance, ERP and workflow systems with the REST API, plug your own AI agent straight into your procurement with MCP, and get notified in real time with webhooks.
REST APIRead tenders, suppliers, contacts, companies, email conversations, call logs, credit checks, Blue and Red Team findings, team, entities, the audit log, billing and reports. Create draft tenders and contacts, log calls, send emails, run credit checks and invite team members from your own systems.MCP for AI agentsGive ChatGPT, Claude, Copilot or your own agent safe, governed access to TenderLock.WebhooksGet a signed HTTPS call when a tender is published, a bid arrives or an award is approved.
Quick start
- Sign in and go to Settings → API & MCP.
- Create a key. Choose Read only or Read + write, and an expiry.
- Call the API with the key as a Bearer token:
curl https://www.tender-lock.co/api/v1/me \
-H "Authorization: Bearer tl_live_YOUR_KEY"
Built-in governance
The same rules that protect your tenders in the app apply to every integration and agent:
- Nothing is published, awarded or deleted through the API or MCP. Integrations create drafts; a named person reviews and publishes them in TenderLock.
- Sealed means sealed. Bids cannot be read by anyone, including the API, until the closing date.
- Emails are real.
send_emailsends straight away, as the person who created the key, from their connected mailbox if they have one. Use a read-only key if you don't want an agent to email anyone. - Roles still apply. Keys act with the permissions of the person who created them, for example who can see everyone's contacts or read the audit log.
- Everything is logged. Each request is recorded against its key, and changes appear in the tender's audit trail.
Availability
| Plan | Access |
|---|---|
| Business | Read-only API and MCP |
| Professional | Full API and MCP (create drafts, add suppliers and contacts, log calls, send emails) and webhooks |
| Enterprise | Full access, plus higher limits by agreement |
