MCP for AI agents
TenderLock runs a remote Model Context Protocol server, so you can connect the AI agent your team already uses and let it work with your tenders, within TenderLock's rules.
| Setting | Value |
|---|---|
| Server URL | https://www.tender-lock.co/api/mcp |
| Transport | Streamable HTTP |
| Authentication | Header Authorization: Bearer tl_live_YOUR_KEY |
Use a read-only key if the agent only needs to look things up. A read + write key lets it create draft tenders, add suppliers and contacts, log calls and messages, and send emails to contacts. Tenders are always left as drafts for a person to review and publish.
Connect your agent
Claude (Desktop or Code)
{
"mcpServers": {
"tenderlock": {
"type": "http",
"url": "https://www.tender-lock.co/api/mcp",
"headers": { "Authorization": "Bearer tl_live_YOUR_KEY" }
}
}
}
ChatGPT, Copilot Studio and other agents
Add a custom MCP server / connector, paste the server URL above and set the Authorization header to your key. Any MCP client that supports remote Streamable HTTP servers works.
Your own agent (OpenAI Agents SDK, Python)
from agents.mcp import MCPServerStreamableHttp
tenderlock = MCPServerStreamableHttp(params={
"url": "https://www.tender-lock.co/api/mcp",
"headers": {"Authorization": "Bearer tl_live_YOUR_KEY"},
})
Tools
| Tool | What it does | Access |
|---|---|---|
list_tenders | List your organisation's tenders, newest first. Optional status filter: draft, pending_approval, live, closed, awarded, no_award, cancelled. | Read |
get_tender | Full detail of one tender: scope, dates, requirements, evaluation criteria and invited suppliers. | Read |
list_suppliers | Search your supplier address book by company, email or category. | Read |
list_clarifications | Clarification questions and answers for a tender. | Read |
list_submissions | Submitted bids for a tender, with prices and weighted scores. Only available after the closing date; bids stay sealed until then. | Read |
get_audit_trail | The append-only audit trail for a tender. | Read |
get_credit_balance | Your organisation's plan and current credit balance. | Read |
create_draft_tender | Create a DRAFT tender (never published). A person must review, run checks and publish it in TenderLock. closes_at is ISO 8601 in your organisation's time zone, e.g. 2026-11-30T12:00. | Read + write |
add_supplier | Add a supplier to your address book. | Read + write |
add_supplier_to_tender | Add a supplier to a DRAFT tender. Nothing is sent: invitations go out only when a person publishes the tender. | Read + write |
list_entities | The companies (entities) in your group, with tender and people counts. | Read |
list_team_members | Your team: roles, super admin and owner flags, entities, 2FA, invite status and last sign-in. Key must be created by an owner, super admin or team admin. Optional status: active, invited, disabled. | Read |
get_team_member | Full audit of one team member: details, roles, entities, 2FA devices, signed-in devices, failed sign-ins, tender stats and recent activity. | Read |
get_supplier | One supplier from your address book with Companies House rating, latest Creditsafe credit check (score, band, limit, turnover, profit, CCJs) and the tenders they were invited to. | Read |
get_blue_team | Blue Team items for a tender: gaps found, suggested fixes and whether each was applied or dismissed. | Read |
get_red_team | The latest Red Team stress test for a tender: readiness, summary and every finding with severity, explanation and status. | Read |
get_review_status | Who is on the Blue and Red review teams for a tender and the sign-offs recorded. | Read |
list_templates | Your saved tender templates. | Read |
get_report_summary | Headline reporting numbers: tenders by status, created, published, awarded value, submissions and credits used. Optional days (default 90). | Read |
run_credit_check | Run a Creditsafe credit check on a supplier (Business plan and above). Uses credits; you are not charged if the check fails. | Read + write |
invite_team_member | Invite someone to your team with one or more roles (role keys or names, e.g. "Evaluator"). Emails the invitation and returns the invite link. Key must be created by an owner, super admin or team admin. Super admin can only be given in TenderLock. | Read + write |
list_contacts | Search your shared contact book (people at suppliers and buyers). Respects the key creator's role: without "see everyone's contacts" only their own contacts are returned. Optional q (name, email, job title), company_id, owner_id, limit. | Read |
get_contact | One contact with phones, all email addresses, owner, creator, linked companies, recent emails and call/SMS/WhatsApp logs. | Read |
list_companies | Search your companies. Each company can be a Supplier, a Buyer or both. Optional type: supplier, buyer or both; q; limit. | Read |
list_email_threads | Email conversations sent or received through TenderLock, newest first, with unread counts and tracking. Optional contact_id, company_id, tender_id, unread_only. | Read |
get_email_thread | Every message in one email conversation, with delivery, open and click events. | Read |
list_comm_logs | Logged calls, SMS and WhatsApp messages for a contact or company: date, time, who, direction, outcome and note. | Read |
get_org_audit_log | Organisation-wide audit log: who did what, when, from which IP and location. Key must be created by an owner or team admin. Optional type (login or action), user_id, since (ISO date), limit. | Read |
get_billing_status | Your plan, billing interval, status, current period, next bill date and amount, cancellation and account credit. | Read |
add_contact | Add a person to your contact book, optionally linked to a company. The key creator becomes the owner. | Read + write |
set_company_type | Mark a company as a Supplier, a Buyer or both. | Read + write |
log_communication | Log a call, SMS or WhatsApp against a contact or company. Date, time and author are recorded automatically. outcome is for calls: connected, no_answer, voicemail, busy, wrong_number. | Read + write |
send_email | Send an email to a contact from TenderLock, as the key creator. Goes from their connected mailbox if they have one, otherwise from TenderLock. body is plain text or simple HTML. Pass thread_id to reply in an existing conversation. Optional company_id and tender_id to link it. | Read + write |
What agents cannot do
- Publish, amend, cancel or award a tender
- Send anything to suppliers
- Delete anything
- See sealed bids before the closing date
Those always need a named person in TenderLock, so every consequential decision stays accountable.
