MCP for AI agents

TenderLock runs a remote Model Context Protocol server, so you can connect the AI agent your team already uses and let it work with your tenders, within TenderLock's rules.

SettingValue
Server URLhttps://tenderlock.co/api/mcp
TransportStreamable HTTP
AuthenticationHeader Authorization: Bearer tl_live_YOUR_KEY
Use a read-only key if the agent only needs to look things up. A read + write key lets it create draft tenders, add suppliers and contacts, log calls and messages, and send emails to contacts. Tenders are always left as drafts for a person to review and publish.

Connect your agent

Claude (Desktop or Code)

{
  "mcpServers": {
    "tenderlock": {
      "type": "http",
      "url": "https://tenderlock.co/api/mcp",
      "headers": { "Authorization": "Bearer tl_live_YOUR_KEY" }
    }
  }
}

ChatGPT, Copilot Studio and other agents

Add a custom MCP server / connector, paste the server URL above and set the Authorization header to your key. Any MCP client that supports remote Streamable HTTP servers works.

Your own agent (OpenAI Agents SDK, Python)

from agents.mcp import MCPServerStreamableHttp
tenderlock = MCPServerStreamableHttp(params={
    "url": "https://tenderlock.co/api/mcp",
    "headers": {"Authorization": "Bearer tl_live_YOUR_KEY"},
})

Tools

ToolWhat it doesAccess
list_tendersList your organisation's tenders, newest first. Optional status filter: draft, pending_approval, live, closed, awarded, no_award, cancelled.Read
get_tenderFull detail of one tender: scope, dates, requirements, evaluation criteria and invited suppliers.Read
list_suppliersSearch your supplier address book by company, email or category.Read
list_clarificationsClarification questions and answers for a tender.Read
list_submissionsSubmitted bids for a tender, with prices and weighted scores. Only available after the closing date; bids stay sealed until then.Read
get_audit_trailThe append-only audit trail for a tender.Read
get_credit_balanceYour organisation's plan and current credit balance.Read
create_draft_tenderCreate a DRAFT tender (never published). A person must review, run checks and publish it in TenderLock. closes_at is ISO 8601 in your organisation's time zone, e.g. 2026-11-30T12:00.Read + write
add_supplierAdd a supplier to your address book.Read + write
add_supplier_to_tenderAdd a supplier to a DRAFT tender. Nothing is sent: invitations go out only when a person publishes the tender.Read + write
list_entitiesThe companies (entities) in your group, with tender and people counts.Read
list_team_membersYour team: roles, super admin and owner flags, entities, 2FA, invite status and last sign-in. Key must be created by an owner, super admin or team admin. Optional status: active, invited, disabled.Read
get_team_memberFull audit of one team member: details, roles, entities, 2FA devices, signed-in devices, failed sign-ins, tender stats and recent activity.Read
get_supplierOne supplier from your address book with Companies House rating, latest Creditsafe credit check (score, band, limit, turnover, profit, CCJs) and the tenders they were invited to.Read
get_blue_teamBlue Team items for a tender: gaps found, suggested fixes and whether each was applied or dismissed.Read
get_red_teamThe latest Red Team stress test for a tender: readiness, summary and every finding with severity, explanation and status.Read
get_review_statusWho is on the Blue and Red review teams for a tender and the sign-offs recorded.Read
list_templatesYour saved tender templates.Read
get_report_summaryHeadline reporting numbers: tenders by status, created, published, awarded value, submissions and credits used. Optional days (default 90).Read
run_credit_checkRun a Creditsafe credit check on a supplier (Business plan and above). Uses credits; you are not charged if the check fails.Read + write
invite_team_memberInvite someone to your team with one or more roles (role keys or names, e.g. "Evaluator"). Emails the invitation and returns the invite link. Key must be created by an owner, super admin or team admin. Super admin can only be given in TenderLock.Read + write
list_contactsSearch your shared contact book (people at suppliers and buyers). Respects the key creator's role: without "see everyone's contacts" only their own contacts are returned. Optional q (name, email, job title), company_id, owner_id, limit.Read
get_contactOne contact with phones, all email addresses, owner, creator, linked companies, recent emails and call/SMS/WhatsApp logs.Read
list_companiesSearch your companies. Each company can be a Supplier, a Buyer or both. Optional type: supplier, buyer or both; q; limit.Read
list_email_threadsEmail conversations sent or received through TenderLock, newest first, with unread counts and tracking. Optional contact_id, company_id, tender_id, unread_only.Read
get_email_threadEvery message in one email conversation, with delivery, open and click events.Read
get_phone_usagePhone numbers on the account, call minutes used and available this month, and whether minutes top up automatically.Read
list_comm_logsLogged calls, SMS and WhatsApp messages for a contact, company or tender: date, time, who, direction, outcome, note, duration, linked tender and AI call summary. Use get_call for the full transcript.Read
get_org_audit_logOrganisation-wide audit log: who did what, when, from which IP and location. Key must be created by an owner or team admin. Optional type (login or action), user_id, since (ISO date), limit.Read
get_billing_statusYour plan, billing interval, status, current period, next bill date and amount, cancellation and account credit.Read
add_contactAdd a person to your contact book, optionally linked to a company. The key creator becomes the owner.Read + write
set_company_typeMark a company as a Supplier, a Buyer or both.Read + write
log_communicationLog a call, SMS or WhatsApp against a contact or company. Date, time and author are recorded automatically. outcome is for calls: connected, no_answer, voicemail, busy, wrong_number.Read + write
send_emailSend an email to a contact from TenderLock, as the key creator. Goes from their connected mailbox if they have one, otherwise from TenderLock. body is plain text or simple HTML. Pass thread_id to reply in an existing conversation. Optional company_id and tender_id to link it.Read + write
list_tasksThe key creator's tasks: follow-ups the AI pulled from their calls and tasks created by the team. Optional status (open, done or all; default open), tender_id, contact_id, company_id, limit.Read
get_taskOne task with its linked contact, company, tender, source call and every note.Read
get_callOne logged call or message with duration, transcript, AI summary, linked tender and the follow-up tasks created from it.Read
list_phone_numbersPhone numbers on your account: number, type (mobile or landline), who it is assigned to, team line flag and capabilities.Read
create_taskCreate a task linked to a contact or company. Optional assignee_id (a team member, default the key creator), due_on (YYYY-MM-DD) and tender_id. It is noted on the contact or company, and on the tender's audit trail if a tender is given. supplier contacts and companies by default; set scope to buyer-contact for buyer-side contacts.Read + write
add_task_noteAdd a note to one of the key creator's tasks. The note is copied to the contact, the company and the linked tender's audit trail.Read + write
complete_taskMark one of the key creator's tasks as done. Completion is logged on the contact, company and tender.Read + write
link_comm_to_tenderLink a logged call or message to a tender (or pass an empty tender_id to unlink). Writes a line on the tender's audit trail and moves its follow-up tasks with it.Read + write

What agents cannot do

  • Publish, amend, cancel or award a tender
  • Send anything to suppliers
  • Delete anything
  • See sealed bids before the closing date

Those always need a named person in TenderLock, so every consequential decision stays accountable.

Before you renew. Before you appoint. Before you buy.
TenderLock it.

Run your first live tender free. No card required.