# Stipple — Government Tenders (remote · www.stipple.sh)

Search AU/NZ government tenders and rank a shortlist against company capabilities.

- Trust score: 74/100 (medium)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-25

## Components

- remote · `www.stipple.sh`: 74/100 (this document), [markdown](https://verifymcp.io/servers/sh-stipple-stipple-tenders/mcp-tenders.md), [page](https://verifymcp.io/servers/sh-stipple-stipple-tenders/mcp-tenders)

## Channel facts

- Endpoint: `https://www.stipple.sh/mcp-tenders`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.1.1`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-25.

- **Endpoint Security**: 57/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 5 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 72/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 1653 tokens (~330/item across 5 items; 5 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 90/100
  - Stability observed for 27 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 71/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 0% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 5 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 6 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the Stipple — Government Tenders MCP server?

Stipple — Government Tenders is a hosted endpoint at https://www.stipple.sh/mcp-tenders, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http sh-stipple-stipple-tenders 'https://www.stipple.sh/mcp-tenders'
```

### Cursor

```json
{
  "mcpServers": {
    "sh-stipple-stipple-tenders": {
      "url": "https://www.stipple.sh/mcp-tenders"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "sh-stipple-stipple-tenders": {
      "type": "http",
      "url": "https://www.stipple.sh/mcp-tenders"
    }
  }
}
```

### Codex

```toml
[mcp_servers.sh-stipple-stipple-tenders]
url = "https://www.stipple.sh/mcp-tenders"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "sh-stipple-stipple-tenders": {
      "type": "remote",
      "url": "https://www.stipple.sh/mcp-tenders",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add sh-stipple-stipple-tenders --url 'https://www.stipple.sh/mcp-tenders' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  sh-stipple-stipple-tenders:
    url: "https://www.stipple.sh/mcp-tenders"
```

### Netclaw

```json
{
  "McpServers": {
    "sh-stipple-stipple-tenders": {
      "Transport": "http",
      "Url": "https://www.stipple.sh/mcp-tenders"
    }
  }
}
```

### Vellum

```bash
assistant mcp add sh-stipple-stipple-tenders -t streamable-http -u 'https://www.stipple.sh/mcp-tenders'
```

### Other

```json
{
  "mcpServers": {
    "sh-stipple-stipple-tenders": {
      "type": "http",
      "url": "https://www.stipple.sh/mcp-tenders"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-25 (score 74, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-24 (score 74, +1)

No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-22 (score 73, +1)

No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-20 (score 72, +1)

No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-18 (score 71, +1)

No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-16 (score 70, 0)

- [security] Tool “find_tenders” rewrote its description, which is the text the model reads
- [security] Tool “match_tenders” rewrote its description, which is the text the model reads
- [functional regression] Schema quality: 1019 → 1653
- [functional] Schema quality: excellent → good
- [functional] New tool “buyer_awards”
- [functional] New tool “find_signals”

### 2026-09-15 (score 70, +1)

No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-12 (score 69, +1)

No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.

## MCP tools (5)

### `find_tenders` (~411 tokens)

Search AU/NZ tenders

Search open tenders across Australia and New Zealand.
FREE, within the weekly cap.

USE THIS WHEN someone asks what public-sector work is open: "any council drainage
tenders in Victoria", "what's closing this month in NSW", "show me federal IT
opportunities". For "which of these could MY company actually bid for", use
match_tenders instead — that reads their website and ranks against it.

\`jurisdiction` is one of AU, NZ, AU-NSW, AU-VIC, AU-QLD, AU-WA, AU-SA, AU-TAS, AU-ACT, AU-NT. `tier` is federal, national,
state, council, university or health. `closing_before` is an ISO date.
\`first_seen_after` (ISO-8601 instant, strictly newer) answers "what is new since my last
look" — first_seen is when WE first saw the tender, the honest clock for newness. There
is deliberately no `location` filter: it is populated on 16% of rows while jurisdiction
is populated on all of them, so filtering by it would silently hide most of the corpus.

Returns `{total, results[], coverage}`. Each result carries title, buyer, jurisdiction,
closing_date, categories, a summary, a link, and source_id/source_tag/source_name/
source_url/source_refresh — plus `link_is_listing` when the portal publishes no
per-tender URL and the link goes to the list it appeared on.

\`coverage` names which sources were searched and which returned nothing. Quote it if
the result is empty: "no match in what we searched" is true, "there are none" is not.

Input parameters:

- `category`
- `closing_before`
- `first_seen_after`
- `include_closed` (boolean)
- `jurisdiction`
- `limit` (integer)
- `q`
- `source`
- `tier`

### `match_tenders` (~360 tokens)

Match tenders to a company

Rank open tenders against what a company actually does. Free, inside the weekly cap.

    USE THIS WHEN someone asks which opportunities suit a specific business: "what could we
    bid for", "is there anything for a civil contractor in Victoria", "find work for
    acme.com.au". Give `company_url` — a plain domain is fine, we resolve it — and we read
    their site, build a capability profile, and score the shortlist against it.

    `example` runs a built-in profile (civil, it, facilities) with no site read, for
    demonstrating the shape of the answer.

    Returns `{profile, matched, shown, withheld, withheld_reason, matches[], degraded,
    score_means, coverage}`. Each match has `score`, `band`, `why[]` — the company's own
    stated capabilities this tender needs — and `gaps[]`, things the tender asks for that
    their website does not mention. An anonymous call shows the strongest few and says
    how many were withheld; relay `withheld_reason` as it is.

    TELL THE USER WHAT THE SCORE IS: relative fit within these results, against what their
    website says. NOT a probability of winning. And `gaps` is what to check before bidding,
    not a list of everything the tender requires — that is in the tender documents.

    When `degraded` is true, scoring was unavailable and the order is keyword relevance
    only, with no `why`/`gaps`. Say so rather than presenting it as a judged ranking.

Input parameters:

- `closing_before`
- `company_url`
- `example`
- `jurisdiction`

### `tender_sources` (~170 tokens)

List tender data sources

Every source we search, what it is allowed to do, and what the last run returned.
    FREE.

    USE THIS WHEN someone asks where the data comes from, whether a particular portal is
    covered, or why a search came back empty. It is the honesty surface: it names sources
    behind login walls, sources whose robots.txt refuses us, and sources that returned
    nothing on the last run and why.

    Returns `{sources[], coverage}` — per source: id, tag, name, URL, refresh mode,
    jurisdiction, tier, how it is accessed, what its robots.txt says, how many tenders we
    hold from it, and its status on the most recent run. Snapshot sources include their
    observed date and are not presented as nightly feeds.

### `buyer_awards` (~289 tokens)

Contract awards and signals for a buyer

What a buyer has awarded, what is ending, and what they plan. FREE.

USE THIS WHEN someone asks about a specific buyer before a bid: "who holds Transport for
NSW's work", "what is ending soon at Queensland Health", "what does this agency usually
pay". Give `buyer` (the organisation name as published) or `buyer_key` (from a tender's
buyer, or a previous answer).

Returns `{buyer, expiring[], planned[], recent_awards[], top_suppliers[], open_tenders[],
computed_at, sources}`: the nightly rollup (awards in the window, value quartiles as
published, median response window), contracts ending within 12 months with the incumbent,
planned procurements with their quarter and spend band, the suppliers who win from them
(name and share), and open tenders under the same name.

ANONYMOUS CALLERS SEE COUNTS, VALUES, DATES AND BUYERS; supplier and incumbent names are
withheld and `withheld_reason` says so. Relay that sentence as it is. Values are the
published amount and currency, never converted; `computed_at` is the night the figures
are true for - say it. Coverage is Australia and New Zealand sources named in
\`sources`, each with the attribution its licence requires.

Input parameters:

- `buyer`
- `buyer_key`

### `find_signals` (~325 tokens)

Find contract expiries and planned procurements

Signals: what may be tendered before it is. FREE.

USE THIS WHEN someone asks what is coming: "which contracts in Queensland end in the next
six months", "what is planned for ICT next quarter", "what is expiring for this buyer".
\`kind` is one of contract_expiry (a contract ending, with its incumbent),
planned_procurement (a buyer's stated plan with its quarter and spend band as published)
or recurring_tender (derived from our own history, labelled `derived`). `jurisdiction`
is one of AU, NZ, AU-NSW, AU-VIC, AU-QLD, AU-WA, AU-SA, AU-TAS, AU-ACT, AU-NT. `window_before` is an ISO date: signals whose
window starts on or before it. `q` searches the subject, buyer and incumbent.

Returns `{total, results[], computed_at, sources}`. Each signal carries `confidence`
(`published` or `derived` - a vocabulary, not a score), its window (never invented: an
expiry's window IS the contract's end date; a planned row with no parseable quarter has
none), `evidence_ref` and `evidence_url`. ANONYMOUS CALLERS SEE EVERYTHING BUT THE
INCUMBENT'S NAME; `withheld_reason` says so - relay it as it is.

Input parameters:

- `buyer`
- `jurisdiction`
- `kind`
- `limit` (integer)
- `q`
- `window_before`

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/sh-stipple-stipple-tenders/mcp-tenders#diagnostics

## Score history

- 2026-09-25: 74
- 2026-09-24: 74
- 2026-09-23: 73
- 2026-09-22: 73
- 2026-09-21: 72
- 2026-09-20: 72
- 2026-09-19: 71
- 2026-09-18: 71
- 2026-09-17: 70
- 2026-09-16: 70
- 2026-09-15: 70
- 2026-09-14: 69
- 2026-09-13: 69
- 2026-09-12: 69
- 2026-09-11: 68
- 2026-09-10: 67
- 2026-09-09: 67
- 2026-09-08: 66
- 2026-09-07: 66
- 2026-09-06: 65
- 2026-09-05: 65
- 2026-09-04: 64
- 2026-09-03: 64
- 2026-09-02: 57
- 2026-09-01: 63
- 2026-08-31: 63
- 2026-08-30: 62
- 2026-08-29: 62

## Common questions

### What is the Stipple — Government Tenders MCP server?

Stipple — Government Tenders is an MCP server listed in the public MCP registry as sh.stipple/stipple-tenders. Search AU/NZ government tenders and rank a shortlist against company capabilities. This page covers its hosted endpoint (https://www.stipple.sh/mcp-tenders).

### Is the Stipple — Government Tenders MCP server safe to use?

Stipple — Government Tenders scores 74 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Stipple — Government Tenders MCP server expose?

Stipple — Government Tenders exposes 5 tools: find_tenders, match_tenders, tender_sources, buyer_awards, find_signals. Their descriptions and schemas cost roughly 1,555 tokens of context every time the server is loaded.

### Does the Stipple — Government Tenders MCP server require authentication?

No. We connected to Stipple — Government Tenders without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Stipple — Government Tenders MCP server still maintained?

Stipple — Government Tenders is still listed as active in the MCP registry. We last reached this channel on 25 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://www.stipple.sh/mcp-tenders
- Repository: https://github.com/Sketchjar/stipple-mcp
- Website: https://www.stipple.sh/tenders
- Changelog RSS feed: https://verifymcp.io/servers/sh-stipple-stipple-tenders/mcp-tenders.xml
- Changelog JSON feed: https://verifymcp.io/servers/sh-stipple-stipple-tenders/mcp-tenders.json
- HTML version of this page: https://verifymcp.io/servers/sh-stipple-stipple-tenders/mcp-tenders
