
Company News
Free Business Plan Upgrades for Open Source Maintainers
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.
Local MCP connector for qlows — bring your live RFP/bid deals and the public tender corpus into Claude, Cursor, Windsurf, Cline and any MCP client.
Bring your live qlows RFP/bid deals — and the public tender corpus across 35 WTO-GPA countries — into Claude, Cursor, Windsurf, Cline, Zed, or any Model Context Protocol client.
qlows-mcp is a tiny local connector. It runs on your machine as a stdio MCP
server and securely proxies tool calls to the qlows API
(https://app.qlows.com). It stores nothing but your token, contains no
backend logic, and is read-only — your AI can pull deal context, never
write back.
Quotes. Flows. Close. qlows preps the bid; your AI drafts from real, grounded context. Learn more at https://qlows.com.
One-click install for the common clients (or copy the JSON snippet below):
# 1. Connect your account (opens the browser, you paste a token back)
npx @qlows/mcp login
# 2. Verify it works
npx @qlows/mcp test # → prints the available tools
# 3. Print the snippet for your AI client
npx @qlows/mcp config
Then add qlows to your client (example: Claude Desktop,
~/Library/Application Support/Claude/claude_desktop_config.json):
{
"mcpServers": {
"qlows": {
"command": "npx",
"args": ["-y", "@qlows/mcp"]
}
}
}
Restart the client. If you didn't run login, pass the token instead:
{
"mcpServers": {
"qlows": {
"command": "npx",
"args": ["-y", "@qlows/mcp"],
"env": { "QLOWS_TOKEN": "qlw_live_…" }
}
}
}
You'll need a qlows account to mint a personal token (free tier works for tender search). Sign up + mint at https://app.qlows.com/mcp.
After connecting, ask your AI:
<deal-id> from qlows and draft the Technical Approach
section, grounding every claim in the compliance items and our approved
answers."All tools are read-only. Personal-data tools need a personal token; the tender tools also work on a free account.
| Tool | What it does |
|---|---|
list_deals | Your RFP/bid deals (lightweight metadata) |
get_deal_snapshot | Full deal snapshot — RFP summary + compliance + Q-routing + intelligence |
search_compliance_items | Keyword search across compliance items |
get_q_routing_state | Sections + questions + answers + assignment state |
get_intelligence_summary | AI summary + tailoring detection |
list_questions | Flat question list |
list_competitors | Per-deal competitor analysis |
search_tenders | Public tender corpus search (FTS + filters) |
search_tenders_for_my_company | Personalised semantic tender search |
get_tender_detail | Full enriched record for one tender |
Plus three prompts (slash-commands) — find_matching_tenders,
draft_rfp_section, weekly_pipeline_review — see Skills below.
The connector discovers tools and prompts live from the server, so new qlows capabilities appear without updating this package.
Three things qlows is built to do inside your AI. Each maps to a prompt (a slash-command your client exposes) plus the read-only tools it drives — all grounded in real qlows data, never invented.
Prompt: find_matching_tenders (args: industry, optional country,
optional deadline_within_days). Drives search_tenders and returns each live
notice with its canonical qlows_url. Full context:
https://qlows.com/platform/qlows-mcp.
"Find open zero-trust networking tenders in Germany closing in the next 30 days, with the qlows link for each."
Prompt: draft_rfp_section (args: deal_id, section). Pulls the deal's
compliance grid and approved answers via get_deal_snapshot +
search_compliance_items, then drafts the section with every claim traced to
source — no fabricated capabilities, dates, or past performance.
"Draft the Technical Approach for deal
<id>, grounded in the compliance items and our approved answers."
Prompt: weekly_pipeline_review (no args). Uses list_deals +
get_q_routing_state to produce a prioritized to-do list: what's due, what's
blocked, and the next action per deal.
"Review my qlows pipeline and tell me which bids need attention first."
The public tender skills work on a free account; the deal skills need a personal token. See the full platform overview.
| Command | Description |
|---|---|
qlows-mcp | Run the MCP server over stdio (how clients launch it) |
qlows-mcp login | Sign in via browser and store a token in ~/.qlows/config.json (0600) |
qlows-mcp test | List available tools to verify your token |
qlows-mcp config | Print config path + a client setup snippet |
qlows-mcp help | Usage |
Environment variables
QLOWS_TOKEN — API token (overrides the stored one).QLOWS_BASE_URL — defaults to https://app.qlows.com; point at
http://localhost:3000 for local testing.MCP client (Claude/Cursor) ⇄ qlows-mcp (stdio, local) ⇄ https://app.qlows.com/api/mcp/<token>/rpc
The connector is a transparent JSON-RPC proxy. It does not implement tools — it
forwards initialize, tools/list, tools/call, prompts/*, and
resources/* to the qlows server and relays the responses. The token travels
in the request to qlows over HTTPS; treat it like a password.
No qlows token found — run qlows-mcp login, or set QLOWS_TOKEN.Token missing, invalid, or expired — the token was revoked or expired;
mint a new one at https://app.qlows.com/mcp and re-run login.Rate limit exceeded — 60 requests/min per token; wait and retry.qlows — restart the client after editing config;
validate the JSON (a stray comma silently breaks it); check the client's MCP
logs.Verify end-to-end with the MCP Inspector:
npx @modelcontextprotocol/inspector npx @qlows/mcp
~/.qlows/config.json
(permissions 0600). It collects no telemetry.login (loopback callback)..mcpb) bundle for a true one-click Claude Desktop
install (the badge above links to setup docs in the meantime).npm install
npm run build
QLOWS_TOKEN=… QLOWS_BASE_URL=http://localhost:3000 node dist/index.js test
Publishing is automated on v* tags (see .github/workflows/release.yml):
npm publish → MCP Registry publish via GitHub OIDC.
##Badges
MIT
FAQs
Local MCP connector for qlows — bring your live RFP/bid deals and the public tender corpus into Claude, Cursor, Windsurf, Cline and any MCP client.
We found that @qlows/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.