Back to Browse

WorkspaceAlberta MCP Server

Developer ToolsUse Caution3.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Canadian procurement intelligence: CanadaBuys and Alberta tenders, ranked for your shop.

About

Canadian procurement intelligence: CanadaBuys and Alberta tenders, ranked for your shop.

Remote endpoints: streamable-http: https://elbowsupknivesout.warreandvavasour.com/mcp

Security Report

3.2
Use Caution3.2High Risk

WorkspaceAlberta is a legitimate procurement intelligence MCP server with reasonable architecture and no obvious malicious intent. However, several security concerns lower the score: unauthenticated API access to sensitive government procurement data, inadequate input validation on user-supplied profiles and search parameters, missing rate limiting on external API calls, and credential handling that relies on environment variables without explicit validation. The service's permissions (network access to government APIs, file I/O, environment variable reading) align with its stated purpose, but the lack of authentication boundaries on the hosted endpoint and insufficient safeguards against parameter injection create moderate risk. Supply chain analysis found 5 known vulnerabilities in dependencies (0 critical, 5 high severity). Package verification found 1 issue.

4 files analyzed · 16 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

WorkspaceAlberta

AI Ethics

Warre & Vavasour does not replace human workers. We build a bigger pie for you. Every capability we ship exists to amplify the people already doing the work — the same promise the photographs above made to the generation that industrialized this country. If a savings plan starts with headcount, it is not a WorkspaceAlberta plan.

Warre & Vavasour does not make apps or chatbots. Don't ask. If this is in your business plan, you are thinking about New Business wrong. We build terminals that deliver real work — code, files, documents — not conversation widgets.

Warre & Vavasour acknowledges the astonishing resources this technology is consuming. Training and inference carry real energy, water, and mineral costs — and nobody asked for this. No one really asked for GRPO to be released on January 20. But it was released, and that is how all models got to reasoning; and from reasoning, we have harnesses now. This is just the way the world is — and it is far too cheap not to deploy post-human-scale reasoning tools on a desktop device that genuinely accelerates ideas to revenue.

So yes: we acknowledge the cost, we say it out loud instead of hiding it, and our answer stays Canadian infrastructure, right-sized models on hardware you own, and local data retention over redundant cloud sprawl. Because it is 1834, and the railroad has been built. The tracks arrive Tuesday. The world as we know it is all changing. WorkspaceAlberta is the way to stay ahead of these changes.

Getting Started

The hosted MCP server is live and free for browsing — no install, no account, no API key. Point any MCP-capable assistant at it:

https://elbowsupknivesout.warreandvavasour.com/mcp

Cursor, Claude Code, and other HTTP-native clients — add to your MCP config:

{
  "mcpServers": {
    "workspacealberta": {
      "url": "https://elbowsupknivesout.warreandvavasour.com/mcp"
    }
  }
}

Claude Desktop (no native HTTP transport) — bridge with mcp-remote:

{
  "mcpServers": {
    "workspacealberta": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://elbowsupknivesout.warreandvavasour.com/mcp"]
    }
  }
}

Then ask it something a real owner would ask:

  • "I run a CWB welding shop in Red Deer — what government work fits my shop right now?"
  • "What closes this week? I don't want to miss anything."
  • "Give me my morning brief — what fits us, and what's closing soon?"

Adding your Pro key

Search, details, deadlines, and the daily brief are open to everyone. Six tools — bid rooms, Cohere tender review, the watchlist, and bid/no-bid scorecards — need an active subscription. Your key arrives by email after checkout and starts with wa_live_.

Send it as an Authorization header. For HTTP-native clients:

{
  "mcpServers": {
    "workspacealberta": {
      "url": "https://elbowsupknivesout.warreandvavasour.com/mcp",
      "headers": {
        "Authorization": "Bearer wa_live_YOUR_KEY"
      }
    }
  }
}

For Claude Desktop, set it on the bridge instead:

{
  "mcpServers": {
    "workspacealberta": {
      "command": "npx",
      "args": ["-y", "@warreandvavasour/workspace-alberta"],
      "env": { "WORKSPACEALBERTA_API_KEY": "wa_live_YOUR_KEY" }
    }
  }
}

On a Linux workstation or a leased terminal, let the installer do it — it verifies the key against the server, writes ~/.config/workspacealberta/credentials at mode 600, and registers the authenticated endpoint with whichever CLIs are present:

./installer/configure-subscriber-key.sh

Check a key at any time:

curl -H "Authorization: Bearer wa_live_YOUR_KEY" \
  https://elbowsupknivesout.warreandvavasour.com/me

Run it locally instead (the whole server is pure Python):

python -m pip install -r requirements.txt
python mcp-servers/canadabuys/server.py

Smoke test: python -m unittest tests.test_canadabuys_mcp_smoke. Client config variants live in mcp.json.example; full tool and REST reference in docs/mcp-tool-reference.md.


Canadian AI Security Is Canadian National Security

WorkspaceAlberta is a Canadian procurement intelligence workspace. It connects public tender data to the people who can actually do the work: fabricators, mills, contractors, shops, manufacturers, and the small teams that keep the real economy moving.

The direction is explicit:

  • Canadian demand signals: CanadaBuys and Alberta Purchasing Connection in one search surface.
  • Canadian AI company: Cohere as the first sovereign-model route.
  • Canadian open source model: Command A+ command-a-plus-05-2026, with the W4A4 Hugging Face route available through CohereLabs/command-a-plus-05-2026-w4a4.
  • Canadian tools: practical MCP wiring for the procurement sources Canadian firms already need to watch.
  • Canadian compute path: designed so sensitive public-sector and industrial workflows can move toward Canadian infrastructure, including Canadian chips and data-centre capacity where those options are available.

The point is not nationalism as decoration. The point is operational independence.

If Canadian companies are going to bid Canadian work, understand Canadian supply chains, and protect Canadian industrial capacity, then the AI layer underneath that work matters.


The Last Mile of Work

AI promised 5X productivity. Most small businesses got a chatbot that writes mediocre marketing copy.

The model is not the whole bottleneck. The connection is.

Wiring up the places where the work lives usually costs money, time, and technical patience a small business does not have. Government tender databases are a perfect example: the work is public, the demand is real, but the discovery process is still awkward enough that good companies miss good opportunities.

WorkspaceAlberta solves the last mile by giving an AI assistant the wiring it needs to search, compare, summarize, and brief public procurement opportunities from inside the workspace where the owner is already working.


What This Actually Does

WorkspaceAlberta is an MCP-first workspace for Canadian procurement.

It now brings together:

  • CanadaBuys for federal tender notices
  • Alberta Purchasing Connection for Alberta public-sector opportunities
  • Cohere Command A+ for optional tender analysis and fit review
  • A daily bid brief that summarizes the market, best-fit matches, and deadlines from both sources

The assistant can:

  • search national and Alberta opportunities together
  • inspect a posting by reference number
  • list what is closing soon
  • match opportunities against a saved business profile
  • generate a free daily brief for the owner or estimator
  • use Cohere Command A+ to review tender fit, risks, requirements, and next actions

This is meant to answer practical questions:

  • What work is open right now?
  • Which opportunities fit what we actually do?
  • What closes soon?
  • What should we read first?
  • What should we ignore?

The Custom Procurement MCP Server

The custom MCP server is the product.

It is a deployed working endpoint that knows the live public procurement pipeline exposed by CanadaBuys and Alberta Purchasing Connection. It can serve that pipeline back to users through an AI assistant based on what they do, where they work, what they can supply, and what deadlines matter.

The core tools are:

  • search_opportunities for unified federal and Alberta search
  • get_opportunity_details for a single posting by reference number
  • list_deadlines for what is closing soon
  • find_matching_opportunities for profile-based ranking
  • daily_bid_brief for the daily owner/operator summary
  • analyze_contract_with_cohere for optional Cohere Command A+ tender review
  • process_bid_room for live E2B attachment processing: Cohere Parse turns tender PDFs and images into markdown, then Command A+ reviews the evidence
  • watch_opportunity / list_watchlist for a persistent tracking list with closing-date countdowns
  • bid_no_bid_scorecard for a fast deterministic go/caution/no-go read on any reference

The full tool and REST reference lives in docs/mcp-tool-reference.md; the architecture walkthrough is docs/architecture.md.

MCP is the first-class interface because this is meant to be used by agents. The same procurement core also exposes REST/OpenAPI so other AI tools can hook into the same contract intelligence without needing native MCP support.

Underneath the endpoint is pure Python procurement logic. The data processing, filtering, matching, deadline ranking, and brief generation do not require an LLM. The model layer is added only where judgment helps: risk review, requirements explanation, and bid/no-bid reasoning.

E2B sandboxes are the isolated compute layer for heavier bid-room work: opening tender packages, turning attachments into evidence, and returning structured bid artifacts without putting unknown user files inside the always-on MCP service. Cohere Parse is the document layer — it converts PDF pages and images into structured markdown (tables, forms, drawings) before review. Command A+ is the review layer: it runs inside the short-lived sandbox with read-only evidence tools over that markdown. If Parse is unset, times out, or rejects a file, the existing pdfminer/python-docx/openpyxl extractors stay as fallback. The build plan lives in docs/e2b-bid-room-plan.md, and the business-owner operating diagram lives in docs/bid-room-operating-diagram.md.


Why This Matters

Get 50% of the population 10% better. Every year. That is generational growth.

Not 10 developers 500% better. That is happening. But it does not scale to the economy.

"How do I save 5 hours a week?" "How do I save $700 a month?"

Those are the real questions. This is how you answer them.

Alberta's steel, lumber, and metals industries represent over 2,500 companies with a combined economic impact exceeding $37 billion annually.

SectorCompaniesEconomic ImpactJobs Supported
Forestry & Wood Products676+ businesses, 40 major mills$14 billion41,400
Fabricated Metal Products1,871 establishments$23.4B manufacturing sector16,600
Primary & Machinery Manufacturing200+ facilitiesIncluded above12,000+

Behind every one of these companies are dozens of systems that need to talk to each other just to get anything done: quoting software, inventory spreadsheets, accounting packages, project trackers, supplier portals, and government tender databases.

Any tool that helps a fabricator create demand, a mill manufacture more efficiently, or a contractor cut costs has multiplier effects across the entire province:

  • $4 billion in forest product exports alone
  • $1.6 billion in annual wages paid to forestry workers
  • 70 communities across Alberta that depend directly on these industries
  • $988 million in tax revenue flowing back to the province

More contracts won. More jobs kept. More skill developed. More value staying here at home.


Technical Notes

MCP server:

Smoke test:

Configuration:

Raspberry Pi terminal setup:

Data and model sources:

Image source notes live in docs/imagery-sources.md.


The OPERA Analytics Server

The country is traveling west. Domestic travel to the western provinces is scaling, and the properties hosting those travelers run on systems like OPERA Cloud.

The Warre & Vavasour tourism thesis: in an extreme-AI world, people crave the analog. Real places, real adventures. The premium goes to authentic, place-bound experiences — and AI is invisible wiring, not the product.

The wiring problem looks exactly like procurement's last mile. A hotel's own data lives inside OPERA Cloud, and getting it out for analysis usually means expensive middleware or manual exports. Front-desk managers, revenue people, and owners can't use what they can't reach.

So the repo ships a second MCP server: mcp-servers/opera-analytics/server.py, a read-only analytics data tap for OPERA Cloud Reporting & Analytics Data APIs. A property's own user signs in as themselves — OAuth2 password grant, with credentials from the hotel's own OPERA Cloud Developer Portal. No partner program, no middleware vendor.

It covers 75 analytics subject areas — guest/deposit/AR ledgers, transactions, reservation statistics and pace, managers report, history and forecast, rate codes, profiles, blocks, catering events, housekeeping inventory — through 9 tools:

  • opera_auth_status to check the session
  • list_subject_areas / describe_subject_area to see what data exists
  • run_graphql_query / query_subject_area to pull it
  • export_to_csv / sync_subject_area to land it locally
  • list_local_tables / query_local_data to work with what's synced

Data lands in local CSV files and a DuckDB database the team can open in Excel or Power BI, or ask questions about in plain language through any MCP-capable assistant. Read-only by design. Set OPERA_MOCK=1 to try it offline with no credentials; smoke test: python -m unittest tests.test_opera_analytics_smoke. Server docs live in mcp-servers/opera-analytics/README.md.

Tools employees can actually use, from the systems they already have. The same pattern as the procurement work: take an awkward system of record, give people their own data back, charge for outcomes not visibility.


Data sources: Statistics Canada, Innovation Canada, Alberta Forest Products Association, Job Bank Canada

Reviews

No reviews yet

Be the first to review this server!