Server data from the Official MCP Registry
Regulations.gov rulemaking dockets, documents, public comments. 8 tools.
About
Regulations.gov rulemaking dockets, documents, public comments. 8 tools.
Security Report
This is a well-engineered federal contracting MCP server suite with strong security practices. The code demonstrates comprehensive input validation, proper authentication handling via environment variables, and extensive regression testing. No malicious patterns, credential exfiltration, or dangerous code execution vulnerabilities were detected. Permissions align well with the stated purpose of querying public federal APIs. Minor findings relate to code quality (broad exception handling, logging considerations) and do not materially impact security. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue (1 critical, 0 high severity).
4 files analyzed · 9 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: REGULATIONS_GOV_API_KEY
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-1102tools-regulations-gov-mcp": {
"env": {
"REGULATIONS_GOV_API_KEY": "your-regulations-gov-api-key-here"
},
"args": [
"bls-oews-mcp"
],
"command": "uvx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
Federal contracting MCPs
Read-only source tools for federal contracting research: opportunities, awards, company records, labor pricing, travel rates, regulations, and rulemaking.
Explore 1102tools · Find a matching prompt · Download the MCP prompt guide
Available in ChatGPT
USAspending, GSA CALC+, and eCFR are also available as published plugins in the ChatGPT directory. Open a listing below to install and connect it in ChatGPT. These hosted plugins require no user API key or local Python setup.
| Plugin | Install |
|---|---|
| USASpending | Install in ChatGPT |
| GSA CALC+ | Install in ChatGPT |
| eCFR | Install in ChatGPT |
After connecting, choose a matching prompt and replace the bracketed details. If a prompt lists multiple MCPs, connect every one it requires. For other sources or compatible MCP clients, use the server setup instructions below.
Server catalog
Choose the sources your work needs. Each server directory contains its own README, code, configuration, tests, and release notes.
| MCP | Source coverage | Access |
|---|---|---|
| SAM.gov | Opportunities, entity registrations, exclusions, and contract-award records. | User API key required |
| USASpending | Awards, obligations, recipients, agencies, and reported subawards. | No user API key |
| GSA CALC+ | Awarded labor-category ceiling rates and comparison data. | No user API key |
| BLS OEWS | Occupational wages by geography and data year. | Optional key; limited keyless access |
| GSA Per Diem | Lodging and meals-and-incidental-expense rates by locality. | Personal key recommended; shared fallback |
| eCFR | Codified regulatory text, dates, and version comparisons. | No user API key |
| Federal Register | Published rules, notices, comment periods, and FAR cases. | No user API key |
| Regulations.gov | Rulemaking dockets, documents, and public comments. | Personal key recommended; shared fallback |
| Acquisition.gov | FAR Overhaul model text, posted agency deviations, and guidance. | No user API key |
Install
- For the three published ChatGPT plugins, use the directory links above. For other sources or MCP clients, open the selected server's README and follow its installation and configuration instructions.
- Configure any required API keys outside chat. The server README identifies the exact environment variables and access limits.
- Restart or reconnect the client as needed, and confirm the server's tools are visible. Where provided,
get_access_statusreports local credential readiness; it does not validate the key with the upstream provider. - Choose a prompt, connect every MCP named beneath it, and replace the bracketed details.
A prompt does not install a server. Local command configuration and remote endpoint configuration differ; use the supported setup documented for the selected server. The ChatGPT directory links above identify the three published plugins; other servers use their documented setup instructions.
USASpending package naming: its package is usaspending-gov-mcp and its executable is usaspending-mcp. Use the exact configuration in its README; do not substitute a similarly named package.
Use the sources together
- Competitors and teaming: combine USASpending award records with SAM.gov entity and exclusion evidence.
- Pricing inputs: compare BLS wages, CALC+ ceiling rates, and GSA travel rates while keeping their different pricing bases clear.
- Regulations and policy: use eCFR for codified text, Federal Register and Regulations.gov for rulemaking, and Acquisition.gov for FAR Overhaul model text and posted deviations.
Results reflect upstream data and retrieval time. Check dates, completeness, identity matches, and reported limitations. The MCPs provide evidence; they do not make a contracting or procurement-specific applicability decision.
Request pacing and hosted limits
These are default MCP safeguards, measured in upstream requests to the government data source. One tool call can require multiple upstream requests. They are not agency-published quotas or guaranteed response times.
| MCP | Minimum interval between upstream starts | Maximum simultaneous upstream requests | Rolling upstream attempt budget |
|---|---|---|---|
| USAspending | 0.6 seconds | 4 | 500 per 5 minutes |
| GSA CALC+ | 0.6 seconds | 2 | 500 per hour |
| eCFR JSON | 0.6 seconds | 2, shared with XML | 500 per 5 minutes, shared with XML |
| Federal Register | 0.6 seconds | 2 | 500 per 5 minutes |
A 0.6-second interval permits approximately 100 request starts per minute, while budget and concurrency slots remain available. Two simultaneous requests means two may be awaiting responses; it does not mean two start every 0.6 seconds. A rolling window counts the immediately preceding five minutes or hour. Failed and cancelled upstream attempts remain counted.
eCFR XML: uncached XML is fetched one request at a time, with three seconds after the previous XML request completes before the next begins. Eligible XML responses are cached for 300 seconds; a cache hit skips that XML download and its pacing wait. The cache holds 128 entries, 32 MiB total, and 2 MiB per entry. Entries can be evicted earlier for capacity. Tools may still require JSON calls, such as resolving the latest date.
Local versus hosted: running the MCP server yourself gives you its local pacing budget. Processes using the same pacing directory and identity share that budget. Connecting any client to a 1102tools hosted endpoint uses the hosted budget, even if the client application runs on your computer.
| Limit | Local MCP process / stdio | Hosted endpoint / plugin for the four services above |
|---|---|---|
| Upstream budget and concurrency | Shared by local processes using the same pacing directory and identity | Shared by all users of that MCP, regardless of their incoming IPs |
| Cloudflare entrance limit | Does not apply | 120 HTTP requests per 60 seconds, per incoming IP and Cloudflare location |
| Hosted backend admission | Does not apply | 16 processing + 32 FIFO waiting = 48 accepted requests total, shared across this service's users |
| Hosted total request deadline | Local/client timeouts apply | 55 seconds including upload, queue wait and processing; startup and network latency may add time |
Shared IPs and shared service capacity are separate limits. People using the same calling IP can share the 120-per-minute entrance counter. With a cloud AI client, that IP may belong to the AI provider rather than your computer. Cloudflare's counter is approximate and location-specific. Different incoming IPs still share the hosted MCP's upstream budget. For example, ten hosted USAspending users share 500 upstream attempts per five minutes, not 500 each. The four services above have separate budgets; USAspending use does not consume eCFR, CALC+ or Federal Register capacity.
Queued requests enter processing in arrival order when a slot opens. Disconnects, cancellations and deadlines free their slots. A full 48-request admission queue returns HTTP 429 with Retry-After: 5; requests exceeding the deadline return HTTP 504 if no response has started. The upstream limits above remain unchanged, so 16 processing slots do not mean 16 simultaneous agency API calls.
HTTP requests include connection setup, tool discovery and tool calls. They are not equivalent to upstream data requests. Government providers can apply additional limits, including to a shared outbound IP or API key. The 500-per-hour CALC+ policy supports short batches at 0.6-second starts; it does not permit continuous 500-per-five-minute use.
For all nine servers' exact defaults, retry intervals, cache rules, shared-IP behavior and budget persistence, see the complete pacing reference. Acquisition.gov's hosted entrance limit remains 60 HTTP requests per minute. The other servers retain their documented three- or four-second completion delays. Cloudflare rate-limit behavior.
Testing and maintenance
Acquisition.gov has 236 offline tests and recorded live checks across all five tools, including P0–P3 coverage for HTML/PDF parsing and transport boundaries.
Current source-specific evidence is in each server's testing.md or TESTING.md, with changes in its changelog. Packages version independently. The shared request-pacing code reduces bursts and handles provider errors; it does not create additional provider quota.
This September 2026 documentation refresh changes the public entry points and removes retired setup links. It does not change MCP runtime behavior or claim a new live test of the entire suite. Earlier release narrative is preserved in historical documentation.
License and author
MIT licensed. Built by James Jenrette. Independently developed and not affiliated with or endorsed by any federal agency.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Paperclip
Freeby Paperclipai · Developer Tools
Trending hip-hop artist momentum scores across four cultural dimensions.
Netdata
Freeby Netdata · Developer Tools
Real-time infrastructure monitoring with metrics, logs, alerts, and ML-based anomaly detection.
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
