CongressCAUTION
An MCP server allowing AI agents and MCP clients to interface with the Congress.gov API
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Live U.S. Congressional data for any MCP client — Claude Code, ChatGPT, Copilot, Codex, Cursor, OpenCode, Gemini CLI, Grok Build, and more.
Bills, full bill text, votes, members, committees, hearings, nominations, and the Congressional Record — queried in natural language through the Model Context Protocol. Runs locally on your machine against the free Congress.gov and GovInfo APIs. No account, no hosted service, no telemetry.
Quick Start
1. Get a free Congress.gov API key
Sign up at [api.congress.gov/sign-up](https://api.congress.gov/sign-up/) — takes 30 seconds. The same key also works for GovInfo (full bill text).
2. Install uv
CongressMCP is published on PyPI and launched with uvx, which ships with uv:
# macOS / Linux curl -LsSf https://astral.sh/uv/install.sh | sh # Windows (PowerShell) powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"
(brew install uv, winget install astral-sh.uv, and pipx install uv also work.) Prefer pip? pip install congressmcp gives you a congressmcp command you can use in place of uvx congressmcp below.
3. Connect your client
Every client needs the same three facts: command uvx, args ["congressmcp"], env CONGRESS_API_KEY. Clients are listed roughly by how many professional developers use them today (JetBrains Developer Ecosystem survey, mid-2026, then Pragmatic Engineer's 2026 tooling survey), so the one you want is probably near the top:
67ee24b04287OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add congressmcp --env CONGRESS_API_KEY=${CONGRESS_API_KEY} --env GOVINFO_API_KEY=${GOVINFO_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- uvx congressmcp{
"mcpServers": {
"congressmcp": {
"command": "uvx",
"args": [
"congressmcp"
],
"env": {
"CONGRESS_API_KEY": "${CONGRESS_API_KEY}",
"GOVINFO_API_KEY": "${GOVINFO_API_KEY}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}"
}
}
}
}Exposed tools (24)
24 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
amendments | read | |
bills | read | |
committee_intelligence | read | |
get_bill_section | read | |
get_bill_toc | read | |
get_committee_bills | read | |
get_committee_communications | read | |
get_committee_nominations | read | |
get_committee_reports | read | |
get_member_cosponsored_legislation | read | |
get_member_details | read | |
get_member_sponsored_legislation | read | |
get_members_by_congress | read | |
get_members_by_congress_state_district | read | |
get_members_by_district | read | |
get_members_by_state | read | |
laws | read | |
records_and_hearings | read | |
research_and_professional | read | |
search_bill_text | read | |
search_committees | read | |
search_members | read | |
treaties_and_summaries | read | |
voting_and_nominations | read |
Trust audit
CAUTIONgrade F · trust 60/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (6 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (22)
module = _parser if module_name == "parser" else __import__(__name__, fromlist=["_"])
resolved_module = importlib.import_module(rel_name, package=container_package)
handler_module = importlib.import_module(call.module_name)
handler_module = importlib.import_module(call.module_name)
logger.info(f" API Key: {api_key}")self.url = f"http://127.0.0.1:{self.port}"api_key="test_api_key_12345_demo",
secret = "ZZfakekeyfakekeyfakekey00"
secret = "ZZfakekeyfakekeyfakekey00"
api_key="lawgiver_free_test12345_WelcomeDemo789",
handler_module = __import__(call.module_name, fromlist=[call.orig_name])
logger.info("HTTP Request: %s", f"GET https://x/?api_key={secret}")logger.info("bare message carrying %s inline" % f"key={secret}")logger.info(f" 🔑 API Key: {api_key}")mcp, pydantic, pydantic-settings, starlette, uvicorn, annotated-types, anyio, certifi
**`"pinned"` shipped (`5242055`) and V11 CLOSED 2026-08-22 — 14/14 scenarios, every check green** (`5e2bb22`; artifact `runs/v11/2026-08-22T035126Z/`, report read by this session; offline sweep indepe
- **Codex driver (2026-08-18):** the maintainer had the implementation session add a Codex CLI driver to the §17 harness (`012bf8a`, a claim not yet adjudicated here). The cross-vendor cell (§17) is n
2. **The per-cell canary returns — F23's ratification is amended for new drivers.** The no-canary ratification (import probe + sibling heuristic) was argued on the Claude path, where the only kill mod
**Fifth adjudication — the F32 re-run (2026-08-20, runs `2026-08-20T171204Z` / `171229Z` / `171300Z`, maintainer-run, build `d24e376` with the F32 fix an ancestor).** Instrument certified per run: can
- **F38 — malformed `version` (e.g. `"e nr!"`) surfaced as `internal_error` on `get_bill_section`/`get_bill_toc`; `package_filename()`'s `ValueError` escaped their handlers while `search_bill_text` ca
| `CONGRESS_API_ENV` | No | `local` | Set to `development`/`staging`/`production` to load the matching `.env.*` file; unset loads only a plain `.env`. Files never override exported variables |
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
67ee24b04287full audit observations/trust-audit/mcp-server/amurshak__congress.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 67ee24b04287 | CAUTION | F | 60 | first audit |
Questions
What is the Congress MCP server?
An MCP server allowing AI agents and MCP clients to interface with the Congress.gov API
What tools does Congress expose?
24 in total: 24 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Congress safe to connect to an agent?
With care. The audit graded it F (60/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Congress need?
It reads CONGRESS_API_KEY, GOVINFO_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Congress run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as congressmcp.
How current is this page?
The grade is for one exact copy of the source (67ee24b04287), read on 2026-10-08. The repository is watched and re-audited when it changes.