Reference
The `hanzo reference` commands.
Also for this capability: API · CLI · MCP · SDKs
The lookup data a risk decision needs but cannot derive: which email domains hand out throwaway inboxes, which addresses belong to a datacentre or a Tor exit, which card scheme an issuer prefix belongs to, which browsers the fleet sees everywhere, and how current the designation lists the screening engine holds actually are.
hanzo reference listEvery command takes --json for the raw response and --help for its own flags. Sign in once with hanzo auth login; the commands below use that session, and the org they act in is the one it carries.
| Command | What it does |
|---|---|
hanzo reference list | Lists every set this plane publishes, with its version and how fresh it is. |
hanzo reference refresh | Takes a new version of one set. |
hanzo reference resolve | Looks keys up against the reference plane. |
get
| Command | What it does |
|---|---|
hanzo reference get <set> | Reference describes one set and lists your org's overrides in it. |
rm
| Command | What it does |
|---|---|
hanzo reference rm <set> | Removes one of your organisation's overrides. |
set
| Command | What it does |
|---|---|
hanzo reference set <set> | Writes your organisation's own allow and deny entries over a set. |
How is this guide?