get_v1_audit
List reads the caller's OWN org audit trail, newest first, with the total the filter matched so a console can page it.
List reads the caller's OWN org audit trail, newest first, with the total the filter matched so a console can page it.
Every filter is optional and applies WITHIN the caller's org — the org itself is the validated principal's and can never be widened by a request. Fails closed: an absent principal is a true "not signed in" (401), and a deployment with no local tamper-evident store answers an honest 501 rather than silently serving somebody else's trail.
| Tool | get_v1_audit |
| Door | https://api.hanzo.ai/v1/mcp |
| Method | tools/call (JSON-RPC 2.0) |
| Arguments | 9 |
| Operation | GET /v1/audit |
| Product | audit |
Arguments
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
action | string | — | — | Action narrows it to one action name, e.g. "machine.create". |
p | string | — | — | Page is the 1-based page number, driving the offset. Anything below 2 reads the first page. |
pageSize | string | — | — | PageSize is rows per page, default 100. A value that is not a positive integer falls back to the default. |
resource | string | — | — | Resource narrows it to one resource TYPE, e.g. "apikey". |
resourceId | string | — | — | ResourceID narrows it to one resource instance. |
result | string | — | — | Result narrows it to one outcome: "success", "deny" or "error". |
since | string | — | — | Since is the inclusive lower time bound, RFC3339. An unparseable value is ignored rather than refused — one malformed filter must not hide the trail. |
sub | string | — | — | Sub narrows the trail to one actor — the validated subject that made the request. Blank means every actor in the org. |
until | string | — | — | Until is the upper time bound, RFC3339, with the same tolerance. |
This tool's schema does not declare which fields are required, nor any default, nor any enumerated value set. The columns above are empty because the door publishes nothing there, not because the answer is "none" — where a field is constrained, the constraint is stated in that field's own description.
Call it
A tools/call carries every argument in one flat object — nothing binds to a path or a query string. Every declared argument is shown, because the door marks none of them required.
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "get_v1_audit",
"arguments": {
"action": "<action>",
"p": "<p>",
"pageSize": "<pageSize>",
"resource": "<resource>",
"resourceId": "<resourceId>",
"result": "<result>",
"since": "<since>",
"sub": "<sub>",
"until": "<until>"
}
}
}'Values are placeholders derived from each field's declared type. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →
The operation behind it
| Operation | Route | Product | Summary |
|---|---|---|---|
cloud_get_v1_audit | GET /v1/audit | audit | List reads the caller's OWN org audit trail, newest first, with the total the filter match |
The same capability over plain HTTP is in the audit API reference, on https://api.hanzo.ai.
All 834 tools · The door · API reference
Generated from tools/list on https://api.hanzo.ai/v1/mcp — 834 tools captured 2026-08-01 (this build read the vendored copy; the door was unreachable).
How is this guide?