Hanzo
Cloud MCPcloud

adminAudit

Reads cloud's tamper-evident audit trail, newest first, with the chain's live integrity attached so a listing can be badged as verified.

Reads cloud's tamper-evident audit trail, newest first, with the chain's live integrity attached so a listing can be badged as verified.

When cloud has no local store configured it falls back to forwarding IAM's own get-records trail verbatim — a DIFFERENT trail, federated so the endpoint never regresses to an empty list. Those rows carry no integrity of ours, so the field is null there.

TooladminAudit
Doorhttps://api.hanzo.ai/v1/mcp
Methodtools/call (JSON-RPC 2.0)
Arguments10
OperationGET /v1/admin/audit
Productcloud

Arguments

FieldTypeRequiredDefaultDescription
actionstringAction restricts it to one action name, e.g. "admin.waitlist.grant".
orgstringOrg restricts the trail to one tenant.
pstringPage is the 1-based page number, driving the offset.
pageSizestringPageSize is rows per page, default 100.
resourcestringResource restricts it to one resource kind, e.g. "credit-grant".
resourceIdstringResourceID restricts it to one resource instance.
resultstringResult restricts it to "success" or "error".
sincestringSince is the inclusive lower time bound, RFC3339. An unparseable value is ignored rather than refused — one malformed filter must not hide the trail.
substringSub restricts it to one actor (the validated subject that made the request).
untilstringUntil is the upper time bound, RFC3339, with the same tolerance.

This tool's schema does not declare which fields are required, nor any default, nor any enumerated value set. The columns above are empty because the door publishes nothing there, not because the answer is "none" — where a field is constrained, the constraint is stated in that field's own description.

Call it

A tools/call carries every argument in one flat object — nothing binds to a path or a query string. Every declared argument is shown, because the door marks none of them required.

curl -X POST https://api.hanzo.ai/v1/mcp \
  -H "Authorization: Bearer $HANZO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
       "jsonrpc": "2.0",
       "id": 1,
       "method": "tools/call",
       "params": {
         "name": "adminAudit",
         "arguments": {
           "action": "<action>",
           "org": "<org>",
           "p": "<p>",
           "pageSize": "<pageSize>",
           "resource": "<resource>",
           "resourceId": "<resourceId>",
           "result": "<result>",
           "since": "<since>",
           "sub": "<sub>",
           "until": "<until>"
         }
       }
     }'

Values are placeholders derived from each field's declared type. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →

The operation behind it

OperationRouteProductSummary
cloud_adminAuditGET /v1/admin/auditcloudReads cloud's tamper-evident audit trail, newest first, with the chain's live integrity at

The same capability over plain HTTP is in the cloud API reference, on https://api.hanzo.ai.


All 834 tools · The door · API reference

Generated from tools/list on https://api.hanzo.ai/v1/mcp — 834 tools captured 2026-08-01 (this build read the vendored copy; the door was unreachable).

How is this guide?

On this page