adminGrants
Reads the credit-grant ledger across ALL orgs, newest first — who granted what to whom, when, and from which money bucket.
Reads the credit-grant ledger across ALL orgs, newest first — who granted what to whom, when, and from which money bucket.
It is a PROJECTION of the tamper-evident audit trail, not a second store: every grant is written there as action "admin.customer.credit", so this view cannot drift from what actually happened, and FAILED grants appear too.
A deployment with no local audit store has no history to project, and says so with an empty list and a msg rather than an error.
| Tool | adminGrants |
| Door | https://api.hanzo.ai/v1/mcp |
| Method | tools/call (JSON-RPC 2.0) |
| Arguments | 3 |
| Operation | GET /v1/admin/grants |
| Product | cloud |
Arguments
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
limit | string | — | — | Limit caps the rows returned. Default 200. |
org | string | — | — | Org filters by the ACTOR's org (the staff org that issued the grant), which is rarely what a reader wants — the target org is a row field, not a filter. |
result | string | — | — | Result filters by outcome: "success" or "error". Empty returns both, which is the point of this view — a refused grant is as interesting as a granted one. |
This tool's schema does not declare which fields are required, nor any default, nor any enumerated value set. The columns above are empty because the door publishes nothing there, not because the answer is "none" — where a field is constrained, the constraint is stated in that field's own description.
Call it
A tools/call carries every argument in one flat object — nothing binds to a path or a query string. Every declared argument is shown, because the door marks none of them required.
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "adminGrants",
"arguments": {
"limit": "<limit>",
"org": "<org>",
"result": "<result>"
}
}
}'Values are placeholders derived from each field's declared type. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →
The operation behind it
| Operation | Route | Product | Summary |
|---|---|---|---|
cloud_adminGrants | GET /v1/admin/grants | cloud | Reads the credit-grant ledger across ALL orgs, newest first — who granted what to whom, wh |
The same capability over plain HTTP is in the cloud API reference, on https://api.hanzo.ai.
All 834 tools · The door · API reference
Generated from tools/list on https://api.hanzo.ai/v1/mcp — 834 tools captured 2026-08-01 (this build read the vendored copy; the door was unreachable).
How is this guide?