post_v1_research_artifacts
RecordResearchArtifact records one research-diary artifact — a board snapshot or a generated report — CONTENT-ADDRESSED inside the trust boundary.
RecordResearchArtifact records one research-diary artifact — a board snapshot or a
generated report — CONTENT-ADDRESSED inside the trust boundary. The caller submits
the bytes as base64 content; the SERVER hashes them and THAT hash is the identity
and the ref, so the address can never be poisoned by a client-asserted one. A
client-supplied sha256, if present, must match the bytes. The project is the
SERVER's value and visibility is forced private. Re-posting the same bytes is a
no-op that reports created=false.
| Tool | post_v1_research_artifacts |
| Door | https://api.hanzo.ai/v1/mcp |
| Method | tools/call (JSON-RPC 2.0) |
| Arguments | 13 |
| Operation | POST /v1/research/artifacts |
| Product | research |
Arguments
| Field | Type | Required | Default | Values | Description |
|---|---|---|---|---|---|
content | string | — | — | — | base64 bytes on write; the server hashes + stores them (never returned) |
git_branch | string | — | — | — | — |
git_dirty | boolean | — | — | — | — |
git_sha | string | — | — | — | — |
kind | string | — | — | — | — |
lib_versions | any | — | — | — | — |
project | string | — | — | — | — |
ref | string | — | — | — | server-derived content address (sha256:<hash>) |
retention_class | string | — | — | — | — |
run_id | string | — | — | — | — |
sha256 | string | — | — | — | SERVER-derived on write; the identity |
ts | integer | — | — | — | — |
visibility | string | — | — | — | — |
tools/list declares a type and a description for each field and nothing further. A — means neither the door nor that operation constrains the field.
Call it
A tools/call carries every argument in one flat object — nothing binds to a path or a query string. Nothing above is required, so every declared argument is shown rather than a guess at which matter.
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "post_v1_research_artifacts",
"arguments": {
"content": "<content>",
"git_branch": "<git_branch>",
"git_dirty": false,
"git_sha": "<git_sha>",
"kind": "<kind>",
"lib_versions": "<lib_versions>",
"project": "<project>",
"ref": "<ref>",
"retention_class": "<retention_class>",
"run_id": "<run_id>",
"sha256": "<sha256>",
"ts": 0,
"visibility": "<visibility>"
}
}
}'Values are the operation's own defaults and enumerated values where it declares them, and a <placeholder> where neither source declares one. git_dirty and ts hold stand-ins that cannot be spelled that way — JSON gives a number, a boolean and a timestamp no placeholder form — so those values are this page's, not the API's. Neither the door nor the operation declares one. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →
The operation behind it
| Operation | Route | Product | Summary |
|---|---|---|---|
post_v1_research_artifacts | POST /v1/research/artifacts | research | Records one research-diary artifact — a board snapshot or a generated report —… |
The same capability over plain HTTP is in the research API reference, on https://api.hanzo.ai.
All 755 tools · The door · API reference
Generated from tools/list on https://api.hanzo.ai/v1/mcp — 833 tools captured 2026-08-01, of which 755 are documented here (the operator surface is not published) (this build read the vendored copy; the door was unreachable).
How is this guide?
get_v1_research_totals
GetResearchTotals returns the caller org's headline aggregate plus a per-kind breakdown — the observatory's poll target.
post_v1_research_experiments
IngestExperiments appends one batch of experiment and attempt versions to the caller org's evidence store, idempotently by content, then rolls it up to the analytics plane best-effort.