post_v1_research_artifacts
RecordResearchArtifact records one research-diary artifact — a board snapshot or a generated report — CONTENT-ADDRESSED inside the trust boundary.
RecordResearchArtifact records one research-diary artifact — a board snapshot or a
generated report — CONTENT-ADDRESSED inside the trust boundary. The caller submits
the bytes as base64 content; the SERVER hashes them and THAT hash is the identity
and the ref, so the address can never be poisoned by a client-asserted one. A
client-supplied sha256, if present, must match the bytes. The project is the
SERVER's value and visibility is forced private. Re-posting the same bytes is a
no-op that reports created=false.
| Tool | post_v1_research_artifacts |
| Door | https://api.hanzo.ai/v1/mcp |
| Method | tools/call (JSON-RPC 2.0) |
| Arguments | 13 |
| Operation | POST /v1/research/artifacts |
| Product | research |
Arguments
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
content | string | — | — | base64 bytes on write; the server hashes + stores them (never returned) |
git_branch | string | — | — | — |
git_dirty | boolean | — | — | — |
git_sha | string | — | — | — |
kind | string | — | — | — |
lib_versions | any | — | — | — |
project | string | — | — | — |
ref | string | — | — | server-derived content address (sha256:<hash>) |
retention_class | string | — | — | — |
run_id | string | — | — | — |
sha256 | string | — | — | SERVER-derived on write; the identity |
ts | integer | — | — | — |
visibility | string | — | — | — |
This tool's schema does not declare which fields are required, nor any default, nor any enumerated value set. The columns above are empty because the door publishes nothing there, not because the answer is "none" — where a field is constrained, the constraint is stated in that field's own description.
Call it
A tools/call carries every argument in one flat object — nothing binds to a path or a query string. Every declared argument is shown, because the door marks none of them required.
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "post_v1_research_artifacts",
"arguments": {
"content": "<content>",
"git_branch": "<git_branch>",
"git_dirty": false,
"git_sha": "<git_sha>",
"kind": "<kind>",
"lib_versions": "<lib_versions>",
"project": "<project>",
"ref": "<ref>",
"retention_class": "<retention_class>",
"run_id": "<run_id>",
"sha256": "<sha256>",
"ts": 0,
"visibility": "<visibility>"
}
}
}'Values are placeholders derived from each field's declared type. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →
The operation behind it
| Operation | Route | Product | Summary |
|---|---|---|---|
cloud_post_v1_research_artifacts | POST /v1/research/artifacts | research | RecordResearchArtifact records one research-diary artifact — a board snapshot or a generat |
The same capability over plain HTTP is in the research API reference, on https://api.hanzo.ai.
All 834 tools · The door · API reference
Generated from tools/list on https://api.hanzo.ai/v1/mcp — 834 tools captured 2026-08-01 (this build read the vendored copy; the door was unreachable).
How is this guide?