Hanzo
Cloud MCPresearch

post_v1_research_artifacts

RecordResearchArtifact records one research-diary artifact — a board snapshot or a generated report — CONTENT-ADDRESSED inside the trust boundary.

RecordResearchArtifact records one research-diary artifact — a board snapshot or a generated report — CONTENT-ADDRESSED inside the trust boundary. The caller submits the bytes as base64 content; the SERVER hashes them and THAT hash is the identity and the ref, so the address can never be poisoned by a client-asserted one. A client-supplied sha256, if present, must match the bytes. The project is the SERVER's value and visibility is forced private. Re-posting the same bytes is a no-op that reports created=false.

Toolpost_v1_research_artifacts
Doorhttps://api.hanzo.ai/v1/mcp
Methodtools/call (JSON-RPC 2.0)
Arguments13
OperationPOST /v1/research/artifacts
Productresearch

Arguments

FieldTypeRequiredDefaultValuesDescription
contentstringbase64 bytes on write; the server hashes + stores them (never returned)
git_branchstring
git_dirtyboolean
git_shastring
kindstring
lib_versionsany
projectstring
refstringserver-derived content address (sha256:<hash>)
retention_classstring
run_idstring
sha256stringSERVER-derived on write; the identity
tsinteger
visibilitystring

tools/list declares a type and a description for each field and nothing further. A means neither the door nor that operation constrains the field.

Call it

A tools/call carries every argument in one flat object — nothing binds to a path or a query string. Nothing above is required, so every declared argument is shown rather than a guess at which matter.

curl -X POST https://api.hanzo.ai/v1/mcp \
  -H "Authorization: Bearer $HANZO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
       "jsonrpc": "2.0",
       "id": 1,
       "method": "tools/call",
       "params": {
         "name": "post_v1_research_artifacts",
         "arguments": {
           "content": "<content>",
           "git_branch": "<git_branch>",
           "git_dirty": false,
           "git_sha": "<git_sha>",
           "kind": "<kind>",
           "lib_versions": "<lib_versions>",
           "project": "<project>",
           "ref": "<ref>",
           "retention_class": "<retention_class>",
           "run_id": "<run_id>",
           "sha256": "<sha256>",
           "ts": 0,
           "visibility": "<visibility>"
         }
       }
     }'

Values are the operation's own defaults and enumerated values where it declares them, and a <placeholder> where neither source declares one. git_dirty and ts hold stand-ins that cannot be spelled that way — JSON gives a number, a boolean and a timestamp no placeholder form — so those values are this page's, not the API's. Neither the door nor the operation declares one. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →

The operation behind it

OperationRouteProductSummary
post_v1_research_artifactsPOST /v1/research/artifactsresearchRecords one research-diary artifact — a board snapshot or a generated report —…

The same capability over plain HTTP is in the research API reference, on https://api.hanzo.ai.


All 755 tools · The door · API reference

Generated from tools/list on https://api.hanzo.ai/v1/mcp — 833 tools captured 2026-08-01, of which 755 are documented here (the operator surface is not published) (this build read the vendored copy; the door was unreachable).

How is this guide?

On this page