Risk
risk: 10 operations.
Also for this capability: API · CLI · MCP · SDKs
risk: 10 operations. Name one in "op" and pass that operation's own arguments in "input". describe returns an operation's input schema.
| Tool | risk |
| Address | https://api.hanzo.ai/v1/mcp |
| Method | tools/call (JSON-RPC 2.0) |
| Arguments | 2, 1 required |
| Operation | GET /v1/risk/health · PUT /v1/risk/state/model · GET /v1/risk/features · POST /v1/risk/learn · GET /v1/risk/policy · POST /v1/risk/state/model · POST /v1/risk/score · POST /v1/risk/search · GET /v1/risk/search/{id} · GET /v1/risk/state |
| Product | risk |
Arguments
| Field | Type | Required | Default | Values | Description |
|---|---|---|---|---|---|
input | object | — | — | — | arguments for the chosen op |
op | string | yes | — | — | — |
tools/list declares a type, a description, which fields are required and an enumerated value set for each field and nothing further, and every column above is MCP's own. This tool takes an operation name and that operation's arguments, so what the document constrains is what goes inside input, field by field, on the operation you name — ask describe for that. A — means MCP does not constrain the field.
Call it
A tools/call carries every argument in one flat object — nothing binds to a path or a query string. This call carries exactly the arguments the operation requires, so it is the smallest one that can run.
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "risk",
"arguments": {
"op": "get_risk_health"
}
}
}'Values are the operation's own defaults and enumerated values where it declares them, and a <placeholder> where neither source declares one. tools/list needs no credential; tools/call does — called without one MCP answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →
The operation behind it
risk dispatches to 10 operations.
| Operation | Route | Product | Summary |
|---|---|---|---|
get_risk_health | GET /v1/risk/health | risk | Whether the risk model plane can actually work right now |
riskAdoptModel | PUT /v1/risk/state/model | risk | Put one of your organisation's own published model values in force |
riskFeatures | GET /v1/risk/features | risk | The feature catalogue: what the model reads, and what your surface carries |
riskLearn | POST /v1/risk/learn | risk | Teach your organisation's own model from its own events |
riskPolicy | GET /v1/risk/policy | risk | Your organisation's decision-regime history, and which version is in force |
riskPublishModel | POST /v1/risk/state/model | risk | Publish your organisation's model as a named, immutable value |
riskScore | POST /v1/risk/score | risk | Score one event against your organisation's own model |
riskSearch | POST /v1/risk/search | risk | Search exhaustively for the model shape that fits your own history |
riskSearchResult | GET /v1/risk/search/{id} | risk | Read back one exhaustive search |
riskState | GET /v1/risk/state | risk | Report your organisation's model: what it learned, and what it realised |
The same capability over plain HTTP is in the risk API reference, on https://api.hanzo.ai.
Generated from tools/list on https://api.hanzo.ai/v1/mcp — 121 tools captured 2026-08-16.
How is this guide?