reference
reference: 6 operations.
reference: 6 operations. Name one in "op" and pass that operation's own arguments in "input". describe returns an operation's input schema.
| Tool | reference |
| Door | https://api.hanzo.ai/v1/mcp |
| Method | tools/call (JSON-RPC 2.0) |
| Arguments | 2, 1 required |
| Operation | DELETE /v1/risk/reference/{set} · GET /v1/risk/reference/{set} · GET /v1/risk/reference · POST /v1/risk/reference/refresh · POST /v1/risk/reference/resolve · PUT /v1/risk/reference/{set} |
| Product | risk |
Arguments
| Field | Type | Required | Default | Values | Description |
|---|---|---|---|---|---|
input | object | — | — | — | arguments for the chosen op |
op | string | yes | — | — | — |
tools/list declares a type, a description, which fields are required and an enumerated value set for each field and nothing further, and every column above is the door's own. This tool takes an operation name and that operation's arguments, so what the document constrains is what goes inside input, field by field, on the operation you name — ask describe for that. A — means the door does not constrain the field.
Call it
A tools/call carries every argument in one flat object — nothing binds to a path or a query string. This call carries exactly the arguments the operation requires, so it is the smallest one that can run.
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "reference",
"arguments": {
"op": "<op>"
}
}
}'Values are the operation's own defaults and enumerated values where it declares them, and a <placeholder> where neither source declares one. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →
The operation behind it
reference dispatches to 6 operations.
| Operation | Route | Product | Summary |
|---|---|---|---|
riskClearReference | DELETE /v1/risk/reference/{set} | risk | Removes one of your organisation's overrides. |
riskReference | GET /v1/risk/reference/{set} | risk | Reference describes one set and lists your org's overrides in it. |
riskReferenceSets | GET /v1/risk/reference | risk | Lists every set this plane publishes, with its version and how fresh it is. |
riskRefreshReference | POST /v1/risk/reference/refresh | risk | Takes a new version of one set. |
riskResolveReference | POST /v1/risk/reference/resolve | risk | Looks keys up against the reference plane. |
riskSetReference | PUT /v1/risk/reference/{set} | risk | Writes your organisation's own allow and deny entries over a set. |
The same capability over plain HTTP is in the risk API reference, on https://api.hanzo.ai.
How is this guide?