Hanzo
Cloud MCPsbom

post_v1_sbom

Ingest persists a CycloneDX SBOM's components keyed by image digest. Gated to a validated SuperAdmin (owner == AdminOrg) — the canonical cloud super-admin check, which the build fleet / CI carries.

Ingest persists a CycloneDX SBOM's components keyed by image digest. Gated to a validated SuperAdmin (owner == AdminOrg) — the canonical cloud super-admin check, which the build fleet / CI carries. Re-ingest is idempotent: rows share the (digest, name, version, purl) ORDER BY, so ReplacingMergeTree keeps the latest by ingested_at (and resolve reads FINAL).

Toolpost_v1_sbom
Doorhttps://api.hanzo.ai/v1/mcp
Methodtools/call (JSON-RPC 2.0)
Arguments6
OperationPOST /v1/sbom
Productsbom

Arguments

FieldTypeRequiredDefaultValuesDescription
documentanyDocument is the raw CycloneDX bill of materials, any JSON. Its components[] are flattened and persisted; nothing else is read or stored.
formatstringFormat names the document format; "cyclonedx" is the only one parsed.
gitShastringGitSha is the commit the image was built from.
imageDigeststringImageDigest is the content-addressed digest (sha256:…) the components are keyed under. Required — it, not a tenant, is what an SBOM belongs to.
imageRefstringImageRef is the human-readable image reference the digest was published as. A resolve matches on either this or the digest.
sourceRepostringSourceRepo is the repository the image was built from.

tools/list declares a type and a description for each field and nothing further. A means neither the door nor that operation constrains the field.

Call it

A tools/call carries every argument in one flat object — nothing binds to a path or a query string. Nothing above is required, so every declared argument is shown rather than a guess at which matter.

curl -X POST https://api.hanzo.ai/v1/mcp \
  -H "Authorization: Bearer $HANZO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
       "jsonrpc": "2.0",
       "id": 1,
       "method": "tools/call",
       "params": {
         "name": "post_v1_sbom",
         "arguments": {
           "document": "<document>",
           "format": "<format>",
           "gitSha": "<gitSha>",
           "imageDigest": "<imageDigest>",
           "imageRef": "<imageRef>",
           "sourceRepo": "<sourceRepo>"
         }
       }
     }'

Values are the operation's own defaults and enumerated values where it declares them, and a <placeholder> where neither source declares one. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →

The operation behind it

OperationRouteProductSummary
cloud_post_v1_sbomPOST /v1/sbomsbomIngest persists a CycloneDX SBOM's components keyed by image digest.

The same capability over plain HTTP is in the sbom API reference, on https://api.hanzo.ai.


All 833 tools · The door · API reference

Generated from tools/list on https://api.hanzo.ai/v1/mcp — 833 tools captured 2026-08-01 (this build read the vendored copy; the door was unreachable).

How is this guide?

On this page