post_v1_sbom
Ingest persists a CycloneDX SBOM's components keyed by image digest. Gated to a validated SuperAdmin (owner == AdminOrg) — the canonical cloud super-admin check, which the build fleet / CI carries.
Ingest persists a CycloneDX SBOM's components keyed by image digest. Gated to a validated SuperAdmin (owner == AdminOrg) — the canonical cloud super-admin check, which the build fleet / CI carries. Re-ingest is idempotent: rows share the (digest, name, version, purl) ORDER BY, so ReplacingMergeTree keeps the latest by ingested_at (and resolve reads FINAL).
| Tool | post_v1_sbom |
| Door | https://api.hanzo.ai/v1/mcp |
| Method | tools/call (JSON-RPC 2.0) |
| Arguments | 6 |
| Operation | POST /v1/sbom |
| Product | sbom |
Arguments
| Field | Type | Required | Default | Values | Description |
|---|---|---|---|---|---|
document | any | — | — | — | Document is the raw CycloneDX bill of materials, any JSON. Its components[] are flattened and persisted; nothing else is read or stored. |
format | string | — | — | — | Format names the document format; "cyclonedx" is the only one parsed. |
gitSha | string | — | — | — | GitSha is the commit the image was built from. |
imageDigest | string | — | — | — | ImageDigest is the content-addressed digest (sha256:…) the components are keyed under. Required — it, not a tenant, is what an SBOM belongs to. |
imageRef | string | — | — | — | ImageRef is the human-readable image reference the digest was published as. A resolve matches on either this or the digest. |
sourceRepo | string | — | — | — | SourceRepo is the repository the image was built from. |
tools/list declares a type and a description for each field and nothing further. A — means neither the door nor that operation constrains the field.
Call it
A tools/call carries every argument in one flat object — nothing binds to a path or a query string. Nothing above is required, so every declared argument is shown rather than a guess at which matter.
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "post_v1_sbom",
"arguments": {
"document": "<document>",
"format": "<format>",
"gitSha": "<gitSha>",
"imageDigest": "<imageDigest>",
"imageRef": "<imageRef>",
"sourceRepo": "<sourceRepo>"
}
}
}'Values are the operation's own defaults and enumerated values where it declares them, and a <placeholder> where neither source declares one. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →
The operation behind it
| Operation | Route | Product | Summary |
|---|---|---|---|
cloud_post_v1_sbom | POST /v1/sbom | sbom | Ingest persists a CycloneDX SBOM's components keyed by image digest. |
The same capability over plain HTTP is in the sbom API reference, on https://api.hanzo.ai.
All 833 tools · The door · API reference
Generated from tools/list on https://api.hanzo.ai/v1/mcp — 833 tools captured 2026-08-01 (this build read the vendored copy; the door was unreachable).
How is this guide?