post_v1_wallets_id_sign
Produces a secp256k1 signature from one of the caller org's wallets over a 32-byte digest, through whichever custody backend that wallet uses.
Produces a secp256k1 signature from one of the caller org's wallets over
a 32-byte digest, through whichever custody backend that wallet uses. Give it
either a digest (32 bytes as hex, signed verbatim) or a message (hashed
with Keccak256 first) — exactly one is required. The private key never leaves
its backend: KMS custody opens the sealed key in-process, MPC custody produces
a threshold signature on the ring. The answer carries the digest that was
signed alongside the signature, so a caller can verify what it got.
| Tool | post_v1_wallets_id_sign |
| Door | https://api.hanzo.ai/v1/mcp |
| Method | tools/call (JSON-RPC 2.0) |
| Arguments | 2 |
| Operation | POST /v1/wallets/{id}/sign |
| Product | wallets |
Arguments
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
digest | string | — | — | Digest is a pre-computed 32-byte digest as hex, with or without the 0x prefix. When present it is signed verbatim and message is ignored. |
message | string | — | — | Message is arbitrary text to hash with Keccak256 and sign. Used only when digest is empty. |
This tool's schema does not declare which fields are required, nor any default, nor any enumerated value set. The columns above are empty because the door publishes nothing there, not because the answer is "none" — where a field is constrained, the constraint is stated in that field's own description.
Call it
A tools/call carries every argument in one flat object — nothing binds to a path or a query string. Every declared argument is shown, because the door marks none of them required.
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "post_v1_wallets_id_sign",
"arguments": {
"digest": "<digest>",
"message": "<message>"
}
}
}'Values are placeholders derived from each field's declared type. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →
The operation behind it
| Operation | Route | Product | Summary |
|---|---|---|---|
cloud_post_v1_wallets_id_sign | POST /v1/wallets/{id}/sign | wallets | Produces a secp256k1 signature from one of the caller org's wallets over a 32-byte digest, |
The same capability over plain HTTP is in the wallets API reference, on https://api.hanzo.ai.
All 834 tools · The door · API reference
Generated from tools/list on https://api.hanzo.ai/v1/mcp — 834 tools captured 2026-08-01 (this build read the vendored copy; the door was unreachable).
How is this guide?