It can only read
No tool creates, edits, deletes, runs or imports anything — in any project, for any credential. That is a property of the server rather than a setting somebody could change.
Hawzu speaks the Model Context Protocol, so Claude, ChatGPT, Cursor or whatever you already work in can answer questions about your test cases, requirements, defects and releases — without leaving the editor, and without seeing anything your own role cannot.
You ask the way you would ask a colleague. The agent works out which questions to put to Hawzu, in what order, and assembles the answer itself.
Which failed tests are blocking 2026.1, and which requirements do they affect?
list_projects Which workspace and project am I looking at?
3 projects · role in each
describe_project_data What can be queried here, in this project's own words?
Record types · your folders, labels and custom fields
get_release_readiness Everything a sign-off needs, in one call.
Not ready · 7 failing cases, joined to their requirements and defects
Seven test cases are failing in 2026.1. Five trace to requirements, three of which have no defect raised against them yet — those are the ones blocking sign-off.
Three calls rather than three of your questions, and your agent does the chaining itself. That is also why no Hawzu AI credits are used: your own AI does the thinking. Inside Hawzu, Oracle answers the same kind of question.
Brings Hawzu to the AI you already use.
Brings AI into Hawzu. See Oracle
Pointing an AI at your test data is a decision worth making on facts. These are the three that matter, and each is a property of the server rather than a promise.
No tool creates, edits, deletes, runs or imports anything — in any project, for any credential. That is a property of the server rather than a setting somebody could change.
A client reads what the credential behind it reads, and never more. If your role cannot open the Defects screen, a connected agent is told it was refused — not handed an empty list. That distinction is the whole thing: an AI told “no rows” will report there are no open defects when the truth is that it was not allowed to look.
Your own AI does the thinking, on your own account with whoever provides it, so no Hawzu credits are used. It is on every plan, including the free one.
All six are reads. You never call them yourself — the agent does — but knowing what exists is what tells you what it can and cannot answer.
list_projects Every workspace and project the credential can reach, with its role in each.
The starting point. Nothing else is useful until the client knows where it is.
describe_project_data What can be queried here: the record types, their fields, and the values those fields actually hold.
Per-project, because your custom fields are. It reads your own names rather than guessing at them.
query_records The general one Runs a structured query and returns rows, a count, or counts per group.
The one that does the work — “test cases in this release that failed and have an open defect” is one question, not four.
get_record One whole record by its human code — CHK-123, REQ-12, DEF-4.
A query returns the columns it asked for; this returns everything.
get_execution_history Executions of one test case, newest first: the run, the result, who ran it and when.
Answers “has this ever passed?” and “when did this start failing?”, which a query over current state cannot.
get_release_readiness The Go/No-Go verdict and the reasons behind it, every gate, coverage, defect health, and each failing case joined to what it touches.
One call instead of eight. The reasons are the same ones Hawzu shows on screen, so the agent reports why a release is blocked rather than inventing a story from the numbers.
Full reference in the documentation.
Which one you use depends on the client rather than on preference — most support only one. The server is a single address, with nothing to install and no gateway to run.
Pasted into the client's configuration as a header. A workspace administrator issues it, it reads every project in that workspace and nothing anywhere else, and there is no scope to pick — give it a name and create it.
Claude Code · Cursor · VS Code · the OpenAI API
Opens a browser, asks you to approve the connection for one workspace, and hands the client a credential that acts as you in it. It expires hourly and refreshes silently. You can disconnect it at any time, and so can an administrator of that workspace.
Claude · Claude Desktop · ChatGPT
https://app.hawzu.com/mcp It supports every version of the protocol from March 2025 to the current one, so a client does not have to be recent to connect.
Worth reading before you connect rather than after you hit one.
No Canon documents, no Hawzu documentation, no charts. Those are Hawzu features, not MCP ones.
With a continuation, so an agent can keep asking — but a narrower question or a count is almost always the better move, and the client is told so.
An oversized result is refused with advice to narrow it, never quietly truncated. Half a table, read confidently, is worse than no table.
Far more than a person asks through an agent; far less than a runaway loop needs.
A token reads the workspace it was issued for. A sign-in connection reads the one workspace you approved, and connecting to a second is a second connection.
There is no tool to enable, no scope to grant and no setting to change. The write half does not exist.
A refused call is recorded as a refusal rather than as an empty answer — which is what makes “there are none” trustworthy when an agent says it. What is kept, and for how long, is in the security documentation.
The Model Context Protocol — an open standard for connecting an AI client to a source of data or tools. Hawzu runs a server that speaks it, so an agent you already use can read your test cases, requirements, defects, releases and runs without anybody building an integration.
No. Every tool is a read, and there is no configuration that makes it otherwise — no tool creates, edits, deletes, executes or imports anything, for any credential. It is a property of what the server exposes rather than a permission it happens to lack.
No. A connection reads exactly what the credential behind it reads. If your role cannot see defects, a connected client is refused when it asks about them — and told it was refused, rather than shown an empty list, because an empty list is indistinguishable from a correct answer of “none”.
No. Your own AI does the thinking, on your own account with that provider, so no Hawzu credits are used. It is on every plan, including the free one.
Anything that speaks the protocol. Claude Code, Cursor and VS Code take a token as a header; Claude, Claude Desktop and ChatGPT connect by signing in with Hawzu; the OpenAI API takes the server address and a token. There is nothing to install and no gateway to run — the server is a single HTTPS address.
The question, not the answer. Each call is recorded — which tool, whether it succeeded or was refused, how many rows came back and how long it took — and for a sign-in connection, which application asked. Nothing that comes back is recorded: not the rows, not the records, not their contents. Records are kept 90 days.
Revoke the token, or disconnect the app in Settings → Security. A workspace administrator can disconnect any connection into their workspace, including one somebody else approved, and the client stops on its next call.
Every feature on every plan. Free for five people, $20 per member after — no credit card.