post_v1_cloud_provider_accounts_label_sync
Re-discovers one already-linked cloud account and reconciles what it folded: kubeconfigs are refreshed, clusters that appeared since the last sync are folded, and clusters this account folded that…
Re-discovers one already-linked cloud account and reconciles what it folded: kubeconfigs are refreshed, clusters that appeared since the last sync are folded, and clusters this account folded that the provider no longer returns are detached — only this account's own, in the fleet shard it was linked into.
It is idempotent, it reads the credential already sealed at link time, and a discovery failure leaves the existing fold set alone rather than mass-detaching it. An account this org has not linked is not found. Requires org admin.
| Tool | post_v1_cloud_provider_accounts_label_sync |
| Door | https://api.hanzo.ai/v1/mcp |
| Method | tools/call (JSON-RPC 2.0) |
| Arguments | 2, 2 required |
| Operation | POST /v1/cloud/{provider}/accounts/{label}/sync |
| Product | cloud |
Arguments
| Field | Type | Required | Default | Values | Description |
|---|---|---|---|---|---|
label | string | yes | — | — | Label is the org-chosen name of the account within that provider. Empty means "default"; anything outside 1–64 of [A-Za-z0-9._-] is refused. |
provider | string | yes | — | — | Provider is the cloud the account belongs to: digitalocean, aws, gcp or azure. An unknown provider is not found. |
tools/list declares a type and a description for each field and nothing further. The Required column is taken from POST /v1/cloud/{provider}/accounts/{label}/sync, the operation this tool dispatches to — the same declaration the REST API validates against. A — means neither the door nor that operation constrains the field.
Call it
A tools/call carries every argument in one flat object — nothing binds to a path or a query string. This call carries exactly the arguments the operation requires, so it is the smallest one that can run.
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "post_v1_cloud_provider_accounts_label_sync",
"arguments": {
"label": "<label>",
"provider": "<provider>"
}
}
}'Values are the operation's own defaults and enumerated values where it declares them, and a <placeholder> where neither source declares one. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →
The operation behind it
| Operation | Route | Product | Summary |
|---|---|---|---|
cloud_post_v1_cloud_provider_accounts_label_sync | POST /v1/cloud/{provider}/accounts/{label}/sync | cloud | Re-discovers one already-linked cloud account and reconciles what it folded: kubeconfigs… |
The same capability over plain HTTP is in the cloud API reference, on https://api.hanzo.ai.
All 833 tools · The door · API reference
Generated from tools/list on https://api.hanzo.ai/v1/mcp — 833 tools captured 2026-08-01 (this build read the vendored copy; the door was unreachable).
How is this guide?
post_v1_cloud_provider_accounts
Links one of the caller org's cloud accounts and folds the Kubernetes clusters it finds there into the ONE Hanzo fleet, so they appear at /v1/clusters and can run work like any managed or…
post_v1_keys
MintKey creates — or rotates — the caller's API key of the requested type and returns it ONCE. A real IAM failure surfaces as 502, never a fabricated key.