post_v1_connectors_provider_credential
Is the direct intake path: a customer-held token/setup-token (Verify) or an externally obtained OAuth bundle from the CLI's local PKCE (Adopt).
Is the direct intake path: a customer-held token/setup-token (Verify) or an externally obtained OAuth bundle from the CLI's local PKCE (Adopt). ALWAYS verify-before-store: a bad credential is refused and NOTHING is persisted (connectByCredential's fail-closed order).
| Tool | post_v1_connectors_provider_credential |
| Door | https://api.hanzo.ai/v1/mcp |
| Method | tools/call (JSON-RPC 2.0) |
| Arguments | 5 |
| Operation | POST /v1/connectors/{provider}/credential |
| Product | connectors |
Arguments
| Field | Type | Required | Default | Values | Description |
|---|---|---|---|---|---|
accountId | string | — | — | — | AccountID scopes the credential where the provider's Verify needs one. |
label | string | — | — | — | Label names this connection; empty means "default". |
oauth | oauthBundleIn | — | — | — | OAuth is a bundle the CLI already obtained through its own local PKCE flow. Present ⇒ the Adopt path; absent ⇒ the Token path. |
provider | string | — | — | — | Provider is the user-scoped provider's registry id, from the path. |
token | string | — | — | — | Token is the customer-held credential for the Verify path. Read on STDIN by the CLI, never argv; never logged, echoed, or stored outside KMS. |
tools/list declares a type and a description for each field and nothing further. A — means neither the door nor that operation constrains the field.
Object types
oauthBundleIn is an object this tool's fields are made of, declared inside the tool's own schema and enumerated in full below.
oauthBundleIn
| Field | Type | Required | Default | Values | Description |
|---|---|---|---|---|---|
access | string | — | — | — | Access is the access token. |
account | string | — | — | — | Account is the account label the flow reported; sanitized on ingest. |
refresh | string | — | — | — | Refresh is the refresh token. It is sealed and NEVER handed back out. |
Call it
A tools/call carries every argument in one flat object — nothing binds to a path or a query string. Nothing above is required, so every declared argument is shown rather than a guess at which matter.
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "post_v1_connectors_provider_credential",
"arguments": {
"accountId": "<accountId>",
"label": "<label>",
"oauth": {
"access": "<access>",
"account": "<account>",
"refresh": "<refresh>"
},
"provider": "<provider>",
"token": "<token>"
}
}
}'Values are the operation's own defaults and enumerated values where it declares them, and a <placeholder> where neither source declares one. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →
The operation behind it
| Operation | Route | Product | Summary |
|---|---|---|---|
post_v1_connectors_provider_credential | POST /v1/connectors/{provider}/credential | connectors | Is the direct intake path: a customer-held token/setup-token (Verify) or an externally… |
The same capability over plain HTTP is in the connectors API reference, on https://api.hanzo.ai.
All 755 tools · The door · API reference
Generated from tools/list on https://api.hanzo.ai/v1/mcp — 833 tools captured 2026-08-01, of which 755 are documented here (the operator surface is not published) (this build read the vendored copy; the door was unreachable).
How is this guide?