Hanzo
Cloud MCPiam

post_v1_iam_onboard

Onboard creates the caller's organization.

Onboard creates the caller's organization. Two flows, keyed on whether the caller already has a home org (mirrors app/onboard/route.ts):

  • FIRST-RUN (no owner): create + MOVE the user in as admin, so their next JWT carries the new owner and the cloud scopes everything to it.
  • ADDITIONAL (owner set): create the org but do NOT move the user — a move changes their IAM owner (stripping a SuperAdmin's status + orphaning their current org). They reach the new org via the OrgSwitcher, which re-scopes X-Org-Id without touching IAM membership. A personal-org request from someone who already has an org is meaningless → 409.
Toolpost_v1_iam_onboard
Doorhttps://api.hanzo.ai/v1/mcp
Methodtools/call (JSON-RPC 2.0)
Arguments2
OperationPOST /v1/iam/onboard
Productiam

Arguments

FieldTypeRequiredDefaultValuesDescription
namestringName is the organization's display name. Ignored when personal is true, which derives the name from the caller's own username instead.
personalbooleanPersonal asks for the caller's own workspace: the name is derived from their username and the slug auto-suffixes to stay unique. Meaningless — and refused — for a caller who already has an organization.

tools/list declares a type and a description for each field and nothing further. A means neither the door nor that operation constrains the field.

Call it

A tools/call carries every argument in one flat object — nothing binds to a path or a query string. Nothing above is required, so every declared argument is shown rather than a guess at which matter.

curl -X POST https://api.hanzo.ai/v1/mcp \
  -H "Authorization: Bearer $HANZO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
       "jsonrpc": "2.0",
       "id": 1,
       "method": "tools/call",
       "params": {
         "name": "post_v1_iam_onboard",
         "arguments": {
           "name": "<name>",
           "personal": false
         }
       }
     }'

Values are the operation's own defaults and enumerated values where it declares them, and a <placeholder> where neither source declares one. personal holds a stand-in that cannot be spelled that way — JSON gives a number, a boolean and a timestamp no placeholder form — so that value is this page's, not the API's. Neither the door nor the operation declares one. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →

The operation behind it

OperationRouteProductSummary
post_v1_iam_onboardPOST /v1/iam/onboardiamFinishes setting up the account of whoever is calling — it creates their organization if…

The same capability over plain HTTP is in the iam API reference, on https://api.hanzo.ai.


All 755 tools · The door · API reference

Generated from tools/list on https://api.hanzo.ai/v1/mcp — 833 tools captured 2026-08-01, of which 755 are documented here (the operator surface is not published) (this build read the vendored copy; the door was unreachable).

How is this guide?

On this page