put_v1_ingress_tls
PutTLS replaces the caller org's ACME intent and hot-applies what can be hot-applied.
PutTLS replaces the caller org's ACME intent and hot-applies what can be hot-applied. extraHosts are normalized and validated, then feed the ACME HostPolicy on the reload this op performs, alongside the per-route tls flags. acmeEmail and staging bind an ACME account for the lifetime of an edge process, so they only take effect when the edge (re)starts — the returned note says so.
| Tool | put_v1_ingress_tls |
| Door | https://api.hanzo.ai/v1/mcp |
| Method | tools/call (JSON-RPC 2.0) |
| Arguments | 3 |
| Operation | PUT /v1/ingress/tls |
| Product | ingress |
Arguments
| Field | Type | Required | Default | Values | Description |
|---|---|---|---|---|---|
acmeEmail | string | — | — | — | ACMEEmail is the ACME account email. It binds an account for the lifetime of an edge process, so it applies only when the edge (re)starts. |
extraHosts | string[] | — | — | — | ExtraHosts get certificates without owning a route — at most 256. They feed the ACME HostPolicy and hot-apply on the next reload. |
staging | boolean | — | — | — | Staging issues from Let's Encrypt's staging directory (untrusted certs, high rate limits). Like ACMEEmail it applies only when the edge (re)starts. |
tools/list declares a type and a description for each field and nothing further. A — means neither the door nor that operation constrains the field.
Call it
A tools/call carries every argument in one flat object — nothing binds to a path or a query string. Nothing above is required, so every declared argument is shown rather than a guess at which matter.
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "put_v1_ingress_tls",
"arguments": {
"acmeEmail": "<acmeEmail>",
"extraHosts": [
"<extraHosts>"
],
"staging": false
}
}
}'Values are the operation's own defaults and enumerated values where it declares them, and a <placeholder> where neither source declares one. staging holds a stand-in that cannot be spelled that way — JSON gives a number, a boolean and a timestamp no placeholder form — so that value is this page's, not the API's. Neither the door nor the operation declares one. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →
The operation behind it
| Operation | Route | Product | Summary |
|---|---|---|---|
put_v1_ingress_tls | PUT /v1/ingress/tls | ingress | PutTLS replaces the caller org's ACME intent and hot-applies what can be hot-applied. |
The same capability over plain HTTP is in the ingress API reference, on https://api.hanzo.ai.
All 755 tools · The door · API reference
Generated from tools/list on https://api.hanzo.ai/v1/mcp — 833 tools captured 2026-08-01, of which 755 are documented here (the operator surface is not published) (this build read the vendored copy; the door was unreachable).
How is this guide?