get_v1_kb_connectors_provider_callback
CompleteConnectorOAuth finishes an OAuth connection: it exchanges the provider's code for a token, seals that token in KMS, and records the connection.
CompleteConnectorOAuth finishes an OAuth connection: it exchanges the provider's code for a token, seals that token in KMS, and records the connection. THE ORG COMES FROM THE SIGNED STATE, not from a header and not from the provider, so an attacker cannot bind their own account to someone else's org — a tampered, expired or foreign-provider state is refused outright. The token itself is never returned, never written into the document, and never logged; the document holds only its KMS path.
| Tool | get_v1_kb_connectors_provider_callback |
| Door | https://api.hanzo.ai/v1/mcp |
| Method | tools/call (JSON-RPC 2.0) |
| Arguments | 4, 1 required |
| Operation | GET /v1/kb/connectors/{provider}/callback |
| Product | kb |
Arguments
| Field | Type | Required | Default | Values | Description |
|---|---|---|---|---|---|
code | string | — | — | — | Code is the provider's authorization code, exchanged for a token. |
error | string | — | — | — | Error is the provider's denial reason when the user refused consent. |
provider | string | yes | — | — | Provider is the connector completing its flow, from the path. |
state | string | — | — | — | State is the org-bound value this server signed at connect time. |
tools/list declares a type and a description for each field and nothing further. The Required column is taken from GET /v1/kb/connectors/{provider}/callback, the operation this tool dispatches to — the same declaration the REST API validates against. A — means neither the door nor that operation constrains the field.
Call it
A tools/call carries every argument in one flat object — nothing binds to a path or a query string. This call carries exactly the arguments the operation requires, so it is the smallest one that can run.
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "get_v1_kb_connectors_provider_callback",
"arguments": {
"provider": "<provider>"
}
}
}'Values are the operation's own defaults and enumerated values where it declares them, and a <placeholder> where neither source declares one. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →
The operation behind it
| Operation | Route | Product | Summary |
|---|---|---|---|
get_v1_kb_connectors_provider_callback | GET /v1/kb/connectors/{provider}/callback | kb | CompleteConnectorOAuth finishes an OAuth connection: it exchanges the provider's code for… |
The same capability over plain HTTP is in the kb API reference, on https://api.hanzo.ai.
All 755 tools · The door · API reference
Generated from tools/list on https://api.hanzo.ai/v1/mcp — 833 tools captured 2026-08-01, of which 755 are documented here (the operator surface is not published) (this build read the vendored copy; the door was unreachable).
How is this guide?
get_v1_kb_connectors_catalog
ListConnectorCatalog returns the ONE catalog of everything a caller can connect: every first-party connector and every long-tail one, in a single list sorted by provider.
get_v1_kb_connectors_provider_connect
StartConnectorOAuth returns the provider authorize URL the console opens to connect this org's account. There is no server-side redirect — the console stays in control of the navigation.