post_v1_orgs_org_entitlements
Post turns products on or off for an org and returns the enabled set afterwards.
Post turns products on or off for an org and returns the enabled set afterwards.
A product may only be ENABLED if the org's plan already ENTITLES it, so enabling never spends new money — a product the plan does not grant answers 402 and the console routes that to an upgrade prompt. DISABLING is never gated. A platform super admin bypasses the plan check (operator comp/grant) and may target any org; everyone else may only change their own. Commerce unreachable is a 503, never an implicit yes.
| Tool | post_v1_orgs_org_entitlements |
| Door | https://api.hanzo.ai/v1/mcp |
| Method | tools/call (JSON-RPC 2.0) |
| Arguments | 2 |
| Operation | POST /v1/orgs/{org}/entitlements |
| Product | orgs |
Arguments
| Field | Type | Required | Default | Values | Description |
|---|---|---|---|---|---|
add | string[] | — | — | — | Add is the product ids to turn ON. Each must already be an ACTIVE entitlement of the org's plan, unless the caller is a platform super admin. |
remove | string[] | — | — | — | Remove is the product ids to turn OFF. Disabling is never gated. |
tools/list declares a type and a description for each field and nothing further. A — means neither the door nor that operation constrains the field.
POST /v1/orgs/{org}/entitlements requires org, which tools/list does not declare on this tool. Where that value goes in a tools/call is not something the door publishes, so this page does not guess — the same capability over plain HTTP is fully specified in the API reference below.
Call it
A tools/call carries every argument in one flat object — nothing binds to a path or a query string. Nothing above is required, so every declared argument is shown rather than a guess at which matter.
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "post_v1_orgs_org_entitlements",
"arguments": {
"add": [
"<add>"
],
"remove": [
"<remove>"
]
}
}
}'Values are the operation's own defaults and enumerated values where it declares them, and a <placeholder> where neither source declares one. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →
The operation behind it
| Operation | Route | Product | Summary |
|---|---|---|---|
post_v1_orgs_org_entitlements | POST /v1/orgs/{org}/entitlements | orgs | Post turns products on or off for an org and returns the enabled set afterwards. |
The same capability over plain HTTP is in the orgs API reference, on https://api.hanzo.ai.
All 755 tools · The door · API reference
Generated from tools/list on https://api.hanzo.ai/v1/mcp — 833 tools captured 2026-08-01, of which 755 are documented here (the operator surface is not published) (this build read the vendored copy; the door was unreachable).
How is this guide?