post_v1_platform_sites_slug_publish
PublishSite promotes a build output into a new release AND goes live with it — create+activate in one call, which is the 99% path.
PublishSite promotes a build output into a new release AND goes live with it — create+activate in one call, which is the 99% path.
It is exactly the two halves in sequence with no extra semantics, so the
staged flow and the one-shot flow can never drift apart: source is promoted
under the same org-relative rule and the same guards CreateRelease applies,
then the site's pointer is flipped to it, the public host is claimed and the
edge is purged. Idempotent on unchanged bytes — same manifest, same release id,
no copy — and billed once, after the release exists.
Scope: a validated principal is required (403 without one) and the site is resolved within that principal's org, so another tenant's slug is a 404.
| Tool | post_v1_platform_sites_slug_publish |
| Door | https://api.hanzo.ai/v1/mcp |
| Method | tools/call (JSON-RPC 2.0) |
| Arguments | 2 |
| Operation | POST /v1/platform/sites/{slug}/publish |
| Product | platform |
Arguments
| Field | Type | Required | Default | Values | Description |
|---|---|---|---|---|---|
slug | string | — | — | — | Slug is the site to publish, from the path. |
source | string | — | — | — | Source is the build output to promote, as a path RELATIVE to your org's own storage space — never a URL and never a bucket. The org segment is prepended server-side from the validated principal, so the worst a hostile source can address is something your own org already owns. |
tools/list declares a type and a description for each field and nothing further. A — means neither the door nor that operation constrains the field.
Call it
A tools/call carries every argument in one flat object — nothing binds to a path or a query string. Nothing above is required, so every declared argument is shown rather than a guess at which matter.
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "post_v1_platform_sites_slug_publish",
"arguments": {
"slug": "<slug>",
"source": "<source>"
}
}
}'Values are the operation's own defaults and enumerated values where it declares them, and a <placeholder> where neither source declares one. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →
The operation behind it
| Operation | Route | Product | Summary |
|---|---|---|---|
post_v1_platform_sites_slug_publish | POST /v1/platform/sites/{slug}/publish | platform | Promotes a build output into a new release AND goes live with it — create+activate in one… |
The same capability over plain HTTP is in the platform API reference, on https://api.hanzo.ai.
All 755 tools · The door · API reference
Generated from tools/list on https://api.hanzo.ai/v1/mcp — 833 tools captured 2026-08-01, of which 755 are documented here (the operator surface is not published) (this build read the vendored copy; the door was unreachable).
How is this guide?