Hanzo
Cloud MCPsettings

put_v1_settings_product

PutSettings writes the caller org's configuration for one product and answers the stored result, secrets masked.

PutSettings writes the caller org's configuration for one product and answers the stored result, secrets masked. Secret VALUES are sealed into KMS under orgs/{org}/settings/{product}/{key} and never touch this deployment's database; with no KMS configured a write that carries any secret is refused whole (503) rather than dropping it or persisting it in the clear. A secret the body omits keeps its stored value, so a partial write never silently clears one.

Toolput_v1_settings_product
Doorhttps://api.hanzo.ai/v1/mcp
Methodtools/call (JSON-RPC 2.0)
Arguments3
OperationPUT /v1/settings/{product}
Productsettings

Arguments

FieldTypeRequiredDefaultValuesDescription
configobjectConfig is the product's non-secret configuration, stored verbatim. Bounded at 64 KiB once serialized. Omit it to store an empty object.
productstringProduct is the catalog slug, from the PATH. zip binds the path last, so the URL names the product being written whatever a body field claims.
secretsobjectSecrets are the secret fields, by name. Each VALUE is sealed into KMS and never reaches this deployment's database; a value that is empty or equal to the mask the read path returns means "unchanged" and is skipped, so a console round-trip cannot blank a stored secret. A key must match ^[a-z0-9][a-z0-9._-]{0,62}$, a value is bounded at 8 KiB, and an org may hold at most 64 secret fields per product.

tools/list declares a type and a description for each field and nothing further. A means neither the door nor that operation constrains the field.

Call it

A tools/call carries every argument in one flat object — nothing binds to a path or a query string. Nothing above is required, so every declared argument is shown rather than a guess at which matter.

curl -X POST https://api.hanzo.ai/v1/mcp \
  -H "Authorization: Bearer $HANZO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
       "jsonrpc": "2.0",
       "id": 1,
       "method": "tools/call",
       "params": {
         "name": "put_v1_settings_product",
         "arguments": {
           "config": {},
           "product": "<product>",
           "secrets": {}
         }
       }
     }'

Values are the operation's own defaults and enumerated values where it declares them, and a <placeholder> where neither source declares one. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →

The operation behind it

OperationRouteProductSummary
put_v1_settings_productPUT /v1/settings/{product}settingsWrites the caller org's configuration for one product and answers the stored result,…

The same capability over plain HTTP is in the settings API reference, on https://api.hanzo.ai.


All 755 tools · The door · API reference

Generated from tools/list on https://api.hanzo.ai/v1/mcp — 833 tools captured 2026-08-01, of which 755 are documented here (the operator surface is not published) (this build read the vendored copy; the door was unreachable).

How is this guide?

On this page