post_v1_tools_call
CallTool runs one of the caller's activated tools and answers with its output.
CallTool runs one of the caller's activated tools and answers with its output.
This is the door onto the tool plane's DYNAMIC half — the half no build-time catalogue can hold, because it is per-tenant: an org's connected connector actions, its authored skills, its agents and functions, and the tools of every external MCP server it registered. A tool's existence, its price and its activation are all rows, not code, so they cannot be known until the caller is.
One policy, the registry's: resolve by precedence, refuse an unactivated tool 403, settle a priced one through the x402 seam or fail closed 402, then dispatch to the winning source bound to the caller's own (org, project). One metered unit, one audit record. A caller can only ever dispatch its own tools.
Discovery is GET /v1/tools — ?activated=true for the callable set.
| Tool | post_v1_tools_call |
| Door | https://api.hanzo.ai/v1/mcp |
| Method | tools/call (JSON-RPC 2.0) |
| Arguments | 2 |
| Operation | POST /v1/tools/call |
| Product | tools |
Arguments
| Field | Type | Required | Default | Values | Description |
|---|---|---|---|---|---|
arguments | object | — | — | — | Arguments is the tool's own input object, passed through verbatim to whichever source owns it. |
name | string | — | — | — | Name is the tool to run, exactly as GET /v1/tools reports it. |
tools/list declares a type and a description for each field and nothing further. A — means neither the door nor that operation constrains the field.
Call it
A tools/call carries every argument in one flat object — nothing binds to a path or a query string. Nothing above is required, so every declared argument is shown rather than a guess at which matter.
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "post_v1_tools_call",
"arguments": {
"arguments": {},
"name": "<name>"
}
}
}'Values are the operation's own defaults and enumerated values where it declares them, and a <placeholder> where neither source declares one. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →
The operation behind it
| Operation | Route | Product | Summary |
|---|---|---|---|
post_v1_tools_call | POST /v1/tools/call | tools | Runs one of the caller's activated tools and answers with its output. |
The same capability over plain HTTP is in the tools API reference, on https://api.hanzo.ai.
All 755 tools · The door · API reference
Generated from tools/list on https://api.hanzo.ai/v1/mcp — 833 tools captured 2026-08-01, of which 755 are documented here (the operator surface is not published) (this build read the vendored copy; the door was unreachable).
How is this guide?
patch_v1_tools_catalog_id
CurateListing sets what WE say about one catalog entry — hidden, featured, official, logo — and answers with the stored listing. SuperAdmin only; every other caller is refused.
post_v1_tools_catalog_sync
SyncCatalog pulls the public MCP registry into our canonical copy and reports what changed. SuperAdmin only; every other caller is refused.