delete_v1_iam_keys
RevokeKey revokes the caller's own API key of the requested class.
RevokeKey revokes the caller's own API key of the requested class. The class is
the same field mint takes — ?type=publishable, defaulting to secret — so
revoking the key that ships in a browser bundle does not sign its holder out of
their own API: the other key keeps working.
Revoking is how a key is replaced when it does not need replacing; minting the same class again rotates it in one step. IAM drops the credential immediately, but the gateway caches keys for a few minutes, so a request that beat the cache expiry may still be served.
For callers written against the older shape, the class is also accepted in a JSON
request body, read only when ?type= is absent.
| Tool | delete_v1_iam_keys |
| Door | https://api.hanzo.ai/v1/mcp |
| Method | tools/call (JSON-RPC 2.0) |
| Arguments | 1 |
| Operation | none in the OpenAPI document |
| Product | — |
Arguments
| Field | Type | Required | Default | Values | Description |
|---|---|---|---|---|---|
type | string | — | — | — | Type is the key class to act on: "secret" (sk-, session-equivalent, belongs on a server) or "publishable" (pk-, org-identifying, safe in a browser bundle). Omitted means secret, which is what every existing caller means. |
tools/list declares a type and a description for each field and nothing further, and the OpenAPI document describes no operation for this tool. A — above means neither source constrains the field, not that it is unconstrained in practice.
Call it
A tools/call carries every argument in one flat object — nothing binds to a path or a query string. Nothing above is required, so every declared argument is shown rather than a guess at which matter.
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "delete_v1_iam_keys",
"arguments": {
"type": "<type>"
}
}
}'Values are the operation's own defaults and enumerated values where it declares them, and a <placeholder> where neither source declares one. tools/list needs no credential; tools/call does — called without one the door answers HTTP 200 with a JSON-RPC result whose isError is set and whose text says what was missing. How to get a key →
The operation behind it
The door exposes delete_v1_iam_keys, but the copy of the OpenAPI document this build holds (pinned at 4e41f04ca) describes no operation for it — neither under that name nor at the route the name implies. That is either a route the document has yet to declare, or one the door has renamed since the pin. Everything on this page comes from tools/list; there is no REST reference to link to until the two agree.
All 755 tools · The door · API reference
Generated from tools/list on https://api.hanzo.ai/v1/mcp — 833 tools captured 2026-08-01, of which 755 are documented here (the operator surface is not published) (this build read the vendored copy; the door was unreachable).
How is this guide?
adminCreateCredit
Mints credit for one org. It is the ONE admin mint surface, and it does NOT mint in-process: it forwards the request to commerce's already-mint-gated POST /v1/billing/credits, authenticated by the…
delete_v1_train_experiments_name
DeleteExperiment deletes a hyperparameter-tuning experiment. Kubernetes garbage-collects the Trials katib created under it, because they carry the Experiment as their owner.