> ## Documentation Index
> Fetch the complete documentation index at: https://docs.paywithlocus.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Turn every mutable tool on or off

> Moves every tool the workspace can switch in one transaction. enabled: true writes tool rows only: provider-level rows never move, so a tool added to a provider later still starts off. enabled: false writes every provider with a tool on at provider scope, resetting its endpoint-level enablement overrides to inherit and clearing their MCP pins, exactly as a provider entry of the batch route does. Markup overrides are preserved; always-on tools and custom endpoints are untouched. Every mutable provider is locked first, in one statement. The write is journaled under a fresh request id of its own, never the caller's x-request-id, and the response returns it so POST /credits/catalog/changes/{requestId}/revert can put exactly this write back. Open to personal accounts. Registered ahead of the provider routes, so all is never read as a provider id.



## OpenAPI

````yaml /api-reference/openapi.json put /credits/catalog/all
openapi: 3.1.0
info:
  title: Locus Pro API
  description: >-
    Access paid tools, manage prepaid balances, and build usage billing. Send
    money as exact decimal strings and reuse Idempotency-Key on retries.
    Management routes require a scoped server key or authorized dashboard
    session. Sensitive workspace changes require an owner or admin with recent
    MFA or passkey verification, except where an operation documents a stricter
    boundary. Interactive agents use MCP OAuth; unattended agents use scoped
    Agent Connections. Browser widgets use end-user tokens.
  version: 0.7.0
servers:
  - url: https://api.paywithlocus.com/api
    description: Production
  - url: https://api.stage.paywithlocus.com/api
    description: Stage — evaluation and integration testing
security:
  - secretKey: []
tags:
  - name: Authentication
    description: Email-verified self-serve account creation and dashboard identity
  - name: Tenants
    description: Tenant profile, keys, and settings (dashboard session or secret key)
  - name: Workspace members
    description: Invite-only human workspace membership and role administration
  - name: Catalog
    description: Enable/disable APIs and set markups
  - name: Custom APIs
    description: Feature-gated enterprise BYOK providers and schema-backed custom actions
  - name: End users
    description: End-user accounts, tokens, and allocations
  - name: Top-ups
    description: Locus-hosted checkout top-ups and quotes
  - name: Ledger
    description: Burn/top-up history and earnings
  - name: Webhooks
    description: Signed events, delivery inspection, and replay
  - name: Burn
    description: Metered pay-per-use calls
  - name: MCP
    description: Stateless Streamable HTTP transport and MCP tool-result contracts
  - name: Okibi Identity
    description: >-
      Feature-gated Okibi identity verification and scoped native CLI credential
      bootstrap
  - name: Widget
    description: End-user JWT surface; a matching publishable key is optional
  - name: Agent-native onboarding
    description: >-
      Self-registration, human Stripe funding handoff, and restricted account
      setup for headless agents
  - name: Hosted Workflows
    description: >-
      Tenant-private TypeScript Workflow definitions, immutable versions,
      bounded runs, artifacts, and recovery
  - name: Agent connections
    description: Scoped, expiring, revocable credentials for agent execution
  - name: Recipes
    description: >-
      Search, research, extraction, enrichment, and travel outcomes across
      providers
paths:
  /credits/catalog/all:
    put:
      tags:
        - Catalog
      summary: Turn every mutable tool on or off
      description: >-
        Moves every tool the workspace can switch in one transaction. enabled:
        true writes tool rows only: provider-level rows never move, so a tool
        added to a provider later still starts off. enabled: false writes every
        provider with a tool on at provider scope, resetting its endpoint-level
        enablement overrides to inherit and clearing their MCP pins, exactly as
        a provider entry of the batch route does. Markup overrides are
        preserved; always-on tools and custom endpoints are untouched. Every
        mutable provider is locked first, in one statement. The write is
        journaled under a fresh request id of its own, never the caller's
        x-request-id, and the response returns it so POST
        /credits/catalog/changes/{requestId}/revert can put exactly this write
        back. Open to personal accounts. Registered ahead of the provider
        routes, so all is never read as a provider id.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - enabled
              properties:
                enabled:
                  type: boolean
              additionalProperties: false
      responses:
        '200':
          description: >-
            Every tool not already there has moved; updated counts tools whose
            effective enablement changed, providers counts the providers touched
          content:
            application/json:
              schema:
                type: object
                required:
                  - success
                  - scope
                  - enabled
                  - updated
                  - providers
                  - unpinned
                  - requestId
                properties:
                  success:
                    const: true
                  scope:
                    const: all
                  enabled:
                    type: boolean
                  updated:
                    type: integer
                    minimum: 0
                  providers:
                    type: integer
                    minimum: 0
                  unpinned:
                    type: array
                    items:
                      type: string
                    description: >-
                      Tools whose MCP pins a turn-off cleared (empty for a
                      turn-on). A revert restores enablement, not pins: the
                      caller may pin these again.
                  requestId:
                    type: string
                    pattern: '^all-(on|off):[0-9]+:'
                    description: >-
                      The journal id of this write, naming its direction and its
                      enablement revision, for the revert route.
                additionalProperties: false
        '400':
          description: enabled missing, not a boolean, or an unexpected body key
        '403':
          $ref: '#/components/responses/InsufficientScope'
        '503':
          description: >-
            Curation could not be read, even after reading it again; nothing was
            changed
      security:
        - dashboardSession: []
        - secretKey: []
components:
  responses:
    InsufficientScope:
      description: >-
        The authenticated management credential lacks one or more required
        scopes
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/InsufficientScopeError'
  schemas:
    InsufficientScopeError:
      type: object
      additionalProperties: false
      required:
        - success
        - error
        - code
        - message
        - requiredScopes
        - presentScopes
      properties:
        success:
          const: false
        error:
          const: Forbidden
        code:
          const: INSUFFICIENT_SCOPE
        message:
          type: string
        requiredScopes:
          type: array
          items:
            $ref: '#/components/schemas/CreditsTenantScope'
          minItems: 1
          uniqueItems: true
        presentScopes:
          type: array
          items:
            $ref: '#/components/schemas/CreditsTenantScope'
          uniqueItems: true
    CreditsTenantScope:
      type: string
      enum:
        - tenant:read
        - tenant:write
        - catalog:write
        - credits:move
        - credentials:manage
        - tokens:manage
        - payouts:manage
        - members:manage
        - widget:read
  securitySchemes:
    secretKey:
      type: http
      scheme: bearer
      description: Tenant secret key (lcr_…). Server-side only.
    dashboardSession:
      type: http
      scheme: bearer
      description: >-
        Locus Pro dashboard session (Cognito). High-risk workspace
        administration requires an owner or admin role and fresh MFA/passkey
        step-up.

````