MCP Tools: What They Are and How They're Controlled
MCP tools are functions an MCP server offers to an AI app, such as "run this query" or "create this issue". Each tool has a name, a description and a schema for its inputs. The AI reads them and decides for itself when a tool is worth calling.
A simple way to picture it
Say you ask Claude, "How many users signed up last week?" Claude looks at the tools your MCP server lists and finds one called query. It fills in the SQL, calls the tool, reads the rows that come back and answers you in plain English.
You never picked the tool. The model did, based on its name and description. That is the defining trait of a tool.
Tools, resources and prompts
As of September 2026, MCP servers can offer three kinds of things, and the difference is who is in control:
- Tools are controlled by the model. The AI decides when to call one, and a tool can run code or change data.
- Resources are controlled by the app. They are read-only context, like a file or a log, that the app attaches.
- Prompts are controlled by you. They are reusable templates you pick from a menu.
Only tools do things. That is why they need the most care.
What a tool looks like
A client finds tools with tools/list and runs one with tools/call. Each entry carries the pieces the model needs to use it well:
- A name, like
list_tables. - A description in plain language, which the model reads to decide when to use it.
- An input schema in JSON Schema, so the model knows which arguments to send.
A good description matters more than you might expect. It is the model's only guide.
Why control over tools matters
Because the model chooses tools on its own, you want to decide which ones it can reach. A database server might offer both a read-only query and an execute that writes data. You probably want the first on and the second off until you need it.
That is the job of a gateway. On MCPifex, write and destructive tools are off by default, the tool list a client sees only shows enabled tools, and a call to anything else is refused. The PostgreSQL server is a good example, and you can browse every server's tools on the marketplace.
Related terms
Tools are one part of the Model Context Protocol. The app that calls them is an MCP client. For the bigger picture, read What is MCP? and how instances and tools work.
Sources
Ready to try it?
Host any MCP server behind one endpoint and control exactly what your agents can reach.