Glossary

MCP Tools: What They Are and How They're Controlled

MCP tools are functions an MCP server offers to an AI app, such as "run this query" or "create this issue". Each tool has a name, a description and a schema for its inputs. The AI reads them and decides for itself when a tool is worth calling.

A simple way to picture it

Say you ask Claude, "How many users signed up last week?" Claude looks at the tools your MCP server lists and finds one called query. It fills in the SQL, calls the tool, reads the rows that come back and answers you in plain English.

You never picked the tool. The model did, based on its name and description. That is the defining trait of a tool.

Tools, resources and prompts

As of September 2026, MCP servers can offer three kinds of things, and the difference is who is in control:

  • Tools are controlled by the model. The AI decides when to call one, and a tool can run code or change data.
  • Resources are controlled by the app. They are read-only context, like a file or a log, that the app attaches.
  • Prompts are controlled by you. They are reusable templates you pick from a menu.

Only tools do things. That is why they need the most care.

What a tool looks like

A client finds tools with tools/list and runs one with tools/call. Each entry carries the pieces the model needs to use it well:

  • A name, like list_tables.
  • A description in plain language, which the model reads to decide when to use it.
  • An input schema in JSON Schema, so the model knows which arguments to send.

A good description matters more than you might expect. It is the model's only guide.

Why control over tools matters

Because the model chooses tools on its own, you want to decide which ones it can reach. A database server might offer both a read-only query and an execute that writes data. You probably want the first on and the second off until you need it.

That is the job of a gateway. On MCPifex, write and destructive tools are off by default, the tool list a client sees only shows enabled tools, and a call to anything else is refused. The PostgreSQL server is a good example, and you can browse every server's tools on the marketplace.

Tools are one part of the Model Context Protocol. The app that calls them is an MCP client. For the bigger picture, read What is MCP? and how instances and tools work.

Sources

  1. Tools — Model Context Protocol specification (2025-06-18)