What is Tool?
In Model Context Protocol, a tool is a callable capability that a server exposes with a name, description, and input schema. A tool lets a model-backed application query data, call an API, perform a computation, or cause another external action.
Why it matters
A tool invocation crosses from generated output into executable behavior. The server must validate the input and decide whether this caller can perform this action.
How it works
- The client sends tools/list to discover the tools currently available to it. The returned set can vary with the authorization presented on the request.
- The client sends tools/call with an exact tool name and arguments.
- The server validates, authorizes, executes, and returns a result or error.
Example
A query_incidents tool accepts a service name and returns open incident summaries. It cannot create or close an incident.
Pomerium boundary
Pomerium Model Context Protocol policy can allow or deny tool names by exact value, prefix, suffix, or list and combine the rule with identity policy.
Limits and non-claims
- Tool descriptions and annotations are untrusted metadata unless the server is trusted.
- Input schema validation is not authorization.
- Model-controlled discovery does not remove the need for user confirmation on sensitive actions.
- Pomerium's mcp_tool criterion applies only to tools/call on protected Streamable HTTP routes. Logged tool parameters are configurable and can contain sensitive data.
Evaluation checklist
- Which server owns the tool schema, implementation, credential, target resource, and allowed action?
- Does deterministic policy authorize normalized arguments instead of trusting model selection?
- Can schema drift, hidden side effects, credential exposure, or a direct target bypass tool controls?
