Skip to main content

Tool

In Model Context Protocol, a tool is a callable capability that a server exposes with a name, description, and input schema.

What is Tool?

In Model Context Protocol, a tool is a callable capability that a server exposes with a name, description, and input schema. A tool lets a model-backed application query data, call an API, perform a computation, or cause another external action.

Why it matters

A tool invocation crosses from generated output into executable behavior. The server must validate the input and decide whether this caller can perform this action.

How it works

  1. The client sends tools/list to discover the tools currently available to it. The returned set can vary with the authorization presented on the request.
  2. The client sends tools/call with an exact tool name and arguments.
  3. The server validates, authorizes, executes, and returns a result or error.

Example

A query_incidents tool accepts a service name and returns open incident summaries. It cannot create or close an incident.

Pomerium boundary

Pomerium Model Context Protocol policy can allow or deny tool names by exact value, prefix, suffix, or list and combine the rule with identity policy.

Limits and non-claims

  • Tool descriptions and annotations are untrusted metadata unless the server is trusted.
  • Input schema validation is not authorization.
  • Model-controlled discovery does not remove the need for user confirmation on sensitive actions.
  • Pomerium's mcp_tool criterion applies only to tools/call on protected Streamable HTTP routes. Logged tool parameters are configurable and can contain sensitive data.

Evaluation checklist

  • Which server owns the tool schema, implementation, credential, target resource, and allowed action?
  • Does deterministic policy authorize normalized arguments instead of trusting model selection?
  • Can schema drift, hidden side effects, credential exposure, or a direct target bypass tool controls?

Sources and further reading

Keep learning

Agentic AccessSecurity Operations and Risk

Tool Surface Area

Tool surface area is the full set of operations, inputs, external resources, and privilege effects that tools make available to an agent.

Learn this term
Agentic AccessApplication and Service Access

Per-Request Authorization

Per-request authorization evaluates each action against current identity, resource, policy, and request context immediately before enforcement.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo