AI agent tools are capabilities—such as searching a database, checking the weather, or updating a record—that an application makes available to a model. Function calling is a structured way for the model to request one of those capabilities. The model can select a tool and propose its inputs, but application code or a provider-hosted service performs the operation.
What is function calling in AI?
Function calling, also called tool calling, lets a model request an operation through a defined interface instead of merely describing what should happen. A tool definition tells the model what the tool does and what inputs it accepts. The definition is not the operation itself: software must execute the request and return the result.
As an Amazon Associate I earn from qualifying purchases.
For example, an app might expose get_weather(location). If a user asks for the forecast in a city, the model can return a structured request naming that tool and supplying the location. The application can then call a weather service and pass the returned information back to the model.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchOpenAI describes function calling as a way for its models to interface with external systems and access data beyond their training data in its function calling guide. The specific request formats, endpoints, and execution behavior depend on the provider and implementation.
#1 Best Overall
What happens when an agent uses a tool?
- The developer defines a tool. The definition describes its purpose and the inputs it accepts. Some interfaces use a JSON Schema-style definition; Anthropic’s user-defined tools, for example, use an
input_schema. - The model chooses whether to request it. Given the user’s request and the available tools, the model may produce a structured call with a tool name and arguments. It may instead respond without a tool, or request another tool if the task needs one.
- The application checks and executes the request. For a client-side tool, application code validates the arguments, applies authorization and other rules, and performs the operation. The model’s structured request is not proof that the user is authorized to carry it out.
- The application returns the result. It sends the tool output back in the conversation, associated with the relevant call. The model can use that result to answer or continue the tool loop.
OpenAI documents this request, execution, and response cycle, including the possibility of additional calls, in its function calling guide. Anthropic illustrates the corresponding exchange with a tool_use block, application execution, and a tool_result in its Claude tool use documentation.
Does the AI actually execute the function?
Not necessarily. In a client-side integration, the model emits a request; the developer’s application executes it. That distinction matters because a model can suggest arguments, but the application remains responsible for deciding whether to accept them and what they are allowed to do.
Some providers also offer tools that run on provider infrastructure. Anthropic distinguishes tools executed by the application from server tools executed on Anthropic’s infrastructure. OpenAI’s MCP documentation describes connections with different origins and configurations, including service, environment, and standard input/output (stdio) options. Check the documentation for the specific tool and provider rather than assuming all tools run in the same place.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →How are AI agent tools different from MCP?
A tool is a capability an agent can use; function calling is one interface for requesting that capability. The Model Context Protocol (MCP) is a way for an application or service to connect to tool servers. An MCP connection can make server-provided tools available, but MCP is not itself the operation those tools perform, nor does it mean every model provider supports the same connection options.
Transport support can differ. Google’s Gemini documentation says remote MCP connections use Streamable HTTP and that Server-Sent Events (SSE) is unsupported. OpenAI documents its own MCP connection choices and credential configuration in its MCP connections guide. For setup, verify the current protocol, transport, authentication, and model requirements for the provider you are using; Google’s details are in its Gemini function-calling guide.
What kinds of tools can an agent use?
A practical way to classify tools is by what they let the agent do. OpenAI’s agent-building guide groups them into three types:
Rank #4
- Data tools retrieve information, such as searching a database or finding a relevant document.
- Action tools change something, such as updating a customer record. These can have consequential side effects.
- Orchestration tools let an agent delegate work to another agent exposed as a tool.
This classification helps clarify the risk of a tool before exposing it. A search may reveal private information if access controls are weak; an update can alter a live system; delegation can expand the path a task takes. The categories and design advice are described in OpenAI’s practical guide to building agents.
How should developers make tool use safer?
Expose only necessary capabilities
Give the agent access only to tools it needs for the task, and restrict which tools it can discover or call where the platform supports it. OpenAI’s MCP documentation describes an allowed_tools control for limiting available tools. A smaller tool set reduces unnecessary access, but does not replace authorization checks in the application.
Best Value
Validate inputs and enforce permissions in code
Use clear, precise tool descriptions and schemas so the model can select tools and format arguments appropriately. Schema validation can catch malformed inputs where supported; it does not establish that a request is safe or authorized. The application should independently validate values, check the user’s permissions, and enforce business rules before execution.
Protect credentials and sensitive data
Keep credentials out of model-generated code and reusable tool definitions where possible. Configure authentication through the provider’s supported mechanisms, and avoid exposing secrets in logs. OpenAI’s MCP documentation covers HTTP and vault credentials for supported connections and cautions against placing secrets in reusable definitions and logs.
Put safeguards around side effects
For irreversible or high-impact actions, consider a confirmation or human-approval step, plus appropriate logging, timeouts, error handling, and a way to stop the operation. The right safeguards depend on what the tool can change and the consequences of a mistaken call. Provider features and oversight mechanisms vary, so verify the exact implementation rather than assuming that a tool call includes approval or rollback.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What do current agent examples show about MCP and stop controls?
The MIT AI Agent Index, published in the FAccT ’26 context and describing its 2025 index, reports that 20 of the 30 agents in its selected sample supported MCP. It also reports that 20 of those 30 documented pause or stop mechanisms. These are counts within the index’s sample, not estimates of adoption across all agent products. The index describes the sample in The 2025 AI Agent Index.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




