Agents

Tool Use

Function calling

The mechanism that lets a model ask your software to run a function (search, look up a record, send a message) and then use the result.

Modelasks, does not executeYour applicationruns the function1 · get_weather(city="Izmir")2 · {"temp": 24, "sky": "clear"}3 · The model writes the answer from the result: “It is 24 °C and clear in Izmir.”

swipe to see the whole diagram →

MEmehmeterkek.com/glossary/tool-use

In plain terms

On its own a model can only write text. Tool use gives it hands. You describe the functions it may call; when it needs one, it writes a structured request naming the function and its arguments. Your application runs it and hands back the result.

Why it matters

This is what connects AI to your systems and live data, and it is the foundation of every agent. It is also where risk enters: a model that can call “send payment” is only as safe as the permissions and checks around that function.

Example

A user asks about the weather in Izmir. The model replies not with an answer but with a request: call get_weather with city “Izmir”. The application calls the weather service, returns “24 °C, clear”, and the model writes the sentence the user sees.

Most often confused with

Tool Use vs. MCP (Model Context Protocol)

Tool UseThe model's ability to request a function
MCP (Model Context Protocol)A standard way to package and connect tools

Tool use is the capability inside the model: emitting a structured call. MCP is a protocol around it: a common format for describing tools and connecting them to any compatible application. MCP servers are consumed through tool use.

Under the hood

Tools are declared with a name, a description and a JSON Schema for the arguments; descriptions matter as much as prompts, because the model chooses tools by reading them. The model never executes anything: it emits a tool-call block, the host runs the function and returns a tool-result message, and the loop continues. Models can request several calls in parallel. Tool results are untrusted input and the main entry point for prompt injection. Large tool sets consume context, which is why tool search and on-demand loading exist.

Written by Mehmet Erkek · Last updated: