In plain terms
On its own a model can only write text. Tool use gives it hands. You describe the functions it may call; when it needs one, it writes a structured request naming the function and its arguments. Your application runs it and hands back the result.
Why it matters
This is what connects AI to your systems and live data, and it is the foundation of every agent. It is also where risk enters: a model that can call “send payment” is only as safe as the permissions and checks around that function.
Example
A user asks about the weather in Izmir. The model replies not with an answer but with a request: call get_weather with city “Izmir”. The application calls the weather service, returns “24 °C, clear”, and the model writes the sentence the user sees.
Most often confused with
Tool Use vs. MCP (Model Context Protocol)
Tool use is the capability inside the model: emitting a structured call. MCP is a protocol around it: a common format for describing tools and connecting them to any compatible application. MCP servers are consumed through tool use.
Under the hood
Tools are declared with a name, a description and a JSON Schema for the arguments; descriptions matter as much as prompts, because the model chooses tools by reading them. The model never executes anything: it emits a tool-call block, the host runs the function and returns a tool-result message, and the loop continues. Models can request several calls in parallel. Tool results are untrusted input and the main entry point for prompt injection. Large tool sets consume context, which is why tool search and on-demand loading exist.