Tool Calling

Turkish equivalent: Araç çağırmaDomain: Large Language Models

A model interaction pattern in which the model emits structured arguments requesting execution of an external function or capability and then uses the returned result.

Language-Model Context

Tool calling is an interaction pattern in which a model produces structured arguments requesting an external operation and then reasons over the returned result. Reliable production use depends on tool schemas, authorization, input validation, retry and idempotency behavior, and grounding of returned data as much as on model quality.

Security Boundary

A model-generated tool call is not proof that the action is safe, valid, or authorized. Policy enforcement must be performed by a trusted layer outside the model.

The Model Proposes; a Trusted Layer Executes

A safe tool-calling pipeline should be split into two decisions. The model produces a proposal containing a tool name and structured arguments; the application layer decides whether to execute it after schema validation, authorization, and business-policy checks. The external result can then be returned to the model as new context.

JSON Schema or an equivalent contract can constrain argument shape, but it does not prove that the user is authorized to perform the operation. Side-effecting tools also need explicit Idempotency, timeout, and retry semantics. Tool calling is not identical to Model Context Protocol: MCP can provide a protocol layer for connecting and discovering tools, while the call decision remains part of model/application orchestration. For a direct API-level example, see the OpenAI function-calling documentation.