MCP servers expose three main kinds of capability, which differ mainly in who decides when to use them.
Tools (Model-Controlled)
Functions the model can choose to call — search tickets, run a query, create an issue. Each tool has a name, a description and a JSON Schema for its inputs. The host typically asks the user to approve tool calls, especially ones with side effects.
Resources (Application-Controlled)
Data identified by URIs — files, database records, documents — that the host application can read and include as context. The application, often guided by the user, decides which resources to attach.
Prompts (User-Controlled)
Reusable prompt templates the server offers, often surfaced as commands the user picks, such as "summarise this pull request".
Choosing
- Use tools for actions and dynamic queries.
- Use resources for content the user or app selects as context.
- Use prompts for common workflows you want to package for users.
Discovery and Change
Clients list what a server provides and can be notified when those lists change, so capabilities can be added at runtime.
Client Features
Clients can also offer features to servers, such as sampling (letting a server request a model completion through the host) and asking the user for input, always subject to the host's controls.