MCP Tools vs Resources
An MCP server can expose tools and resources, and the difference is whether the model is invoking an action or just reading data. A tool is a real action the AI can take — it gets called, with arguments, and does something. A resource is data the AI can read for context — a file's contents, a database record — with nothing invoked at all.
What an MCP tool is
A real action the model can request, with arguments, that the server actually carries out — the same mechanism as tool calling generally, just supplied by an MCP server instead of written by the application itself. Listing open pull requests or posting a comment are both tools: something happens as a result.
What an MCP resource is
Content the model can read for context — a file's contents, a configuration value, a database record — without any action being invoked. Reading a resource has no side effect; it's information handed to the model, not a request the server executes.
Side by side
| Tool | Resource | |
|---|---|---|
| What happens | An action gets invoked | Data gets read, nothing invoked |
| Has side effects? | Can — a real action, real consequence | No — reading it changes nothing |
| Model's role | Decides to call it, with arguments | Reads what it's given |
| Example | Post a comment, list pull requests | Read a file's contents, a config value |
A resource is lower-risk by design
A tool needs the same caution any real action does — the narrowest access that does the job, approval for anything sensitive, treating its result as untrusted. A resource is lower-risk by design: reading a file can't delete it, post something, or spend money. Confusing the two in a system's design means either treating a harmless read like a dangerous action, adding friction for no reason, or worse, treating a real action as if reading it were the only risk.
In this guide
FAQ
If a resource always has no side effects, is it always safe to expose freely?
Not necessarily — reading it can't change anything, but it can still expose sensitive data if the content itself is sensitive. A resource being invocation-free doesn't mean the information in it is safe for every reader; access control on what a resource can return still matters.