Skip to content

Tool Calling

Last updated:

What tool calling is

A language model on its own can only produce text. It cannot check today's stock level or look up a booking. Tool calling closes that gap. The developer describes the available tools to the model: a name, what each one does and which inputs it needs. When a question calls for one of them, the model replies with a structured request, such as the tool name and parameters in JSON, instead of a normal answer.

How it works

A typical tool call runs in four steps:

  • The application sends the user's message plus the tool descriptions to the model.
  • The model decides whether a tool is needed and, if so, returns the tool name and arguments.
  • The application, not the model, runs the call, for example an HTTP request to an API.
  • The result goes back to the model, which writes the final answer from it.

Example

A customer asks a bike shop's chatbot: “Do you have the Trail 500 in a medium frame?” The model calls a product search tool with the product name and size. The shop's system returns availability and the current price, and the chatbot answers with that live information instead of guessing from an old product page.

Why it matters for business chatbots

Tool calling turns a chatbot from a reader of documents into an assistant that works with live systems: product catalogs, availability, account data or internal tools. It also raises the stakes. Because the application executes each call, it controls which tools exist, which credentials are used and which parts of a response the model sees. Tools should be limited to what the chatbot needs, read-only where possible, and guarded so that a cleverly worded message cannot trigger actions it should not, a risk known as prompt injection.

Tool calling in intoCHAT

In intoCHAT, tool calling is available through actions:

  • Custom API actions let the agent call your HTTP API during a chat, with any method and authentication by bearer token, basic auth, API key or custom headers. You can import a cURL command, define inputs the agent fills from the conversation, choose which response fields the model sees and test each action. Up to 25 actions per agent.
  • Client-side actions run JavaScript functions on your own page.
  • Connect your store detects Shopify, WooCommerce, Magento, VTEX, WordPress or a custom site from a shop URL and creates live product-search actions from public shop data, with results shown as product cards.

Frequently asked questions

Is tool calling the same as function calling?

Yes, the terms are used interchangeably. Some providers call it function calling, others tool calling or tool use. All describe a model requesting an external function and using its result.

Does the AI model run the API call itself?

No. The model only requests the call by returning a tool name and arguments. The surrounding application executes it, which is where credentials, permissions and limits are enforced.

Is tool calling safe?

It can be, with sensible limits. Expose only the tools and data the chatbot needs, prefer read-only actions, keep credentials on the server side and restrict which response fields reach the model. Also test how the bot behaves with unusual or manipulative requests.

See it answer from your own website

Paste your website address and chat with an agent built from your pages. It takes about a minute.

Create your agent free

Free plan, no credit card needed.