MCP Tools vs Resources

An MCP server can expose tools and resources, and the difference is whether the model is invoking an action or just reading data. A tool is a real action the AI can take — it gets called, with arguments, and does something. A resource is data the AI can read for context — a file's contents, a database record — with nothing invoked at all.

What an MCP tool is

A real action the model can request, with arguments, that the server actually carries out — the same mechanism as tool calling generally, just supplied by an MCP server instead of written by the application itself. Listing open pull requests or posting a comment are both tools: something happens as a result.

What an MCP resource is

Content the model can read for context — a file's contents, a configuration value, a database record — without any action being invoked. Reading a resource has no side effect; it's information handed to the model, not a request the server executes.

Side by side

ToolResource
What happensAn action gets invokedData gets read, nothing invoked
Has side effects?Can — a real action, real consequenceNo — reading it changes nothing
Model's roleDecides to call it, with argumentsReads what it's given
ExamplePost a comment, list pull requestsRead a file's contents, a config value

A resource is lower-risk by design

A tool needs the same caution any real action does — the narrowest access that does the job, approval for anything sensitive, treating its result as untrusted. A resource is lower-risk by design: reading a file can't delete it, post something, or spend money. Confusing the two in a system's design means either treating a harmless read like a dangerous action, adding friction for no reason, or worse, treating a real action as if reading it were the only risk.

In this guide
  1. What an MCP tool is
  2. What an MCP resource is
  3. Side by side
  4. A resource is lower-risk by design
  5. FAQ

FAQ

If a resource always has no side effects, is it always safe to expose freely?

Not necessarily — reading it can't change anything, but it can still expose sensitive data if the content itself is sensitive. A resource being invocation-free doesn't mean the information in it is safe for every reader; access control on what a resource can return still matters.