API

Tool calling

Let a model request functions while your application controls execution.

Define a tool

Choose a model whose tools capability is true.

{
  "model": "pro",
  "messages": [{"role": "user", "content": "What is order 813 status?"}],
  "tools": [
    {
      "type": "function",
      "function": {
        "name": "get_order",
        "description": "Get an order by its numeric ID.",
        "parameters": {
          "type": "object",
          "properties": {"order_id": {"type": "integer"}},
          "required": ["order_id"],
          "additionalProperties": false
        }
      }
    }
  ],
  "tool_choice": "auto"
}

When the model returns tool_calls, validate the function name and arguments against an allowlist. Authorize the action for the signed-in user. Apply timeouts and output limits. Never execute model-generated shell commands or database statements without a separate safety layer.

Send each result back with role tool, the matching tool_call_id, and serialized content. Then request the final assistant answer. Treat tool arguments as untrusted input even when they match the schema.