MCP tools vs resources vs prompts: who controls each

MCP tools are called by the model, resources are attached by the app, and prompts are picked by the user. What each one is for, and how to choose.

5 min readSume
All posts

MCP tools are functions the model decides to call, resources are read-only data the application attaches as context, and prompts are templates the user picks, for example as slash commands. The difference is who is in control: the model, the application, or the user. A server declares which of the three it supports, and a client may use only the ones it declares.

The definitions come from the MCP specification's Server overview, Tools, Resources, and Prompts pages (revision 2025-11-25) and MCP's Understanding MCP servers guide, read on 2026-09-28. Sume's side is from its MCP tools and gates page and current server code. New to MCP? Start with What is an MCP server?

What is the difference between MCP tools, resources, and prompts?

The spec sums it up as a control hierarchy, and each primitive has its own protocol methods:

From the MCP Server overview (2025-11-25) and Understanding MCP servers, read 2026-09-28.
PrimitiveControlled byWhat it isExamplesMethods
ToolsThe modelFunctions exposed to the LLM to take actionsAPI POST requests, file writing, search flightstools/list, tools/call
ResourcesThe applicationContextual data attached and managed by the clientFile contents, git history, calendarsresources/list, resources/templates/list, resources/read
PromptsThe userInteractive templates invoked by user choiceSlash commands, menu options, "Plan a vacation"prompts/list, prompts/get

What is an MCP resource?

Data a server shares as context, such as a file's contents, a database schema, or API documentation. Each resource has a unique URI, like file:///path/to/document.md, and declares its MIME type. A server can list fixed resources, such as calendar://events/2024, or publish resource templates, URIs with parameters such as weather://forecast/{city}/{date}. The application decides how to use what it reads: select the relevant portions, search it with embeddings, or pass it all to the model.

Should it be a tool or a resource?

Ask who should trigger it and whether it changes anything. If the model should fetch or act on its own in the middle of a task, make it a tool: tools can write to databases, call external APIs, or modify files, and the spec wants a human in the loop who can deny a tool call. If it is context that the app or the user chooses to include, and reading it changes nothing, make it a resource.

One server can offer all three. MCP's architecture guide describes a database server with tools for querying the database, a resource that contains its schema, and a prompt with few-shot examples for using the tools.

When should I use a prompt instead of a tool?

When a person should start the workflow. Prompts are user-controlled and require explicit invocation; clients typically offer them as slash commands such as /plan-vacation, command palettes, or dedicated buttons. A prompt gives the model structured messages and instructions, customized by arguments the user supplies, and it can reference the server's tools and resources. A tool, by contrast, can be discovered and invoked by the model automatically.

How does a client know which ones a server offers?

From the capabilities the server declares. The spec says servers that support tools, resources, or prompts must declare that capability, and its Lifecycle page says both sides must use only the capabilities negotiated when they connect. The MCP Inspector's web client, for one, shows its Tools, Resources, and Prompts tabs only for the capabilities a server reports. Client support varies too. Cursor's docs list tools, prompts, and resources as supported, while Android Studio's say its MCP integration supports neither MCP resources nor prompt templates.

What does Sume's MCP server expose?

Only tools. In current code, Sume's hosted server declares just the tools capability when a client connects, and other requests, such as resources/list or prompts/list, get the JSON-RPC error -32601 (method not found). A client's resource or prompt picker has nothing to show for Sume.

Its tools wrap selected Sume API capabilities, from read tools such as jobs_list to paid generation tools such as generate_image, and the model decides when to call them. Even discovery is a tool: tools_list and tools_schema show what the session can call. Sume MCP tools list groups them, and agent skills vs MCP covers the know-how side. Sume's basics page says hosted MCP still works but is not part of the primary path today.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume