MCP tools vs resources vs prompts: who controls each
MCP tools are called by the model, resources are attached by the app, and prompts are picked by the user. What each one is for, and how to choose.

MCP tools are functions the model decides to call, resources are read-only data the application attaches as context, and prompts are templates the user picks, for example as slash commands. The difference is who is in control: the model, the application, or the user. A server declares which of the three it supports, and a client may use only the ones it declares.
The definitions come from the MCP specification's Server overview, Tools, Resources, and Prompts pages (revision 2025-11-25) and MCP's Understanding MCP servers guide, read on 2026-09-28. Sume's side is from its MCP tools and gates page and current server code. New to MCP? Start with What is an MCP server?
What is the difference between MCP tools, resources, and prompts?
The spec sums it up as a control hierarchy, and each primitive has its own protocol methods:
| Primitive | Controlled by | What it is | Examples | Methods |
|---|---|---|---|---|
| Tools | The model | Functions exposed to the LLM to take actions | API POST requests, file writing, search flights | tools/list, tools/call |
| Resources | The application | Contextual data attached and managed by the client | File contents, git history, calendars | resources/list, resources/templates/list, resources/read |
| Prompts | The user | Interactive templates invoked by user choice | Slash commands, menu options, "Plan a vacation" | prompts/list, prompts/get |
What is an MCP resource?
Data a server shares as context, such as a file's contents, a database schema, or API documentation. Each resource has a unique URI, like file:///path/to/document.md, and declares its MIME type. A server can list fixed resources, such as calendar://events/2024, or publish resource templates, URIs with parameters such as weather://forecast/{city}/{date}. The application decides how to use what it reads: select the relevant portions, search it with embeddings, or pass it all to the model.
Should it be a tool or a resource?
Ask who should trigger it and whether it changes anything. If the model should fetch or act on its own in the middle of a task, make it a tool: tools can write to databases, call external APIs, or modify files, and the spec wants a human in the loop who can deny a tool call. If it is context that the app or the user chooses to include, and reading it changes nothing, make it a resource.
One server can offer all three. MCP's architecture guide describes a database server with tools for querying the database, a resource that contains its schema, and a prompt with few-shot examples for using the tools.
When should I use a prompt instead of a tool?
When a person should start the workflow. Prompts are user-controlled and require explicit invocation; clients typically offer them as slash commands such as /plan-vacation, command palettes, or dedicated buttons. A prompt gives the model structured messages and instructions, customized by arguments the user supplies, and it can reference the server's tools and resources. A tool, by contrast, can be discovered and invoked by the model automatically.
How does a client know which ones a server offers?
From the capabilities the server declares. The spec says servers that support tools, resources, or prompts must declare that capability, and its Lifecycle page says both sides must use only the capabilities negotiated when they connect. The MCP Inspector's web client, for one, shows its Tools, Resources, and Prompts tabs only for the capabilities a server reports. Client support varies too. Cursor's docs list tools, prompts, and resources as supported, while Android Studio's say its MCP integration supports neither MCP resources nor prompt templates.
What does Sume's MCP server expose?
Only tools. In current code, Sume's hosted server declares just the tools capability when a client connects, and other requests, such as resources/list or prompts/list, get the JSON-RPC error -32601 (method not found). A client's resource or prompt picker has nothing to show for Sume.
Its tools wrap selected Sume API capabilities, from read tools such as jobs_list to paid generation tools such as generate_image, and the model decides when to call them. Even discovery is a tool: tools_list and tools_schema show what the session can call. Sume MCP tools list groups them, and agent skills vs MCP covers the know-how side. Sume's basics page says hosted MCP still works but is not part of the primary path today.
Sources
- MCP specification 2025-11-25: Server features overview (read 2026-09-28)
- MCP specification 2025-11-25: Tools (read 2026-09-28)
- MCP specification 2025-11-25: Resources (read 2026-09-28)
- MCP specification 2025-11-25: Prompts (read 2026-09-28)
- MCP specification 2025-11-25: Lifecycle (read 2026-09-28)
- Model Context Protocol: Understanding MCP servers (read 2026-09-28)
- Model Context Protocol: Architecture overview (read 2026-09-28)
- MCP Inspector: Web client (read 2026-09-28)
- Cursor Docs: Model Context Protocol (MCP) (read 2026-09-28)
- Android Developers: Add an MCP server (read 2026-09-28)
- JSON-RPC 2.0 Specification (read 2026-09-28)
- MCP tools and gates
- MCP quickstart
- Sume basics
Related posts
More in Developers
- Faststart MP4: moving the moov atom to the front
A faststart MP4 has its index, the moov atom, at the start of the file. FFmpeg moves it there with -movflags +faststart in a second pass.
- p-limit npm: cap concurrent AI API jobs in Node.js
p-limit runs at most n promise-returning functions at once. For paid AI jobs, wrap the submit and the wait, not just the POST, and set n to your limit.
- Rate limit headers: what limit, remaining and reset mean
Rate limit headers report your request budget: the window's limit, what's left, and when it resets. What each means and how a client should pace itself.
- Retry-After header: how long to wait after a 429 or 503
Retry-After tells a client how long to wait before retrying: a number of seconds or an HTTP date, sent with 429 or 503. How to read it and what to do.
Written by Sume