This feature implements the MCP Tools specification. FrontMCP handles all protocol details automatically.
Why Tools?
In the Model Context Protocol, tools serve a distinct purpose from resources and prompts:
Tools are ideal for:
- API integrations — call external services, webhooks, third-party APIs
- Data mutations — create, update, delete records
- Calculations — perform computations, transformations
- System operations — file operations, process management
- Workflows — trigger multi-step processes, orchestration
Creating Tools
Class Style
Use class decorators for tools that need dependency injection, lifecycle hooks, or complex logic:Function Style
For simpler tools, use the functional builder:Registering Tools
Add tools to your app via thetools array:
Loading from npm or Remote Servers
You can mix local tool classes with tools loaded from npm packages or proxied from remote MCP servers:Tool.esm() loads a single named tool from an npm package at runtime. Tool.remote() proxies a single tool from a remote MCP server.
For loading entire apps (all tools, resources, prompts), use App.esm() or App.remote().Input Schemas
Tools use Zod schemas for type-safe input validation. The schema is automatically converted to JSON Schema for MCP protocol compatibility.Basic Types
With Descriptions
Optional and Default Values
Complex Types
Output Schemas
Optionally define an output schema for response validation:Output schema exposure
By default a structuredoutputSchema is advertised as the tool’s outputSchema (JSON Schema) in tools/list. The output policy lets you control where that schema surfaces. It is declarable on @Tool, @App, and @FrontMcp, and the effective value for a tool is resolved with a Tool > App > server > default cascade — mirroring the OpenAPI adapter’s outputSchema.mode.
When the schema is folded into the description (
'description' / 'both'), schemaDescriptionFormat picks the rendering: 'summary' (a compact human-readable property list) or 'jsonSchema' (a fenced JSON Schema code block).
Output-schema exposure only applies to structured object outputs (a Zod raw shape or a top-level
z.object) — the same forms that get advertised as outputSchema. Primitive, media, multi-content, and union outputs flow through content and have nothing object-shaped to expose. Runtime output validation still applies to every form regardless of schemaMode.Return Values
Tools support multiple return formats. The SDK automatically converts your return value to the MCPCallToolResult format.
Simple Returns
Full MCP Format
For complete control over the response, return the fullCallToolResult structure:
Multiple Content Items
Return an array to include multiple content blocks:Tool Metadata
Tool Examples
Provide examples to improve discoverability and help LLMs understand how to use your tools effectively.CodeCall Discovery
Examples are indexed for semantic search with 2x weight, helping users find the right tools faster.
LLM Understanding
The
codecall:describe tool returns up to 5 examples per tool to help LLMs understand usage patterns.Tool Annotations
Annotations provide hints to clients about tool behavior:Tool Context
Class-based tools have access to a rich execution context viathis:
Using Providers
Inject services via theget() method:
Request Context
Class-based tools have access to the full request context (FrontMcpContext) including tracing, timing, and authentication:
Progress Notifications
Send real-time updates to clients during long-running operations using MCP notifications.Sending Messages
Usethis.notify() to send log messages to the client:
'debug', 'info', 'warning', 'error'
Sending Progress
Usethis.progress() for progress bar updates. This only works when the client includes a progressToken in the request:
Progress notifications are only sent if the client includes a
progressToken in the request’s _meta field.
If no token is provided, this.progress() returns false and silently succeeds.Progress Token Access
TheprogressToken is automatically extracted from the request’s _meta field and made available via the ToolCallExtra type for advanced use cases:
this.progress() which handles the token automatically.
Real-World Examples
Calculator Tool
API Integration Tool
Database Mutation Tool
File Operation Tool
MCP Protocol Integration
Tools integrate with the MCP protocol via two flows:
When a client requests
tools/call with a name and arguments:
- The SDK locates the tool by name
- Arguments are validated against the tool’s
inputSchema - The
execute()method is called with the validated arguments - The return value is validated against
outputSchema(if provided) and converted to MCPCallToolResultformat
Capabilities
FrontMCP automatically advertises tool capabilities during MCP initialization:
The SDK sets
listChanged: true when you have any tools registered, enabling clients to receive real-time notifications when tools are dynamically added or removed.
Change Notifications
When tools change dynamically (e.g., via adapters or plugins), FrontMCP automatically sendsnotifications/tools/list_changed to connected clients. Clients that support this notification will refresh their tool list.
Tool UI
Tools can render visual widgets alongside their responses. This enables rich, interactive presentations of tool outputs—weather cards, order summaries, data tables, and more.Basic UI Configuration
Add aui property to attach a visual template:
Template Types
FrontMCP auto-detects your template type:UI Configuration Options
.tsx/.jsx widgets require @frontmcp/ui installed. When ui.template points at a .tsx/.jsx file (the recommended pattern for non-trivial widgets), FrontMCP injects an auto-generated React mount that imports McpBridgeProvider from @frontmcp/ui/react. Install @frontmcp/ui in the consuming project at the same version as @frontmcp/sdk — without it, server-side bundling fails.In the default resourceMode: 'cdn' mode, react / react-dom stay external and load from the CDN at runtime, so only @frontmcp/ui needs to be present on disk. When the framework selects resourceMode: 'inline' — either explicitly or via host detection (Claude, #456) — react and react-dom must also be resolvable from the consuming project so esbuild can bundle them into the widget; install them as devDependencies if your project doesn’t already pull them in. See building-tool-ui for the install snippet and the per-host trade-offs.resourceMode is host-detected for .tsx widgets. When you leave resourceMode unset, FrontMCP picks the right default per connecting client: Claude auto-switches to 'inline' (React bundled in — #456), so the widget actually renders in Claude’s sandboxed iframe. Other hosts keep 'cdn' (smaller payload, fetched from esm.sh). Set the value explicitly to opt out of detection:servingMode: 'static' widgets compile at server startup with no client context — set resourceMode: 'inline' explicitly when a static widget needs to render in Claude.ui.csp is honored by Claude (#455). FrontMCP now attaches ui.csp to the resources/read content item’s _meta.ui.csp (and _meta['ui/csp']), not just to the tool listing. Claude only reads CSP from the resource content — declarations on the tool were previously silently ignored. Use ui.csp.connectDomains for fetch/XHR/WebSocket allow-lists and ui.csp.resourceDomains for images / scripts / fonts / styles.Widget files use the
*.widget.tsx naming convention. .tsx/.jsx widgets are bundled separately by uipack/esbuild at render time. The tsconfig.json scaffolded by frontmcp init excludes **/*.widget.tsx / **/*.widget.jsx from the server typecheck so widgets don’t force the project to set jsx: 'react-jsx' or pull in @types/react. Running frontmcp init on an existing project also adds these excludes. For IDE typecheck of widget sources, add a sibling tsconfig.widget.json with jsx: 'react-jsx' and include: ['src/**/*.widget.tsx'].Using @frontmcp/ui Components
Combine Tool UI with the@frontmcp/ui component library:
Testing Tool UI
Use@frontmcp/testing for E2E validation of rendered widgets:
Building Tool UI
Complete configuration options and examples
React SDK
Pre-built React components from @frontmcp/react
Best Practices
Do:- Use descriptive
nameanddescriptionfields to help models understand tool purpose - Define clear input schemas with
.describe()on each field - Use appropriate annotations (
destructiveHint,idempotentHint, etc.) to guide client behavior - Validate inputs thoroughly and return meaningful error messages
- Keep tools focused on a single action or operation
- Create tools for read-only data retrieval (use resources instead)
- Skip input validation—always define a proper
inputSchema - Ignore error handling—wrap external calls in try/catch
- Create overly complex tools—split into multiple tools if needed
- Expose sensitive operations without proper authentication checks