Tool Calling
Understand how agents safely call APIs, databases, browsers, and external tools.
Topic guide
Go deep on tool calling.
Read the full IndieFounder collection, from fundamentals to production implementation, security boundaries, failure modes, and operational practices.
All Tool Calling articles
Newest and most relevant articles first. The collection grows automatically as new articles are published.
AI Agent Tool Retries: How to Handle Failed Function Calls Without Duplicates
Retries are essential for unreliable APIs, but blindly repeating a side effect can create duplicate payments, messages, or records.
AI Agent Idempotency: How to Make Tool Execution Safe to Repeat
An agent may retry the same action after a timeout even when the external system already completed it. Idempotency prevents duplicate side effects.
AI Agent Tool Timeouts: How to Prevent Stuck Agent Workflows
External APIs hang, queues back up, and browsers stop responding. Agents need explicit timeout and cancellation behavior.
AI Agent Tool Schemas: How to Design Functions Models Can Use Reliably
A tool schema is an API contract between an agent and your application. Good schemas reduce ambiguity, invalid calls, and unsafe assumptions.
AI Agent Tool Calling Explained for Developers
Tool calling is the bridge between model reasoning and real application actions. The server still owns validation and authorization.
AI Agent Tool Errors: How to Return Errors the Model Can Recover From
A tool error should tell the agent what failed, whether retrying makes sense, and whether the action changed anything.
AI Agent Tool Validation: Never Trust Model-Generated Arguments
Structured function calling does not make arguments trustworthy. Every tool input still needs server-side validation.
AI Agent Parallel Tool Calls: When to Run Tools Concurrently
Parallel tool execution can dramatically reduce latency, but only when calls are independent and safe to run together.
MCP Tool Discovery: How to Keep Large Agent Toolsets Manageable
As an agent connects to more MCP servers, the available tool set can become difficult to reason about.
MCP Prompt Injection Defense: How to Protect Agent Tools
MCP-connected content can contain instructions that attempt to influence an agent.
MCP Client Architecture: How AI Agents Discover and Use Tools
MCP clients connect agent runtimes to external capabilities, but discovery does not equal authorization.
AI Agent Tool Design: Why Narrow Tools Beat Generic API Clients
Giving an agent a generic HTTP client creates a huge capability surface. Narrow business tools make authorization, validation, and observability easier.
How to Build an AI Agent Around the Responses API
Build a focused agent around the Responses API with typed tools, server-side authorization, safe retries, and an evaluation loop.
AI Agent External API Data Filtering: How to Limit What Agents Can See
An external API may return far more data than an agent needs.

Wikimedia’s OpenAI Agent Report Is a Release Gate for Indie Tools
On 5 October 2026 Wikimedia said OpenAI-linked agents edited wikis, probed a public pad, and may have contributed to a May query-service outage. Ship the control list before your own agent does the smaller version.
MCP Tool Permissions: How to Limit What an Agent Can Access
Connecting an MCP server can expose many capabilities at once.
MCP Server Design: How to Build Tools Agents Can Use Safely
An MCP server is a capability boundary. Good design keeps tools narrow, explicit, validated, and easy to audit.
MCP Observability: What to Log for Agent Tool Usage
When agents use multiple MCP servers, debugging requires a clear trail of discovery and execution.
How to Give AI Agents Secure Access to External Tools
A practical architecture for giving AI agents useful tool access without turning the model into a production superuser.
AI Agent Reliability: Retries, Timeouts, Fallbacks and Human Review
Reliable agents use bounded retries, explicit timeouts, fallbacks, idempotent writes, and human review for uncertain or high-impact operations.
AI Agent Architecture: Models, Tools, Memory, Permissions and Logs
A production agent is a software system around a model. Separate reasoning, tools, state, permissions, approvals, and observability.
The New Developer Tooling Layer: Security for AI Agents
As coding agents gain access to repositories and external tools, security around permissions, provenance, and safe execution is becoming a new product category.
MCP Security for AI Agents: How to Review Tools Before Connecting Them
Connecting an agent to an MCP server expands its capabilities and its attack surface. Review tools, permissions, trust boundaries, and outputs before enabling them.
Docker Cloud Sandboxes Change Where Long-Running AI Coding Work Happens
Docker is moving its microVM-based agent sandbox from the laptop to managed cloud compute, giving developers a way to leave long-running coding tasks running after the laptop closes.
ByteAsk Is Betting on Specialized AI Coding Agents for C and C++
A new $1 million-backed startup is targeting reliability-heavy software where generic coding copilots face harder constraints.
Ando Emerges: Agent-Native Messaging That Treats AI as Teammates, Not Bots
Ando raised $20M and launched a Slack alternative where agents get identities, inboxes, and the right to join conversations without being tagged — a practical signal for indie founders building agent-heavy teams.
Morning Briefing: Desktop AI Agents Land and Indie Founders Keep Shipping
Cua-style agents control apps without hijacking the mouse, Meta Muse keeps climbing charts, and a fresh wave of micro-tools hit InventList. Here’s what solo builders should watch today.
OpenAI Agents API in Public Beta: The Solo Founder Playbook for Managed Cloud Agents
OpenAI shipped the Agents API on September 10 with the Codex harness, hosted sandboxes, and multi-agent support — here is how an indie team should adopt it this week without rebuilding infrastructure.
Meta Muse Hits Amazon’s Wall: What Agentic Commerce Means for Solo Founders
Amazon blocked Meta’s viral Muse agent from shopping. Indie teams now need explicit agent identity, opt-in APIs, and fallback paths—not silent browser automation.
GitHub Copilot OpenTelemetry Arrives: Agent Observability Playbook for Indie Founders
On September 22 GitHub enabled managed OpenTelemetry export for Copilot agents. Solo builders finally get the same session traces enterprises already use—here is how to apply it to your micro-SaaS agents this week.
Claude Opus 5.5 Dropped Yesterday: The Solo Founder Playbook for a Cheaper Frontier Model
Anthropic shipped Opus 5.5 on September 22 with Fable-class agentic coding, $4/$20 token pricing, and cache reads at $0.20 — here is how an indie team should switch this week.
Grok 4.7 Landed September 21: A Builder’s Read on Speed, Voice, and Cost
xAI shipped Grok 4.7 a day before the Anthropic and OpenAI price cuts. Pair it with Grok Voice Transcribe 2.0 only where latency beats another 2% on a coding bench.
GPT-6 Sol and Luna Cut API Prices in Half: What a Micro-SaaS Should Route Where
OpenAI shipped Sol and Luna on September 22 at 50% of GPT-5.6 rates. Here is the routing table for a bootstrapped product that cannot put Astra on every request.
Qwen3.8-Omni-Flash: 1M Context for Builders Who Hate Brittle RAG
Alibaba’s mid-September omni model takes text, image, audio, and video and answers in text with a 1M-token window. Useful if your agent is still a pile of chunkers.
AI Agent Tracing: How to Design End-to-End Agent Traces
A useful trace should explain what an agent did, why it did it, and where the workflow spent time.
AI Agent Session Replay: How to Debug Multi-Step Agent Runs
Multi-step agent failures are difficult to reproduce because the final error often hides the earlier decision that caused it.
AI Coding Agent Secret Protection: How to Stop Credential Leaks
Agents can read files, logs, environment variables, and command output where secrets may appear.
AI Coding Agent Sandboxing: How to Isolate Agent-Generated Code
Coding agents can execute commands, install packages, inspect files, and run applications.
AI Coding Agent Command Permissions: How to Control Shell Access
A coding agent with unrestricted shell access can do far more than edit source files.
Flatkey and the One-API Model: AI Access Is Becoming a Commodity Layer
As startups bundle access to many official AI models behind one billing and routing layer, the competitive advantage is moving upward into workflow and product experience.
OpenAI vs Claude for Building AI Agents: What Developers Should Compare
Compare OpenAI and Claude on the runtime details that affect your workflow: tools, state, sandboxing, latency, cost, and evaluation.
AI Coding Agents Need a Production Control Loop, Not Just a Prompt
AI coding agents can compress implementation time, but production quality still needs an explicit engineering loop.
AI Agents Are Creating a New Runtime Security Layer
As software agents gain permission to use tools, access data and take actions, security is moving from model prompts into the runtime itself.
AI Coding Agents Are Becoming Development Workspaces
Coding agents are moving beyond autocomplete into repositories, tests, tools, and review workflows.
SaaS Security When Your Agent Can Use the Computer
Frontier models now click, type, and open shells. The security checklist for a solo shop is secrets, scopes, and a kill switch — not a PDF policy.
Palo Alto’s AI Defense Push Shows Security Is Becoming an Agent Runtime Problem
Continuous AI-powered security testing points toward a future where applications and agents are checked continuously instead of only during periodic security reviews.
Cognition SWE-2 Is Out: Treat Coding Agents Like Junior Hires, Not Magic
SWE-2 shipped September 10. The indie take is process: specs, evals, and a human merge gate — not a new religion about autonomous engineers.
More from the hub
Explore another topic
AI Agent Security
Protect agents, tools, credentials, data, and execution environments.
ExploreAgent Permissions
Design least-privilege access and approval boundaries for autonomous agents.
ExploreAgent APIs
Build reliable APIs and interfaces for agents that need to take actions.
ExploreMCP
Connect models to tools and data without turning every integration into a security hole.
Explore