Blog
4 min read

What Is Function Calling (Tool Calling) in AI? Explained With Examples

Function calling — also called tool calling or tool use — lets an AI model ask your code to do things: look up an order, check the weather, query a database. How it works step by step, a Claude example, why the model never runs your code itself, and how to keep it safe.

On its own, a language model can only produce text. It can't check your stock levels, look up an order, or book a meeting. Function calling — also called tool calling or tool use; they mean the same thing — is how you let it.

The short version

You tell the model: "Here are some functions you can ask me to run, and what each one needs." When answering a question, the model can reply with a request to call one of them instead of a final answer. Your code runs the function and sends the result back. The model then uses that result to answer.

The model never runs anything itself. It asks; your code decides.

A worked example

You're building a support chat for a shop. You give the model one tool:

  • Name: get_order_status
  • Description: "Look up the status of a customer's order by its order number."
  • Input: an order_id string.

A customer types: "Where's my order 48213?"

  1. Your app sends the question and the tool description to the model.
  2. The model replies: "Call get_order_status with order_id: "48213"."
  3. Your code runs the real lookup against your database: shipped, arriving Thursday.
  4. Your app sends that result back to the model.
  5. The model answers: "Your order 48213 has shipped and should arrive on Thursday."

What it looks like with Claude

Here's the tool definition and the first request, using Anthropic's TypeScript SDK:

import Anthropic from "@anthropic-ai/sdk";

const client = new Anthropic();

const tools: Anthropic.Tool[] = [
  {
    name: "get_order_status",
    description: "Look up the status of a customer's order by its order number.",
    input_schema: {
      type: "object",
      properties: {
        order_id: { type: "string", description: "The order number, e.g. 48213" },
      },
      required: ["order_id"],
    },
  },
];

const response = await client.messages.create({
  model: "claude-opus-5-5",
  max_tokens: 1024,
  tools,
  messages: [{ role: "user", content: "Where's my order 48213?" }],
});

If Claude wants the tool, the response has stop_reason: "tool_use" and contains a tool_use block with the tool's name and input. Your code runs the lookup and sends back a tool_result block carrying the same id. Claude then writes the final answer. The SDKs also include a "tool runner" helper that does this back-and-forth for you.

The input schema uses JSON Schema — a standard way to describe what shape of data you expect. (New to JSON? See what is JSON?)

Where you've already seen this

  • AI coding agents like Claude Code are function calling at scale: "read this file", "run this command" and "edit this line" are all tools. See what is an AI coding agent?
  • MCP is a standard for packaging tools so any AI app can use them. See what is MCP?
  • Chat assistants that search the web or create calendar events use tools.

Writing good tools

  • Clear names and descriptions. The model decides which tool to use almost entirely from the description. "Look up an order's shipping status by order number" beats "order tool".
  • Few, focused tools. Five well-defined tools work better than thirty overlapping ones.
  • Strict inputs. Mark required fields, use enums for fixed choices, and consider strict mode, which guarantees the model's input matches your schema.
  • Helpful results. Return what the model needs in a readable form, and return clear errors ("order not found") rather than crashing.

Keeping it safe

Function calling is where an AI feature touches real data, so treat the model's requests like user input — because they partly are.

  • Check permissions in your code. If customer A asks about customer B's order, your get_order_status function must refuse, regardless of what the model asked. Pass the logged-in user's ID from your session, not from the model. (This is the AI version of IDOR.)
  • Validate every input before using it — see validating input with Zod.
  • Read-only first. Start with tools that look things up. Add tools that change things (refunds, deletions) only with confirmation steps.
  • Watch for prompt injection. Text the model reads — a web page, an email, a product review — can contain instructions trying to make it misuse tools. See prompt injection in coding agents.

The summary

  • Function calling lets a model ask your code to run a function and use the result.
  • You describe tools with a name, description and JSON Schema; your code executes them.
  • It powers AI agents, MCP and assistants that "do things".
  • Enforce permissions and validation in your code — never trust the model's request blindly.

EasySpawn gives your app and Claude Code a real server with a real database, so the tools you build can be tested against actual data before anything reaches users. See how it works or join the waitlist.

Related: What Is an LLM? · Structured Output From LLMs · How to Add an AI Chatbot to Your App · Securing MCP Servers

Keep reading