App functionality
Let the agent use selected features of your application with the user's permissions.
App functionality tools connect the agent to your product. Each tool wraps an existing oRPC procedure, so the agent uses the same validation and authorization as the rest of your app.
The included notification tools are a complete reference implementation. Users can ask which notifications are unread, or ask the agent to mark them as read.
How it works
- The agent decides to call a tool.
- The API invokes the underlying oRPC procedure with the current user's identity.
- The procedure validates the input and enforces permissions.
- The result is returned to the agent.
This means the agent can only act for the signed-in user, and only on data that user is allowed to access.
Example
Here is the included list_notifications tool from packages/api/lib/tools/notifications.ts:
import {
listNotifications,
listNotificationsInput,
listNotificationsOutput,
} from "../../modules/notifications/procedures/list-notifications";
{
name: "list_notifications",
label: "List notifications",
description: "List the current user's recent notifications and their read state.",
scope: "mcp:read",
input: listNotificationsInput,
output: listNotificationsOutput,
procedure: listNotifications,
executionMode: "sequential",
invalidates: [],
}The matching procedure lives in packages/api/modules/notifications/procedures/list-notifications.ts. It exports the Zod schemas and the authenticatedProcedure that performs the actual database query for the current user.
After this tool is registered, a user can ask:
Which of my notifications are unread?
The agent calls list_notifications, receives only that user's notifications, and answers from the result.
Add your own app functionality
- Write or reuse an oRPC procedure.
- Export its Zod input and output schemas.
- Add a tool definition under
packages/api/lib/tools/. - Register it in
applicationTools.
See Extending the agent for a complete walkthrough.