▸ Agent Skills
5 min read

Documentation Index

Fetch the complete documentation index at: https://agentclientprotocol.com/llms.txt Use this file to discover all available pages before exploring further.

Tool Calls

How Agents report tool call execution

Tool calls represent actions that language models request Agents to perform during a prompt turn. When an LLM determines it needs to interact with external systems—like reading files, running code, or fetching data—it generates tool calls that the Agent executes on its behalf.

Agents report tool calls through session/update notifications, allowing Clients to display real-time progress and results to users.

While Agents handle the actual execution, they may leverage Client capabilities like permission requests or file system access to provide a richer, more integrated experience.

Creating

When the language model requests a tool invocation, the Agent SHOULD report it to the Client:

{
  "jsonrpc": "2.0",
  "method": "session/update",
  "params": {
    "sessionId": "sess_abc123def456",
    "update": {
      "sessionUpdate": "tool_call",
      "toolCallId": "call_001",
      "title": "Reading configuration file",
      "kind": "read",
      "status": "pending"
    }
  }
}
A unique identifier for this tool call within the session A human-readable title describing what the tool is doing The category of tool being invoked. * `read` - Reading files or data - `edit` - Modifying files or content - `delete` - Removing files or data - `move` - Moving or renaming files - `search` - Searching for information - `execute` - Running commands or code - `think` - Internal reasoning or planning - `fetch` - Retrieving external data * `other` - Other tool types (default)

Tool kinds help Clients choose appropriate icons and optimize how they display tool execution progress.

The current [execution status](#status) (defaults to `pending`) [Content produced](#content) by the tool call [File locations](#following-the-agent) affected by this tool call The raw input parameters sent to the tool The raw output returned by the tool

Updating

As tools execute, Agents send updates to report progress and results.

Updates use the session/update notification with tool_call_update:

{
  "jsonrpc": "2.0",
  "method": "session/update",
  "params": {
    "sessionId": "sess_abc123def456",
    "update": {
      "sessionUpdate": "tool_call_update",
      "toolCallId": "call_001",
      "status": "in_progress",
      "content": [
        {
          "type": "content",
          "content": {
            "type": "text",
            "text": "Found 3 configuration files..."
          }
        }
      ]
    }
  }
}

All fields except toolCallId are optional in updates. Only the fields being changed need to be included.

Requesting Permission

The Agent MAY request permission from the user before executing a tool call by calling the session/request_permission method:

{
  "jsonrpc": "2.0",
  "id": 5,
  "method": "session/request_permission",
  "params": {
    "sessionId": "sess_abc123def456",
    "toolCall": {
      "toolCallId": "call_001"
    },
    "options": [
      {
        "optionId": "allow-once",
        "name": "Allow once",
        "kind": "allow_once"
      },
      {
        "optionId": "reject-once",
        "name": "Reject",
        "kind": "reject_once"
      }
    ]
  }
}
The session ID for this request The tool call update containing details about the operation Available [permission options](#permission-options) for the user to choose from

The Client responds with the user’s decision:

{
  "jsonrpc": "2.0",
  "id": 5,
  "result": {
    "outcome": {
      "outcome": "selected",
      "optionId": "allow-once"
    }
  }
}

Clients MAY automatically allow or reject permission requests according to the user settings.

If the current prompt turn gets cancelled, the Client MUST respond with the "cancelled" outcome:

{
  "jsonrpc": "2.0",
  "id": 5,
  "result": {
    "outcome": {
      "outcome": "cancelled"
    }
  }
}
The user's decision, either: - `cancelled` - The [prompt turn was cancelled](https://agentclientprotocol.com/protocol/v1/prompt-turn#cancellation) - `selected` with an `optionId` - The ID of the selected permission option

Permission Options

Each permission option provided to the Client contains:

Unique identifier for this option Human-readable label to display to the user A hint to help Clients choose appropriate icons and UI treatment for each option.
  • allow_once - Allow this operation only this time
  • allow_always - Allow this operation and remember the choice
  • reject_once - Reject this operation only this time
  • reject_always - Reject this operation and remember the choice

Status

Tool calls progress through different statuses during their lifecycle:

The tool call hasn't started running yet because the input is either streaming or awaiting approval The tool call is currently running The tool call completed successfully

The tool call failed with an error

Content

Tool calls can produce different types of content:

Regular Content

Standard content blocks like text, images, or resources:

{
  "type": "content",
  "content": {
    "type": "text",
    "text": "Analysis complete. Found 3 issues."
  }
}

Diffs

File modifications shown as diffs:

{
  "type": "diff",
  "path": "/home/user/project/src/config.json",
  "oldText": "{\n  \"debug\": false\n}",
  "newText": "{\n  \"debug\": true\n}"
}
The absolute file path being modified The original content (null for new files) The new content after modification

Terminals

Live terminal output from command execution:

{
  "type": "terminal",
  "terminalId": "term_xyz789"
}
The ID of a terminal created with `terminal/create`

When a terminal is embedded in a tool call, the Client displays live output as it’s generated and continues to display it even after the terminal is released.

Learn more about Terminals

Following the Agent

Tool calls can report file locations they’re working with, enabling Clients to implement “follow-along” features that track which files the Agent is accessing or modifying in real-time.

{
  "path": "/home/user/project/src/main.py",
  "line": 42
}
The absolute file path being accessed or modified Optional line number within the file

Last updated Oct 08, 2026