A chatbot answers from what it already knows. An AI agent can also take actions: search a database, call an API, run code, then use the results to decide the next step. The key capability that makes this possible is tool calling (also called function calling).
Chatbot vs agent
| Chatbot | Agent |
|---|---|
| One question, one answer | Works in a loop until the goal is met |
| Uses only its training data | Calls tools to get fresh data or act |
| No memory of steps | Keeps track of previous tool results |
How tool calling works
- You describe your tools to the model: name, purpose and input parameters (as JSON Schema).
- The model reads the user request and replies either with a final answer or with a request to call a tool with specific arguments.
- Your code runs the tool and sends the result back to the model.
- Repeat until the model gives a final answer.
The model never runs code itself. It only asks; your program decides whether to execute. This is where you add validation and permissions.
Step 1: Define tools
import json
def get_batch_dates(course: str) -> dict:
data = {"playwright": ["2026-11-03", "2026-11-17"], "java": ["2026-11-10"]}
return {"course": course, "dates": data.get(course.lower(), [])}
def get_fee(course: str) -> dict:
fees = {"playwright": 25000, "java": 40000}
return {"course": course, "fee_inr": fees.get(course.lower())}
TOOLS = {"get_batch_dates": get_batch_dates, "get_fee": get_fee}
TOOL_SPECS = [
{"name": "get_batch_dates", "description": "Upcoming batch start dates for a course",
"parameters": {"type": "object", "properties": {"course": {"type": "string"}}, "required": ["course"]}},
{"name": "get_fee", "description": "Course fee in INR",
"parameters": {"type": "object", "properties": {"course": {"type": "string"}}, "required": ["course"]}},
]Step 2: The agent loop
The exact API call differs by provider (OpenAI, Gemini, Claude, or a local model), but the loop is always the same. call_llm below stands for your provider's chat API with tools enabled.
def run_agent(user_message: str, max_steps: int = 5) -> str:
messages = [
{"role": "system", "content": "You help students with course info. Use tools for dates and fees."},
{"role": "user", "content": user_message},
]
for _ in range(max_steps):
reply = call_llm(messages, tools=TOOL_SPECS)
if not reply.tool_calls:
return reply.content # final answer
messages.append(reply.as_message())
for call in reply.tool_calls:
fn = TOOLS.get(call.name)
args = json.loads(call.arguments)
result = fn(**args) if fn else {"error": f"unknown tool {call.name}"}
messages.append({"role": "tool", "tool_call_id": call.id, "content": json.dumps(result)})
return "Sorry, I could not finish that request."
print(run_agent("When does the next Playwright batch start and what is the fee?"))For this question the model typically calls get_batch_dates and get_fee, receives both results, and then writes one combined answer.
Design rules for safe agents
- Limit steps (
max_steps) so a confused agent cannot loop forever. - Validate arguments before running a tool; never pass model output straight into SQL or shell commands.
- Least privilege: give read-only tools unless writing is truly needed, and ask for human confirmation before payments, emails or deletes.
- Log every tool call with inputs and outputs for debugging and audits.
- Small, clear tools work better than one giant tool with many options.
Where MCP fits
The Model Context Protocol (MCP) is an open standard for exposing tools and data to AI apps. Instead of writing custom tool code for every app, you run an MCP server (for example, for GitHub, a database or your file system), and any MCP-compatible client can discover and use its tools.
Interview questions
| Question | Short answer |
|---|---|
| What is tool calling? | The model returns a structured request to run a named function with JSON arguments. |
| How do you stop infinite loops? | A maximum step count, timeouts and clear stop conditions. |
| What is a multi-agent system? | Several specialised agents (planner, researcher, coder) that hand work to each other. |
| What is MCP? | An open protocol that standardises how AI apps connect to tools and data sources. |
Next steps
Extend the agent with a search tool and memory, then add human approval for risky actions. Build production agents and MCP servers in our AI Agents, Agentic AI & MCP course.
