Tools
Give your AI real capabilities with executable Python functions.
Tools are Python functions the model can call to take action: query a database, hit an internal API, run a calculation, search the web. Unlike Skills (plain-text instructions), a Tool actually executes code on the server and returns a real result back to the model.
Write a tool once in the built-in code editor, attach it to any model, and every conversation with that model gains the capability — no redeployment needed.
Why Tools?
Real actions, not just text
A skill can tell the model how to format a support ticket. A tool actually files it. Anything that needs to touch a live system — a database, an API, the filesystem, a calculation engine — belongs in a tool.
Python, not a plugin SDK
Tools are plain Python classes with a Tools class and typed methods. Docstrings and type hints become the function schema the model sees — no separate manifest file to maintain.
Reusable across models
Write a tool once, attach it to as many models as need it. Update the implementation in one place and every model that uses it gets the change immediately.
AI-assisted authoring
Describe what you want in plain English and Generate with AI drafts the Python implementation for you, ready to review and edit in the code editor.
Tools run real Python on the server. Creating or importing a tool is equivalent to shell access to your instance. See Tools Access = Root-Equivalent Access and the Plugin Security Warning before granting this permission to anyone you don't fully trust.
Key Features
| 🐍 Python code editor | Full syntax-highlighted editor with a starter boilerplate for new tools |
| ✨ Generate with AI | Describe the tool in plain English and get a working implementation |
| 🤖 Model binding | Attach tools to models so they're always callable |
| 📥 Import / Export | Import a .py file directly, or a bundle via Import Bundle; export as .py |
| 🏷️ Tags | Tag tools for organization, then filter the list by tag |
| ☑️ Delete Selected | Check multiple tools and remove them in one confirm-and-go action |
| 🔒 Access control | Private by default, shareable with users or groups |
| 🔀 Active/Inactive toggle | Deactivate tools without deleting them |
Creating a Tool
Navigate to Workspace > Tools and click + New Tool.
| Field | Description |
|---|---|
| Tool Name | Human-readable display name |
| Tool ID | Unique slug, auto-generated from the name |
| Tool Description | Short summary shown to the model when deciding whether to call the tool |
| Content | The Python implementation — a Tools class with one method per callable function |
| Tags | Free-text labels for organizing and filtering the tool list |
Docstrings on each method become the description the model sees for that specific function; type-annotated parameters become the function's argument schema.
Importing a tool
Click Import and select a .py file to create a tool from existing code. For migrating a whole batch of scripts or a plugin bundle at once, use Import Bundle (.zip) — see Import Bundle.
Tags
Add tags while creating or editing a tool. Type a tag and press Enter, or type it and click Save directly — both commit the tag.
On the Workspace > Tools list, the tag dropdown next to the search box filters the visible list down to tools carrying the selected tag. Tags are stored per-tool and are independent of access control — tagging a tool doesn't change who can see or use it.
Tool Management
From the Tools workspace list, use the ellipsis menu (...) on any tool:
| Action | Description |
|---|---|
| Edit | Modify the implementation, name, description, or tags |
| Clone | Create a copy with (Clone) appended to the name |
| Export | Download as a .py file |
| Delete | Permanently remove |
Delete Selected: Check the boxes on multiple tools (checkbox appears on each card) and click Delete Selected (N) in the toolbar. Confirms once, then removes every checked tool; if some fail (e.g. a permission change mid-batch), you get a summary of how many succeeded versus failed rather than a silent partial delete.
Active/Inactive toggle: Inactive tools are excluded from the model's function list and cannot be called in chat.
Binding Tools to a Model
- Go to Workspace > Models.
- Edit a model and scroll to the Tools section.
- Check the tools you want this model to have access to.
- Click Save.
Tools can also be toggled per-chat from the ⬡ Tools popup in the chat input, the same way per-chat Skills work.
Access Control
Tools use the same Access Control system as other workspace resources:
- Private by default: Only the creator can see and edit a new tool.
- Share with users or groups: Grant
readorwriteaccess via the Access button. - Read-only access: Users with read access can use the tool but not edit its code.
Required permissions
| Permission | What it controls |
|---|---|
| Workspace > Tools Access | Access the Tools workspace and create/manage tools |
| Workspace > Tools Import | Import tools from .py files or a bundle |
| Workspace > Tools Export | Export tools to .py files |
| Sharing > Share Tools | Share tools with individual users or groups |
| Sharing > Public Tools | Make tools publicly accessible |
Granting Tools Access lets a user create and run arbitrary Python on your server. Only grant it to users you'd trust with direct server access. See Permissions for the full warning.
Use Cases
Internal API integrations
Wrap an internal REST API in a tool so the model can look up order status, create a ticket, or fetch account details directly in chat.
Calculations and data transforms
Anything a plain-text instruction can't reliably do — precise math, date arithmetic, unit conversion, parsing structured data — belongs in a tool where actual code runs it.
Migrating an existing script library
Bring in a folder of standalone .py scripts via Import Bundle — each script is wrapped as a callable tool automatically, with a code-execution warning shown before you confirm the import.
Limitations
Requires trusted authors
Because tool code executes on the server, tool creation should be restricted to trusted users. See the Access Control section above.
No sandboxing beyond the process boundary
Tools run as regular Python in the backend process. They are not sandboxed beyond what the server's own OS-level permissions provide — write your tools defensively and avoid granting Tools Access broadly.