Tool Calling
The model proposes a tool name and JSON arguments. Your server, not the model, validates permissions and performs the database, network, or write operation.
Declare a tool
bash
# Start with a read-only tool to verify model compatibility safely.
curl https://sprelaytoken.com/v1/chat/completions \
-H "Authorization: Bearer $SPRELAY_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"model": "gpt-5.6-sol",
"messages": [
{"role": "user", "content": "What is the weather in London today?"}
],
"tools": [
{
"type": "function",
"function": {
"name": "get_weather",
"description": "Get weather for a city",
"parameters": {
"type": "object",
"properties": {
"city": {"type": "string", "description": "City name"}
},
"required": ["city"],
"additionalProperties": false
}
}
}
]
}'| Field | Meaning |
|---|---|
tools | Tools the model may request during this call |
type: function | Declares a function-style tool |
name | Stable name used to select your handler |
description | Helps the model decide when to use it |
parameters | JSON Schema for allowed arguments |
required | Arguments that must be present |
additionalProperties: false | Rejects undeclared arguments |
JSON cannot contain comments, so preserve its punctuation when editing.
Execution loop
- Send messages and tool definitions.
- Check whether the model returned a tool call.
- Validate the name against an allowlist and the arguments against the Schema.
- Apply business authorization and a timeout.
- Execute the approved server-side handler.
- Send the result back with the original tool-call ID.
- Read the model's final answer.
Treat all model-generated arguments as untrusted input. Never concatenate them directly into SQL, shell commands, or unrestricted URLs. Require confirmation or idempotency for writes, cap tool-call loops, and avoid returning credentials or internal stack traces.
