What are MCP tool annotations?
Optional hints on an MCP tool that describe its behaviour: readOnlyHint, destructiveHint, idempotentHint and openWorldHint.
readOnlyHint: true says the tool does not change anything; destructiveHint says whether updates can be destructive; idempotentHint says repeating the same call has no extra effect; openWorldHint says the tool reaches outside systems such as the web. Clients can use them to decide when to ask for confirmation.
They are hints, not guarantees: the specification says clients must treat annotations as untrusted unless they come from a trusted server.
Example: "annotations": {"readOnlyHint": true, "openWorldHint": true, "idempotentHint": true, "destructiveHint": false}
Real example
The annotations published by our Kevscope MCP server's tools/list:
| Tool | Annotations |
|---|---|
cve_priority | readOnlyHint=true, openWorldHint=true, idempotentHint=true, destructiveHint=false |
kev_recent | readOnlyHint=true, openWorldHint=true, idempotentHint=true, destructiveHint=false |
epss_watchlist | readOnlyHint=true, openWorldHint=true, idempotentHint=true, destructiveHint=false |
Sources
Related terms
- Tool call (tools/list, tools/call)How an AI model uses an MCP tool: the client lists the server's tools with tools/list, the model picks one, and the client runs it with tools/call and returns the result to the model.
- MCP serverA program that exposes tools, resources or prompts to AI applications over the Model Context Protocol.