> ## Documentation Index
> Fetch the complete documentation index at: https://docs.checkfu.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Tool sources

> Discover callable tools and review their enablement and access.

A **ToolSource** describes where Checkfu discovers callable Tools. It can
point to an MCP server, an OpenAPI document, or inline API tool definitions.
A Tool has a name, schema, transport binding, and governed call path.

## Discover, review, and enable

Sync refreshes the source's Tool catalog. Review each Tool's schema and
enablement before making it available. A source can default newly discovered
Tools off; a later sync preserves explicit enablement decisions for Tools
already discovered. See [discovery and defaults](/concepts/capabilities#tool-sources).

Enablement does not grant permission. Safety hints are catalog metadata;
PermissionAssignments and ActionPolicies govern calls. In particular, MCP
hints alone do not authorize a call without review.

## Choose the right tool path

* Use a ToolSource for discovered MCP or HTTP operations
* Use a [Custom tool](/guides/serve-tools-from-your-app) when your application executes the handler
* Use the [Tools overview](/concepts/tools) to learn about built-in tools and their launch-time scope

[Managed Tools](/concepts/managed-tools) describe Checkfu-operated provider
accounts. The catalog is preview-only; execution and commercial activation
are not yet finished. They are separate from the built-in toolset.

The [Tools overview](/concepts/tools) compares these paths.
[Catalog search](/concepts/capabilities#searching-the-catalog) finds Tools and
Skills, while [Concepts](/concepts/concepts) add your Workspace's vocabulary.
Search ranking and reliability statistics never grant runtime authority.

## Operation boundaries

A ToolSource has no item-level read or delete operation. Its per-source
operations include sync, listing Tools, and versioned source revision.
Individual Tools support targeted read and enablement changes.

`reviseToolSource` (`POST /v1/tool-sources/{id}/source-versions`) adopts a
host-configured A2A ProviderPackage/source version. It requires mutation
headers (`RequiredMutationHeaders`), including `Idempotency-Key`, and returns
`ToolSourceVersionResult`. See the
[operation limits](/concepts/capabilities#surfaces-that-exist-only-in-part)
and [HTTP reference](/reference/overview) for exact contracts.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.