# Tool scoping

Each endpoint has an `enabled_tools` allowlist with **allow-by-default** semantics: an **empty**
list permits **every** tool (including tools added later), and a **non-empty** list narrows to
exactly the tools named in it. The same predicate governs what `tools/list` shows and what
`tools/call` accepts, so the two cannot disagree. A disabled tool is hidden from the list AND
rejected at call time, reported identically to an unknown tool — and that rejection is audited.

:::info{title="New tokens are read-only by default"}

The console defaults a new endpoint to the read-only tools, so a fresh token cannot mutate
anything until someone deliberately grants a write tool.

:::

See the [Tools overview](/tools/overview) for which tools are read-only and which mutate state.
