Each tool calls only the REST operations listed beside it, with the same request fields and error codes as the REST API. The tools stay at parity with the public REST API, except deposits and withdrawals: every public operation is reached by a tool or excluded for a stated reason, and the build fails when either drifts. Each hosted request requires an approved read-capable key, even for catalogue tools. Tools cannot make deposits or withdrawals. They also cannot change a Canton Party or manage API keys. Those actions require the owner’s passkey session. See API keys. For live market and account updates, use WebSockets. MCP market tools return snapshots, not a streaming feed.