MCP tool annotations explained — readOnly, idempotent, destructive, openWorld
MCP servers can tag each tool with hints about what calling it will do — read-only, idempotent, destructive, open-world. Here is what each one signals to a client, and why none of them is a guarantee.