How MCP clients use read-only and destructive hints, and why calendar grants and confirmations still matter.
An MCP client should know whether a calendar tool reads data or changes it before it asks an agent to call that tool. Tool annotations supply that signal, but they do not replace account permissions or human confirmation.
The MCP tools specification defines hints such as readOnlyHint, destructiveHint, and openWorldHint. They describe expected tool behavior for the client. They are not an authorization system. A client still needs to treat the server as a trust boundary.
In CalendarMCP, list_events, get_event, and list_calendars are annotated as read-only. A create operation is a write. A delete or attendee-changing operation carries a stronger warning. The exact hints are visible in the tool definitions returned to an MCP client.
For example, an agent can call list_calendars first, then draft a proposed change. Even if the client permits update_event, the server will reject a write to a calendar with only Read access.
Use annotations to choose the right approval UX, and use calendar grants to enforce access. Neither one makes a bad calendar edit safe by itself.
Sources: MCP tools specification and CalendarMCP tool documentation.
Connect your Google Calendar to Claude and any MCP client in about two minutes.
Connect Google Calendar