tools/list at connection time. All tools are workspace-scoped — you only access data in your own workspace.
Tool availability depends on your scope:
read:<module> lets you call read-only tools, write:<module> (which implies read) lets you call both read and write tools, and delete:<module> lets you call delete tools. See Authentication for scope details.