Configuration
Pass an IoCodeMode.Config object to IoCodeModeFactory.
interface Config {
wasmLocation: string;
overwriteSystemInstruction?: (current: string) => string;
interceptors?: {
onToolCall?: (context: ToolCallContext) => Promise<InterceptorDecision>;
};
timeout?: number;
memoryLimit?: number;
toolFilter?: (tool: ToolDefinition) => boolean;
}
| Property | Required | Default | Purpose |
|---|---|---|---|
wasmLocation | Yes | - | URL in a browser or filesystem path in Node.js to the QuickJS WebAssembly file. |
overwriteSystemInstruction | No | Identity | Replaces or extends the built-in instructions given to the model. |
interceptors.onToolCall | No | Allow | Asynchronous authorization, approval, validation, or input-rewriting hook. |
timeout | No | 30000 | Maximum execution time in milliseconds. |
memoryLimit | No | 128 | Sandbox memory limit in megabytes. |
toolFilter | No | Include all | Returns true to expose a tool or false to hide it. |
Delivering the WASM File
Code Mode publishes the QuickJS asset at @interopio/code-mode/dist/emscripten-module.wasm. You can copy this file from the installed package into a location of your choosing and set wasmLocation to its browser URL or server filesystem path.
For browser applications, a version-pinned CDN path is also supported:
wasmLocation: "https://unpkg.com/@interopio/code-mode@0.0.2/dist/emscripten-module.wasm";
Use an exact package version with a CDN URL. Self-host the asset when the application must control availability, satisfy a restrictive content security policy, or avoid a runtime dependency on a public CDN.
Tool Policies
Use toolFilter to remove tools from both discovery and execution. Use interceptors.onToolCall to decide whether an individual call is allowed, denied with a reason, or run with replacement input.
const codeMode = await IoCodeModeFactory({
wasmLocation: "/quickjs/emscripten-module.wasm",
toolFilter: (tool) => !tool.name.startsWith("admin."),
interceptors: {
onToolCall: async ({ tool, input }) => {
if (tool.name === "payments.transfer") {
return { allowed: false, reason: "Transfers require manual approval." };
}
return { allowed: true, input };
},
},
});
The sandbox isolates generated JavaScript from the host runtime, but it does not make underlying tools safe. The host remains responsible for validating inputs and enforcing authorization for side-effecting operations.
Pass opaque caller state to an individual executeCode invocation with execute(args, { context }). Code Mode forwards it to onToolCall as callContext and to each underlying tool as options.context, without exposing it to sandbox code. For example, an MCP host can forward request metadata for authorization:
const executeCode = session.getLlmTools().find((tool) => tool.name === "executeCode")!;
const result = await executeCode.execute({ code: "return await tool_search({ query: 'orders' });", explanation: "Search for orders." }, { signal, context: requestMetadata });
The signal and context belong to this execution only, even if another call uses the same session. onToolCall can inspect callContext for policy decisions; sandbox code cannot read or forge it.