Skip to main content

Capabilities

Code Mode lets an assistant write programs that call your tools, and runs those programs in an isolated environment. Your application decides which tools a program can reach and remains responsible for carrying out any actions.

Capability Overview

The assistant writes the plan as code; Code Mode runs it safely.

Tools become functions the program can call. Your application controls which tools are offered and can check each call before it happens.

Capability Areas at a Glance​

Code-driven orchestration

Express a multi-step task as a program that calls tools, branches on results, and combines them.

Tool discovery

Offer the assistant three stable tools for finding, inspecting, and calling the rest of your catalog.

Isolated execution

Run model-generated code in a sandbox that can reach only the tools you registered.

Browser and Node.js

Run the same sandbox inside a web application or a Node.js server, with no external execution service.

Controlled access

Hide tools, check each call before it runs, and require approval before sensitive actions.

Independent sessions

Serve concurrent runs with their own tool sets, cancellation, and caller context.

Limits and cancellation

Cap execution time and memory, and stop a program's tool calls when a request is cancelled.


Orchestrate Tools Through Code​

The assistant writes a program instead of issuing tool calls one at a time. Inside that program, each tool is an asynchronous function. For example, the assistant can look up an order, check its delivery status, and prepare a response from both results in a single program, using ordinary loops and conditions to decide what to call next. Only the program's final result goes back to the assistant.

BenefitDescription
Fewer round tripsSeveral tool calls run in one step instead of one conversation turn each
Smaller conversationIntermediate results stay inside the program; only the final value returns
Familiar logicLoops, conditions, and data transformations are written as ordinary JavaScript
Best For
  • Tasks that chain several dependent tool calls
  • Filtering or aggregating large tool results before the assistant sees them
  • Repeating the same call across a list of items

Discover Tools as Needed​

Instead of receiving every tool in your catalog, the assistant receives three stable tools. It uses them to find what is available, read the schemas it needs, and run its program. A growing catalog therefore does not make every request larger.

ToolPurpose
getToolsLists the available tools and their descriptions
getToolDefinitionReturns the input and output schemas for a selected tool
executeCodeRuns a program with the available tools bound as asynchronous functions

Inside the program, tool names become safe JavaScript identifiers under a tool_ prefix. For example, weather.get-current may be exposed as tool_weather_get_current.


Run Generated Code in Isolation​

Code Mode executes the assistant's program in an isolated environment, separate from your application's runtime. The program can use only the tool functions your application registered, and every tool call crosses back into your application, which carries out the real work.


Run in the Browser or Node.js​

Code Mode provides separate entry points for browser and Node.js hosts, and both use the same WebAssembly sandbox. The sandbox runs inside your application's process, so it does not depend on an external server:

BenefitDescription
Data stays localGenerated code and the data it handles stay inside your environment instead of being sent to a hosted sandbox
Local tool callsEach tool call returns straight to your application instead of passing through a remote service
No extra infrastructureThere is no separate execution service to deploy or scale

Keep Control of Actions​

Code Mode gives your application two points of control over what a program can do:

ControlDescription
Tool filteringHide tools from the catalog so the program can neither see nor call them
Call interceptionCheck each call just before it reaches a tool, then allow it, deny it with a reason, or replace its input

Because interception is asynchronous, your application can pause a call while someone approves it:

onToolCall: async ({ tool, input }) => {
if (tool.name === "payments.transfer") {
return { allowed: false, reason: "Transfers require manual approval." };
}
return { allowed: true, input };
}
Isolation Is Not Authorization

Isolation keeps generated code away from your application's internals, but it does not replace your own input validation and authorization. Your tools should still check every request they receive.


Run Independent Sessions​

A single Code Mode instance can serve many runs at once. Each session has its own tool set and cancellation, so concurrent conversations do not affect each other, while all sessions share one sandbox.

CapabilityDescription
Separate tool setsEach session registers and filters its own tools
Scoped cancellationCancelling one run or removing one session leaves the others running
Caller contextPer-call information, such as a request or thread identifier, reaches your tools and interception checks without ever entering the sandbox, so generated code cannot read or forge it

Limit Unneeded Work​

Code Mode caps how long a program runs and how much memory it uses.

LimitDefault
Execution time30 seconds
Memory128 MB

When a request is cancelled, the program cannot make further tool calls and its result is discarded. Cancellation does not interrupt a program that is only computing; it continues until the time limit, but nothing it produces is used.


Next Steps​

  • Integration — Choose where Code Mode runs in your application
  • API Reference — Configuration, tool details, and setup
  • Overview — Return to the Code Mode overview