Capabilities
Code Mode lets an assistant write programs that call your tools, and runs those programs in an isolated environment. Your application decides which tools a program can reach and remains responsible for carrying out any actions.
Capability Overview
The assistant writes the plan as code; Code Mode runs it safely.
Tools become functions the program can call. Your application controls which tools are offered and can check each call before it happens.
Capability Areas at a Glance
Code-driven orchestration
Express a multi-step task as a program that calls tools, branches on results, and combines them.
Tool discovery
Offer the assistant three stable tools for finding, inspecting, and calling the rest of your catalog.
Isolated execution
Run model-generated code in a sandbox that can reach only the tools you registered.
Browser and Node.js
Run the same sandbox inside a web application or a Node.js server, with no external execution service.
Controlled access
Hide tools, check each call before it runs, and require approval before sensitive actions.
Independent sessions
Serve concurrent runs with their own tool sets, cancellation, and caller context.
Limits and cancellation
Cap execution time and memory, and stop a program's tool calls when a request is cancelled.
Orchestrate Tools Through Code
The assistant writes a program instead of issuing tool calls one at a time. Inside that program, each tool is an asynchronous function. For example, the assistant can look up an order, check its delivery status, and prepare a response from both results in a single program, using ordinary loops and conditions to decide what to call next. Only the program's final result goes back to the assistant.
| Benefit | Description |
|---|---|
| Fewer round trips | Several tool calls run in one step instead of one conversation turn each |
| Smaller conversation | Intermediate results stay inside the program; only the final value returns |
| Familiar logic | Loops, conditions, and data transformations are written as ordinary JavaScript |
- Tasks that chain several dependent tool calls
- Filtering or aggregating large tool results before the assistant sees them
- Repeating the same call across a list of items
Discover Tools as Needed
Instead of receiving every tool in your catalog, the assistant receives three stable tools. It uses them to find what is available, read the schemas it needs, and run its program. A growing catalog therefore does not make every request larger.
| Tool | Purpose |
|---|---|
getTools | Lists the available tools and their descriptions |
getToolDefinition | Returns the input and output schemas for a selected tool |
executeCode | Runs a program with the available tools bound as asynchronous functions |
Inside the program, tool names become safe JavaScript identifiers under a tool_ prefix. For example, weather.get-current may be exposed as tool_weather_get_current.
Run Generated Code in Isolation
Code Mode executes the assistant's program in an isolated environment, separate from your application's runtime. The program can use only the tool functions your application registered, and every tool call crosses back into your application, which carries out the real work.
Run in the Browser or Node.js
Code Mode provides separate entry points for browser and Node.js hosts, and both use the same WebAssembly sandbox. The sandbox runs inside your application's process, so it does not depend on an external server:
| Benefit | Description |
|---|---|
| Data stays local | Generated code and the data it handles stay inside your environment instead of being sent to a hosted sandbox |
| Local tool calls | Each tool call returns straight to your application instead of passing through a remote service |
| No extra infrastructure | There is no separate execution service to deploy or scale |
Keep Control of Actions
Code Mode gives your application two points of control over what a program can do:
| Control | Description |
|---|---|
| Tool filtering | Hide tools from the catalog so the program can neither see nor call them |
| Call interception | Check each call just before it reaches a tool, then allow it, deny it with a reason, or replace its input |
Because interception is asynchronous, your application can pause a call while someone approves it:
onToolCall: async ({ tool, input }) => {
if (tool.name === "payments.transfer") {
return { allowed: false, reason: "Transfers require manual approval." };
}
return { allowed: true, input };
}
Isolation keeps generated code away from your application's internals, but it does not replace your own input validation and authorization. Your tools should still check every request they receive.
Run Independent Sessions
A single Code Mode instance can serve many runs at once. Each session has its own tool set and cancellation, so concurrent conversations do not affect each other, while all sessions share one sandbox.
| Capability | Description |
|---|---|
| Separate tool sets | Each session registers and filters its own tools |
| Scoped cancellation | Cancelling one run or removing one session leaves the others running |
| Caller context | Per-call information, such as a request or thread identifier, reaches your tools and interception checks without ever entering the sandbox, so generated code cannot read or forge it |
Limit Unneeded Work
Code Mode caps how long a program runs and how much memory it uses.
| Limit | Default |
|---|---|
| Execution time | 30 seconds |
| Memory | 128 MB |
When a request is cancelled, the program cannot make further tool calls and its result is discarded. Cancellation does not interrupt a program that is only computing; it continues until the time limit, but nothing it produces is used.
Next Steps
- Integration — Choose where Code Mode runs in your application
- API Reference — Configuration, tool details, and setup
- Overview — Return to the Code Mode overview