跳转到内容

Cloudflare Code Mode (@cloudflare/codemode)

Cloudflare Code Mode (@cloudflare/codemode)

Section titled “Cloudflare Code Mode (@cloudflare/codemode)”

Related: 2026-09-26 Cloud agent orchestrators in the wild · 2026-09-26 Herdr for v0 cloud orchestrator · Cloud agent orchestrator


Primary (this note): Cloudflare Code Mode / npm @cloudflare/codemode — high confidence. Coined and productized by Cloudflare (Kenton Varda, Sunil Pai / @threepointone); documented in Agents SDK docs; independent parallel framing from Anthropic as “code execution with MCP.”

Other meanings (brief):

NameWhat it isRelevance to Noa
Anthropic code execution with MCPSame core idea (tools as code APIs + sandbox); filesystem progressive disclosureSister pattern; cite alongside CF
Community “Code Mode MCP” meta-serversDIY wrappers that collapse many MCPs into search + execute_codeUseful DIY precedent
VS Code / Copilot Agent ModeIDE agent harness with MCP—not “Code Mode”Naming collision only
OpenCode / other harness “codemode” supportHarnesses adopting the pattern (MCP resources as Code Mode tools, etc.)Watch for client-side adoption
Unrelated “code mode” (editors, games, accessibility)Generic UI labelsIgnore

Code Mode = pattern: LLMs are better at writing code than at direct tool calling, because training data has vast real TypeScript and little synthetic tool-call markup. So: convert tools/MCP/OpenAPI into a typed SDK, give the model a single codemode({ code }) (or search + execute) surface, execute in a sandbox, return only what the code logs/returns.

Cloudflare’s implementation:

  • Package: @cloudflare/codemode inside cloudflare/agents (MIT; marked experimental).
  • Authors/public face: Kenton Varda (Workers / isolates / Dynamic Worker Loader), Sunil Pai (@threepointone) — Agents SDK implementation.
  • First public framing: blog “Code Mode: the better way to use MCP” (2025-09-26). Follow-on: “Code Mode: give agents an entire API in 1,000 tokens” (2026-02-20) — full Cloudflare API MCP via server-side Code Mode.
  • Anthropic independently described the same pattern (2025-11-04) and notes Cloudflare’s “Code Mode” naming.

  1. Tools are not listed as dozens of separate function calls.
  2. The model sees roughly one outer tool (codemode) whose input is { code: string }, or (large APIs) two tools: search + execute.
  3. Inside the sandbox, connectors appear as globals (github.*, stripe.*, …) plus a platform SDK:
    • codemode.search(query) → ranked paths (methods/snippets), not full schemas
    • codemode.describe(path) → focused TypeScript docs
    • codemode.step / codemode.run → durable steps / saved snippets
  4. Generated code composes calls, loops, filters, branches; only the final result (plus logs) returns to the model.
PieceRole
ExecutorRuns one code block once; no durable state. Default: DynamicWorkerExecutor (Worker Loader → fresh V8 isolate). Also: browser IframeSandboxExecutor.
ConnectorsHost-side capabilities exposed into the sandbox: McpConnector, OpenApiConnector, AI SDK ToolSetConnector, custom CodemodeConnector. Credentials stay on the host; sandbox gets RPC bindings.
Durable runtimecreateCodemodeRuntime() — SQLite-backed Durable Object facet: execution log, approvals, replay, rollback, snippets.

Isolation: fetch/connect blocked by default (globalOutbound: null). External I/O only via connectors. No API keys in sandbox.

Approvals: Methods marked requiresApproval pause the pass; approve/reject resume via replay of the same script (applied calls return recorded results). Optional revert enables compensation/rollback.

AI SDK path (stateless):

const executor = new DynamicWorkerExecutor({ loader: env.LOADER });
const codemode = createCodeTool({ tools: myTools, executor });
streamText({ model, messages, tools: { codemode } });

MCP server patterns:

  • codeMcpServer() — wrap an existing MCP → one code tool
  • openApiMcpServer() — large OpenAPI → fixed search + execute (~1k tokens for whole Cloudflare API in CF’s own MCP)

Problem it attacks: MCP tool catalogs and intermediate results eat the context window. CF claims ~99.9% input-token reduction vs naive per-endpoint MCP for the Cloudflare API (~1.17M → ~1k tokens); earlier Code Mode work cited ~80%+ savings and better multi-step results. Anthropic reports similar (~98.7% in a filesystem progressive-disclosure example).

When to use Code Mode vs direct tools (CF docs):

Prefer direct toolsPrefer Code Mode
Small, fixed tool set; simple one-shot callsComposition, dependent calls, loops/branching
Large catalogs / progressive discovery
Filter/transform before results hit the model
Reusable snippets / durable approvals

Use cases aligned with Noa (agents, Cursor, herdr, DIY):

  • DIY orchestrators / personal MCP hubs — collapse Slack+GitHub+browser+internal APIs into search/execute without stuffing every schema into Cursor/Claude/Codex context (see Cloud agent orchestrator, herdr fleet tooling).
  • Server-side Code Mode — agent clients need no special sandbox; MCP server runs JS in isolates (CF’s mcp.cloudflare.com pattern). Good when harnesses lag on client-side Code Mode.
  • Harness adoption — X discussion (OpenCode, dax/@thdxr, others) frames Code Mode as something clients/harnesses should own so every MCP doesn’t ship its own sandbox.
  • Security model — keys never enter generated code; bindings + approvals + rollback fit “agent may write side-effecting scripts” better than raw shell.

ApproachIdeaTradeoff
Direct MCP tool callingOne schema per tool in contextSimple; collapses at scale
Anthropic code execution with MCPTools as FS modules / code APIsSame insight; different packaging
Dynamic tool search (e.g. Claude Code)Retrieve relevant tools per turnStill pays per matched schema
CLI / shell progressive disclosureAgent runs --help, scriptsBroader attack surface; needs a shell
Programmatic tool calling (various SDKs)Client-side code mode variantsNeeds a sandbox in the agent host
MCP server portals (Cloudflare One)Gate approved MCPs; Code Mode policiesEnterprise/gateway layer on top of the pattern

X / Twitter (public posts via X API; not login-walled for these URLs)

Section titled “X / Twitter (public posts via X API; not login-walled for these URLs)”

Primary authors

Recent discussion / adoption


  1. Treat Code Mode as a design default for any DIY MCP hub or agent coordinator that might grow past ~dozens of tools—especially before stuffing more servers into Cursor/Claude/Codex.
  2. Prefer server-side Code Mode (two tools, host sandbox) when the coding harness doesn’t own a good isolate yet; push client-side Code Mode when building on Cloudflare Agents / Dynamic Workers.
  3. Complementary to Cloud agent orchestrator / Herdr: Herdr owns sessions & panes; Code Mode owns efficient tool composition inside a session.
  4. Mark experimental: CF docs warn of breaking changes; durable approvals/replay are powerful but add ops complexity (replay divergence, connector lifetime hooks).