Cloudflare Code Mode (@cloudflare/codemode)
Cloudflare Code Mode (@cloudflare/codemode)
Section titled “Cloudflare Code Mode (@cloudflare/codemode)”Related: 2026-09-26 Cloud agent orchestrators in the wild · 2026-09-26 Herdr for v0 cloud orchestrator · Cloud agent orchestrator
Confidence / disambiguation
Section titled “Confidence / disambiguation”Primary (this note): Cloudflare Code Mode / npm @cloudflare/codemode — high confidence. Coined and productized by Cloudflare (Kenton Varda, Sunil Pai / @threepointone); documented in Agents SDK docs; independent parallel framing from Anthropic as “code execution with MCP.”
Other meanings (brief):
| Name | What it is | Relevance to Noa |
|---|---|---|
| Anthropic code execution with MCP | Same core idea (tools as code APIs + sandbox); filesystem progressive disclosure | Sister pattern; cite alongside CF |
| Community “Code Mode MCP” meta-servers | DIY wrappers that collapse many MCPs into search + execute_code | Useful DIY precedent |
| VS Code / Copilot Agent Mode | IDE agent harness with MCP—not “Code Mode” | Naming collision only |
| OpenCode / other harness “codemode” support | Harnesses adopting the pattern (MCP resources as Code Mode tools, etc.) | Watch for client-side adoption |
| Unrelated “code mode” (editors, games, accessibility) | Generic UI labels | Ignore |
What it is / who makes it
Section titled “What it is / who makes it”Code Mode = pattern: LLMs are better at writing code than at direct tool calling, because training data has vast real TypeScript and little synthetic tool-call markup. So: convert tools/MCP/OpenAPI into a typed SDK, give the model a single codemode({ code }) (or search + execute) surface, execute in a sandbox, return only what the code logs/returns.
Cloudflare’s implementation:
- Package:
@cloudflare/codemodeinsidecloudflare/agents(MIT; marked experimental). - Authors/public face: Kenton Varda (Workers / isolates / Dynamic Worker Loader), Sunil Pai (
@threepointone) — Agents SDK implementation. - First public framing: blog “Code Mode: the better way to use MCP” (2025-09-26). Follow-on: “Code Mode: give agents an entire API in 1,000 tokens” (2026-02-20) — full Cloudflare API MCP via server-side Code Mode.
- Anthropic independently described the same pattern (2025-11-04) and notes Cloudflare’s “Code Mode” naming.
How it works
Section titled “How it works”Model-facing shape
Section titled “Model-facing shape”- Tools are not listed as dozens of separate function calls.
- The model sees roughly one outer tool (
codemode) whose input is{ code: string }, or (large APIs) two tools:search+execute. - Inside the sandbox, connectors appear as globals (
github.*,stripe.*, …) plus a platform SDK:codemode.search(query)→ ranked paths (methods/snippets), not full schemascodemode.describe(path)→ focused TypeScript docscodemode.step/codemode.run→ durable steps / saved snippets
- Generated code composes calls, loops, filters, branches; only the final result (plus logs) returns to the model.
Runtime pieces (@cloudflare/codemode)
Section titled “Runtime pieces (@cloudflare/codemode)”| Piece | Role |
|---|---|
| Executor | Runs one code block once; no durable state. Default: DynamicWorkerExecutor (Worker Loader → fresh V8 isolate). Also: browser IframeSandboxExecutor. |
| Connectors | Host-side capabilities exposed into the sandbox: McpConnector, OpenApiConnector, AI SDK ToolSetConnector, custom CodemodeConnector. Credentials stay on the host; sandbox gets RPC bindings. |
| Durable runtime | createCodemodeRuntime() — SQLite-backed Durable Object facet: execution log, approvals, replay, rollback, snippets. |
Isolation: fetch/connect blocked by default (globalOutbound: null). External I/O only via connectors. No API keys in sandbox.
Approvals: Methods marked requiresApproval pause the pass; approve/reject resume via replay of the same script (applied calls return recorded results). Optional revert enables compensation/rollback.
AI SDK path (stateless):
const executor = new DynamicWorkerExecutor({ loader: env.LOADER });const codemode = createCodeTool({ tools: myTools, executor });streamText({ model, messages, tools: { codemode } });MCP server patterns:
codeMcpServer()— wrap an existing MCP → onecodetoolopenApiMcpServer()— large OpenAPI → fixedsearch+execute(~1k tokens for whole Cloudflare API in CF’s own MCP)
Why it matters / use cases
Section titled “Why it matters / use cases”Problem it attacks: MCP tool catalogs and intermediate results eat the context window. CF claims ~99.9% input-token reduction vs naive per-endpoint MCP for the Cloudflare API (~1.17M → ~1k tokens); earlier Code Mode work cited ~80%+ savings and better multi-step results. Anthropic reports similar (~98.7% in a filesystem progressive-disclosure example).
When to use Code Mode vs direct tools (CF docs):
| Prefer direct tools | Prefer Code Mode |
|---|---|
| Small, fixed tool set; simple one-shot calls | Composition, dependent calls, loops/branching |
| Large catalogs / progressive discovery | |
| Filter/transform before results hit the model | |
| Reusable snippets / durable approvals |
Use cases aligned with Noa (agents, Cursor, herdr, DIY):
- DIY orchestrators / personal MCP hubs — collapse Slack+GitHub+browser+internal APIs into search/execute without stuffing every schema into Cursor/Claude/Codex context (see Cloud agent orchestrator, herdr fleet tooling).
- Server-side Code Mode — agent clients need no special sandbox; MCP server runs JS in isolates (CF’s
mcp.cloudflare.compattern). Good when harnesses lag on client-side Code Mode. - Harness adoption — X discussion (OpenCode, dax/
@thdxr, others) frames Code Mode as something clients/harnesses should own so every MCP doesn’t ship its own sandbox. - Security model — keys never enter generated code; bindings + approvals + rollback fit “agent may write side-effecting scripts” better than raw shell.
Alternatives / related concepts
Section titled “Alternatives / related concepts”| Approach | Idea | Tradeoff |
|---|---|---|
| Direct MCP tool calling | One schema per tool in context | Simple; collapses at scale |
| Anthropic code execution with MCP | Tools as FS modules / code APIs | Same insight; different packaging |
| Dynamic tool search (e.g. Claude Code) | Retrieve relevant tools per turn | Still pays per matched schema |
| CLI / shell progressive disclosure | Agent runs --help, scripts | Broader attack surface; needs a shell |
| Programmatic tool calling (various SDKs) | Client-side code mode variants | Needs a sandbox in the agent host |
| MCP server portals (Cloudflare One) | Gate approved MCPs; Code Mode policies | Enterprise/gateway layer on top of the pattern |
Sources
Section titled “Sources”Docs & blogs
Section titled “Docs & blogs”- Code Mode · Cloudflare Agents docs
- How Code Mode works
- AI SDK integration
- Durable Code Mode runtime
- Code Mode API reference
- Code Mode MCP server patterns
- Dynamic Workers — Code Mode example
- Code Mode: the better way to use MCP (2025-09-26, Kenton Varda & Sunil Pai)
- Code Mode: give agents an entire API in 1,000 tokens (2026-02-20, Matt Carey)
- Sandboxing AI agents, 100x faster (Dynamic Workers)
- Anthropic — Code execution with MCP (2025-11-04)
GitHub
Section titled “GitHub”X / Twitter (public posts via X API; not login-walled for these URLs)
Section titled “X / Twitter (public posts via X API; not login-walled for these URLs)”Primary authors
- Kenton Varda — early teaser (2025-09-04 CST+8: ~23:18) — “everyone using MCP wrong” + unannounced Workers feature; later revealed as Code Mode
- Kenton Varda — Cloudflare OS thread (2026-08-05) — agents act via Code Mode snippets + Cap’n Web RPC / Gatekeepers (high-engagement primary thread)
- Sunil Pai (
@threepointone) — “code mode!” (2026-09-17) - Sunil Pai — “throw codemode at this” (2026-09-17)
Recent discussion / adoption
- dax (
@thdxr) — “now that we have codemode you can add as many MCPs as you want without cost” (2026-09-11) — OpenCode / harness angle - Nathan Flurry — CLI vs MCP; Code Mode / scripting tipped the scale (2026-09-10)
- Marwan Atef — Code Mode on MCP server portals:
portal_codemode_search+portal_codemode_execute(2026-09-08) - chebyte — CF API MCP as search+execute ~1k tokens (2026-09-06)
- OpenCode Changelog — MCP resources as Code Mode tools in v2.0.16 (2026-09-24)
- Yifan Xu — codemode + script as coding-agent endgame (2026-09-27)
Takeaways for Noa
Section titled “Takeaways for Noa”- Treat Code Mode as a design default for any DIY MCP hub or agent coordinator that might grow past ~dozens of tools—especially before stuffing more servers into Cursor/Claude/Codex.
- Prefer server-side Code Mode (two tools, host sandbox) when the coding harness doesn’t own a good isolate yet; push client-side Code Mode when building on Cloudflare Agents / Dynamic Workers.
- Complementary to Cloud agent orchestrator / Herdr: Herdr owns sessions & panes; Code Mode owns efficient tool composition inside a session.
- Mark experimental: CF docs warn of breaking changes; durable approvals/replay are powerful but add ops complexity (replay divergence, connector lifetime hooks).