# Code Mode

> Source: https://elaichi.ai/docs/guides/mcp-servers/code-mode/

Normally an AI client uses your connected apps one call at a time. It finds a tool, runs it, reads the whole result, then decides what to do next. That works, but a job like "find last week's unread emails from customers and summarize each one" means a dozen round trips. Every full result passes through the conversation, including the parts the model never needed.

With Code Mode, the client can also send Elaichi a short program instead. The program calls your tools, loops over the results, picks out what matters, and sends back only the answer. The intermediate data stays out of the conversation.

## What changes for the client

The client gets one more tool beside `search_tools` and `execute_tool`: `run_code`. It takes the body of a JavaScript function that calls tools as `await tools.<name>(args)`, using the exact names `search_tools` returns. A program passes each tool the same arguments `execute_tool` would. Nothing else changes: `search_tools` and `execute_tool` behave exactly as they did before `run_code` existed, and the client still picks whichever fits the task.

You don't write the programs; the AI client does. You'll see the program in your client's tool-call details.

## What a program can and cannot do

- **The same access as a direct call.** Every tool call a program makes goes through exactly the checks a direct call goes through: your own toolboxes and connections, your organization's [restrictions](/guides/governance/set-restrictions), and the permissions you gave the client on Elaichi's consent screen. A program can't reach anything you couldn't reach yourself.
- **Deleting still needs permission to delete.** A program can only call a tool that deletes something if the client was allowed to delete when you connected it, the same as a direct call.
- **In the Elaichi assistant, changes still ask you.** A running program can't stop and wait for your approval. So a call that would normally show you an approval card is refused inside a program, and the assistant makes that call on its own, where you can approve it. Changes you've set to "always allow" run as usual.
- **No internet.** A program has no network access of its own. It can only reach the outside world through your connected tools.
- **Everything is logged.** Each run is one entry in your [audit log](/guides/governance/read-the-audit-log), and each tool call inside it is its own entry, linked to the run. The program text itself isn't stored, because it often contains your data. The log keeps a fingerprint of it instead.

## What you see in chat

In Claude and other clients that show Elaichi's cards, each run gets a short receipt: whether the program finished, every change it made as a line of its own ("Created a contact in Work"), and how many lookups it did. A change that failed, or was still running when the program ended, says so. In the Elaichi assistant, the same summary appears on the tool card, and pressing stop ends a running program straight away. Changes it had already made are not undone.

## Limits

Each run can make up to 50 tool calls, run for up to 30 seconds, and return up to 100,000 characters. An organization can start up to 20 runs a minute and 1,000 a day; past either, clients do the rest with `execute_tool`, one call at a time. A run that hits a limit stops and says which one. The tool calls it already made are not undone.

## Availability

Code Mode is part of every organization's connected tools, the same way `execute_tool` is. There is nothing to turn on: any AI client that can run your connected tools, and the Elaichi assistant, gets `run_code` beside them. Clients that never call it see exactly what they saw before.

## Related

- [How Elaichi connects to AI clients](/guides/mcp-servers/how-it-works)
- [Set restrictions](/guides/governance/set-restrictions)
- [Read the audit log](/guides/governance/read-the-audit-log)
