---
title: 'Programmatic tool calling'
description: 'A model writing a program that coordinates enabled tool calls through loops, conditions, parallel work, and result processing.'
canonical_url: 'https://darkfactory.dev/glossary/programmatic-tool-calling'
markdown_url: 'https://darkfactory.dev/glossary/programmatic-tool-calling.md'
collection: glossary
date_published: '2026-10-07T00:00:00-04:00'
date_modified: '2026-10-07T00:00:00-04:00'
---

# Programmatic tool calling


## Definition

Programmatic tool calling lets a model write a program that coordinates enabled tools. The program can sequence calls, apply conditions, run parallel work, and reduce intermediate results before returning information to the model.

For example, a program can retrieve issue records, score each one, and return a short ranked list. The application controls the available tools and executes or mediates their effects.

## Origin and current usage

Kenton Varda and Sunil Pai described Cloudflare's Code Mode in September 2025: expose MCP tools as a TypeScript API and have a model write code against it. Anthropic introduced a feature named Programmatic Tool Calling in November 2025, using Python to coordinate tools through its code-execution environment. These are documented introductions of particular implementations; neither announcement establishes invention of the general practice.

OpenAI documents this as Programmatic Tool Calling: model-written JavaScript runs in an isolated runtime and can call enabled tools. Earendil's September 2026 Codemode explanation describes a sandbox on the harness side that coordinates tools and keeps its state with the session.

## Scope and implementation differences

Code mode and codemode name this pattern in several products. Their runtimes, state models, and trust boundaries differ. Compare which tools the program can reach, where state persists, and where permissions are enforced before transferring a guarantee from one implementation to another.

## Operational significance

Code can handle repeated calls and intermediate processing without placing every result into the next model context. Whether that reduces latency, cost, or errors depends on the task, tool responses, runtime, and amount of model-generated code.

Generated programs also need limits. Bound the number of calls, concurrency, elapsed time, and result size. Enforce permissions where tools execute; a program that loops over a tool must not acquire more authority than a direct invocation.

Inspect error and partial-success behavior. If three updates succeed and a fourth fails, the application needs records sufficient to reconcile those effects. A JavaScript exception is not proof that earlier external changes were rolled back.

## Distinguish it from nearby terms

- Function calling supplies one or more invocation requests. Programmatic tool calling adds executable control flow around invocations.
- A workflow may be authored and fixed in advance. Here, the model can generate the coordinating program during a run.
- Code execution can perform arbitrary computation within its environment. Programmatic tool calling specifically exposes governed tools to that computation.
- Deferred tool loading determines when a definition enters context. It can accompany programmatic calling but solves a different problem.

## Check your understanding

An agent writes a program to update 200 tickets and return only a count. What call limits, per-ticket evidence, and partial-failure handling would you require before enabling the update tool?

## Also called

code mode, codemode

## Related terms

- [Function calling](https://darkfactory.dev/glossary/function-calling)
- [Tool](https://darkfactory.dev/glossary/tool)
- [Model Context Protocol (MCP)](https://darkfactory.dev/glossary/model-context-protocol)
- [Orchestration](https://darkfactory.dev/glossary/orchestration)
- [Sandbox](https://darkfactory.dev/glossary/sandbox)
- [Deferred tool loading](https://darkfactory.dev/glossary/deferred-tool-loading)
- [Recursive language model (RLM)](https://darkfactory.dev/glossary/recursive-language-model)
- [Computer use](https://darkfactory.dev/glossary/computer-use)

## Related factory areas

- [Tools & project interfaces](https://darkfactory.dev/factory/tools-interfaces)
- [Orchestration, state, concurrency & recovery](https://darkfactory.dev/factory/orchestration-state)
- [Context, memory, knowledge & skills](https://darkfactory.dev/factory/context-memory-skills)

## Evidence and further reading

- [Cloudflare: Code Mode, the better way to use MCP](https://blog.cloudflare.com/code-mode/)
- [Anthropic: Introducing advanced tool use](https://www.anthropic.com/engineering/advanced-tool-use)
- [OpenAI API: Programmatic tool calling](https://developers.openai.com/api/docs/guides/tools-programmatic-tool-calling)
- [Earendil: You Said No MCP](https://earendil.com/posts/you-said-no-mcp/)
