Videos 8txf05vVVl4
Code Mode: Let the Code do the Talking - Sunil Pai, Cloudflare
Scene timeline
67 shot(s).
keyframes kept every frame deduplicated
What was stored
- cues
- 253
- whisperx 253
- chunks
- 34
- from 253 cues
- keyframes
- 55
- kept of 67 captured
- frames with text
- 55
- 1,141 lines read
- chapters
- 15
- from the source metadata
- keyframe bytes
- 5.3 MB
- word timings on 253 cues
Provenance
| stage | state | model | started | took |
|---|---|---|---|---|
fetch |
done | — | 2026-08-10 23:38 | 1m 06s |
stt |
done | — | 2026-08-10 23:39 | 21s |
chunk |
done | — | 2026-08-10 23:39 | 0s |
text_embed |
done | — | 2026-08-10 23:39 | 0s |
keyframe |
done | — | 2026-08-10 23:39 | 2m 00s |
ocr |
done | — | 2026-08-10 23:41 | 27s |
frame_embed |
done | — | 2026-08-10 23:42 | 9s |
Frames, and what the machine read
-
- Al Engineer0.94
- EUROPE1.00
-
- PRESENTINGSPONSOR1.00
- Google DeepMind1.00
-
- PLATINUM SPONSORS0.98
- # Braintrust0.95
- WorkOS OpenAI0.95
-
- AlEngineer0.98
- AlEngineer1.00
- EUROPE1.00
- CLOÚDFLARE0.97
- EUROPE0.99
- AIE1.00
-
- SUNIL1.00
- PAI1.00
- AE0.88
- FOUNDER I PRINCIPAL SYSTEMS ENGINEER0.97
- AIE0.99
-
- tageeercai0.65
- AMEEgijieeer0.86
- ELRUROPE0.92
- AA0.97
- #田Beairttrusst0.88
- AAEEngineer0.95
- LEUROPE0.92
- AAFEngineer0.96
- MMicrosoft0.94
- EUROPE1.00
- AlEngineer0.98
- EUROPE1.00
- Trigger.dew1.00
- AlEngineerr0.99
- Google DeepMind1.00
- EUROPE0.98
- AMEngijieeer0.97
- tailsalee0.90
- EURORPE0.99
-
- AIEngineer0.98
- together.ai1.00
- AlEngineer0.96
- EUROPE1.00
- EUROPE1.00
- SAF0.96
- AlEngineer0.99
- Braintrust1.00
- INTELLIM0.95
- EUROPE1.00
- arize0.92
- AlEngineer0.98
- EUROPE1.00
- AlEngineer0.97
- EUROPE1.00
- PRESENTED BY1.00
- AlEngineer0.97
- △Trigger.dev0.95
- Google DeepMind1.00
- EUROPE1.00
- 1/28→0.95
- Modal1.00
- AlEngineer0.95
- EUROPE1.00
-
- AIEngineer0.95
- Worl0.89
- EUROPE1.00
- SAF1.00
- AlEngine0.98
- INTELLIG1.00
- EUROPE1.00
- ari:0.89
- Tool calling gets weird at scale1.00
- AlEngineer0.98
- EUROPE1.00
- model0.99
- tool0.97
- model0.99
- tool0.97
- PRESENTED BY0.99
- AIEngine0.94
- Google DeepMind1.00
- Giving models bash helped - one tool instead of many. But it's still text0.98
- EUROPE1.00
- in, text out, with no types, no permissions model, no composition.0.99
- context bloat0.98
- intermediate results1.00
- Mc0.95
- awkward composition1.00
- giant tool surfaces1.00
- 2/28 40.84
- AlEngineer0.98
- KEYNOTE1.00
- EUROPE1.00
- PRESENTED BY1.00
- Google DeepMind1.00
- SUNIL PAI / Founder, Principal Systems Engineer0.99
- CLOUDFLARE1.00
-
- AIEngineer0.98
- Wor1.00
- EUROPE1.00
- SAFE1.00
- AlEngin0.95
- INTELLIGEN1.00
- EUROPE1.00
- \ari0.98
- Let the model write code instead0.98
- AlEngineer0.99
- EUROPE1.00
- 40.85
- Google DeepMind1.00
- PRESENTED BY1.00
- AlEngin0.96
- Tool calling1.00
- Code mode0.97
- EUROPE1.00
- × thousands of tool definitions0.97
- ✓ typed API0.96
- ×repeated back-and-forth0.98
- ✓ generated code0.95
- ✓ one execution0.96
- M1.00
- 3/28 +0.87
- AlEngineer0.98
- KEYNOTE1.00
- EUROPE1.00
- PRESENTED BY1.00
- Google DeepMind1.00
- SUNIL PAI / Founder, Principal Systems Engineer1.00
- CLOUDFLARE1.00
-
- Let the model write code instead0.99
- 40.98
- Tool calling1.00
- Code mode0.98
- × thousands of tool definitions0.98
- ✓ typed API0.95
- × repeated back-and-forth0.98
- ✓generated code0.98
- ✓ one execution0.96
- ← 3/280.91
-
- JeDeepN0.93
- Code is the only tool that composes0.98
- Every other tool is atomic. You call it, get a result, feed it back. Code0.99
- composes - and once written, it executes deterministically.0.97
- of0.85
- hold state1.00
- branch1.00
- 10op0.95
- sequence1.00
- parallelize1.00
- ← 4/28 +0.84
- AlEngineer0.98
- KEYNOTE1.00
- EUROPE1.00
- PRESENTED BY1.00
- Google DeepMind1.00
- SUNIL PAI / Founder, Principal Systems Engineer0.98
- CLOUDFLARE1.00
-
- EorkOS0.89
- From 2,594 endpoints to two tools0.99
- 2,5941.00
- 400.50
- Cloudflare API endpolnts0.99
- search()1.00
- execute()1.00
- ~1,000 tokens0.96
- 99.9% reduction1.00
- with code mode1.00
- vs nave MCP0.99
- 5/28 +0.90
- AlEngineer0.98
- KEYNOTE1.00
- EUROPE1.00
- PRESENTED BY1.00
- Google DeepMind1.00
- SUNIL PAI / Founder, Principal Systems Engineer0.99
- CLOUDFLARE1.00
-
- orkOS0.99
- From 2,594 endpoints to two tools0.99
- 2,5941.00
- 40.78
- Cloudflare API endpolnts0.98
- search()1.00
- execute()1.00
- ~1,000 tokens0.97
- 99.9% reduction0.97
- with code mode0.93
- vs nave MCP0.97
- 5/28 +0.88
- AlEngineer0.98
- KEYNOTE1.00
- EUROPE1.00
- PRESENTED BY1.00
- Google DeepMind1.00
- SUNIL PAI / Founder, Principal Systems Engineer0.98
- CLOUDFLARE1.00
-
- WorkOS1.00
- Same task. One round trip.1.00
- "We're getting DDoSed - find the attacking IPs and blook them"0.95
- tool calling 8 round tripe0.97
- code node 1 execution0.98
- ↓ model + getZones()0.87
- model + getZoneAnalytics(zone)0.96
- const zone = await codemode.getZones()0.96
- then(zs => zs. find(z => z.nane =s= target)):0.90
- ainee0.97
- 8 model + getZoneAnalytics(zone)0.98
- model + identifyAttackPattern(analytics)0.99
- model + listFirwwallRules(zone)0.97
- model + createFirewallRule(zone, rule)0.95
- model + enableRateltmit(zone, config)0.97
- model verifyRule(zone, ruleId)0.97
- const attackIPs = analytics.requests0.94
- const analytics = await codemode0.96
- getZoneAnalytics(zone.1d);0.95
- filter(x => s.rate > threshold):0.89
- each call twtuzns to the model, te-serialized into context0.95
- avait Promise.all(attackIPs.map(ip a>0.95
- codemode.createfirewallRule(zone.id, {0.91
- filter: 'ip.src eq $(ip.address)'0.94
- action: "block*,0.95
- return (blocked: attackIPs.length ):0.96
- 6/28 +0.89
- AlEngineer0.98
- KEYNOTE1.00
- EUROPE1.00
- PRESENTED BY1.00
- Google DeepMind1.00
- # Braintrust0.96
- WorkOS1.00
- OpenAl0.95
-
- Same task. One round trip.1.00
- "We're getting DDoSed - find the attacking IPs and block them*0.97
- tool calling 8 round trips1.00
- code mode 1 execution0.98
- 1 model + getZones()0.95
- const zone = await codemode.getZones()0.98
- 40.89
- 2 model + getZoneAnalytics(zone)0.98
- .then(zs => zs.find(z => z.name === target));0.97
- 3 model + identifyAttackPattern(analytics)1.00
- 4 model + listFirewallRules(zone)0.97
- 5 model → createFirewallRule(zone, rule)0.97
- const analytics = await codemode1.00
- .getZoneAnalytics(zone.id);0.99
- 6 model + enableRateLimit(zone, config)0.99
- const attackIPs = analytics.requests1.00
- 7 model + verifyRule(zone, ruleId)0.97
- .filter(r => r.rate > threshold);0.99
- 8 model + getZoneAnalytics(zone)0.96
- await Promise.all(attackIPs.map(1p =>0.99
- each call returns to the model, re-serialized into context1.00
- codemode.createFirewallRule(zone.id, (0.98
- action: "block*,0.97
- filter: 'ip.src eq $(ip.address)'0.98
- ));0.88
- return ( blocked: attackIPs.length );0.96
- OOOO0.83
- ← 6/28 ÷0.82
-
- AIEngineer0.95
- Brain1.00
- EUROPE1.00
- Tessl0.97
- AlEngin0.95
- EUROPE1.00
- Same task. One round trip.1.00
- Sno1.00
- "We 're getting DDoSed - find the attacking (Ps and block them"0.95
- AlEngineer0.99
- tool calling 8 round tripe0.96
- code mode 1 execution0.97
- EUROPE1.00
- I model + getZanes()0.88
- model * getZoneAnalytics(zone)0.96
- const zone = await codemode.getZones()0.98
- then(zs => zs. find(z => z.name =a= target)):0.90
- Google DeepMind1.00
- PRESENTED BY0.97
- AlEngin0.98
- EUROPE1.00
- 8 model + getZoneAnalytics(zone)0.97
- model + identifyAttackPattern(analytics)0.98
- model + listFirewallRules(zone)0.97
- model + createFirewallRule(zone, rule)0.98
- model enableRateltmit(zone, config)0.97
- model verify@ule(zone, ruleId)0.97
- const attackIPs - analytics.requests0.96
- const analytics = await codemode0.95
- getZoneAnalytics(zone.1d);0.97
- filter(x => r.rate > threshold):0.91
- await Promise.all(attackIPs.rap(ip =>0.94
- So0.89
- each call retuzns to the model, te-serialized into context0.95
- codemode.createfirewallRule(zone.id. {0.84
- filter: ip.src eq $(ip.address)'0.96
- action: "block*,0.96
- return (blocked: attackIPs.length ):0.97
- 6/28 +0.93
- Engineering the future of Al1.00
- AlEngineer0.98
-
- AIEngineer0.99
- Brair1.00
- EUROPE1.00
- Cloudflare MCP1.00
- Tessl1.00
- AlEngii0.89
- Real Cloudflare API via remote MCP server0.94
- EUROP1.00
- cloudflare0.94
- MCP cllent rosot0.88
- Sno0.81
- AlEngineer1.00
- EUROPE1.00
- PRESENTED BY1.00
- AlEngir0.88
- Google DeepMind1.00
- EUROP1.00
- What's the traffio today?0.98
- Sc0.73
- Ask Cloudflare anything0.97
- mop.oloudflare.com/mop0.92
- OAuth -MOP cllent0.90
- 2.500+ endpoints0.99
- 7/28 +0.88
- Engineering the future of Al0.99
- AlEngineer0.98
-
- Cloudflare MCP1.00
- Real Cloudflare API via remote MCP server0.97
- cloudflare1.00
- MCP client reset1.00
- Try the Cloudflare MCP server0.99
- What's the taffic today?0.92
- List mykers0.92
- Create a hello world Worker1.00
- List my Workers0.97
- Send1.00
- mcp.cloudflare.com/mcp1.00
- OAuth - MCP cllent 2,500+ endpoints0.96
- ← 7/280.90
-
- C0.69
- mcp.cloudflare.com/authorize?response_type=code&client_0.99
- ☆0.99
- 白0.67
- Work0.98
- Authorize Application1.00
- Grant access to Cloudflare API0.99
- a68fe653-218b-4fc0-9f3e-7108289dbc761.00
- ACCESS LEVEL1.00
- Read Only (Recommended) View resources without0.99
- making changes. Safest option for exploration.0.99
- Workers Full Access Full access to Workers, KV, D1,0.99
- R2, and related services with observability.1.00
- DNS Full Access Full access to DNS records and zone0.98
- settings.1.00
- Advanced: Select individual permissions0.98
- You'll be redirected to Cloudflare to sign in and confirm access.0.99
- Cancel1.00
- Continue0.98
- Privacy · Terms · Docs0.93
-
- Support1.00
- 20.54
- 40.59
- Support1.00
- System Status0.99
- Careers1.00
- Terms of Use1.00
- Report Security Issues1.00
- Privacy Policy1.00
- Cookie Preferences1.00
- © 2026 Cloudflare, Inc.0.96
-
- Allow Cloudflare MCP Server access to1.00
- your Cloudflare account?0.99
- Signed in as [email protected]1.00
- You are a member of [email protected]'s Account0.98
- Allowing will authorize Cloudflare MCP Server to:0.98
- Read:1.00
- Cloudflare Access, Cloudflare Account, Cloudflare0.99
- Workers Al, Cloudflare DNS Analytics, Cloudflare DNS0.99
- records, Cloudflare DNS Settings, Cloudflare for0.99
- Logpush, Cloudflare Pages, User, Cloudflare Workers,1.00
- Cloudflare Workers Builds, Cloudflare Workers1.00
- Deployments, Cloudflare Workers Observability, and0.99
- Cloudflare Account Zone0.99
- See details0.99
- Deny1.00
- Allow1.00
Transcript
253 cues· 3,148 words· 16,626 chars
- 0:15 Our next presenter created PartyKit, the open-source tool for real-time multiplayer apps.
- 0:22 For his day job, he builds AI agents at Cloudflare.
- 0:27 Please join me in welcoming to the stage Sunil Pai.
- 0:58 20 minutes to the pub.
- 1:01 Hi, my name is Sunil Pai.
- 1:03 I work at CloudFlare.
- 1:05 I build agents over there for the agents SDK.
- 1:08 I'm trying very hard for this not to be a CloudFlare talk, but I think we are on the sponsor board, so that's nice.
- 1:16 This is a talk about something we call code mode.
- 1:19 I've been wearing the hat, and there's some prior art to it.
- 1:23 We don't claim to have invented it, but this is a talk about the implications of something new that we're discovering.
- 1:31 So you guys have built AI applications.
- 1:35 And tool calling gets weird at scale.
- 1:37 When it's just a couple of tools and very short runs, it's fine.
- 1:41 But the moment you start stuffing in your Google services, your JIRA, your Wiki, et cetera, and you're like hundreds of tools filling up the context, it starts breaking.
- 1:53 And the composition is weird, and there's this back and forth that you have to do with the model that's really slow.
- 2:04 We decided to take a different tact.
- 2:06 Instead of doing this JSON back and forth thing, we asked the model to generate code, usually JavaScript, that we could run against an environment.
- 2:19 And some of the benefits seem a little obvious to us.
- 2:23 With code you get a typed API, you can do type checking, there are syntax errors, models are trained on gigabytes if not terabytes of data already in the training set.
- 2:35 And instead of doing this back and forth, you could write code that executes it all in one run, just one execution.
- 2:43 So this is what I mean.
- 2:45 There are fundamental capabilities of code.
- 2:48 You're able to do looping.
- 2:50 You're able to hold state.
- 2:52 You're doing sequencing, parallelization, things that you would normally do with code anyway as an engineer.
- 3:01 So the first place we applied this, my colleague Matt Carey, who's actually going to be speaking about this a little more tomorrow, you should watch his talk.
- 3:09 The Cloudflare API surface is about 2,600 API endpoints.
- 3:14 If we exposed a tool for every single one of them, it's about 1.2 million tokens in your first call.
- 3:21 It just blows.
- 3:22 There's no way to create an MCP server for the entire Cloudflare API surface.
- 3:27 And he had a very clever idea where he exposes just two tool calls, search and execute.
- 3:35 Both of these endpoints accept code as an input, literally a string of code.
- 3:41 For search, the input to the function that you pass to it is the entire open API JSON spec.
- 3:48 And once it does that, execute
- 3:51 gives you a whole bunch of functions that you can call against the things that you call.
- 3:55 And it reduced that 1.2, 1.5 million token thing down to 1,000 tokens, kind of unheard of.
- 4:01 I think it's like 99.9% reduction.
- 4:05 This is going to be scary.
- 4:06 I actually have a live demo of this.
- 4:09 And demos don't usually do me well on stage.
- 4:13 But the point being that we were able to take a wide, super wide API surface and make it incredibly fast.
- 4:22 The prompt itself can be fairly generic.
- 4:27 So I should have kicked up the font size on this one.
- 4:29 The prompt here is, as a customer, you come in and say, we are getting DDoSed.
- 4:34 I want you to find every offending IP that's attacking us and block them.
- 4:41 In a moment of panic when your website is going down,
- 4:44 You don't have the time to do menu diving.
- 4:48 The Cloudflare dashboard is famously a little cumbersome to handle.
- 4:53 And you just want the thing done.
loading
Chapters
- 0:00 Introduction and speaker background
- 1:16 What is "Code Mode"?
- 1:31 Limitations of traditional tool calling at scale
- 2:03 The shift to generating executable code
- 3:01 Scaling API usage at Cloudflare
- 4:05 Why code generation is more efficient
- 5:28 Live demonstration of the Mythical server
- 7:20 A new way of interacting with systems
- 9:09 Example: The Kenton canvas and tic-tac-toe anecdote
- 11:46 New software architecture: The "Harness"
- 13:28 Observability and security in sandboxed environments
- 14:15 Long-running workflows and generative UI
- 16:41 Future outlook: Building for the next generation of users
- 17:50 The resurgence of capability-based security
- 18:33 Conclusion and final thoughts