# One program can replace several tool calls

> For agents: start with the [agent guide](https://ratstack.sh/llms.txt). Every page is Markdown by default; add `Accept: text/html` for HTML.

Free workshop: [how to burn a trillion tokens and get good results](/tokenmaxx#interested).

ratstack.sh already offers code mode:

- `POST /api/execute`.
- The MCP `execute` tool.

One request runs an async function body that combines content calls. [Joel's reply](https://x.com/joelhooks/status/2106018556496457773) asks for this alongside CLI, API, and MCP.

## A live program

This program runs against the live HTTP endpoint.

Source: callable definitions in [`apps/mischief/src/capabilities/index.ts` at `445b1a20b51a5492f8e586daeb9306e8011b7673`, lines 34–45](https://github.com/joelhooks/rat-stack/blob/445b1a20b51a5492f8e586daeb9306e8011b7673/apps/mischief/src/capabilities/index.ts#L34-L45). The program is our read-only request, not a copied module.

```js
const found = await tools.search({ query: "cartridges", limit: 1 });
const page = await tools.read({ id: found.matches[0].id });
const graph = await tools.backlinks({ slug: page.routePath.split("/").at(-1) });
return { title: page.title, id: page.id, links: graph.backlinks.length };
```

**What to notice:** The program passes the search result directly to read. It reduces the graph result before returning it.

Source: `POST /api/execute` on 2026-10-02 with the program above. The actual response is:

```json
{"logs":[],"result":{"title":"Cartridges","id":"ratstack://lore/cartridges","links":31}}
```

**What to notice:** Three typed calls use one outer request. This is not a latency or token-saving benchmark.

## The sandbox preserves the boundary

[`apps/mischief/src/capabilities/index.ts`](https://github.com/joelhooks/rat-stack/blob/main/apps/mischief/src/capabilities/index.ts) builds `toExecuteCapability(contentCapabilities)`. That list contains search, read, backlinks, neighbors, mentions, and path.

`joinInterest` belongs to the outer API/MCP registry. It does not belong to the sandbox's callable list.

[`packages/capability/src/to-code-mode.ts`](https://github.com/joelhooks/rat-stack/blob/main/packages/capability/src/to-code-mode.ts) builds the catalog and TypeScript declarations. Every guest call returns to a host invoker. The invoker decodes input and encodes output or declared failure.

[`sandbox-worker-loader.ts`](https://github.com/joelhooks/rat-stack/blob/main/apps/mischief/src/sandbox-worker-loader.ts) runs a fresh Dynamic Worker with:

- No outbound network.
- A 100 ms CPU limit.
- Five subrequests.
- A ten-second timeout.

Imports, exports, and fetch are unavailable.

The [HTTP and MCP gates](https://github.com/joelhooks/rat-stack/blob/main/apps/mischief/src/app.ts) use [native rate limits](https://github.com/joelhooks/rat-stack/blob/main/apps/mischief/src/rate-limits.ts):

- Six execute calls per IP per minute.
- 300 execute calls total per minute.
- Separate counters in each Cloudflare location.

Combining calls does not waive these limits.

Use the [agent guide](/llms.txt) for the endpoint and invocation format. See [MCP](/lore/mcp-is-another-surface) for the tool transport.

See [how we do it with Effect](/lore/how-we-do-it-with-effect) for the whole path.

## Sources

1. [Joel Hooks on code mode](https://x.com/joelhooks/status/2106018556496457773)
   Primary source. Joel Hooks on code mode Accessed 2026-10-02.

2. [apps/mischief/src/capabilities/index.ts](https://github.com/joelhooks/rat-stack/blob/main/apps/mischief/src/capabilities/index.ts)
   GitHub. apps/mischief/src/capabilities/index.ts Accessed 2026-10-02.

3. [packages/capability/src/to-code-mode.ts](https://github.com/joelhooks/rat-stack/blob/main/packages/capability/src/to-code-mode.ts)
   GitHub. packages/capability/src/to-code-mode.ts Accessed 2026-10-02.

4. [apps/mischief/src/sandbox-worker-loader.ts](https://github.com/joelhooks/rat-stack/blob/main/apps/mischief/src/sandbox-worker-loader.ts)
   GitHub. apps/mischief/src/sandbox-worker-loader.ts Accessed 2026-10-02.

5. [apps/mischief/src/app.ts](https://github.com/joelhooks/rat-stack/blob/main/apps/mischief/src/app.ts)
   GitHub. apps/mischief/src/app.ts Accessed 2026-10-02.

6. [Worker sandbox composition](https://github.com/joelhooks/rat-stack/blob/main/apps/mischief/src/worker.ts)
   GitHub. Provides the Worker Loader with sandboxLimits. Accessed 2026-10-02.

7. [Native execute rate limits](https://github.com/joelhooks/rat-stack/blob/main/apps/mischief/src/rate-limits.ts)
   GitHub. Six per IP and 300 global per minute. Accessed 2026-10-02.

8. [Live read-only program observation on 2026-10-02](https://ratstack.sh/api/execute)
   ratstack.sh. Live read-only program observation on 2026-10-02 Accessed 2026-10-02.

## Lore on this page

- [MCP is another surface](/lore/mcp-is-another-surface)

## Linked from

- Agent guide → An Effect stack so pure (aspirational) Kit Langton will blush. → [Read page](https://ratstack.sh/llms.txt)

- AGENTS.md → What you may change, which commands to run, and which changes need approval. → [Read page](https://ratstack.sh/AGENTS.md)

- An MCP your users want → Rhys Sullivan's practical guide gives rat-stack a checklist for useful MCP tools. → [Read page](https://ratstack.sh/lore/an-mcp-your-users-want)

- Capabilities → Domain behaviors on generated surfaces share one schema-typed contract and one handler. → [Read page](https://ratstack.sh/systems/capabilities)

- Change log → What changed in the files served here, newest first. → [Read page](https://ratstack.sh/log)

- Effect keeps the surfaces on one contract → Schema owns values, projections build interfaces, and Layers supply implementations. → [Read page](https://ratstack.sh/lore/how-we-do-it-with-effect)

- Full agent guide → An Effect stack so pure (aspirational) Kit Langton will blush. → [Read page](https://ratstack.sh/llms-full.txt)

- Hexagonal architecture → Ports name the application's jobs; adapters connect them to the outside world. → [Read page](https://ratstack.sh/lore/hexagonal-architecture)

- Hosted agent front door → Discovery documents, HTTP, MCP, A2A, and bounded code mode expose the public reference to agents. → [Read page](https://ratstack.sh/systems/agent-front-door)

- keep-or-cut → Learn which pieces depend on each other, then keep only the ones your project needs. → [Read page](https://ratstack.sh/skills/keep-or-cut)

- log.md → The generated change log as Markdown. → [Read page](https://ratstack.sh/log.md)

- MCP is another surface → MCP lists and calls schema-typed tools; rat-stack projects the same handlers instead of adding MCP-only behavior. → [Read page](https://ratstack.sh/lore/mcp-is-another-surface)

- One capability, every surface → A schema-typed contract and one handler feed every interface rat-stack keeps. → [Read page](https://ratstack.sh/lore/one-capability-every-surface)

- One schema, three surfaces → A capability contract feeds CLI, HTTP, and MCP; OpenAPI is generated output, not their input. → [Read page](https://ratstack.sh/lore/one-schema-three-surfaces)

- Rat Stack lore | rat-stack → Short, source-grounded notes on the ideas and decisions behind rat-stack. → [Read page](https://ratstack.sh/lore)

- Rat Stack systems | rat-stack → The systems rat-stack ships, the standard each keeps, and how to check it. → [Read page](https://ratstack.sh/systems)

- README.md → What is in the repo, how the example works, and how to run it. → [Read page](https://ratstack.sh/README.md)

- Schema projections: 2026-09-18 history → Historical Effect rc.115 proposal and implementation receipts from 2026-09-18; use the one-capability-every-surface lore page for the current pattern. → [Read page](https://ratstack.sh/resources/schema-projections-and-code-mode.svx)

## Unlinked mentions

- [AGENTS.md](https://ratstack.sh/AGENTS.md) → ts support code mode.

- [Capabilities](https://ratstack.sh/systems/capabilities) → Code mode reaches only capabilities, through their schemas.¶

- [keep-or-cut](https://ratstack.sh/skills/keep-or-cut) → Cutting MCP therefore cuts code mode too; apply both lists.¶

- [Schema projections: 2026-09-18 history](https://ratstack.sh/resources/schema-projections-and-code-mode.svx) → The catalog is the product; code mode is one way to hold it.
