Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
---
title: Admins can turn on Code Mode by default for MCP portal users
description: New MCP portal policies let admins turn on Code Mode by default, drastically reducing token usage from large tool catalogs.
date: 2026-07-30
products:
- access
---

[MCP server portals](/cloudflare-one/access-controls/ai-controls/mcp-portals/) now support four Code Mode policies: _Off_, _Opt-in_, _On by default_, and _Enforced_. Admins can choose whether Code Mode is unavailable, optional, enabled by default, or required for every session.

Existing portals retain their current behavior. Portals that previously allowed Code Mode use _Opt-in_, while portals that did not allow Code Mode use _Off_. New portals also use _Opt-in_ by default.

Clients turn on Code Mode for an _Opt-in_ portal with `?codemode=search_and_execute`. The _On by default_ policy lets clients opt out with `?codemode=off`, which avoids nested code execution when a client runs its own Code Mode implementation. The _Off_ and _Enforced_ policies ignore client overrides.
Comment thread
kennyj42 marked this conversation as resolved.

The Cloudflare API exposes these policies through the `code_mode` field:

```json
{
"code_mode": "default_on"
}
```

The supported values are `off`, `opt_in`, `default_on`, and `enforced`. The previous `allow_code_mode` boolean is deprecated.

For configuration details and client behavior, refer to [Code Mode policies](/cloudflare-one/access-controls/ai-controls/mcp-portals/#code-mode-policies).
Loading
Loading