> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ada.cx/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ada.cx/_mcp/server.

# Limits and best practices

Code tools run in a restricted sandbox. Knowing the limits helps you design a tool that stays fast, predictable, and safe for an AI Agent to run mid-conversation.

## Limits

Every run is sandboxed, with these limits:

* **Language**: a sandboxed subset of Python. Importable modules are `json`, `re`, `datetime`, `math`, `os`, `pathlib`, `sys`, and `typing`, plus built-in helpers for hashing, Base64, URL-encoding, and UUIDs. See [Supported Python](/docs/automation/tools/code-tools/inputs-outputs-and-environment#supported-python).
* **Compute time**: about 5 seconds per run.
* **Sandbox round trips**: up to 10,000 per run. Each call to a built-in function such as `log` or `fetch` counts, and so does each read of `os.getenv`, `os.environ`, `datetime.now()`, or `date.today()`. A run that exceeds this limit fails with the message `suspension limit 10000 exceeded`.
* **Total time**: a roughly 65-second ceiling end to end, including any network calls.
* **Result type**: text, a number, true/false, a list, or an object. A code tool cannot return files or images.
* **Network access**: deny-by-default. Code makes requests with the `fetch` function, reaching only the domains on your allowed-domains list plus your own Ada instance. Internal and metadata addresses are always blocked, and redirects are not followed. Up to 10 requests and a 1 MB response each per run.

## Best practices

* **Keep each tool small and single-purpose.** One tool should do one thing: reshape a response, run a calculation, or format a value. Small tools are easier to test and reuse across [Playbooks](/docs/automation/playbooks).
* **Return only what the Agent needs.** Trim the result to the specific fields the AI Agent will use. A smaller, well-named result is easier for the Agent to use correctly and keeps replies accurate.
* **Keep secrets in environment variables.** Store API keys and other credentials as environment variables rather than in the code. Secrets are stored redacted. See [Inputs, outputs, and environment](/docs/automation/tools/code-tools/inputs-outputs-and-environment).
* **Write a specific description.** Describe exactly what the tool does and what it returns. A precise description helps the Agent choose the tool at the right moment and use its output as intended.

---

Have any questions? Contact your Ada team, or email us at [](mailto:help@ada.cx?subject=Help%20Docs%20inquiry).