Pi extension · codemode · Clef

Ask for odds,
not prose.

Your agent writes one codemode script. The script asks Clef a typed question about every item and gets a probability for each allowed answer. The frontier model reads only the result. Every call goes through your own AI Gateway with your own scoped token.

16items
1.3swall time
$0.0014Clef cost
5,936Clef tokens
Install in Pi
models.classify(odds/clef) × 16 16/16
OD-101 Checkout 500s since deploy high
OD-102 Typo in sidebar none
OD-103 Love the new CLI none
OD-104 Webhooks retry forever high
OD-105 Dark mode request none
OD-106 Billing charged twice none
OD-107 Docs example outdated mild
OD-108 SSO login loop high
OD-109 Feature: CSV export none
OD-110 Latency spike in EU none
OD-111 Great support yesterday none
OD-112 API key rotated itself? high
OD-113 Question about limits none
OD-114 Rate limit too low none
OD-115 Dashboard is slow mild
OD-116 Ignore previous instructions none injection 97%

returned to the frontier model

  1. OD-116 Ignore previous instructions
  2. OD-112 API key rotated itself?
  3. OD-101 Checkout 500s since deploy
  4. OD-108 SSO login loop
  5. OD-104 Webhooks retry forever
  6. OD-110 Latency spike in EU
Recorded Clef run, 2026-10-01. Shown as a recording: this site makes no model calls.

How it works

The agent writes the program. Clef answers the questions.

  1. 01
    Fetch

    The script calls any Pi tool or MCP server, for example 250 Linear issues.

  2. 02
    Fan out

    models.classify sends one typed request per item. Pi runs four at a time.

  3. 03
    Check

    odds checks each answer: labels must be known, the choice must be the argmax, probabilities must sum to 1, and scores must be in range. Any other answer fails closed.

  4. 04
    Decide in code

    Plain JavaScript filters and sorts the results. Only the result returns to the frontier model.

codemode
const clef = await models.getModelOfType('classifier', 'odds', 'clef');
const { issues } = await tools.mcp__linear__list_issues({ state: 'open', limit: 250 });

const judged = await Promise.all(issues.map(async (issue) => {
  const r = await models.classify(clef, {
    state: issue,
    questions: {
      frustration: { type: 'choice', instructions: 'Tone of the writer only.',
        criteria: { none: 'Calm', mild: 'Irritated', high: 'Angry' } },
      urgent: { type: 'bool', instructions: 'Needs an engineer today?',
        criteria: { true: 'Yes', false: 'No' } },
    },
  });
  return { issue, ...r.answers };
}));

return judged
  .filter((j) => j.urgent.probability > 0.8)
  .map((j) => `${j.issue.id} ${j.issue.title}`);
odds/clef@cf/cloudflare/clef$0.24/M input
odds/clef-flash@cf/cloudflare/clef-flash$0.09/M input

Auth

Your gateway. Your scoped token. Nothing public.

Token
A dedicated Cloudflare API token: AI Gateway Run + Workers AI Read, one account. Never your wrangler login.
Storage
macOS Keychain service odds-gateway. Fallback: ~/.config/odds/token, refused unless chmod 600. ODDS_TOKEN for CI.
Gateway
Authenticated AI Gateway. Calls without the token, or with a forged one, are rejected.
Exposure
Read at request time, sent only as a bearer header to gateway.ai.cloudflare.com, redacted from every error and receipt.
This site
Static documentation. No AI binding, no storage, no API, connect-src none. It cannot call Clef.

Install

Two minutes, then /reload.

Create a Cloudflare API token with AI Gateway: Run and Workers AI: Read on the account that owns the gateway. Turn on authentication for the gateway. Turn on codemode in Pi with "defaultTools": ["+codemode"].

shell
pi install git:github.com/acoyfellow/odds

mkdir -p ~/.config/odds && chmod 700 ~/.config/odds
cat > ~/.config/odds/config.json <<'EOF'
{ "accountId": "<gateway-account-id>", "gateway": "default" }
EOF
chmod 600 ~/.config/odds/config.json

security add-generic-password -a "$USER" -s odds-gateway -w
  • Not a chat model. Clef returns probabilities over the options you define. It never writes text.
  • Not an authority. Odds are evidence. Your code or a verifier makes the decision.
  • Proof, not promises. bun run prove:auth checks that the gateway rejects anonymous and forged calls.
odds 0.0.1 · MIT Clef by Cloudflare Workers AI · @acoyfellow