Code AF is a new open-source software factory that sits on the Pareto frontier of cost, speed and quality. On Deep SWE it solved nearly 4× as many real GitHub issues as Claude Code on the same open model, and matched the official leaderboard result at half the cost. It is built from the ground up for the next era of coding, where you stop chatting with agents and start directing them. Built for open models like Deep Seek, Qwen, GLM and Kimi, it gives you frontier-grade coding without locking you into a closed model, and it still works with any provider you choose.
The utility of AI agents increases when they can take real actions in real systems. This involves the use of tools. While MCP made it easier to expose these tools, there were a lot of other concerns that had to be handled in order to make it work at an enterprise level. DoorDash built a shared Agent Gateway to control how AI agents discover and use tools. The gateway brings together several responsibilities: checking permissions, managing credentials, choosing which tools an agent can see, forwarding requests, and recording what happened.
In this article, we will look at how the DoorDash engineering team built this gateway and the decisions they made. Here’s what we will cover: Why does an AI agent need tools, why MCP is not enough, the core components of the gateway, verifying who is calling and what they can do, why identifying the caller is different from supplying credentials, how a user connects an account during a tool call, why agents should see a tool catalog, what happens during discovery and execution, and how DoorDash made the platform easy to adopt.