Pi is an open-source AI agent that runs in your terminal. You give it a goal and a working folder, and it can read files, write and edit them, and run shell commands to work through multi-step tasks. It is made by Earendil, released under the MIT license, and reached version 1.0 on October 1, 2026. The software is free; what costs money is the model behind it. Pi connects to subscription logins such as ChatGPT Plus or Pro, GitHub Copilot, and Claude Pro or Max, to API keys from dozens of providers, and to local servers such as llama.cpp, Ollama, or LM Studio. On safety, Pi is unusually direct: its documentation says it has no built-in sandbox and no permission system. Its tools and extensions run with the permissions of the user who started it, and its project trust prompt only controls which project settings and extensions load, not what the model can do. That makes Pi reasonable for your own repositories with version control as a safety net, and a poor fit for untrusted repositories or unattended automation unless you run it inside a container or VM.
What is the Pi coding agent, and is it safe to use?
Pi is a minimal, extensible AI agent that runs in your terminal, made by Earendil and released under the MIT license. Version 1.0 shipped on October 1, 2026 and added Codemode with built-in MCP support. The software is free, but you pay for whichever model provider you connect. It is safe to use only in the sense that any local agent is: Pi has no built-in sandbox or permission prompts, so its tools run with your user account and you need a container or VM for untrusted work.
Published · Updated · Evidence-linked, not search-volume ranked.
Why this question is current
Exact query-volume data was unavailable, so RepoRadar uses these as current demand and intent signals rather than a claimed volume ranking.
- what is pi coding agent · Google Suggest · US; English · checked 2026-10-02T22:27:08Z
Observed completions: what is pi coding agent, what is pi coding agent written in, what is pi ai coding agent, is pi coding agent free, is pi coding agent open source, is pi coding agent good, is pi coding agent safe. A formulation signal captured at this time, not a volume or ranking claim. - pi coding agent · Google Suggest · US; English · checked 2026-10-02T22:27:08Z
Observed completions: pi coding agent, pi coding agent github, pi coding agent extensions, pi coding agent vs opencode, pi coding agent install, pi coding agent vs claude code, pi coding agent mcp, pi coding agent skills. A formulation signal captured at this time, not a volume or ranking claim. - pi vs claude code · Google Suggest · US; English · checked 2026-10-02T22:27:08Z
Observed completions: pi vs claude code, pi vs claude code vs codex, pi vs claude code reddit, pi vs claude code benchmark, pi vs claude code token usage, pi vs claude code cost. A formulation signal captured at this time, not a volume or ranking claim. - stories with more than 50 points, trailing 48 hours · Hacker News Algolia search_by_date · global English-language developer community · checked 2026-10-02T22:26:40Z
Story 49926069, Pi 1.0 (earendil.com), created 2026-10-01T19:33Z, 1633 points and 568 comments at check time, the highest-scoring story in the 48-hour sample. Interest signal, not search volume. - stories with more than 50 points, trailing 48 hours · Hacker News Algolia search_by_date · global English-language developer community · checked 2026-10-02T22:26:40Z
Story 49925969, Pi Durable (earendil.com), created 2026-10-01T19:24Z, 484 points and 66 comments at check time. Interest signal, not search volume. - stories with more than 50 points, trailing 48 hours · Hacker News Algolia search_by_date · global English-language developer community · checked 2026-10-02T22:26:40Z
Story 49922729, Figma restricts MCP access to whitelisted clients, excluding Pi, created 2026-10-01T15:10Z, 186 points and 104 comments at check time. Interest signal, not search volume.
Who this helps
- developers comparing terminal coding agents who want a minimal, model-agnostic option
- builders who want to embed an agent loop in their own app through an SDK
- anyone deciding whether to run a coding agent on a machine that holds credentials or client code
What Pi actually is
Pi describes itself as an extensible AI agent that works from your terminal. You start it in a project folder, type a request, and the model works through it using tools. By default it gets four: read, write, edit, and bash. Optional read-only tools for grep, find, and ls can be switched on. It is not limited to code; the docs list research notes, writing projects, and data files as other uses.
The GitHub repository, earendil-works/pi, is a TypeScript monorepo. Alongside the interactive coding agent CLI it ships a unified multi-provider LLM API, an agent runtime with tool calling and state management, and a terminal UI library, so you can build your own agent on the same parts. When we checked it on October 2, 2026, the repository showed the MIT license, about 111,000 stars, and a v1.0.0 release published on October 1, 2026.
Earendil says hundreds of thousands of people use Pi every week. That is the vendor's own claim and we have not verified it.
What changed in Pi 1.0
The 1.0 announcement lists the additions: Codemode with native MCP support, extension support for virtual models, deferred tool loading, cache warming for Anthropic models, mid-conversation system messages, a new terminal theme, and full-screen mode by default.
The MCP part is a reversal. Pi used to say publicly that it did not support MCP, and Earendil wrote a separate post explaining the change. In Pi, MCP tools are exposed to Codemode, a small JavaScript sandbox where the model writes a script that calls tools as functions and combines their results, rather than every tool being dumped into the context. The commit that added it describes Codemode as model-written JavaScript running in a QuickJS WebAssembly VM inside a worker.
Earendil also released Pi Durable the same day, a separate package for long-running agent applications. The announcement labels it experimental, so treat it as a preview rather than part of the stable 1.0 core.
Is it free?
The software is free and MIT licensed. Running it is not, unless you use a local model. Pi needs a model provider, and you pay that provider. The docs list subscription logins for Claude Pro or Max, ChatGPT Plus or Pro through Codex, and GitHub Copilot, plus API keys for dozens of providers including Anthropic, OpenAI, Google Gemini, DeepSeek, Mistral, Groq, and OpenRouter.
One billing detail is worth reading before you log in with a Claude subscription. Pi's provider documentation says that third-party harness usage on Claude Pro or Max draws from extra usage and is billed per token, not against your plan limits. That is Pi's description of Anthropic's policy; check your own Claude usage settings before relying on it.
For a zero-API-cost setup, the docs cover the llama.cpp router server directly and Ollama, LM Studio, or vLLM through a models.json entry. You then pay in hardware and in the quality gap between a local model and a frontier one.
Is it safe? What the docs say plainly
Pi's security page is unusually blunt. Pi does not include a built-in sandbox. Its built-in tools can read files, write files, edit files, and run shell commands with the permissions of the Pi process, and extensions are TypeScript modules that run with the same permissions. The repository README adds that Pi has no built-in permission system for restricting filesystem, process, network, or credential access.
Project trust is the feature most likely to be misunderstood. When you open a folder containing project-level Pi settings, extensions, skills, or prompts, Pi asks whether to trust it. The docs say this is only an input-loading guard. It stops a repository from silently changing Pi settings or loading its extensions, but it does not restrict what the model asks tools to do. Context files such as AGENTS.md and CLAUDE.md load regardless of trust.
The docs also say prompt injection from repository files, comments, documentation, or build output is an expected local-agent risk that Pi cannot reliably prevent. In other words, a malicious file in a repository you open can try to steer the agent, and the agent can run shell commands.
How that compares with Claude Code
The difference is design, not quality. Claude Code ships a permission system: by its own documentation, shell commands outside a built-in read-only set and file edits require approval in the default mode, and administrators can set allow and deny rules. Pi deliberately leaves that out and argues that a partial in-process sandbox would be easy to mistake for a real security boundary.
Neither approach makes a local agent safe against a determined prompt injection. Approval prompts help only if you read them before approving. Pi's position is that real isolation has to come from the operating system, a container, or a VM, which is also the conclusion of our answer on whether a VM is enough to sandbox an agent.
Who Pi suits, and who should skip it
Pi suits developers who want a small, model-agnostic agent they can reshape: switch providers per session, write extensions, load skills, or build their own agent on its SDK. It also suits people who already sandbox their agents and find permission prompts slow them down.
Skip it, or contain it first, if you plan to open repositories you did not write, run it unattended, or use it on a machine that holds production credentials, client data, or SSH keys you cannot afford to expose. RepoRadar has not run hands-on tests of Pi; this answer is based on its documentation and repository.
How to try it with less risk
Install it the way the quickstart shows, through npm with lifecycle scripts disabled: npm install -g --ignore-scripts @earendil-works/pi-coding-agent. The announcement also offers a curl or PowerShell one-line installer, which pipes a remote script straight into your shell; the npm route is easier to inspect.
Start in a repository that is committed to git, so you can review and roll back every change. For anything you do not fully trust, use one of the isolation patterns in the containerization guide: plain Docker, Docker Sandboxes with credentials kept on the host, NVIDIA OpenShell, or the Gondolin micro-VM extension. The guide warns that Gondolin commands inherit host environment variables, so provider keys set that way can be visible inside the VM.
Limits of this answer
Facts here come from the Pi 1.0 announcement, the pi.dev documentation, and the GitHub repository, checked on October 2, 2026. Star counts, the provider list, and the billing note change often. We have not benchmarked Pi against other agents and do not make claims about its output quality. Usage figures are the vendor's own.
A useful next action
If you are curious, give Pi one bounded task in a throwaway clone of a repository you know well, inside a container, using the model you already pay for. Read every command it runs. If the workflow feels better than your current agent, then decide where its permission model fits your machine before moving real work to it.
Sources checked
- Earendil: Pi 1.0 announcement ↗ checked · vendor announcement, global
Primary source for the 1.0 release, the list of new features including Codemode and MCP, the experimental Pi Durable package, the install commands, the MIT license, and the vendor claim of hundreds of thousands of weekly users.
- Earendil: You Said No MCP! ↗ checked · vendor engineering post, global
Explains why Pi previously rejected MCP, why MCP is now in the core, and how Codemode exposes tools to a JavaScript sandbox.
- Pi documentation: Security ↗ checked · official documentation, global
States that Pi has no built-in sandbox, that tools and extensions run with the permissions of the Pi process, that project trust is only an input-loading guard, and that prompt injection is an expected local-agent risk.
- Pi documentation: Quickstart ↗ checked · official documentation, global
Shows the npm install with --ignore-scripts, the default read, write, edit and bash tools, subscription and API key login options, and context-file loading.
- Pi documentation: Providers ↗ checked · official documentation, global
Lists subscription and API-key providers, the llama.cpp, Ollama, LM Studio and vLLM options, and the note that Claude Pro or Max usage in third-party harnesses draws from extra usage billed per token.
- Pi documentation: Containerization ↗ checked · official documentation, global
Describes plain Docker, Docker Sandboxes, OpenShell and Gondolin isolation patterns and warns that Gondolin commands inherit host environment variables.
- GitHub: earendil-works/pi ↗ checked · public repository, global
Shows the MIT license, the package list, the README statement that Pi has no built-in permission system, the Codemode QuickJS commit description, and about 111,000 stars and a v1.0.0 release dated 2026-10-01 at check time.
- Claude Code Docs: Configure permissions ↗ checked · official documentation, global
Documents that Claude Code requires approval for most shell commands and file edits in its default mode and supports allow and deny rules, used for the comparison.
RepoRadar separates factual source claims from analysis. Recheck vendor docs before purchase, deployment, or policy decisions.