What is the Pi coding agent, and where should you run it?
Pi is a minimal open-source coding agent with no permission prompts: what it leaves out, sign-ins, extensions, and where its makers say to run it.
Pi is a minimal, open-source coding agent that runs in your terminal, from pi.dev. Its makers call it “a minimal, extensible agent harness that you can make your own”: four tools to start with (read, bash, edit, write), any of 15-plus model providers, and, by design, no permission prompts, no plan mode, no sub-agents and no to-do list. You add what you want as extensions, skills or packages, or ask Pi to write them. It is MIT-licensed, made by Earendil since April 2026 after Mario Zechner wrote it, and reached version 1.0 on October 1, 2026 (1.1.0 on October 7).
Because Pi doesn’t ask before it acts, its own security guide says where to run it: entirely inside a container, virtual machine or sandbox “is usually the strongest practical option.” It isn’t related to the Raspberry Pi.
What Pi leaves out, on purpose
Most coding agents add features every release. Pi’s 1.0 announcement states the opposite habit: “We wait until something has proven itself, and only then do we consider adopting it; weighing its true functionality against its inherent added complexity.” Its home page lists what it didn’t build and what to do instead:
| Not built in | Pi’s answer, in its words |
|---|---|
| Sub-agents | “Spawn Pi instances via tmux, or build your own with extensions, or install a package that does it your way.” |
| Permission popups | “Run in a container, or build your own confirmation flow with extensions inline with your environment and security requirements.” |
| Plan mode | “Write plans to files, or build it with extensions, or install a package.” |
| To-dos | “Use a TODO.md file, or build your own with extensions.” |
| Background bash | “Use tmux. Full observability, direct interaction.” |
One line on that list has moved. Pi used to say it would never support MCP; since version 0.99 (September 29, 2026) it is built in, with “Codemode” letting the model call tools from a JavaScript sandbox, and the old “No MCP” is struck through on pi.dev. Older write-ups that call Pi MCP-free are out of date. The other half of the design is a small prompt: Pi “is very token efficient due to its minimal system prompt,” which leaves more of the context window for your work.
Installing it and starting
The installer pins Pi’s dependencies and can install Node.js for you: curl -fsSL https://pi.dev/install.sh | sh on macOS and Linux, and a PowerShell one-liner on Windows. Through npm it is npm install -g --ignore-scripts @earendil-works/pi-coding-agent, with Node.js 22.19 or newer; the package moved from @mariozechner/pi-coding-agent, now deprecated, in May 2026. Then cd into a project, run pi, and type /login to connect a model. The quickstart’s own warning comes with it: “Pi shows each file read, search, command, and edit it performs. It does not ask before every tool call.”
Besides the full-screen interface there is pi -p "…" for a single answer, --mode json for a stream of events, an RPC mode for driving it from another program, and an SDK for building it into one. pi --continue picks up the last session in the folder, and pi --tools read,grep,find,ls gives a read-only run.
Models and sign-ins
Pi talks to Anthropic, OpenAI, Google, Azure, Bedrock, Mistral, Groq, xAI, OpenRouter, Ollama and more, by API key or by signing in, and switches model mid-session with /model. The subscriptions /login offers include ChatGPT (through OpenAI’s Sign in with ChatGPT, since 0.99), GitHub Copilot, and Claude Pro or Max. On the last, Pi itself warns, as soon as you use it: “Anthropic subscription auth is active. Third-party harness usage draws from extra usage and is billed per token, not your Claude plan limits.” That is Pi’s own reading of Anthropic’s terms, which Anthropic’s pages state more than one way (the OpenCode pricing guide sets them side by side); the Claude plans guide covers what the plan itself includes. Keys and sign-in tokens are kept in ~/.pi/agent/auth.json.
Extensions, skills and packages
An extension is a TypeScript module that can add tools, commands, keyboard shortcuts, model providers or interface, loaded without a build step; Pi’s examples include sub-agents, plan mode, a permission gate, protected paths and a sandbox. Skills follow the open Agent Skills format, and Pi reads .agents/skills/ as well as its own .pi/skills/. A package bundles any of these, installed with pi install npm:<package> or from git; Earendil counts more than 5,000 extensions shared by Pi’s users. The makers’ warning on extensions is blunt: one “runs inside the Pi process with the same operating-system permissions. It can inspect prompts, tool calls, files, credentials, and session history, so load extensions only from sources you trust.” Pi asks before loading a project’s own settings, extensions and skills (it calls this project trust), but that controls what loads, not what Pi can then do.
Where its makers say to run it
Pi’s security guide (“Run Pi safely”, read October 9, 2026) opens: “Treat model-generated commands and code as untrusted. Pi can read, change, and execute files with the permissions of the account that started it, and it does not ask for approval before every tool call.” And then: “Safety comes from limiting the files, credentials, processes, and network services Pi can access and affect if a generated action is wrong or hostile. Watching the transcript, using project trust, and reviewing changes do not create a security boundary.” It sets out three ways to run it:
| How Pi runs | What remains protected, in the guide’s words |
|---|---|
| Directly, with the permissions of its operating-system user | “Anything that user cannot access. A dedicated user account can narrow those permissions, but Pi still shares the operating system and network with other users.” |
| Entirely inside a container, virtual machine, or sandbox | “Host files and processes that you do not expose to the environment. Credentials and network services remain accessible if you make them available inside it. This is usually the strongest practical option.” |
| Outside the isolated environment, with only its built-in tools running inside | “Host resources are protected from actions performed through those tools. Pi itself and other extensions remain outside the boundary, so this is a narrower form of isolation.” |
The guide’s advice applies whichever you pick: “only provide the files and services required for the task. Keep credentials outside the environment where possible, or use narrowly scoped, short-lived credentials. Restrict network access when commands do not need it.” Its isolation page gives recipes for plain Docker, Docker Sandboxes, OpenShell and Gondolin, Earendil’s micro-VM extension, and the quickstart sums it up: “For untrusted or unattended work, use a container or another sandbox.” Earendil also describes Pi as “built to run on your (remote) machine, inside a terminal, driven by one person”: a computer of its own, with nothing on it you haven’t chosen to give it, fits that advice better than the laptop that holds your keys.
Many Pis at once, with tmux
Pi has no background jobs and no sub-agent tool, and its site points to tmux for both: start each Pi in its own tmux session, and you can watch it, type into it, or leave it running while you close the terminal. Pi’s tmux page asks for one setting so Pi can tell Enter from Shift+Enter: set -g extended-keys on, plus set -g extended-keys-format csi-u on tmux 3.5 or newer.
Pi and OpenClaw
Pi’s site points to OpenClaw as “a real-world integration”, and Earendil’s April 2026 announcement called Pi “the minimal agent within OpenClaw.” OpenClaw’s own package lists tell the history: from January to late May 2026 it depended on Pi’s agent, model and coding-agent packages; since version 2026.5.28 it depends on Pi’s terminal interface library alone (@earendil-works/pi-tui in the current 2026.9.9). So by its own manifests, OpenClaw depended on Pi’s agent until late May 2026 and today depends only on its terminal library. It is a different agent with a different job, an assistant you talk to from chat apps, where Pi is a coding agent in your terminal.
Pi against OpenCode and Claude Code
All three are coding agents you run in a terminal. They differ in how much each does before you add anything, read from each maker’s pages on October 9, 2026 (Pi 1.1.0, OpenCode 2.0.26, Claude Code 2.1.295):
| Pi | OpenCode | Claude Code | |
|---|---|---|---|
| Asks before acting | Never, by design | Rules you can set to ask; by default only paths outside the project and .env reads ask | Auto mode, where a second model reviews each action, or prompts in manual mode |
| Plan first | No; plans go in files, or an extension | A Plan agent | Plan mode |
| Sub-agents | None built in; tmux or an extension | General and Explore, in the foreground or background | Built in, and your own |
| A project’s own extensions and settings | Loaded only once you trust the project | No trust step in its docs | Hooks held back until you trust the folder, in interactive sessions |
| Where you use it | Terminal; print, JSON, RPC and SDK modes | Terminal, desktop app, web interface | Terminal, editors, desktop, web, phone |
| Models | 15-plus providers, several subscriptions | 75-plus providers, several subscriptions | Claude only |
| Instructions | AGENTS.md or CLAUDE.md | AGENTS.md | CLAUDE.md, else AGENTS.md |
| Reporting | Anonymous install and update reporting, on unless you set enableInstallTelemetry to false | No statement in its docs | Usage metrics and error reports, each with an opt-out variable |
On how well Pi does the work, the published evidence is thin and points one way. No official benchmark board lists Pi. Its creator ran Terminal-Bench 2.0 with Claude Opus 4.5 himself in late 2025, five runs a task, and reported 49.8% (47.9% counted the way the board counts runs); it was never listed, and he patched the test harness before running it. The only independent test that puts Pi, OpenCode, Claude Code and Codex on one model, OpenBench, run by one developer on 15 tasks with three runs each, had them solving between 74% and 81% with GPT-5.6 Sol, within each other’s error bars, and Pi the fastest, at a median of 40 seconds a task against 59 to 95 for the others; on its smaller panels with open models, Pi came out level or ahead, which its author puts down to speed under a time limit, on samples he says are too small to rank. So with the same model the agents solve about the same; what Pi changes is speed, a small prompt, and who adds the guardrails, which is you. OpenCode vs Claude Code weighs the wider evidence on harnesses.