Key takeaways
- Pi enables four tools by default, with additional built-in tools and extensions available.
- Interactive, scripting, RPC, and SDK modes serve both terminal users and developers building other agents.
- The MIT core remains under Earendil stewardship; adjacent commercial products can use different licenses.
- Pi inherits its process permissions, so stronger isolation requires an explicit deployment boundary.
FAQ
What is Pi?
An extensible terminal coding agent and agent harness created by Mario Zechner, with multiple model providers and an SDK for embedding.
Does Pi only have four tools?
Four tools are enabled by default: read, write, edit, and bash. The current reference also lists grep, find, ls, and Windows PowerShell, while extensions can add more.
Is Pi sandboxed by default?
No. It runs with the launching process's permissions. A container, sandbox, or carefully scoped tool-routing extension supplies a separate boundary.
Is Pi free after the Earendil acquisition?
The core remains MIT-licensed. Model providers charge separately, and Earendil's licensing policy permits adjacent commercial offerings under other licenses.
Executive Summary
Pi is a terminal coding agent and embeddable agent harness built around customization. Mario Zechner created it and announced its move to Earendil in April 2026. The core remains MIT-licensed; ownership and the open-source license are separate facts.[1][2]
Its appeal in the AI coding assistants category is direct control over tools, context, sessions, and model choice. The official site also points to OpenClaw as an integration example. That relationship demonstrates reuse, not guaranteed long-term relevance or reliability.[3]
| Attribute | Checked September 15, 2026 |
|---|---|
| Creator and stewardship | Mario Zechner; Earendil ownership announced April 8, 2026[1] |
| Stable release | v0.85.1, September 5, 2026[4] |
| License | MIT; retain copyright and permission notices[2] |
| Source | earendil-works/pi on GitHub[5] |
Product Overview
Pi enables read, write, edit, and bash by default. This is not its complete built-in inventory: the CLI reference also includes grep, find, ls, and Windows powershell. Tools can be selected or excluded, and extensions can provide additional ones.[5]
| Mode | Purpose |
|---|---|
| Interactive | Terminal UI for everyday coding |
| Print/JSON | Scriptable runs and event output |
| RPC | Integration through stdin/stdout |
| SDK | Embed the harness in an application |
These four modes are documented public interfaces. Experimental server/client work should not be confused with the supported SDK and stdio RPC API: v0.85.1 explicitly moved accidentally published experimental paths back to source-only status.[5][4]
Technical Architecture
Sessions form a tree that can be revisited and branched. Extensions can alter tools, commands, events, UI, and context handling; skills and prompt templates provide lighter customization. Providers can be switched during a session.[3]
The supported provider list includes Anthropic, OpenAI, and other hosted or local-compatible endpoints. Authentication varies between API keys and provider-specific login flows; credentials and billing behavior are not interchangeable.[6]
Pi still does not bundle an MCP client, sub-agent workflow, or plan mode as core features. Its documentation points users to extensions or external tools for those capabilities.[5]
Choosing a Customization Layer
Pi separates reusable instructions from changes to the harness itself. That distinction is useful when deciding how much custom code a workflow needs.
| Need | Pi mechanism | Practical consequence |
|---|---|---|
| Repeat a review or implementation prompt | Markdown prompt template, invoked by its slash-command name | Expands text and arguments; it does not add an enforcement boundary [7] |
| Package a domain workflow with references and helper scripts | A skill loaded from SKILL.md | Descriptions enter context first; full instructions load when selected or explicitly invoked with /skill:name [8] |
| Add a tool, intercept calls, change compaction, or customize UI | A TypeScript extension | Executes code in the Pi process and can react to lifecycle events [9] |
Project-local prompts and skills load after the project is trusted. Skills are still powerful instructions: their supporting code can be executed by the model, and automatic selection is not guaranteed. The documentation recommends explicit skill invocation when the workflow must be loaded. Review packages before enabling them. [8][7]
A concrete adoption sequence is to start with a recurring task such as reviewing a staged diff. Put the review questions in a prompt template, move longer repository-specific procedures into a skill, and add an extension only when the task needs behavior such as intercepting a tool call or recording state. Extensions in the documented discovery directories support /reload, which helps iterate on that implementation. [9]
This is an example workflow, not a tested performance result. Evaluate whether the customization reduces repeated setup without making the harness harder to maintain. A review prompt can ask for checks; enforcement still depends on actual tool behavior, deployment permissions, and the repository's checks.
Permissions and Isolation
Pi runs with the permissions of its launching process. The containerization guide distinguishes running the whole process in isolation from routing only selected tools elsewhere. This matters because custom extensions execute wherever the Pi process runs.[10]
| Pattern | Documented boundary |
|---|---|
| Gondolin extension | Routes built-in tools and shell shortcuts into a micro-VM; other host extensions need their own delegation |
| Plain container | Runs the complete process inside a container, with credentials and mounts configured by the operator |
| OpenShell or Docker Sandboxes | Runs the complete process inside an external managed boundary |
A mounted workspace can still expose host files, and host-side extensions remain outside a tool-only sandbox. The guide explains these distinctions; this review did not test their resistance to escape.[10]
Strengths
- Adaptable workflow: extensions, skills, and prompt templates allow users to shape the harness around their work.[3]
- Reusable runtime: SDK and RPC modes support applications beyond the terminal interface.[5]
- Clear licensing policy: Earendil commits to an MIT core while explicitly reserving different terms for adjacent commercial offerings.[11]
Cautions
- Isolation is an operator decision: installing a tool-routing extension is not equivalent to isolating every extension and credential.[10]
- Provider economics differ: the stable provider guide says Claude Pro/Max third-party harness usage is billed through extra usage per token, rather than included plan limits.[6]
- Version interfaces matter: v0.85.1 repairs SDK/package problems from v0.85.0. Applications should test the supported interfaces they actually consume.[4]
What Developers Say
Helmut Januschka describes model switching and the session tree as reasons Pi became his daily tool. He also links his own merged contributions, so this is a first-hand contributor perspective rather than an independent benchmark. The article has no clear publication date; it was reviewed September 15, 2026, and its older installation examples are not used here as current guidance.[12]
A more recent concrete failure report came from GitHub user kleb on September 4: v0.85.0's non-bundled entrypoint imported an undeclared package, while the official bundled executable still worked. The issue is closed and v0.85.1 documents the packaging fix. That is a version-specific integration lesson, not evidence that the current CLI is broken.[13][4]
The site links a Discord community, but this review did not measure responsiveness or support quality.[3]
Pricing & Licensing
| Component | Cost model |
|---|---|
| Pi core | Free software under MIT[2] |
| Model usage | Provider API or subscription-specific terms; authentication does not imply included inference[6] |
| Adjacent products | Earendil's policy allows Fair Source and proprietary commercial additions[11] |
The software license permits commercial reuse subject to its conditions. It does not include model service, hosting, or a support contract.[2]
Pi with Tembo
Disclosure: Ry Walker is Tembo’s co-founder and CEO. Tembo is discussed here as a deployment option. [14]
Tembo explicitly lists Pi as a supported harness. Its agent configuration selects a harness and model, with runs launched by schedules, integration events, or webhooks in a prepared sandbox. This makes Tembo a concrete deployment option for teams that want Pi's runtime inside a shared background-work system. [15]
The decision is whether to run and extend Pi directly or operate it through a team platform. Local Pi gives the operator direct control of the process and extensions; Tembo adds the surrounding orchestration. Verify your required extensions, provider authentication, and task triggers in the chosen deployment, since supported Pi execution alone does not establish compatibility with every custom extension. [5][10]
Bottom Line
Recommended for: terminal users who want to control their agent's tools and context, and developers embedding an agent runtime.
Poor fit: teams expecting built-in permission enforcement or a complete managed workflow without extension and deployment choices.
Outlook: Pi's supported interfaces and explicit licensing policy are more useful evaluation signals than star counts or claims about the shortest prompt. This refresh checked documentation and release evidence, not comparative coding performance.
Research by Ry Walker Research • methodology
Sources
- [1] Mario Zechner — I've sold out, April 8, 2026
- [2] Pi MIT license
- [3] Pi official site
- [4] Pi v0.85.1 release — September 5, 2026
- [5] Pi v0.85.1 coding-agent README
- [6] Pi v0.85.1 provider authentication and billing notes
- [7] Pi v0.85.1 prompt-template behavior
- [8] Pi v0.85.1 skill discovery and invocation
- [9] Pi v0.85.1 TypeScript extension API
- [10] Pi v0.85.1 containerization patterns and boundaries
- [11] Earendil RFC 0015 — Pi licensing
- [12] Helmut Januschka — Why I Switched to Pi
- [13] Pi issue #9132 — v0.85.0 package entrypoint failure
- [14] Tembo founding team
- [15] Tembo supported harnesses and workflow triggers