Earendil Ships Pi 1.0 Coding Agent With Built-In MCP and a New Pi Durable Framework
TL;DR
Earendil shipped Pi 1.0 on October 1, declaring its minimal, MIT-licensed coding agent harness stable after months of hardening. The headline change is philosophical as much as technical: the project that once proudly said it did not support MCP now ships MCP in core, routed through a JavaScript sandbox called Codemode, plus deferred tool loading, virtual models, and mid-conversation system messages. Alongside it, Earendil released Pi Durable, an experimental framework for long-running agents that checkpoint every step, resume after a crash, and let multiple people steer the same conversation. Both are MIT licensed.
What shipped in Pi 1.0
Pi started as Mario Zechner's answer to bloated coding agents: four tools (read, write, edit, bash), a tiny system prompt, and a TypeScript extension system for everything else. It is now developed under Earendil, and the numbers say it is no longer a niche hobby harness. The GitHub repo sits above 111,000 stars and 14,000 forks, and @earendil-works/pi-coding-agent pulled about 4.54 million npm downloads in the week before the release, per the npm downloads API. Earendil's own claim is "hundreds of thousands of people" using Pi every week.
The 1.0 feature list, from the announcement and the v1.0.0 release notes:
- Codemode, with native MCP support and access to non-LLM models such as Jev and image models.
- Virtual models that extensions can define, for example a router that plans with one model and implements with another.
- Deferred tool loading, so a big tool catalog does not sit in every prompt.
- Cache warming for Anthropic models.
- Mid-conversation system messages, so prompt and tool changes land in the transcript where they happened.
- Fullscreen TUI by default and a new theme. Set
tuiModeto"regular"if you want your scrollback back.
Upgrading or installing is the usual one-liner:
curl -fsSL https://pi.dev/install.sh | sh
The MCP reversal, explained by the people who reversed
Pi's identity was minimalism, and MCP was its favorite punching bag. Two days before 1.0, Earendil published "You Said No MCP!", which reads like a polite apology to its own past homepage. The argument: MCP itself matured, and the plumbing needed to support it well (tool metadata for deferral, a sandbox to compose calls) turned out to be useful for everything else, including Jev classifiers.
The key piece is Codemode. Instead of dumping every MCP tool schema into context and letting the model call tools one by one, Pi exposes tools to a small JavaScript sandbox that runs on the harness side. The model writes a short script that calls several tools, loops, filters, and returns only the result. Earendil compares the goal to how agents already use CLIs: wire things together with "efficient bashisms" rather than one round trip per call.
Think of classic tool calling as phoning a contractor for every single nail. Codemode hands the model a nail gun and a parts list, and you get one call back when the shelf is up.
The release notes put a number on the prompt diet. With the default tools and Codemode active, a GPT-5.6 request drops from about 5,300 prompt tokens to about 3,300, because tool declarations shrink to one line each and the full models API reference moves to a doc the model reads only when needed.
Codemode errors also got smarter: ask for tools.Bash and it suggests tools.bash; pass malformed arguments to models.classify() and it returns the expected shape. Scripts can now call models.generateImages() with the session's credentials. The 1.0 release also hardens MCP OAuth, including RFC 9207 issuer checks and per-server credential storage, which is the boring security work you want done before a tool hits 1.0.
Not everyone is sold on the timing. One commenter on the Hacker News thread (past 700 points) pointed out that MCP had a two-year head start on Jev support yet landed later. That is a fair jab, and Earendil's own post concedes many MCP servers are still built for harnesses that "just dump tools into the context."
Pi Durable: the part to watch
Pi the coding agent assumes one person, one terminal, and a process you can restart by hand. Pi Durable is the opposite shape: a framework (not a replacement for the coding agent) for agents that run for a long time, anywhere there is a JavaScript runtime, and that several humans can drive at once. It ships as @earendil-works/pi-durable on npm and shares the pi-ai model layer with the coding agent.
How crash recovery works
Every model request, tool call, and compaction is a task that writes a checkpoint before moving on. If the process dies, a new process opens the same storage, finds unfinished tasks, and resumes each from its last checkpoint. A cut-off model request is resent, with the partial answer kept in the transcript and marked aborted. A cut-off tool call reruns only if the tool declares replay: "safe"; otherwise the model is told it was interrupted and decides what to do. A requestId makes submissions exactly-once, so a client retrying after a crash gets the original submission back.
The other design choices
- Pluggable storage. Memory, SQLite, and JSONL backends ship in the box, with a conformance suite for your own. The SQLite and JSONL code avoids Node APIs, so Earendil says it runs on Bun or inside a Cloudflare Durable Object with a small adapter.
- Forkable conversations. A conversation can fork another at any message and see the parent's history without copying it. Earendil's example: a Slack channel is one conversation, a thread is a fork, and both run concurrently.
- Background compaction. Summaries are built while the conversation keeps going and slot in at the next turn boundary. Older messages stay in storage, so a tool can still search them after a handoff.
- Hot-swappable extensions. Install a new version of an extension while conversations run; in-flight tool calls finish on the old code, the next call uses the new one.
- Multiplayer. Any number of clients can attach to a conversation, get the current view, then receive only diffs, and any of them can steer or queue follow-ups.
It is also built to be read by agents. Earendil says the whole source, without tests, is about 15,000 lines, roughly 150,000 tokens with a GPT tokenizer and 250,000 with Claude's. The repo includes more than thirty examples, and the demo vacation planner is about 1,300 lines of TypeScript, most of it TUI. Yes, the flagship demo for a crash-proof agent framework is a holiday planner. It is honestly a better test than another todo app.
Why builders should care
Most "durable agent" stories today mean bolting an LLM loop onto a workflow engine and hoping the semantics line up. Pi Durable bakes durability into the transcript itself: tool intent is stored before execution, application state lives in typed documents committed atomically with the transcript, and forks declare what state they inherit. If you have ever had an agent half-finish a deploy and then forget it started, the replay flag alone is worth reading the source for.
For Pi users, 1.0 is the signal that config and extension APIs are meant to hold still. Pi's pitch has been that you build your own agent on top of it; Earendil says it waits until a feature "has proven itself" before adopting it, and the MCP turn shows that bar can move. Pi Durable, meanwhile, is explicitly experimental and its API "might still change," so treat it as something to prototype with, not to bet a production SLA on yet.
Key Takeaways
- Pi 1.0 is out under MIT, with MCP and Codemode in core, deferred tool loading, virtual models, Anthropic cache warming, and a fullscreen TUI by default.
- Codemode lets the model compose tool calls in a JavaScript sandbox; in 1.0 its prompt overhead fell from about 5,300 to 3,300 tokens on a GPT-5.6 request.
- Pi is big: 111,000+ GitHub stars and about 4.54 million npm downloads of the coding agent package in the week before release.
- Pi Durable is a separate, experimental framework for crash-surviving, forkable, multiplayer agents with pluggable storage, about 15,000 lines of source.
- Tools in Pi Durable declare whether replay is safe, so a crash never silently reruns a side effect like a deploy.
Sources: Earendil: Pi 1.0, Earendil: Pi Durable, Earendil: "You Said No MCP!", GitHub: Pi v1.0.0 release notes, GitHub: earendil-works/pi, npm downloads API, Hacker News discussion