What changed
On October 1, 2026, Earendil released Pi 1.0, the first stable release of its MIT-licensed coding-agent harness. The core now includes Codemode, which gives Pi native MCP support and lets it work with non-LLM models such as decision and image models; extension support for virtual models; deferred tool loading; cache warming for Anthropic models; and transcript-aware mid-conversation system messages. Earendil says hundreds of thousands of people use Pi each week. It also released Pi Durable separately as an experimental package for longer-running agent applications rather than expanding the terminal agent itself into a larger orchestration system.
Why it matters
Pi is a useful counterpoint to coding agents that accumulate planning modes, subagents and built-in workflow layers. Its 1.0 boundary shows a smaller harness deciding that MCP and code-driven tool orchestration are now foundational enough to belong in the core while more opinionated long-running orchestration stays outside it. For builders, the practical appeal is an open, extensible substrate that can route across providers and models without tying the workflow to one vendor. The caveat is that Pi’s minimalism also pushes more responsibility onto extensions and the surrounding execution environment; stable 1.0 does not make arbitrary agent tools safe.
Codemode moves tool orchestration into code
Pi 1.0 includes Codemode with native MCP support and support for non-LLM models. Instead of exposing every integration as a large flat tool surface, the agent can write code that invokes tools and composes results. Earendil also added deferred tool loading to keep the active tool surface smaller.
Virtual models make routing an extension concern
Extensions can expose virtual models that combine underlying providers or decision models. Earendil demonstrates a router that plans with Claude Opus, uses Jev to detect the transition to implementation and then hands work to GPT-6 Luna.
Long-running agents stay outside the core
Earendil launched Pi Durable on the same day as an experimental package for longer-running agent applications. Keeping it separate preserves the terminal agent's smaller core while giving developers a path to build persistent or differently surfaced agent systems.
Stable does not mean sandboxed
Pi is designed as a malleable agent harness rather than a restrictive execution environment. Builders still need to reason about the permissions granted to tools, extensions, shells and MCP servers instead of treating the 1.0 label as a security boundary.