BuildNot yet confirmed elsewhere1 publisher3 min readPublished
Pi 1.0 brings MCP into its core by batching tool calls in a JavaScript sandbox
Earendil's Pi 1.0, an agent harness whose website once advertised "No MCP", now builds MCP into its core. The team ties the reversal to Codemode, a JavaScript interpreter beside the harness loop that lets the model batch MCP calls into one script.
The Engineer · Build desk

What happened
- In a September 29 post opening with a section titled "Things Change", the team said MCP has changed a lot in a year, though not enough on its own to justify moving it into the core.
- In the team's demo, Pi pulled issue threads through Linear's MCP server and had Jev score their tone four at a time to find the 20 most frustrated people.
- The Pi repository had 113,973 stars and 14,485 forks on GitHub when the dev.to writeup was published.
Why it matters
- exposure Model-written scripts now run beside the agent loop, the part of a harness that usually sits in a trusted environment. Pi's WASM-compiled interpreter becomes the main barrier between those scripts and the harness.
- decision MCP server authors who flatten output to plain text to save tokens are tuning for the context-stuffing harnesses Pi's team calls old, and their replies give a Codemode script less to compose.
- precedent For other minimal harnesses, Pi's route ties MCP support to building an interpreter sandbox first. One project's switch is thin evidence that MCP is now required everywhere.
According to Pi's team, many MCP servers were built for older harnesses that load every tool into the context window and then try to save tokens by returning plain text [15]. A dev.to writeup of the release describes how Codemode avoids that. The model writes one JavaScript script that orders the calls and merges the results, then returns only the final answer, instead of calling tools one at a time through a limited context window [10]. The writeup, by Nokka, says it was drafted by deepseek-v4.1-flash through Hermes Agent under human review [20].
A harness can execute a tool call in one of two places: where bash runs, or where the agent loop runs [8]. The loop usually sits in a trusted environment. Tools usually sit in a less trusted sandbox [8]. Codemode runs on the loop's side [9]. That puts the security argument on the choice of language. The team says a small version of JavaScript compiles to a WASM binary, and that this gives reasonable protection against risk [12]. Codemode keeps its state in the conversation log, not the filesystem [11]. We think that is good engineering. The writeup notes the design leaves no trace on the machine and lets a user look back at what the script did [11].
Pi 1.0 shipped on October 1, 2026 [2], and the site now reads "Now with MCP+Codemode" [3]. The change was visible. The launch post claims hundreds of thousands of weekly users without giving a number [23], and the 1.0 thread on Hacker News reached first place with 1,687 points and 609 comments [19]. The earlier skepticism was on the record too, including an older article by Mario Zechner asking what working without MCP would look like [4].
The team's other reasons concern Pi's own design. The restructuring MCP required also made Jev and classifier models easier to use in Pi [6]. And Pi's needs, the team wrote, turned out to resemble MCP's: a sandbox to play in, in the form of an interpreter [7].
In our view, the evidence supports a narrow conclusion. Pi took MCP into its core once it had an interpreter that keeps tool calls away from the model's context. The evidence covers one harness, and its team gives architectural reasons for the move. The team also stops short of calling the protocol fixed. It says MCP's biggest problem, that it is hard to compose, remains [14]. It wants MCP to move closer to OpenAPI and return structured data [16].
Size is the other test. Pi is a TypeScript project under the MIT license [1], pitched as small enough to understand whole and open to extension at almost every layer [21]. The team puts the Pi Durable code, excluding tests, at about 15,000 lines. That is roughly 150,000 tokens for GPT-family models and 250,000 for Claude, sized so an agent can read the harness it runs in [17]. Per line, that comes to 10 tokens against about 17, so the same self-inspection costs about two-thirds more on Claude [22]. The writeup does not say how many lines MCP and Codemode added to the core.
What to watch
- A line or token count for Pi 1.0's core with MCP and Codemode included, set against the 15,000-line Pi Durable figure.
- Whether MCP server authors start returning structured, OpenAPI-style data that a Codemode script can compose.
- Any independent security review of the WASM-compiled JavaScript interpreter that runs on Pi's trusted side.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence40
- Adoption55
- Hype gap+10
- Incentives45
- Confidence45
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Pi is an agent harness written in TypeScript and published on GitHub under the MIT license.
- [2]
The Earendil team released Pi 1.0 on October 1, 2026, and in this version MCP became part of the core.
- [3]
pi.dev previously carried a proud statement that Pi does not support MCP; the site now contrasts "No MCP" with "Now with MCP+Codemode".
ReportedSupportedSource: dev.to writeup citing pi.dev and the team's September 29 postView cited source - [4]
Several podcasts contained dismissive remarks about MCP, and an older article by Mario Zechner asked directly what it would be like to work without MCP.
- [5]
In a September 29, 2026 post whose first section is titled "Things Change", the team said MCP itself has changed a lot from a year earlier, though that reason alone would not have been enough to move it into the core.
- [6]
The team said the restructuring needed to support MCP had other benefits, such as making it easier to use Jev or classifier models in Pi.
- [7]
The team said that in the end Pi's needs resemble MCP's needs: a sandbox to play in, in the form of an interpreter.
- [8]
When a harness calls a tool, it can run on the side where bash runs or the side where the agent loop runs; the harness loop is usually in a trusted environment, while the tools it calls usually sit in a less trusted sandbox.
- [9]
Codemode runs where the harness runs and coordinates multiple tool calls into a single batch.
- [10]
In practice, instead of the model calling tools one at a time through a limited context window, it writes one JavaScript script to sequence the calls and combine the results, then returns only the final answer.
- [11]
Codemode's state is stored in the conversation log, not the filesystem; the writeup says this leaves no trace on the machine and allows looking back at what was done.
- [12]
The team chose JavaScript because a small version of JavaScript can be compiled to a WASM binary, giving a reasonable level of protection against risk.
- [13]
In the team's example, a one-sentence instruction to use Jev through Codemode to find the 20 most frustrated people in the issue tracker led Pi to write code that pulled data from Linear MCP and called Jev to score the tone of each thread, four threads at a time.
- [14]
The team said MCP's biggest problem remains the same: it is hard to compose.
- [15]
The team said part of the problem is that many MCP servers are still designed for older harnesses that dump all tools into the context window and try to save tokens by returning plain text.
- [16]
The team proposed that MCP move closer to the OpenAPI approach, sending structured data.
- [17]
The team said the Pi Durable code, excluding tests, is about 15,000 lines, roughly 150,000 tokens for GPT-family models and roughly 250,000 tokens for Claude, so that agents running on Pi can inspect the code of the harness they run in.
- [18]
At the time the writeup was written, the Pi repository had 113,973 stars, 14,485 forks and 325 open issues on GitHub.
- [19]
The Pi 1.0 announcement thread on Hacker News reached number one with 1,687 points and 609 comments.
- [20]
The dev.to writeup by Nokka states it was written by AI (deepseek-v4.1-flash) via Hermes Agent under human control and quality review.
- [21]
The team's stated selling point is minimalism and extensibility: a tool small enough to understand in full and open to extension at almost every layer.
- [22]
Pi Durable's code works out to 10 tokens per line for GPT-family models and about 16.7 tokens per line for Claude, so reading it costs Claude about 1.67 times the tokens.
- [23]
The Pi 1.0 launch post says hundreds of thousands of people use Pi each week worldwide, without giving a precise figure.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toharness AI ที่เคยประกาศว่าไม่รองรับ MCP เปลี่ยนใจได้ยังไง? เจาะ Pi 1.0 และ Codemode
1 article · October 10, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Agent code execution sandboxingFollow
- AI agent harnessesFollow