Ground Truth.
AI, checked against the source.

News · 2026-10-02

Pi 1.0 adds MCP and OAuth hardening while leaving host permissions to operators

Earendil released Pi 1.0 on October 1 with native support for the Model Context Protocol, composable tool calls, and hardening of its tool-server authentication. The open-source coding agent still has no built-in permission system for access to the host computer, making the distinction between connecting tools and restricting their authority central to its deployment.

Key facts

A terminal coding agent can read a repository, change files, and run programs. Its usefulness comes from those powers. Its security depends on where those powers stop. Pi’s new release expands how tools enter the agent’s working loop without replacing the operator’s responsibility for the surrounding computer.

The Pi repository describes a minimal, extensible toolkit and explicitly says the agent runs with the privileges of the process that launches it. It recommends sandboxing for stronger restrictions. That is a concrete deployment property: a language model’s instructions do not substitute for operating-system controls over files, processes, networking, or credentials.

Pi’s newly integrated protocol, usually shortened to MCP, provides a common language for connecting an agent to tool servers. Codemode puts those tools behind a JavaScript interpreter so calls can be combined in a program. Imagine a technician receiving a cabinet of compatible instruments and a workbench where several measurements can be composed. Standard connectors make the instruments easier to use; they do not decide which rooms the technician can enter.

Earendil’s September 29 explanation makes the change especially interesting. The team had resisted adding the protocol, then concluded that the required interpreter and tool metadata improvements addressed broader needs. Earendil wrote, “The best way to positively influence something is to embrace it.” Its argument is about architecture and ecosystem direction, rather than a published performance measurement.

The design favors discoverable tools and structured results over loading every server’s descriptions and text output into the model’s conversation. Deferred loading is part of the release. The interpreter also helps integrate models that make bounded decisions rather than produce conversational answers. An application can therefore use a specialist decision component alongside the main language model.

Authentication and execution isolation solve different problems. The release notes list OAuth hardening, but the dossier provides no basis for claiming a specific vulnerability was exploited or fixed. OAuth governs delegated access to a service. Host isolation governs what a running process can do locally. Likewise, Codemode’s interpreter sandbox should not be read as a complete permission boundary around every external tool the agent can invoke.

The official model guide documents local models and compatible endpoints, including a route through llama.cpp. Local model support gives operators another deployment choice, although tool-calling quality still depends on the selected model and serving software. Pi itself is an agent application, not a downloadable model checkpoint, so a single model-weight download size or video-memory requirement does not describe this release.

Practitioner reception is divided. The Hacker News discussion includes praise for a small prompt and an adaptable base, alongside complaints about unvetted extensions and missing built-in controls. Creator Mario Zechner argues that the new capabilities remain optional. Those comments establish a real design disagreement, rather than a representative assessment of reliability or adoption.

The strongest objection is that extensibility shifts work onto the operator: choosing extensions, isolating the process, and deciding which services receive access. The strongest case for Pi is the same flexibility, especially when a team wants to construct a particular workflow instead of accept a fixed product. Our lessons on agent harnesses and sandboxing explain why those decisions can change behavior substantially.

For a team evaluating the release, the configuration is part of the product judgment. The chosen model, connected servers, extension set, and enclosing process permissions determine the working system. Two installations of the same agent version can therefore expose different capabilities and authority, even before comparing answer quality.

Pi 1.0 is consequently both a shipping coding-agent release and an agent-security story. It makes tool integration more capable while leaving several authority boundaries explicit. The public evidence confirms the release and its documented design; it does not establish independent security assurance, measured productivity gains, or a universal safe configuration.


Primary source, verified: read the paper →

Key questions

Does Pi 1.0 include a host permission system?

Pi’s repository says it has no built-in permission system for filesystem, process, network, or credential access. Operators must supply stronger boundaries through a container or external sandbox.

Does native MCP support connect Pi to servers automatically?

Pi users still choose and configure their servers. Codemode supplies the integration and tool-composition layer once configured.

Who created Pi?

Mario Zechner created Pi and joined Earendil after it acquired the project. Armin Ronacher is a company steward, rather than a co-author of the original project.
Cite this

APA

Ground Truth. (2026, October 2). Pi 1.0 adds MCP and OAuth hardening while leaving host permissions to operators. Ground Truth. https://groundtruth.day/news/pi-1-mcp-oauth-and-host-permissions.html

BibTeX

@misc{groundtruth:pi-1-mcp-oauth-and-host-permissions,
  title  = {Pi 1.0 adds MCP and OAuth hardening while leaving host permissions to operators},
  author = {{Ground Truth}},
  year   = {2026},
  month  = {oct},
  url    = {https://groundtruth.day/news/pi-1-mcp-oauth-and-host-permissions.html}
}

Topics: agents · coding · open-source · cybersecurity · ai-security · authentication

Comments are replies to this story on Bluesky — reply with any Bluesky account to join in.