Byte by Mahmud logoByteby Mahmud

Byte

Pi 1.0 Hit #1 on Hacker News. The MCP Surrender Isn't the Interesting Part.

Technology6 min read1 views

Pi 1.0 Hit #1 on Hacker News. The MCP Surrender Isn't the Interesting Part.

Mahmud Hasan

Mahmud Hasan

October 3, 2026

The agent that made saying no a brand

Pi is a terminal coding agent created by Mario Zechner and acquired by Earendil in spring 2026 (Armin Ronacher's company, backed by Accel and Balderton). It's MIT licensed, talks to models from every major provider, and gives the model exactly four tools out of the box — read, write, edit, bash. At launch the entire system prompt plus tool definitions measured under 1,000 tokens, where competing harnesses carry tens of thousands. The 1.0 announcement put the philosophy bluntly: "We wait until something has proven itself, and only then do we consider adopting it; weighing its true functionality against its inherent added complexity."

The anti-MCP argument was never vibes. It was a token argument, and it was concrete. In the standard MCP pattern, every connected server pre-loads the full schema definitions for all of its tools into your context window — 550 to 1,400 tokens per tool definition. Zechner's go-to example was the Playwright MCP server: 21 tools, roughly 13,700 tokens, on every single session. The number everyone quoted came from Perplexity's CTO, who said at a conference in March 2026 that three MCP servers consumed 143,000 of their 200,000-token context window. A 72 percent tax before the agent answers its first question. Perplexity dropped MCP internally, and for a while the loudest takes of early 2026 declared the protocol dead.

Three things changed

On September 29, 2026, Pi shipped version 0.99.0, and MCP became a supported core feature. The team published a self-aware announcement titled "You Said No MCP!" — and it shot to the top of Hacker News within hours. Two days later, 1.0 proper landed at #1 with 1,200+ points. The team didn't cave to peer pressure; the announcement laid out specific conditions:

  • MCP itself evolved. The July 2026 spec revision made stateless operation the primary focus and removed the initialize handshake and session layer that made production deployments painful. The protocol was donated to the Linux Foundation in December 2025, and adoption climbed anyway — 17,000+ public servers, hundreds of millions of monthly SDK downloads. Arguing against a protocol your users already run in production is a losing position regardless of technical merit.
  • The cost problem got a real solution. Pi didn't bolt on naive MCP support. It shipped Codemode — the part of this release actually worth studying.
  • Integration was nearly free. The harness needed a JavaScript sandbox for Codemode anyway. Once that existed, MCP support was a small addition. As the team put it: "The best way to positively influence something is to embrace it." A year of loud public criticism had pushed the protocol somewhere better. That is how it's supposed to work.

Codemode: the model stops reading tool output and starts computing over it

The old pattern: the model sees every tool schema up front, emits a JSON tool call, waits for the result to return into context, and repeats. Every intermediate result becomes a permanent resident of your context window.

Codemode: the model writes JavaScript instead, executed inside a QuickJS sandbox in Pi's harness, with the MCP tools available to it. The model discovers tools through documentation rather than pre-loaded schemas, calls them from code, chains them together — and only the distilled result re-enters the context. The announcement's example combines the Linear MCP server with a sentiment classifier to find frustrated commenters across 167 open issues, processed in parallel, none of it touching the context except the final answer. MCP stays the wire protocol; the model interface changes from "here are 40 tool schemas" to "here's a programmable environment." Tool results stop being prompt tax.

The wins: fewer round trips (a ten-call chain is one sandbox execution), fewer tokens (the changelog reports a GPT-5.6 request shrinking from about 5,300 to about 3,300 prompt tokens), and repeatability — the agent reuses tomorrow the script it wrote today.

One detail: earlier Codemode-style implementations had a composability problem — each MCP server that wanted code execution shipped its own sandbox, and the sandboxes couldn't call into each other. Pi puts the sandbox in the harness, not the server: one sandbox, every configured tool inside it, composition across vendors works. Newer frontier models are increasingly trained on this shape of tool use, and Cloudflare's earlier Code Mode work showed you can hand an agent an entire large API for a fixed cost of around 1,000 tokens.

The rest of 1.0 — and the sleeper release

Beyond Codemode, the 1.0 list is short by design: deferred tool loading, cache warming for Anthropic models, mid-conversation system messages that change prompts and tools mid-transcript, extension support for virtual models and non-LLM models like classifiers and image models, a new TUI theme, and full-screen mode as the default. (tuiMode: "regular" gets your scrollback back.)

The sleeper release: Pi Durable, an experimental framework for agents that are long-running, crash-resistant, and reachable from multiple surfaces — terminal, Slack, whatever. It does not replace the terminal agent. Its selling point is boring correctness: every step is a durable checkpoint, so a dead process resumes where it stopped. Tools declare a replay policy — replay: "safe" re-runs after a crash; anything not marked (a deploy, a payment) does not re-run, and the model is told the call was interrupted. Interrupted model requests are resent with a requestId for exactly-once submission. Approvals store decisions in a memo — first write wins — so a crash after a human clicks approve doesn't ask twice. ~15,000 lines of TypeScript, storage in memory, SQLite, or JSONL, experimental, MIT licensed.

The security footnote nobody should skip

Before you install it on anything important: Pi has no built-in permission system. The agent runs with the privileges of the process that launches it; stronger boundaries come from a container or an external sandbox. The 1.0 release hardens MCP OAuth authentication, but OAuth governs delegated access to a service — not what a running process can do on your machine. The Codemode sandbox is not a permission boundary around external tools either. Two installations of the same Pi version can expose different authority, because the model, servers, extensions, and permissions you choose define the working system. Try it in a disposable container first.

What to take from this

If you took the March 2026 "MCP is dead" discourse seriously and ripped the protocol out of your stack, this week was awkward. The takeaways aren't about picking a side — ecosystem gravity settled that. Steal the architecture instead: stop pre-loading tool schemas, move composition out of the model loop, return structured data instead of text dumps, and watch where the models are trained — tool-calling patterns that match training data perform better, the same way models got better at writing bash than at inventing shell syntax.

Pi spent a year making a technically literate argument against MCP and adopted it anyway. That's not a story about being wrong: the MCP Pi adopted isn't the MCP that was criticized — stateless transport, deferred loading, structured returns, harness-level sandboxes fix the exact complaints the skeptics raised. The critics didn't lose; their feedback became the roadmap. The team earned the reversal by refusing everything for long enough that a yes means something.

Install it with curl -fsSL https://pi.dev/install.sh | sh — or don't. Either way, copy the ideas. Your context window will thank you.

References

  • Ashraf Chowdury, "Pi 1.0 Just Hit #1 on Hacker News. The Agent That Hated MCP Now Ships It." DEV Community, October 2026. dev.to
  • Jamil, "One Coding Agent Spent a Year Mocking MCP. It Just Made MCP a Core Feature." DEV Community, October 2026. dev.to
  • Subagentic, "Pi 1.0 adds Codemode with native MCP; same-day Pi Durable is experimental." October 1, 2026. subagentic.ai
  • Ground Truth, "Pi 1.0 adds MCP and OAuth hardening while leaving host permissions to operators." October 2, 2026. groundtruth.day

Comments

Leave a comment

Your email stays private — only your name is shown.

More in Technology