Pi vs Claude Code vs Darce: is the Pi coding agent right for you?
Pi is a minimal, MIT-licensed terminal agent with no built-in permission prompts. Here's how it compares with Claude Code and with Darce, and how to run Pi safely.
Updated October 2026
Pi is a minimal, MIT-licensed terminal coding agent created by Mario Zechner and now developed under Earendil Inc. It has four core tools, many model providers and no built-in permission prompts. Claude Code is Anthropic's Claude-only agent. Darce is an open source terminal agent with risk-scored approvals and undo for shell commands.
Last checked: October 2026. Facts about Pi and Claude Code come from their official sites, repos and docs, linked in the sources below.
What is the Pi coding agent?
Pi (pi.dev) is "a minimal, extensible agent harness that you can make your own" (pi.dev). Mario Zechner introduced it in November 2025 as a reaction to heavier agents: a system prompt and tool definitions that together come in under 1,000 tokens, and four tools, read, write, edit and bash (Zechner's post). The project now lives in the earendil-works/pi repository, the site credits "Earendil Inc. & Contributors", and the license is MIT.
You install it from npm as @earendil-works/pi-coding-agent (or with an install script) and it needs Node.js 22.19 or newer. It runs on macOS, Linux and Windows, in four modes: interactive terminal UI, print/JSON, RPC over stdin/stdout, and a TypeScript SDK (coding agent README).
Its philosophy is to ship less and let you add what you need. Sub-agents, plan mode, to-do lists, background bash and permission popups are left out on purpose; you build them as extensions, install a package, or use tmux and files instead.
At a glance
| Pi | Claude Code | Darce | |
|---|---|---|---|
| What it is | Minimal, extensible terminal agent harness | Agentic coding tool for the terminal, with IDE extensions, desktop, web and mobile | Terminal AI coding agent |
| License | MIT | Proprietary ("All rights reserved") | MIT |
| Models | Many providers: Anthropic, OpenAI, Google, Azure, Bedrock, Mistral, Groq, Cerebras, xAI, OpenRouter, Ollama and more; API keys or OAuth | Claude models only | 250+ via OpenRouter, no provider keys needed |
| How you pay | Free tool; you pay your model providers | Claude Pro $20/month, Max from $100/month, or API usage | Free plan, Builder $15/month, Power $65/month |
| Permission prompts | None built in; runs with your user's permissions; use a container or an extension | Permission modes from Manual to auto (classifier) and bypass; optional Bash sandbox | Every command risk-scored; risky ones ask with the reason |
| Undo files | Not built in; /tree navigates the conversation; community packages add git-based file restore | Checkpoint per prompt; doesn't track Bash changes | /undo and /rewind, including files shell commands changed |
| Sub-agents and plan mode | Not built in, by design | Built in | Plan mode, /swarm parallel agents, /derby model races |
| Extensibility | Extensions, skills, prompt templates, themes, packages via npm or git | Skills, hooks, plugins, MCP | Skills (Claude Code skills work as-is), memory |
Is the Pi coding agent safe?
Pi is safe in the sense that it's open source, widely used and you can read every line. It is not safe in the sense of protecting you from the agent itself, and it doesn't claim to be. Its README says plainly: "Pi does not include a built-in permission system for restricting filesystem, process, network, or credential access." It runs with the permissions of the user who started it (Pi README).
Zechner's original post puts it more bluntly: Pi "runs in full YOLO mode and assumes you know what you're doing", with "no permission prompts for file operations or commands". His argument is that permission checks in other agents are "mostly security theater" once an agent can write and run code (Zechner's post).
If you use Pi, the project's own guidance is to:
- Run it in a container or sandbox. The README points to options such as Docker for stronger isolation.
- Add a confirmation flow if you want one. Pi links example extensions for a permission gate, protected paths and sandboxing; they aren't on by default.
- Review packages before installing. Pi packages and extensions run code on your machine, so treat them like any dependency.
- Commit often. Without built-in file undo, git is your safety net.
That's a coherent position, and many experienced developers prefer it. But if you want an agent that stops before rm -rf or a deploy on its own, Pi as shipped won't.
How Claude Code and Darce handle the same risk
Claude Code asks or delegates. Its modes range from Manual (only reads run without asking) through auto, where a classifier reviews actions instead of you, to bypassPermissions for isolated containers. An optional Bash sandbox on macOS, Linux and WSL2 limits what commands can reach (permission modes).
Darce scores every command before it runs: read-only, changes the project, reaches outside (network, installs, unknown commands), or destructive (rm -rf, sudo, force-push). In the default auto mode, the first two run and the rest ask first with the reason. Scripts like npm run x get a second look from a classifier that reads the real script line, effects /undo can't reverse always ask, and destructive commands can never be "always allowed". Credential-like environment variables are hidden from commands, and known secret formats are redacted before reaching a model. Darce has no OS sandbox, and its full mode asks for nothing, like Pi. See Safety.
Undo and session history
Pi stores sessions as trees you can navigate with /tree, export or share. That rewinds the conversation, not your files. File restore comes from community packages such as checkpoint-pi and pi-rewind, which take git-based snapshots (pi-rewind). They're third-party, so check them before relying on them.
Claude Code checkpoints each prompt and can restore code, conversation or both, but its docs say changes made by Bash commands aren't tracked (checkpointing). See Claude Code rewind vs Darce undo.
Darce snapshots your working tree before every step into private git refs, so /undo reverses Darce's edits and the files shell commands created, changed or deleted. Limits: shell-command coverage needs a git repo, history lasts for the session, gitignored files like node_modules aren't snapshotted, and remote actions can't be undone, so they ask first.
Models and pricing
Pi is free; you pay your providers. It supports a long list of them, including OpenRouter and local models through Ollama, and you can switch models mid-session with /model or Ctrl+L.
Claude Code is included with Claude Pro ($20/month, $17 billed yearly) or Max (from $100/month), or billed per token through the API, with Claude models only (Claude pricing).
Darce has a free trial with no account, a Free plan with a daily allowance, Builder at $15/month and Power at $65/month, covering 250+ models without your own keys. Pi is cheaper if you already have provider keys or run local models; Darce is simpler if you don't want to manage them. See pricing.
Parallel work and extras
Pi deliberately has no sub-agents; you spawn more Pi instances in tmux or build orchestration as an extension. Claude Code has subagents, background agents and cloud sessions. Darce has /swarm, which splits a task into 2-4 agents in git worktrees and merges them, and /derby, which races three models on one task so you keep the best diff.
Who Pi is for
Pi suits experienced developers who want a small, fast, hackable harness with a tiny system prompt, full control over context, and the freedom to build exactly the workflow they want. It's a strong choice if you already run agents in containers and see permission prompts as noise.
Who Claude Code is for
Claude Code suits developers who want Claude models with Anthropic's batteries-included harness: permission modes, sandboxing, subagents, and the terminal, IDE, desktop and web surfaces.
Who Darce is for
Darce suits developers who want guardrails without writing them: risk-scored approvals out of the box, a second look at scripts, and an undo that also reverses what shell commands did, with 250+ models on one plan. Try it with npx darce-cli, no account: Getting started.
Bottom line
Pick Pi for a minimal, MIT-licensed harness you shape yourself, and run it in a container. Pick Claude Code for Claude with built-in permission modes. Pick Darce if you want safety and undo built in rather than bolted on. Related: OpenCode, Cline, Kilo Code and the Claude Code alternative.
Sources
- pi.dev
- earendil-works/pi on GitHub
- Pi coding agent README
- Mario Zechner: What I learned building an opinionated and minimal coding agent
- pi-rewind package
- Claude Code overview
- Claude Code permission modes
- Claude Code checkpointing
- Claude pricing
Frequently asked questions
What is the Pi coding agent?
Pi is a minimal, extensible terminal coding agent created by Mario Zechner and now developed under Earendil Inc. It is MIT licensed, ships four core tools (read, write, edit, bash) and supports many model providers.
Is the Pi coding agent safe?
Pi has no built-in permission system: it runs commands and edits files with your user's permissions without asking. Its README recommends running it in a container or sandbox, and example extensions can add a permission gate.
Is Pi better than Claude Code?
Pi is better if you want a tiny, hackable harness and many model providers, and you're comfortable adding your own guardrails. Claude Code is better if you want Claude with built-in permission modes, sandboxing and subagents.
Is Pi free?
Yes. Pi is free and MIT licensed; you pay your model providers directly through API keys or OAuth logins.
Does Pi have undo or checkpoints?
Pi's /tree command navigates the conversation history, not your files. Community packages such as checkpoint-pi and pi-rewind add git-based file restore.
How do I install Pi?
Install it with npm install -g @earendil-works/pi-coding-agent (Node.js 22.19 or newer) or the install script from pi.dev, then run /login inside Pi to connect a provider.