Pi vs Claude Code vs Darce: is the Pi coding agent right for you?

Pi is a minimal, MIT-licensed terminal agent with no built-in permission prompts. Here's how it compares with Claude Code and with Darce, and how to run Pi safely.

Updated October 2026

Pi is a minimal, MIT-licensed terminal coding agent created by Mario Zechner and now developed under Earendil Inc. It has four core tools, many model providers and no built-in permission prompts. Claude Code is Anthropic's Claude-only agent. Darce is an open source terminal agent with risk-scored approvals and undo for shell commands.

Last checked: October 2026. Facts about Pi and Claude Code come from their official sites, repos and docs, linked in the sources below.

What is the Pi coding agent?

Pi (pi.dev) is "a minimal, extensible agent harness that you can make your own" (pi.dev). Mario Zechner introduced it in November 2025 as a reaction to heavier agents: a system prompt and tool definitions that together come in under 1,000 tokens, and four tools, read, write, edit and bash (Zechner's post). The project now lives in the earendil-works/pi repository, the site credits "Earendil Inc. & Contributors", and the license is MIT.

You install it from npm as @earendil-works/pi-coding-agent (or with an install script) and it needs Node.js 22.19 or newer. It runs on macOS, Linux and Windows, in four modes: interactive terminal UI, print/JSON, RPC over stdin/stdout, and a TypeScript SDK (coding agent README).

Its philosophy is to ship less and let you add what you need. Sub-agents, plan mode, to-do lists, background bash and permission popups are left out on purpose; you build them as extensions, install a package, or use tmux and files instead.

At a glance

PiClaude CodeDarce
What it isMinimal, extensible terminal agent harnessAgentic coding tool for the terminal, with IDE extensions, desktop, web and mobileTerminal AI coding agent
LicenseMITProprietary ("All rights reserved")MIT
ModelsMany providers: Anthropic, OpenAI, Google, Azure, Bedrock, Mistral, Groq, Cerebras, xAI, OpenRouter, Ollama and more; API keys or OAuthClaude models only250+ via OpenRouter, no provider keys needed
How you payFree tool; you pay your model providersClaude Pro $20/month, Max from $100/month, or API usageFree plan, Builder $15/month, Power $65/month
Permission promptsNone built in; runs with your user's permissions; use a container or an extensionPermission modes from Manual to auto (classifier) and bypass; optional Bash sandboxEvery command risk-scored; risky ones ask with the reason
Undo filesNot built in; /tree navigates the conversation; community packages add git-based file restoreCheckpoint per prompt; doesn't track Bash changes/undo and /rewind, including files shell commands changed
Sub-agents and plan modeNot built in, by designBuilt inPlan mode, /swarm parallel agents, /derby model races
ExtensibilityExtensions, skills, prompt templates, themes, packages via npm or gitSkills, hooks, plugins, MCPSkills (Claude Code skills work as-is), memory

Is the Pi coding agent safe?

Pi is safe in the sense that it's open source, widely used and you can read every line. It is not safe in the sense of protecting you from the agent itself, and it doesn't claim to be. Its README says plainly: "Pi does not include a built-in permission system for restricting filesystem, process, network, or credential access." It runs with the permissions of the user who started it (Pi README).

Zechner's original post puts it more bluntly: Pi "runs in full YOLO mode and assumes you know what you're doing", with "no permission prompts for file operations or commands". His argument is that permission checks in other agents are "mostly security theater" once an agent can write and run code (Zechner's post).

If you use Pi, the project's own guidance is to:

  • Run it in a container or sandbox. The README points to options such as Docker for stronger isolation.
  • Add a confirmation flow if you want one. Pi links example extensions for a permission gate, protected paths and sandboxing; they aren't on by default.
  • Review packages before installing. Pi packages and extensions run code on your machine, so treat them like any dependency.
  • Commit often. Without built-in file undo, git is your safety net.

That's a coherent position, and many experienced developers prefer it. But if you want an agent that stops before rm -rf or a deploy on its own, Pi as shipped won't.

How Claude Code and Darce handle the same risk

Claude Code asks or delegates. Its modes range from Manual (only reads run without asking) through auto, where a classifier reviews actions instead of you, to bypassPermissions for isolated containers. An optional Bash sandbox on macOS, Linux and WSL2 limits what commands can reach (permission modes).

Darce scores every command before it runs: read-only, changes the project, reaches outside (network, installs, unknown commands), or destructive (rm -rf, sudo, force-push). In the default auto mode, the first two run and the rest ask first with the reason. Scripts like npm run x get a second look from a classifier that reads the real script line, effects /undo can't reverse always ask, and destructive commands can never be "always allowed". Credential-like environment variables are hidden from commands, and known secret formats are redacted before reaching a model. Darce has no OS sandbox, and its full mode asks for nothing, like Pi. See Safety.

Undo and session history

Pi stores sessions as trees you can navigate with /tree, export or share. That rewinds the conversation, not your files. File restore comes from community packages such as checkpoint-pi and pi-rewind, which take git-based snapshots (pi-rewind). They're third-party, so check them before relying on them.

Claude Code checkpoints each prompt and can restore code, conversation or both, but its docs say changes made by Bash commands aren't tracked (checkpointing). See Claude Code rewind vs Darce undo.

Darce snapshots your working tree before every step into private git refs, so /undo reverses Darce's edits and the files shell commands created, changed or deleted. Limits: shell-command coverage needs a git repo, history lasts for the session, gitignored files like node_modules aren't snapshotted, and remote actions can't be undone, so they ask first.

Models and pricing

Pi is free; you pay your providers. It supports a long list of them, including OpenRouter and local models through Ollama, and you can switch models mid-session with /model or Ctrl+L.

Claude Code is included with Claude Pro ($20/month, $17 billed yearly) or Max (from $100/month), or billed per token through the API, with Claude models only (Claude pricing).

Darce has a free trial with no account, a Free plan with a daily allowance, Builder at $15/month and Power at $65/month, covering 250+ models without your own keys. Pi is cheaper if you already have provider keys or run local models; Darce is simpler if you don't want to manage them. See pricing.

Parallel work and extras

Pi deliberately has no sub-agents; you spawn more Pi instances in tmux or build orchestration as an extension. Claude Code has subagents, background agents and cloud sessions. Darce has /swarm, which splits a task into 2-4 agents in git worktrees and merges them, and /derby, which races three models on one task so you keep the best diff.

Who Pi is for

Pi suits experienced developers who want a small, fast, hackable harness with a tiny system prompt, full control over context, and the freedom to build exactly the workflow they want. It's a strong choice if you already run agents in containers and see permission prompts as noise.

Who Claude Code is for

Claude Code suits developers who want Claude models with Anthropic's batteries-included harness: permission modes, sandboxing, subagents, and the terminal, IDE, desktop and web surfaces.

Who Darce is for

Darce suits developers who want guardrails without writing them: risk-scored approvals out of the box, a second look at scripts, and an undo that also reverses what shell commands did, with 250+ models on one plan. Try it with npx darce-cli, no account: Getting started.

Bottom line

Pick Pi for a minimal, MIT-licensed harness you shape yourself, and run it in a container. Pick Claude Code for Claude with built-in permission modes. Pick Darce if you want safety and undo built in rather than bolted on. Related: OpenCode, Cline, Kilo Code and the Claude Code alternative.

Sources

Frequently asked questions

What is the Pi coding agent?

Pi is a minimal, extensible terminal coding agent created by Mario Zechner and now developed under Earendil Inc. It is MIT licensed, ships four core tools (read, write, edit, bash) and supports many model providers.

Is the Pi coding agent safe?

Pi has no built-in permission system: it runs commands and edits files with your user's permissions without asking. Its README recommends running it in a container or sandbox, and example extensions can add a permission gate.

Is Pi better than Claude Code?

Pi is better if you want a tiny, hackable harness and many model providers, and you're comfortable adding your own guardrails. Claude Code is better if you want Claude with built-in permission modes, sandboxing and subagents.

Is Pi free?

Yes. Pi is free and MIT licensed; you pay your model providers directly through API keys or OAuth logins.

Does Pi have undo or checkpoints?

Pi's /tree command navigates the conversation history, not your files. Community packages such as checkpoint-pi and pi-rewind add git-based file restore.

How do I install Pi?

Install it with npm install -g @earendil-works/pi-coding-agent (Node.js 22.19 or newer) or the install script from pi.dev, then run /login inside Pi to connect a provider.