Pi coding agent adds MCP support after refusing it, and runs each server inside a JavaScript sandbox called Codemode
Earendil said on 29 September that its Pi coding agent now supports MCP through a JavaScript sandbox called Codemode, reversing a public position it held for over a year.

Image: Earendil
Why it mattersA team that has been paying the token cost of MCP servers dumping their whole tool catalog into every prompt has a new pattern to copy, because the sandbox runs on the agent side and keeps its state in the session transcript.
An MCP server usually pushes its whole tool catalog into the model's context on every call, and the token bill adds up before the agent has done any work. Earendil Engineering said on 29 September that its Pi coding agent now supports MCP through a JavaScript sandbox called Codemode, reversing a position pi.dev had carried on its own homepage for over a year: "Pi does not support MCP."
The post, by Earendil Engineering, opens with that reversal in the author's voice: "You said no MCP! What happened?" Earendil answers with two reasons. The first is that MCP has changed. The second is that the work needed to bring MCP in was work Earendil wanted to do anyway, because it made room for other things such as easier use of TypeSafe AI's Jev decision model inside Pi.
What Codemode actually is
Earendil frames Codemode as a place to orchestrate and coordinate tool calls from the trusted side of the agent. A coding agent has two places to run tools. One is where bash runs, in a sandbox with low trust. The other is where the harness agent loop runs, with the same trust as the agent itself. Codemode sits on the harness side, so its state lives in the session transcript, and an agent can combine several tool calls together in JavaScript before returning a result to the model.
The choice of JavaScript is deliberate. Earendil writes that "small versions of JavaScript can be shipped as WASM binaries and allow reasonable levels of protection". In Pi, Codemode is loaded automatically when MCP is configured, or a user can ask Pi to reconfigure itself to enable it as a default tool.
Why this changes MCP's cost shape
Earendil is direct about what MCP still gets wrong: "The biggest issue with MCP continues to be that it's hard to compose. Even with codemode, which is just a neat little sandbox to allow composing of tool calls, MCP doesn't fully deliver on this." Earendil pins the blame on MCP servers built for harnesses that "just dump tools into the context" and try to save tokens by returning text. Earendil's own preferred shape is closer to OpenAPI with intelligent tool discovery: tools return structured data, and are discoverable through their documentation.
The example the post gives is a Linear ticket triage. A single Codemode call fetches 250 open issues from a Linear MCP server, then a Jev classifier rates each thread's emotional tone in four parallel workers, all inside the sandbox. The tools are exposed to the JavaScript runtime, not stuffed into the prompt for the model to read.
What has to be true for the pattern to work
Earendil says Pi's tool loadout had to support metadata that told each tool whether to be loaded normally, deferred until needed, or exposed only inside Codemode. A plain MCP extension, they say, did not carry enough metadata to make that experience work. So the switch to native MCP support was partly a way to give the harness enough information to choose.
The post reached 150 points on Hacker News on the morning of 30 September. For a team weighing whether to add another MCP server to a coding agent, the concrete pattern to copy is this: expose each tool inside a sandbox that lives beside the agent loop, and let the model call each tool through code so the tool descriptions stay out of the prompt.
Source
- Earendil Engineering: You Said No MCP!
- Hacker News discussion: Pi.dev: You Said No MCP
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.