At 13:30 UTC on September 30, Pi's admission that it had changed its mind about MCP had reached 423 points on Hacker News. The useful part of the reversal sits one layer below the protocol decision: by default, Pi keeps an MCP server's tool declarations out of the model's active context, then lets a JavaScript sandbox find and combine them when needed.
That design tackles the complaint Pi's maintainers made before they supported the Model Context Protocol. A large integration can spend thousands of tokens describing tools before the agent has done any work, while results from separate calls pass through the conversation before they can be joined. Pi has accepted MCP as the connection standard and moved the composition work somewhere else. It kept the protocol and rejected the familiar practice of exposing every tool at once.
Why Pi originally said no
Mario Zechner, who created Pi's coding agent, put numbers on the old objection in November 2025. In his comparison of MCP servers with small command-line tools, the Playwright MCP server exposed 21 tools whose descriptions occupied 13,700 tokens. Chrome DevTools MCP exposed 26 tools and used 18,000 tokens. His replacement README used 225 tokens because the model already knew how to write shell commands and JavaScript.
The other complaint was harder to count. When one tool returns a large result and a second tool needs only a slice of it, a conventional agent loop may show the first result to the model, ask it what to do, and then make the second call. Zechner's scripts could pipe, filter and save data without putting every intermediate value into the conversation. The new Pi announcement says many MCP servers still return prose for token efficiency and remain difficult to compose. Core support does not withdraw that criticism.
Pi's answer is Codemode, a JavaScript execution environment on the agent harness side. A script can discover an MCP tool, call it, retain the full result, filter the data and call another tool. Only the value explicitly returned by the script goes back to the model. State is recorded in the session transcript rather than written to the project filesystem, according to Earendil's account of the implementation.
The launch example makes the distinction visible. Pi fetched 167 open Linear issues and their comments, then sent them to the Jev classifier with four workers. The replay shows 331 earlier calls before the final batch. Its script returned counts and a short list of flagged issues: 156 threads were rated neutral, 11 mildly frustrated and none highly frustrated. The model received the condensed result instead of hundreds of comment payloads. Earendil published the replay, though it did not include a comparison of token use, latency or classification quality against direct MCP calls.
What developers get in the core
Pi's MCP documentation now covers local servers over standard input and remote servers over streamable HTTP. Configuration lives in ~/.pi/agent/mcp.json for a user or .pi/mcp.json for a trusted project. Existing mcpServers entries from Claude Desktop, Claude Code and Cursor can be copied over. Codex TOML and OpenCode entries need mechanical conversion. The old HTTP plus SSE transport is rejected.
For a project-local command server, the documented setup is short:
pi mcp add -l tools --env API_KEY='${TOOLS_KEY}' -- uvx tools-mcp
pi mcp list
The first command writes the project entry. The second connects enabled servers and exits with an error if a configuration is invalid or a server cannot connect. Inside a session, /mcp shows connection state, tool count and the source of each configuration. Pi also handles OAuth for remote servers, storing its tokens in the agent directory and refreshing access when necessary.
Exposure settings determine how much of that integration reaches the model. codemode, the default, keeps tools callable from scripts but leaves their declarations out of the model request. deferred waits for tool search to load a matching declaration. direct behaves like an ordinary built-in tool, while hidden makes a registered tool unreachable. Per-tool patterns let a developer expose a frequently used read operation directly and keep a deletion operation hidden.
This matters most when one server has dozens of methods or several servers are connected at once. Pi's documentation says Codemode scripts can inspect ALL_TOOLS or search for a name at runtime. Direct text results over 20 KB are shortened in the middle before the model sees them, with the full value saved to a temporary file. A Codemode script receives the complete result and can select the fields it needs. Context savings therefore depend on the script returning a smaller value. The connection alone does not make a verbose server economical.
MCP changed while Pi was resisting it
The reversal also follows a large protocol revision. The MCP 2026-07-28 specification removed protocol-level sessions, made each HTTP request self-describing and added cache controls to tool, prompt and resource lists. Method and tool names now travel in headers, so a gateway can route or authorize a call without parsing its JSON body. The release also tightened issuer validation in OAuth flows and set a minimum 12-month window between deprecation and removal.
Those changes make remote servers easier to deploy and tool catalogs cheaper to refresh, but they do not decide how an agent should use 40 tools together. Pi treats MCP more like an API description with discovery than a menu that must be pasted wholesale into every request. That is Pi's design judgment, not a requirement of the MCP specification. Other clients can expose the same server differently.
Structured output is the remaining pressure point. The July specification expanded tool schemas to full JSON Schema 2020-12 and lets structured results contain any JSON value. Earendil argues that MCP tools should return structured data that code can combine, rather than prose optimized for a model to read. A server can comply with MCP and still return a wall of text. Codemode can trim that wall, but it cannot reconstruct fields the server never supplied.
The sandbox does not settle trust
Codemode runs where Pi's harness runs, even though its JavaScript executes in a sandbox. That placement lets it coordinate registered tools and keep temporary values in the transcript. It also means developers should read the word "sandbox" narrowly. The MCP guide says every call still passes through Pi's tool pipeline, including extension handlers that can approve or block operations. Calls made by a script retain the parent Codemode call identifier for that review path.
Server annotations can label a tool read-only, destructive, idempotent or able to reach an outside system. Pi's extension documentation warns that those annotations are hints rather than verified facts. A permission extension can consult them, but a server's self-description does not prove its behavior. Hiding a declaration from the model also saves context. It does not reduce what the tool can do once a script invokes it.
That separation is useful when evaluating the release. Pi now supplies the protocol client and the hooks where permissions can be applied. Teams still choose which servers run, what credentials they receive and which exposure mode each tool gets. None of those choices can be inferred from the fact that MCP support is built in.
How to test the reversal
Pi's change is more interesting than a compatibility checkbox because it preserves the strongest part of the earlier objection. A shared protocol can remove custom connection work. It does not require an agent to carry every tool schema or intermediate response through its context. Codemode gives Pi a concrete way to separate those two decisions.
The next evidence should come from mixed-server tasks, where composition costs are easiest to see. Compare the same job with direct and codemode exposure, then inspect input tokens, tool-call failures, elapsed time and the final answer. Watch whether popular servers adopt structured results and whether Pi publishes repeatable measurements beyond the Linear replay. Before moving an existing setup, follow Pi's diagnostic path: run pi mcp list, inspect each exposure rule and check the transcript for the data Codemode returns. If the reversal works as intended, that transcript should be smaller without hiding the facts the model needs.