npm @earendil-works/pi-coding-agent 1.0.0
v1.0.0

4 hours ago

New Features

  • Fullscreen by default — The TUI now runs fullscreen. Set tuiMode to "regular" to keep the terminal's normal scrollback. See Terminal and display.
  • Leaner codemode — About 40% fewer prompt tokens, and errors that tell the model how to recover. See Codemode.
  • Image generation in codemode — Scripts call models.generateImages() with the session's credentials. See Generate images and Use image models.
  • Radius in /login — Sign in with Radius and set up its MCP server in one step. See Radius.
  • Anthropic copy code login — Sign in when the browser runs on another machine. See Authenticate interactively.
  • MCP OAuth hardening — oauth.authServerMetadataUrl, RFC 9207 iss checks, credentials per server, and step-up sign-in that keeps granted scopes. See Authenticate with OAuth.
  • Header-only quiet startup — quietStartup: "header" keeps the version and key hints and hides the rest. See Terminal and display.

Added

  • Added an oauth.authServerMetadataUrl setting for MCP servers that advertise a wrong OAuth authorization server or none. Pi uses the configured metadata document instead of discovery (#10172).
  • Added quietStartup: "header", which keeps the startup header with version and key hints but hides the model scope line and loaded-resource listing.
  • Added models.generateImages() to codemode scripts. It runs image models such as OpenRouter's with the session's credentials and returns base64 image blocks that image() attaches to the result; usage counts toward the session cost like models.classify(). Extensions can call ctx.modelRegistry.generateImages(). See Use image models.
  • Added a copy code login method to Anthropic /login for headless setups where the browser runs on another machine (#10194 by @lucasmeijer).

Changed

  • Changed the default TUI mode to fullscreen. Set tuiMode to "regular" or pass --tui-mode regular to keep the terminal's normal scrollback.
  • /login now offers "Sign in with Radius" at the top level, as the last option, with its status. After a Radius sign-in, /login offers to configure the Radius MCP server in the global mcp.json with "auth": { "provider": "radius" } and reloads. Cancelling a login returns to the menu it was started from.
  • The provider docs page is renamed to Providers, its "Cloud Providers" section is now "Provider Specific Config", and it documents Radius first.
  • MCP OAuth credentials are now stored per server name and URL, so MCP servers with the same URL can sign in with different accounts. Credentials stored by URL alone move to the first server that uses them (#10252).
  • Codemode costs far fewer prompt tokens: with the default tools and codemode active, a GPT-5.6 request shrinks from about 5,300 to 3,300 tokens. The codemode description lists the script globals in one line each and points to the new Codemode reference for the models API, which the model reads when it needs it. Declared tools say in one line how scripts call them and what the call resolves to, instead of repeating their full declaration, and the system prompt's codemode guidance and MCP server section are shorter.
  • Codemode errors now say how to recover: reading a tool or models member that does not exist names the close matches (tools.Bash suggests tools.bash), models.classify() and models.generateImages() reject malformed arguments with the expected shape, an unknown model points to models.getAvailableOfType(), an oversized store() value explains what the store is for, and a script that generates images without showing them gets a note. Scripts that probed for a tool with typeof tools.name must use "name" in tools.
  • /login and /logout now label providers without credentials as "not configured" instead of "unconfigured".
  • OAuth browser pages now show the color Pi logo.

Fixed

  • Fixed MCP OAuth sign-in accepting an authorization response whose iss parameter names another authorization server; the code is now rejected before it is exchanged (RFC 9207).
  • Fixed MCP OAuth sign-in failing with Invalid scope when the token response contains "scope": "", and similar failures for other empty or null optional OAuth fields (#10266).
  • Fixed the sign-in URL printed by /mcp login not being clickable when it wraps (#10186).
  • Fixed --provider without --model being silently ignored and running the default model from another provider; it now fails with an error (#10236).
  • Fixed MCP servers that ask for more scope (insufficient_scope) requesting sign-in over and over. The new sign-in requested only the missing scopes, so the new token lost access the previous one had; it now keeps the granted scopes.
  • Fixed user messages in the transcript keeping two full-width copies of every rendered line; they keep one, with identical output.
  • Fixed /login and /logout labeling every OAuth sign-in, including Radius, as a subscription; only subscription-backed providers say "subscription", other OAuth sign-ins say "account".
  • Fixed the startup header logo rendering with gaps in Apple Terminal; it now shows a colored "Pi" with the version instead.
  • Fixed deferred MCP tools that tool_search loaded being dropped on resume and /reload even when their server reconnected before the next prompt, because the session restored its tools before the MCP servers reconnected.
  • Fixed the system theme making pastel palettes such as Catppuccin Frappe much more vivid; palette colors now keep their chroma (#10255, #10293 by @dgtlntv).
  • Fixed slash command autocompletion not triggering when the input starts with whitespace (#10218 by @haoqixu).
  • Fixed color bleeding past mouse selections and search highlights in fullscreen mode when a styled token ends at the highlight boundary (#10169).
  • Fixed memory retained per rendered message in the transcript; a long assistant message keeps about a fifth of the heap it kept before.

Don't miss a new pi-coding-agent release

NewReleases is sending notifications on new releases.