pi-mcp
Uses a GitHub Copilot subscription as the default pi provider, allowing Claude Code to delegate prompts to non-Claude models such as GPT-5.5 through pi's model access.
Can use an OpenAI/ChatGPT subscription via pi's openai-codex provider, enabling delegation to OpenAI Codex models with a 272K context when PI_MCP_PROVIDER is set to openai-codex.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@pi-mcpask gpt-5.5 for an adversarial review of U:/repo/src/auth.ts"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
pi-mcp
MCP server that lets Claude Code delegate work to non-Claude models (GPT-5.5, Gemini 3.1 Pro, and others) through pi, billed to a flat-rate subscription.
Metric | Value |
Language | TypeScript on Bun |
Dependencies |
|
Billing | Subscription only: |
Sub-agent rights | Read files, search the web, fetch pages. No shell, no writes. |
Platform | Developed on Windows; paths in examples are Windows-style |
Why
Claude Code can only ever ask another Claude. Every subagent it spawns shares the same training, the same blind spots, the same failure modes, so three of them agree with each other more than the evidence warrants. For research and adversarial review, that correlation is the enemy.
The cost saving is secondary. The point is model diversity. A GPT-5.5 and a Gemini 3.1 Pro reviewing Claude's work will surface things Claude structurally will not.
Related MCP server: claude-code-codex-agents
Features
Feature | Description |
| Ask a model a question. Returns the answer inline, or writes it to |
| List models pi can reach on the active provider. |
| Kill only the pi process trees this server spawned. Use when a call wedges. |
Evidence contract | By default the delegate must declare which files it read and which searches it ran. Answers with zero of both are flagged as prior-derived. |
Continuations | Each answer ends with |
Probed leash |
|
Web search | Bundled search MCP server using Serper.dev (preferred) or SerpAPI. If Serper fails and a SerpAPI key is set, search falls back and says so in the result. |
pi_ask parameters
Parameter | Default | Description |
| required | Model id, for example |
| required | Full prompt. Reference files by absolute path. |
| none | Write the full answer here and return only a preview. Use for anything long. |
|
|
|
| none | Continue a previous thread. |
|
| Append the evidence contract and prefix the answer with a verdict. |
Use output_file for anything long. A four-model research fan-out returning
inline costs the caller tens of thousands of tokens of context. Returning a path
costs a few hundred.
Prerequisites
pi, authenticated (pi --list-modelsprints a table)uvxformcp-server-fetch, the official keyless URL-to-markdown serverA GitHub Copilot or ChatGPT subscription connected to pi
Installation
Clone and install:
git clone https://github.com/SShadowS/pi-mcp.git cd pi-mcp bun installRegister with Claude Code:
claude mcp add pi -s user -- bun --no-env-file run <path-to>/pi-mcp/src/pi-server.tsKeep
--no-env-file. Claude Code starts the server in your project directory, and without the flag Bun loads that project's.envinto the server. pi then inherits those keys.Set a search API key (see Configuration). Restart your terminal so child processes inherit it.
Usage
From Claude Code, once registered:
pi_models()
pi_ask({
model: "gpt-5.5",
prompt: "Review U:/Git/myrepo/src/parser.ts for off-by-one errors.",
output_file: "U:/tmp/gpt-review.md"
})Run /mcp reconnect pi (or restart Claude Code) after any change to src/. Until then, tool results carry a warning that old code answered.
Configuration
Variable | Default | Description |
|
| Subscription provider: |
| none | Serper.dev key. Preferred search provider. |
| none | SerpAPI key. Used when no Serper key is set, or when Serper fails (for example, out of credits). |
Keys are read from the environment, or from a gitignored .env at the repo root (copy .env.example). They are never stored in the repo. Without a key, fetch still works and search reports plainly that it is unavailable.
[Environment]::SetEnvironmentVariable("SERPER_API_KEY", "<your-key>", "User")Choose the provider per registration:
claude mcp add pi -s user -e PI_MCP_PROVIDER=openai-codex -- bun --no-env-file run <path-to>/pi-mcp/src/pi-server.tsModel ids differ per provider, so call pi_models after switching. openai-codex models have a 272K context, smaller than Copilot's.
Which config serves which consumer
Config | Consumer | Contains |
Claude Code MCP settings | Claude Code | the |
| pi |
|
fetch and search must never go in a project's .mcp.json. Claude Code
reads those, and Claude already has WebSearch and WebFetch.
Architecture
Claude Code
|
v (stdio, MCP)
pi-server.ts pi_ask / pi_models / pi_cleanup
|
v spawn, cwd = pi-workspace/, --tools read,mcp, prompt on stdin
pi (sub-agent, GPT-5.5 / Gemini / ...)
|-- read absolute paths only
|-- mcp -> fetch uvx mcp-server-fetch
|-- mcp -> search search-server.ts (Serper / SerpAPI)Why pi always runs in pi-workspace/
pi discovers MCP servers from exactly one place: the .mcp.json in its
working directory. Not its own settings file, not ~/.mcp.json. And pi has
no built-in web access, only an mcp gateway tool. So pi can reach the web
if and only if its cwd holds a .mcp.json wiring one up.
runPi always spawns pi in pi-workspace/. Run it anywhere else and it
silently loses the web: pi reports no error, it simply has no servers.
That is why pi_ask has no cwd parameter, and why callers must pass absolute
paths.
Putting fetch/search into each target repo's .mcp.json was rejected. Claude
Code reads those too, and it would mean committing a search server into every
repo pi is pointed at.
The leash, and why it is probed
--tools read,mcp restricts the sub-agent, but pi's --tools allowlist fails
open: unknown tool names are silently ignored. A typo would change the
boundary and error nowhere. The only proof is asking pi to cross it and watching
it fail, which is what test/leash.test.ts does.
Accepted risk
Read access plus web reach is, in principle, an exfiltration path: a model can read a file and then fetch a URL with the contents in the query string. This is inherent to letting it read the code and reach the internet. It is accepted, not mitigated. Point this at code you would be relaxed about open-sourcing.
Sharp edges
Edge | Detail |
Code changes need a reconnect | Claude Code spawns the server once and does not respawn it. After edits to |
Project | Without |
Wedged call | Use |
Tests
bun test
bun run typechecktest/leash.test.ts hits the real Copilot API deliberately (~30s). A mock would
prove nothing about a security boundary.
Key Files
File | Purpose |
| MCP server: |
| Spawns pi in the workspace, provider pinning, process-tree tracking |
| Search MCP server used by pi (Serper / SerpAPI) |
| MCP servers pi sees: |
| Live probe that the sub-agent cannot run a shell or write |
| Template for search API keys |
| Open issues and deferred work |
Author: Torben Leth (SShadowS@SShadowS.dk) License: MIT (see LICENSE)
This server cannot be deployed
Maintenance
Related MCP Connectors
No-data MCP handoff for local Claude Code to Codex harness moves. $49 lifetime.
Multi-model code review: a panel of models + detectors return a pass/fail verdict. Paid via x402.
Source-checked CLI guides and model-aware planning for Claude Code, Codex, and Grok Build.
Paid remote MCP for Claude Code skill update gate MCP, structured receipts, audit logs, and reviewer
Related MCP Servers
- AlicenseAqualityCmaintenanceEnables Claude to delegate tasks to OpenAI expert models (GPT-5.3-Codex and GPT-5.5) as subagents, with orchestration patterns for safe and effective use.3MIT
- AlicenseAqualityDmaintenanceEnables Claude Code to delegate tasks to OpenAI's Codex CLI (GPT-5.4) with structured execution traces, parallel execution, session persistence, and adversarial code review.15MIT
- AlicenseAqualityBmaintenanceDelegate tasks from Claude Code to other models (Codex CLI, DeepSeek, OpenRouter, etc.) without leaving the app.219MIT
- AlicenseAqualityAmaintenanceEnables Claude Code to delegate coding tasks—investigation, review, long-running background jobs, and optional file edits—to a locally installed OpenAI Codex CLI, with the model and reasoning effort chosen per task and read-only execution by default. Follow-up requests reuse Codex's existing context, and write-enabled delegations can be confined to a managed git worktree so the user's own checkout stays untouched.8204 npmMIT