rpi is a self-contained Rust coding agent CLI for interactive and
non-interactive AI-assisted coding, with pluggable
provider support, automatic context compaction, and native Pi v3 session
storage.
The executable binary is rpi. Runtime configuration remains compatible with
the upstream Pi layout (~/.pi/agent, project .pi/, and PI_* environment variables).
The headless JSONL RPC control plane is rpi rpc (≡ --mode rpc).
Install the prebuilt rpi binary from GitHub Releases. The installer selects
the current platform archive, verifies SHA256SUMS, and activates the binary:
curl -fsSL https://raw.githubusercontent.com/0x8f701/rpi/master/install.sh | shWindows (PowerShell):
irm https://raw.githubusercontent.com/0x8f701/rpi/master/install.ps1 | iexPin both the installer source and selected release to v0.2.11:
curl -fsSL https://raw.githubusercontent.com/0x8f701/rpi/v0.2.11/install.sh | bash -s -- --version v0.2.11& ([scriptblock]::Create((irm https://raw.githubusercontent.com/0x8f701/rpi/v0.2.11/install.ps1))) -Version v0.2.11The release archive contains the compiled rpi executable; users do not need
Rust or a source checkout. Maintainers who need a local source build can follow
the explicitly separated developer fallback in docs/src/introduction/install.md.
The release installer places the active binary at ~/.rpi/bin/rpi
(%USERPROFILE%\.rpi\bin\rpi.exe on Windows) and adds that directory to
the user PATH when needed. Open a new terminal before running rpi if the
installer reports that it changed PATH. See docs/src/introduction/install.md
for supported platforms, manual verification, and rollback behavior.
Configure one provider before the first model request:
rpi login anthropicFor non-interactive setup, set the provider-specific environment variable to a
redacted credential value (see docs/src/user-guide/authentication.md).
Then run:
# Non-interactive print mode
rpi --print -m anthropic/claude-sonnet-4-5 "List the Rust files in this directory"
# JSON event stream (headless, one-shot)
rpi --mode json -m anthropic/claude-sonnet-4-5 "List Rust files"
# Interactive inline TUI (or line REPL when no terminal is available)
rpi -m anthropic/claude-sonnet-4-5
# List available models
rpi models
# Continue the newest saved session for the current directory
rpi --continueSee docs/src/introduction/quickstart.md for the first-run walkthrough and
docs/src/user-guide/cli-modes.md for every flag and subcommand.
docs/src/introduction/install.md— installation, platforms, and verificationdocs/src/introduction/quickstart.md— first stepsdocs/src/user-guide/cli-modes.md— print mode, REPL, TUI, slash commandsdocs/src/reference/settings-trust.md—settings.json, config directory, and trust boundariesdocs/src/reference/architecture.md— crate dependency and runtime architecture diagramsdocs/src/user-guide/authentication.md— env vars,auth.json,models.json, and precedencedocs/src/user-guide/models.md— model catalog, model spec syntax, and custom providersdocs/src/user-guide/rpc-json.md— event schema for library consumersdocs/src/user-guide/tui.md— TUI keybindings and status bardocs/src/reference/prompt-templates.md— system prompt assemblydocs/src/reference/skills.md—.pi/skillsdiscoverydocs/src/reference/update.md— release and update safetydocs/src/reference/export-share.md— session export, clipboard, and gist sharingdocs/src/reference/local-llama.md— local/self-hosted modelsdocs/src/reference/extensions.md— process extension protocol and UI requestsdocs/src/reference/packages.md— local/git packages forrpi install(npm package sources deferred; the plugin marketplace acceptsnpm:sources viarpi plugin install)docs/src/reference/security.md— credentials, path scoping, and installer safetydocs/src/reference/environment-variables.md— all environment variablesdocs/src/user-guide/goals.md— durable session goals: lifecycle, token budget, pins, journaldocs/src/user-guide/todos.md— the Todo DAG,/todopanel, and steering/follow-up queuesdocs/src/user-guide/orchestration.md— subagents, jobs, soft budgets, IRC, and thetask/hub/yieldtoolsdocs/src/user-guide/workflows.md— isolated concurrent workflows (worktree/overlayfs/none) with planning and Todo-DAG executiondocs/src/user-guide/session-recovery.md—/rewind,/checkpoint,/snapcompact,/handoff, doom-loop recovery, and session TTLdocs/src/user-guide/live.md— TUI hold-to-talk STT (/live) and Web realtime voice (/web)docs/src/reference/configuration-profiles.md—--profile, TOML settings, env expansion, and scoped authdocs/src/reference/sandbox-isolation.md— Linux filesystem sandbox and overlayfs isolationdocs/src/reference/hooks.md— host hooks and the trust hookdocs/src/reference/memory.md— local and Hindsight memory backendsdocs/src/reference/tools.md— extended tool catalog (LSP, browser, GitHub, debug, eval, notebook, images, ask)docs/src/reference/mcp.md— Model Context Protocol clientdocs/src/reference/acp.md— Agent Client Protocol mode (rpi agent stdio/serve)docs/src/user-guide/e2e-scenarios.md— user-perspective end-to-end scenarios (tmux-driven)
Runnable examples are in examples/.
| Area | Status |
|---|---|
| Print mode, line REPL, TUI, JSON/RPC headless modes | Implemented |
Default coding tools (read, bash, edit, write); optional grep, find, glob, ls tools |
Implemented |
| Native Pi v3 session storage, resume, import, export, and share | Implemented |
Built-in model catalog + custom models via models.json |
Implemented |
Authentication via env vars, auth.json, models.json, rpi login/logout |
Implemented |
| Provider streaming for OpenAI, Anthropic, Google, and OpenAI Responses | Implemented |
| Faux provider for tests and examples | Implemented |
| Automatic context compaction | Implemented |
AGENTS.md / CLAUDE.md project context and .pi/skills |
Implemented |
Local/self-hosted models via rpi llama + llama.cpp router |
Implemented |
JSON-RPC / stdio server (--mode rpc and rpi rpc) |
Implemented |
| Custom TUI themes and keybindings | Implemented |
Local/git packages (rpi install/remove/list/update) |
Implemented |
Process extension protocol via pi-extension.json manifests |
Implemented |
Plugin marketplace (rpi plugin install/list/remove/update; sources: directory, archive, GitHub owner/repo, npm:<name>[@<version>] with sha512 dist.integrity verification) |
Implemented |
npm package sources for the rpi install package manager |
Not implemented (deferred) |
Durable session goals (/goal: lifecycle, token budget, pins, journal) |
Implemented |
Todo DAG (todo tool, /todo panel, dependency execution) |
Implemented |
Orchestration: subagents, jobs, soft budgets, IRC, task/hub/yield tools |
Implemented |
Isolated concurrent workflows (/workflow: worktree/overlayfs/none isolation, planning + Todo-DAG execution) |
Implemented |
Session recovery (/rewind, /checkpoint, /snapcompact, /handoff) and startup session TTL pruning |
Implemented |
TUI hold-to-talk voice input (/live STT) |
Implemented (requires live-capture build feature) |
Web realtime voice (WebRTC Codex Live on /web) |
Implemented (requires live.mode = realtime + CLIProxyAPI) |
| Web command picker, bounded Git code review, multi-file image/code attach (paste/picker/drop), improved Rust fence highlight | Implemented |
Linux filesystem sandbox (sandbox settings) and overlayfs isolation |
Implemented (Linux) |
Model Context Protocol (MCP) client (mcpServers + mcp tool) |
Implemented (stdio transport) |
Agent Client Protocol (ACP) mode (rpi agent stdio / rpi agent serve) |
Implemented |
Host hooks (settings.hooks) and trust hooks |
Implemented |
Memory backends (local JSONL; recall/retain/reflect via configured Hindsight HTTP API) |
Implemented |
| Extended tools: LSP, headless browser, GitHub, DAP debug, eval, notebook, image generation/inspection | Implemented |
rpi models [filter]— list modelsrpi sessions— list sessionsrpi import-session SOURCE INPUT [--output PATH]— convert external sessionsrpi export SESSION_PATH [--output PATH] [--jsonl]— export to HTML/JSONLrpi login [provider]/rpi logout [provider]— manage stored credentialsrpi reload— validate and print active resourcesrpi install SOURCE [--local]/rpi remove SOURCE [--local]/rpi list— manage local/git packagesrpi plugin list [--updates]/rpi plugin install SOURCE/rpi plugin remove NAME/rpi plugin update NAME— manage marketplace pluginsrpi update [--self] [--extensions] [--all] [--models] [--extension SOURCE] [PACKAGE]— update rpi, packages, or model catalogsrpi llama configure|status|refresh|load|unload|search|details|download|installed— manage local modelsrpi agent stdio/rpi agent serve— Agent Client Protocol (ACP) mode for ACP-speaking editors
See docs/src/user-guide/cli-modes.md for details.
rpi --listen <SOCKET_ADDR> runs a headless Web-only backend and serves the
embedded client at /web. It never starts the TUI or line REPL, stays alive
with closed stdin until Ctrl-C/SIGTERM, and records Web conversations in the
normal session store so --continue/--resume restore them after restart.
The flag requires a socket address. By default it uses HTTPS with an
auto-generated self-signed certificate; provide real certificates with
--listen-cert and --listen-key, or opt out with --listen-plaintext.
Authentication rules:
- Loopback (127.0.0.0/8 or ::1) may be tokenless or tokenized.
- A non-loopback HTTPS bind requires
--listen-token-file; tokenless remote TLS is rejected pre-bind. --listen-allow-insecure-remoteis the explicit tokenless-remote opt-in: it permits tokenless browsers on a non-loopback bind. Combined with--listen-plaintextit is both unauthenticated and unencrypted; without--listen-plaintextit is encrypted but unauthenticated.
Local HTTPS, no token — loopback:
$ rpi --listen 127.0.0.1:8765Open https://127.0.0.1:8765/web; accept the self-signed certificate warning for local testing. The page auto-connects with no token.
Local plaintext, no token — opt out of TLS on loopback:
$ rpi --listen 127.0.0.1:8765 --listen-plaintextOpen http://127.0.0.1:8765/web; the page auto-connects with no token.
Remote / LAN HTTPS — non-loopback; a token file is mandatory:
$ rpi --listen 0.0.0.0:8765 --listen-token-file <workspace>/rpi-tokenOpen https://<host>:8765/web. The browser must present the token.
Remote plaintext, tokenless — explicit insecure opt-in (not recommended):
$ rpi --listen 0.0.0.0:8765 --listen-plaintext --listen-allow-insecure-remoteOpen http://<host>:8765/web. Same-origin browser access applies (Origin
authority equals HTTP Host). This is unauthenticated and unencrypted:
anyone reachable on the network can drive the agent and observe traffic. Prefer
loopback, real certificates, or a TLS-terminating proxy on untrusted networks.
The /web page stores the token per listener authority in localStorage;
it is never placed in a URL or cookie. The token authenticates clients but
does not encrypt the bearer token or control traffic against passive network
observers. rpi agent serve remains loopback-only and rejects tokenless
browsers.
Collaboration join links (/collab, collab_start without an explicit
baseUrl) cannot be synthesized from a wildcard bind. For a wildcard
--listen address (0.0.0.0 or ::), pass
--listen-advertised-origin <URL> — a strict http/https origin with no
credentials, path, query, or fragment — so collab links point at a reachable
host. Loopback and other specific binds advertise their bound address
automatically.
Startup also prints a reachable Web UI hint. Explicit
--listen-advertised-origin wins (Web UI: <origin>/web). On a concrete bind
the bound address is used. On a wildcard bind without that flag, rpi
best-effort discovers a route-selected LAN address and prints
Web UI: <scheme>://<lan-ip>:<port>/web; if discovery is unavailable it tells
you to use this machine's LAN IP and port rather than an unreachable wildcard
URL. Ordinary /web access does not depend on the banner.
See CHANGELOG.md.
MIT — see LICENSE.