A durable agent harness writes every step of an agent run to storage before it acts on that step or shows it, so a new process can reopen the storage and continue mid-turn after a crash, a redeploy or a sleeping laptop, and several clients can attach to the same run. Earendil shipped one, Pi Durable, as an experimental package on 1 October 2026, the same day as the Pi coding agent's 1.0 release. The Pi 1.0 post had 1,659 points on Hacker News by 3 October. Pi Durable sits beside the coding agent, not in place of it.
The harness post defined a harness as everything in a coding agent except the model. Durability adds one property to that list: the run outlives the process. This post covers what that means, which Pi 1.0 features fill which harness part, and what Earendil has shown in code.
What is a durable agent harness, and how is it different from a terminal coding agent? #
A terminal coding agent runs in one process for one person. If it dies, you read what happened and tell it to continue. A durable harness commits each step first, so a restarted process resumes the turn on its own. It also keeps the run apart from any one client, so several people can watch and steer it.
Earendil's Pi Durable post defines a harness as "storage plus the machinery needed to run one or more conversations with large language models in parallel". It describes its own terminal agent as "built to run on your (remote) machine, inside a terminal, driven by one person". When that process dies, "you review what happened and instruct it to continue. This remains Pi 1.0's focus and strength."
| Terminal coding agent | Durable harness | |
|---|---|---|
| Who drives | One person in one terminal | Any client attached to the run |
| Crash mid-tool-call | You read the log and tell it to continue | Reopen the storage and the turn finishes |
| What is stored | A session file | Every step, committed before it is shown |
| Where it runs | Your machine or a remote shell | Any runtime with a storage adapter |
The same three properties, crash recovery, a harness separate from its clients and several clients at once, appear in Temporal's harness announcement of 20 August and in Anthropic's Managed Agents post, where a failed harness "can be rebooted with wake(sessionId)".
Terminal agents have partial durability. Claude Code sessions resume after a restart, but the Agent SDK docs note that "Sessions persist the conversation, not the filesystem".
What did Pi 1.0 add, and which of those parts belong to the harness slot? #
All six features in the Pi 1.0 post shipped, but across ten weeks, not on 1 October. The changelog dates deferred tool to 16 July, cache warming and mid-conversation system messages to 19 September, and MCP, codemode and virtual models to 29 September. All but the screen changes are harness parts.
| Feature | First shipped | Harness part | Note |
|---|---|---|---|
| Codemode | 0.99.0, 29 September | Tools | Runs model-written JavaScript in a QuickJS sandbox. Opt-in |
| MCP | 0.99.0 | Tools | Servers are reached through codemode by default, not declared to the model |
| Virtual models | 0.99.0 | The loop | An extension picks the model for each request. Marked experimental in the changelog, not in the post |
| Deferred tool | 0.80.9, 16 July, to tool_search in 0.99.0 |
Startup context | Fewer tools declared up front |
| Cache warming | 0.86.0, 19 September | The loop | Runs when Pi estimates at least $0.05 in avoided cache misses |
| Mid-conversation system messages | 0.86.0 | Startup context | Instructions and tools change mid-session without breaking the cache |
| Full-screen mode, new theme | 1.0.0 and 0.99.0 | Not harness | Terminal UI |
Codemode can also call Jev classifiers and image models. The maintainers say 1.0 made it use "about 40% fewer prompt tokens", with no method published. Armin Ronacher, Earendil's co-founder, explained the turn to MCP on Hacker News: the models "are trained on their respective harnesses and we're not here to fight their behavior."
1.0 also deleted the experimental AgentHarness from Pi's agent core, with the note: "Use @earendil-works/pi-durable for durable sessions."
Where does Pi Durable sit next to the Pi coding agent rather than replacing it? #
One layer down. Pi Durable is a library for building agent applications, and the Pi 1.0 coding agent does not run on it. The two share pi-ai, Pi's model access layer. Earendil: "It does not replace the Pi coding agent. It is a framework for building any agentic application, coding agents included." MCP and codemode are coding-agent features, absent from Pi Durable's source.
Its README describes commits, not a replayed event log. "All changes go through one line of atomic commits, and nothing is shown before its commit is stored." Each tool call commits its intent before it runs. After a crash, the call reruns only if it is declared replay: "safe". Otherwise the model gets an interrupted result. Streamed output is committed at most every 100 ms. Storage is memory, SQLite or JSONL.
Two limits matter for a team. "One process owns a storage at a time; there is no cross-process locking", and there is no user identity or authorisation. A late joiner gets "the current view; nothing is replayed".
The repo includes an experimental durable version of the coding agent, without session lists, forks, extensions or /login. One team's decision record of 2 October shows the gap: it chose a coding-agent extension because it needed skills, AGENTS.md files and subagents, and called Pi Durable "experimental, not installed, version-skewed".
Which other harnesses are competing for the same slot right now? #
Temporal Agent Harness, Cloudflare's Agents SDK, which now hosts Pi Durable itself, and Hermes Agent document crash recovery. Claude Code and OpenAI Codex cloud sessions keep running with the laptop closed but do not document mid-run recovery. DeepSeek Harness and ZCode are desktop apps.
| Harness | Survives a crash mid-run | Several people on one run | Runs on | Latest |
|---|---|---|---|---|
| Pi Durable | Yes, checkpointed tasks | In the API, with no transport or auth | Node; Durable Objects via Cloudflare | 1.0.0, 1 October |
| Cloudflare Agents SDK with PiHarness | Yes, an alarm restarts an evicted run | Multi-client WebSockets | Cloudflare Durable Objects | 0.26.0, 2 October, beta |
| Temporal Agent Harness | Yes, "resume mid-turn" | Mid-turn client messages | Temporal workers and server | 0.6.0, 3 October |
| Hermes Agent | Yes, an interrupted turn "auto-resumes once" | Yes, in shared chat threads | Local, Docker, SSH, Modal | v0.21.5, 24 September |
| Claude Code cloud sessions | Partly: subagents and shell commands are not restored after a VM is reclaimed | Shared view does not update live | Anthropic's cloud | 2.1.288, 2 October |
| Codex cloud tasks | Not stated | Not stated | OpenAI's cloud | CLI 0.160.0, 1 October |
| DeepSeek Harness | A resumable session log, per a secondary source | Not stated | macOS and Windows desktop | 0.2.0-rc.2, 29 September |
| ZCode | Not stated | Remote control of your own desktop | Desktop | v3.14.3, 24 September |
Sources: each project's docs and release pages on 3 October. Temporal's harness calls itself "earlier than public preview", and Cloudflare marks PiHarness beta.
Durable-execution libraries fill the same slot under your own loop: LangGraph checkpointers, Restate and DBOS. One HN user runs a Slack on-call agent on the Pi SDK with DBOS so sessions survive Kubernetes pod restarts, "although it still feels like overkill".
What did Earendil demonstrate, and what is only claimed so far? #
Crash recovery, late joining and steering are in the code: recovery tests and 32 runnable examples, which I read but did not run. Durable Objects support was built and tested by Cloudflare, not Earendil. Running on Bun, tools on another machine and the memory claims have no code or numbers behind them yet. No benchmarks are published.
| Claim | Status | Evidence |
|---|---|---|
| Survives the process dying mid-turn | Demonstrated | Recovery tests, examples 13, 24 and 31, two kill-and-restart demos |
| Many clients can watch, join late and steer | Demonstrated in one process | Examples 20 and 21; over a network only in Cloudflare's example |
| Runs in a Cloudflare Durable Object | Demonstrated by Cloudflare, beta | Cloudflare's tests include a crash mid-tool-call |
| Runs on Bun | Claimed | No adapter ships |
| Harness on one machine, tools on another | Claimed | An interface; only a local environment ships |
| "Tens of thousands of messages" fit in memory | Claimed | Benchmark scripts, no results |
| "Hundreds of thousands" of weekly Pi users | Claimed, disputed on HN | No method |
The Pi Durable HN thread raised two harder points. One commenter disputed "exactly-once" for submissions: "Just having an ID cannot alone guarantee exactly once semantics." Mario Zechner, Pi's creator, replied that the ID is an idempotency key. It covers the submission; a tool's side effects depend on the replay flag. Another asked about state outside the transcript: after recovery the agent "will think it has already navigated to page N, but in reality the browser on the runner might be on page 0". Ronacher: "If you give a user a full sandbox then you're going to be in a position where you probably need to snapshot it."
Earendil was founded by Ronacher and Colin Daymond Hanna, and acquired Pi in April 2026. Its investors include founders of OpenClaw, which an HN commenter says depends on Pi, a claim I could not verify that would inflate Pi's npm downloads. Cloudflare's changelog says "Built with Earendil", with no financial tie disclosed.
When does a team need durability, and when is a terminal session enough? #
When the agent outlives the person who started it: unattended runs of hours, agents triggered by Slack, cron or events, infrastructure that restarts under it, or more than one person steering. If one person drives one session and can tell it to continue, a terminal agent on a remote host or in tmux is enough. That is Earendil's own position for Pi.
Temporal argues that for agents that "cross process boundaries, depend on unreliable external systems, and wait on humans, this isn't an edge case. It's table stakes." In the HN threads, people who need it describe Slack and cron agents, and laptops that run out of memory when "the session spawns 5 ambitious subagents".
The case against is cheaper. One Pi user keeps a git worklog: "Restarting pi just continues from the worklog + last commit/uncommitted changes." Anthropic's SDK docs suggest capturing results as application state and passing them to a fresh session, "often more robust than shipping transcript files around." Neither approach, durable or not, recovers a browser or a VM.
On Stackness, as of 3 October 2026, 8 real profiles list Claude Code, 2 list Codex and 1 lists Pi. DeepSeek Harness and ZCode have none, and nobody lists a durable harness (data sources). The numbers are small. The AI coding tools developers list on Stackness are still terminal agents.
Key numbers #
- 1 October 2026 : Pi 1.0 and Pi Durable 1.0.0 ship, Pi Durable marked experimental (Earendil ).
- 1,659 points and580 comments on the Pi 1.0 HN thread, and492 points on Pi Durable's, as of3 October 2026 .
- 10 weeks : Pi 1.0's listed features shipped between 0.80.9 on16 July and 1.0.0, per its changelog.
- 100 ms : the most streamed output Pi Durable can lose in a crash, per its README.
- 32 runnable examples and0 published benchmarks for Pi Durable, counted on3 October 2026 .
- 8 real Stackness profiles list Claude Code,1 lists Pi and0 list a durable harness, as of3 October 2026 (data sources ).
Quick answers #
What is a durable agent harness? A harness that commits every step of an agent run to storage before acting on it, so a restarted process can resume mid-turn, and that keeps the run apart from its clients so several people can attach and steer.
Is Pi Durable the same as Pi? No. Pi is a terminal coding agent for one person. Pi Durable is an experimental library for building long-running agent applications. They share Pi's model layer, and Pi 1.0 does not run on Pi Durable.
What was new in Pi 1.0? Full-screen mode by default and a leaner codemode. MCP, codemode and virtual models arrived in 0.99.0 two days earlier, and cache warming and mid-conversation system messages in 0.86.0 on 19 September.
Does Pi Durable run on Cloudflare? Yes, in beta, through the PiHarness class in Cloudflare's Agents SDK, which Cloudflare built and tested. Earendil's own repo ships Node adapters only.
Do I need a durable harness for coding? Usually not. If one person drives the session and can restart it, a terminal agent is enough. Durability pays off for unattended, triggered or shared agents.
Tools in this post #
Use any of these tools? #
Put them on a Stackness profile, say how you use each one and see who pairs them the same way. It takes a couple of minutes.