Pi support is in Beta.
Prerequisites
Before setting up the integration, ensure you have:- Unbound CLI: version 1.16.19 or later, installed and logged in — see the CLI guide
- Pi: version 0.87.1 or later
- Node.js: version 22 or later
Setup with Unbound CLI
~/.pi/agent/extensions/unbound/index.js, stores your API key in ~/.unbound/config.json, and reports the install to Unbound. If you set PI_CODING_AGENT_DIR, the extension goes into that folder instead. Start a new pi session after setup — a session already running does not pick it up.
Pi is not part of unbound setup --all. From CLI 1.16.20, unbound onboard sets it up when it detects pi on the device and skips it otherwise; unbound setup pi sets it up either way.
To remove the Unbound configuration:
What is enforced
Pi asks Unbound before each call, so your rule decides whether it runs.
Every call is recorded, and the prompt text is captured with it.
What each action does
If a device cannot reach Unbound, the call runs — the extension waits up to 20 seconds, then lets it through. Your organization can require the opposite, so an unreachable check blocks instead. See Settings.
Account identity
When pi is signed in to Anthropic, Unbound records the signed-in account — its email and plan. When pi uses an API key from any provider, Unbound recordsapi_key only.
Limitations
Pi has no managed configuration, so a developer can step around the extension. Runningpi --no-extensions, or pointing PI_CODING_AGENT_DIR at a different folder, starts pi without it.
Discovery still reports every pi install, so you can see where it is in use.
Deploying through MDM
MDM onboarding sets Pi up only on devices that have pi. The Python onboarding command andsudo unbound onboard look for pi across every user on the device: the pi command, or pi’s own files in a home (.pi/agent/auth.json, .pi/agent/sessions). Where pi is found, the extension is installed for every user on that device. Where it is not, the Pi step is skipped and reported as skipped, not as a failure.
A device picks this up the next time its policy runs the onboarding command. Clearing (--clear) always removes the Pi extension, whether or not pi is still installed.
The signed macOS package does not set up Pi. There, or to install on every device regardless of detection, run the pi/mdm/setup.py script from your device management platform. See MDM Integrations for deployment guides.
Agent Coverage
What each agent supports, side by side
Tool Policies
Configure security guardrails for AI tools

