Pi Integration

Pi is an open-source terminal-first AI coding agent and minimal harness that enables developers to automate code generation, file management, and terminal commands directly within their development environment.

Pi logo

Pi

Benefits with Ory + Pi Integration

Ory integrates with Pi to provide security guardrails for developers building and running AI agents. Ory's harness hook executes identity and credential checks for every session and tool call, enforcing fine-grained authorization to permit or deny actions while logging all activity for complete audit trails. Teams can utilize Observe mode to monitor tool usage or Enforce mode to strictly restrict agents to authorized permissions.

The fastest way to get started with Ory Agent Security is to sign up for the Ory Network. Installing an Ory Agent Security plugin for your AI coding agent takes seconds. You simply copy and paste the provided command in the harness's project directory.

npm install @ory/pi npx -y -p @ory/pi ory-pi install
View on npm (opens in a new tab)

Use Cases

Agent IAM

Secures Pi terminal sessions, code generation, and tool execution by enforcing fine-grained authorization, identity checks, and complete audit logging.

Explore Agent IAM

CIAM

Accelerates embedding customer authentication and identity management into consumer-facing applications directly within Pi using Ory best practices.

Explore CIAM

B2B IAM

Streamlines building enterprise SSO, multi-tenant organization structures, and role-based access control into business software using Pi, scaling seamlessly with business growth.

Explore B2B IAM

Core Functionality

  1. Identity

    Verifies developers and Pi agent identities before session initiation across your ecosystem through a unified control plane.

  2. Authorization

    Enforces fine-grained, policy-based access control for every Pi tool execution and action.

  3. Shell

    Intercepts and secures terminal-level shell commands and local CLI execution within Pi.

  4. Audit

    Logs complete audit trails for all session activity, tool invocations, and API calls.

  5. Rollout

    Supports seamless deployment with Observe mode for monitoring agent behavior and Enforce mode for strict permission enforcement.

  6. Security Control

    Provides vendor-agnostic governance across all AI tools, complete with instant token revocation to immediately cut off compromised sessions.