Head to head · Agent harness · October 2026 research run

Pi vs Qwen Code

Qwen Code scores 72.4 (BB) on agent readiness against Pi's 68.4 (B), and leads in 3 of 7 scored categories. Pi leads on reliability and security & auth. Both do agent harness.

Which one, for what

Pi B

Good for Developers and pipelines that want a small, scriptable coding agent they can extend in TypeScript and drive over JSONL or RPC, inside their own container.

Ahead on

  • Reliability, 75 against 69
  • Security & auth, 61 against 53

Also in its favour

  • No key needed to call it

Watch for

No permission system or sandbox. Tool calls run with the user's rights and without an approval prompt

Qwen Code BB

Good for Developers and CI jobs that want an open-source harness tied to no single model vendor, with run budgets and SDKs.

Ahead on

  • Schema & documentation, 91 against 84
  • Agent ergonomics, 85 against 76

Also in its favour

  • Agent-ready, a grade of BB or better
  • No incidents deducted, where Pi loses 4 points for them

Watch for

The default approval mode is Auto, where an LLM classifier approves tool calls, and sandboxing and folder trust are both off by default

Score by category

CategoryWeight this runPiQwen CodeEdge
Reliability16%207569Pi +6
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28491Qwen Code +7
Agent ergonomics13%16.27685Qwen Code +9
Security & auth14%17.56153Pi +8
Payments & pricing10%12.56060even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88788Qwen Code +1
Transparency & trust7%8.86463Pi +1
Negative events≤15-40
Total68.4 · B72.4 · BB

Facts side by side

FactPiQwen Code
KindAgent harnessAgent harness
VendorEarendilAlibaba (Qwen team)
Hosted endpointno (local only)no (local only)
Transports
AuthNoneAPI key
PricingFreeFree
x402nono
LicenceMITApache-2.0
Read-only variant documentednono
llms.txtnoyes
Last release2026-10-072026-10-05
Terms last updatedno document linked2026-10-01
Privacy policy last updatedno document linked2026-10-01
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity113k stars, 5.2M npm/wk28k stars, 105k npm/wk

Verdicts

Pi

Four default tools, a JSONL event stream, an RPC mode and MCP tools kept out of the model's declarations by default keep context small and scripting simple. Pi has no permission system or sandbox and doesn't ask before tool calls, so isolation is the operator's job. Version 1.0.0 is dated 1 October 2026.

Qwen Code

Apache-2.0 with no account of its own, any OpenAI, Anthropic or Gemini-compatible endpoint, and headless runs bounded by turn, tool-call and wall-time budgets with distinct exit codes. Out of the box, Auto mode lets an LLM classifier approve tool calls, with the sandbox and folder trust both off. Usage statistics are on by default.

Before you call either

Pi

  1. Run Pi inside a container or VM for unattended work. It has no sandbox and doesn't ask before running shell commands
  2. Use pi --mode json and wait for agent_settled. A failed response doesn't set a nonzero exit code in JSON mode
  3. Split the JSONL stream on LF only. Node's readline also splits on U+2028 and U+2029, which are valid inside JSON strings
  4. Pass --no-approve or --approve in scripts to make the project trust decision explicit
  5. Set PI_TELEMETRY=0 and PI_SKIP_VERSION_CHECK=1, or PI_OFFLINE=1, to stop the default requests to pi.dev

Qwen Code

  1. Pass --approval-mode on every run. The settings default is auto, and one docs page says headless runs default to asking, so don't rely on either
  2. Add --max-session-turns, --max-wall-time and --max-tool-calls. All three are unlimited by default. Exit 53 is the turn limit and 55 a budget
  3. --yolo doesn't turn on a sandbox. Add --sandbox, or on Linux set tools.executionSandbox with network set to closed
  4. Set QWEN_USAGE_STATISTICS_ENABLED=false to stop usage statistics
  5. Authenticate with OPENAI_API_KEY, OPENAI_BASE_URL and OPENAI_MODEL in CI. The browser sign-in is discontinued

Questions

Which is better for AI agents, Pi or Qwen Code?

Qwen Code scores 72.4 (BB) on agent readiness against Pi's 68.4 (B), and leads in 3 of 7 scored categories. Pi leads on reliability and security & auth.

Are Pi and Qwen Code open source?

Yes. Pi is open source (MIT). Qwen Code is open source (Apache-2.0).

Other comparisons with Pi or Qwen Code

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.