pi-typesafe-ai
Generic TypeSafe (Jev / System One) capability for the pi coding agent: agent-owned credential storage, a thin SDK client, and a question-bundle helper.
Package details
Install pi-typesafe-ai from npm and Pi will load the resources declared by the package manifest.
$ pi install npm:pi-typesafe-ai- Package
pi-typesafe-ai- Version
0.2.0- Published
- Sep 23, 2026
- Downloads
- 658/mo · 658/wk
- Author
- schuettc
- License
- MIT
- Types
- extension
- Size
- 65.6 KB
- Dependencies
- 1 dependency · 0 peers
Pi manifest JSON
{
"extensions": [
"./src/index.ts"
]
}Security note
Pi packages can execute code and influence agent behavior. Review the source before installing third-party packages.
README
pi-typesafe-ai
A generic TypeSafe (Jev / System One) capability for the pi coding agent.
TypeSafe's Jev is not a chat model. It answers typed questions about a piece of state and returns structured, typed answers (a choice, a score, a noul, …) rather than free-form text. This package gives pi three things:
- agent-owned credential storage for the TypeSafe API key,
- a thin SDK client (
JevClient) around@typesafe-ai/sdk, and - a question-bundle helper for mapping typed answers into your own shape.
It is the generic core. Higher-level features (for example an automated reviewer) build on top of it.
Install
pi install npm:pi-typesafe-ai
This registers a /typesafe command and exports a small library you can import
from other pi extensions.
Commands
Type /typesafe on its own to open the settings panel: a bordered box
with four rows.
- API key:
configuredornot set. Enter opens a masked field inside the box; the key is never shown. - Model: the default model. After a test it also shows the exact version
that answered, e.g.
jev-latest → jev-1.13.0. - Test connection: runs one tiny Jev evaluation and shows the latency, or
a short reason such as
HTTP 401 (key rejected). - Remove key: deletes the stored key after a
y/Nprompt.
Use ↑↓ (or j/k) to move, enter or space to act, and esc to close. Without the
interactive TUI, a bare /typesafe reports status instead.
The subcommands still work. Typing /typesafe (with the trailing space)
autocompletes them, each with a short description:
/typesafe setup— opens a masked field (characters are shown as•). Paste your key, press enter to save or esc to cancel (ctrl+u clears). Prompts before replacing an existing key. Requires the interactive pi TUI./typesafe status— report whether a key is configured and where it lives./typesafe logout— delete the stored key (prompts to confirm).
The client also honors the TYPESAFE_API_KEY environment variable as a
fallback when no key has been stored.
Library
import { CredentialStore, JevClient, evaluateBundle, type Bundle } from "pi-typesafe-ai";
// Agent-owned credential file at <pi agent dir>/typesafe/config.json.
const credentials = new CredentialStore({ dir: resolveTypeSafeDir() });
const client = new JevClient({ credentials });
// Ask Jev one or more typed questions about some state.
const { answers, usage, latencyMs } = await client.evaluate(
{ text: "hi" },
{ q: { type: "noul", instructions: "how confident?" } },
);
// Or wrap a fixed set of questions in a Bundle and map the answers to a value.
const bundle: Bundle<number> = {
id: "confidence",
questions: { q: { type: "noul", instructions: "how confident?" } },
map: (a) => (a.q as any).noul,
};
const { value } = await evaluateBundle(client, bundle, { text: "hi" });
Exports
CredentialStore— safe read/write/clear/inspect of the API-key file.resolveTypeSafeDir(env?, home?)— resolves the agent-owned credential directory (honorsPI_CODING_AGENT_DIR, else~/.pi/agent/typesafe).validateApiKey(value)— validation helper used by the command.JevClient— thin wrapper over@typesafe-ai/sdk's System One endpoint; resolves the key (stored or env), applies a timeout, and returns{ answers, usage, latencyMs, model? };modelis the versioned id that answered.TypeSafePanel/renderBox: the settings panel and its bordered-box renderer.Bundle<T>/evaluateBundle— bundle a fixed set of questions with amapfunction that turns the typed answers into your own value.
Credential storage & security
The API key is stored as plaintext JSON in an extension-owned directory:
<pi agent dir>/typesafe/config.json
where <pi agent dir> is $PI_CODING_AGENT_DIR if set, otherwise
~/.pi/agent.
The directory is created with mode 0700 and the file with mode 0600
(owner-only). Writes are atomic (write-to-temp then rename), and the store
refuses to follow symlinks or touch non-regular files. This is the same
security posture as pi's own auth.json: plaintext on disk, protected by
filesystem permissions rather than encryption. Anyone who can read your home
directory as your user can read the key, so treat the machine accordingly.
Attribution
The CredentialStore implementation is adapted from
legacybridge-tech/pi-typesafe-jev
(src/config.ts), MIT License, © 2025 pi-typesafe-jev authors.
License
MIT.