Rivet reports 0.82 MB per session for its Pi integration
Rivet's Pi integration keeps the agent loop, sessions, and credentials in the backend while sandboxes provide tools. Rivet reports durable execution, shared control, and SQLite persistence alongside the 0.82 MB per-session figure.

TL;DR
- Rivet puts the agent loop, session, and credentials in the backend, while the sandbox is called only for tools, according to rivet_dev's architecture post.
- The reported 0.82 MiB per session is the incremental RSS of 100 live sessions, not the total worker footprint, based on rivet_dev's memory measurement.
- Each session gets durable SQLite-backed state and can survive sleep, crashes, and deploys, per rivet_dev's production feature list.
- The integration keeps Pi's API surface, including prompt, steer, abort, and raw events, as rivet_dev's vanilla Pi note describes.
The official Pi 1.0 changelog includes a 100-session RSS chart, code for E2B, Daytona, Modal, and agentOS, plus an agent-to-agent reviewer example. Rivet's earlier harness architecture post explains why retries, session history, permissions, and credentials live outside the sandbox, while the SQLite documentation documents one database per Actor.
Backend-hosted loop
Each Pi session runs as its own Rivet Actor in the backend, while a sandbox provider is exposed as a remote tool layer, according to rivet_dev's launch post.
Rivet's architecture post assigns the durable responsibilities to the backend:
- The backend owns the agent loop, retries, session history, permissions, credentials, and failure reporting.
- The sandbox receives on-demand shell and filesystem operations as tool calls.
- The harness can wake a sleeping sandbox for schedules and workflows.
The boundary follows the failure modes Rivet lists for in-sandbox agents: out-of-memory builds, runaway processes, broken environments, and corrupted files can take down the loop along with the tools.
0.82 MiB sessions
In its benchmark, Rivet measured 100 live Pi sessions on one worker. RSS rose from a 223.0 MiB baseline to 304.3 MiB, an additional 81.3 MiB.
That averages to 0.82 MiB per live session. The figure is incremental session memory, not the worker's total footprint. Rivet says sessions start in tens of milliseconds, and idle sessions hibernate without using memory.
Sandbox tools
Rivet's integration list names agentOS, E2B, Daytona, and user-provided sandboxes. The launch code also shows a Modal adapter.
Pi's standard read, write, edit, grep, find, ls, and bash tools execute in the sandbox. Custom tools created with Pi's defineTool run in the backend, where they can call private APIs without placing their credentials in the sandbox.
Durable state
The session tree, compaction state, and retries are saved to the Actor's SQLite database, according to the Pi changelog. Rivet says sleep, crashes, and deploys do not lose the conversation, and the agent reconnects to the same sandbox when it wakes.
The SQLite documentation scopes one database to each Actor and supports disk-backed storage, indexes, transactions, and raw SQL. That gives a Pi session a durable transcript store without putting its history inside the disposable execution environment.
One user, onusoz, described Pi Durable, concurrent sessions, and SQLite storage as the defining parts of the update, noting that an existing SQLite workflow could be refactored around it.
Multiplayer sessions
A joining client receives the current transcript, streamed answer, running tools and output, queued messages, agent, and usage, then receives only subsequent changes, as the multiplayer documentation screenshot shows.
The launch example has Alice prompt a session while Bob joins and steers it with “Check the staging logs first.” Rivet's production list also includes agent-to-agent calls, which keep communication in the backend rather than exchanging sandbox addresses and credentials.
Vanilla Pi API
Rivet exposes the official Pi package without a wrapper, fork, or reimplementation. The changelog lists the preserved surface:
- Session actions:
prompt,steer,followUp,abort,compact,setModel,setThinkingLevel, andnavigateTree. - Events: Pi events stream to clients unchanged.
- Tools: the standard shell and filesystem tools run through the selected sandbox.
- Configuration: custom
defineTooltools, resource loaders for system prompts andAGENTS.md,models.jsonproviders, thinking levels, and settings.
Installation and deployment
The launch command is npm add @rivet-dev/pi @rivet-dev/sandbox-adapter rivetkit. Each Actor key gets its own session and sandbox, and the changelog provides adapter examples for E2B, Daytona, Modal, and agentOS.
The evidence thread advertises the integration as open-source and self-hostable rivet_dev's package list. The public Rivet Actors repository is licensed under Apache 2.0 and includes workflows, queues, scheduling, WebSockets, and SQLite-backed state as part of the Actor runtime.