{
  "data": {
    "a": {
      "slug": "devin",
      "name": "Devin",
      "vendor": "Cognition AI, Inc.",
      "vendorUrl": "https://devin.ai",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Devin is Cognition's hosted coding agent. It works in its own cloud virtual machine to plan, edit code, run commands and open pull requests. Outside agents start and steer sessions through a REST API and a remote MCP server.",
      "url": "https://www.anchorterminal.com/tools/devin",
      "markdownUrl": "https://www.anchorterminal.com/tools/devin.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/devin.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/devin.json",
      "license": "Proprietary service under Cognition's Platform Terms of Service",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://mcp.devin.ai/mcp",
      "packages": [],
      "auth": "api-key",
      "authNotes": "A Bearer token with the `cog_` prefix on every request to https://api.devin.ai/v3. Service-user keys are provisioned by a person in Settings \u003e Devin API, shown once, and carry a role (Admin or Member on Teams, custom roles on Enterprise). Personal access tokens act as the user who made them and can expire. Legacy `apk_` keys work only with the deprecated v1 and v2 APIs. The MCP server takes the same keys, and enterprise keys and personal tokens add an `X-Org-Id` header. Access is self-serve, with no app review or sales approval for Teams.",
      "pricing": "freemium",
      "pricingNotes": "Free $0, Pro $20 a month, Max $200 a month, Teams $80 a month minimum with full seats at $40 each, Enterprise by quote (devin.ai/pricing, checked 2026-10-08). Paid plans include a daily or weekly usage quota, then prepaid on-demand credits described as usage at API pricing, with no unit rate on the page. The pricing page lists cloud agents from Pro upward, while the docs say Free includes limited Devin usage. Whether the API works on Free, and whether signup needs a card, wasn't established.",
      "priceSummary": "$20 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the v3 OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 13,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.devin.ai",
      "llmsTxt": "https://docs.devin.ai/llms.txt",
      "openapi": "https://docs.devin.ai/v3-openapi.yaml",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "hosted",
        "cloud-agent",
        "closed-source",
        "api-key",
        "rbac",
        "openapi",
        "llms-txt",
        "mcp",
        "status-page",
        "soc2",
        "freemium"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.7,
        "grade": "C",
        "agentReady": false,
        "rank": 505,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 15,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 62,
          "maintenance": 63,
          "payments": 20,
          "reliability": 30,
          "schema": 80,
          "security": 72,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation.",
        "bestFor": "A team that wants to hand whole tasks to a cloud agent and collect pull requests, driven from a pipeline or another agent.",
        "strengths": [
          "Public OpenAPI 3.1 spec for the v3 API with 239 operations, each declaring 401, 403, 404, 409, 422 and 429 responses in RFC 9457 problem+json",
          "Service-user keys carry a role, every endpoint except GET /v3/self names the permission it needs, and audit logs list service users separately from people",
          "Security profiles can limit a session to a network allowlist, an MCP server allowlist, read-only git and a read-only Devin MCP",
          "Remote MCP server at mcp.devin.ai/mcp with 13 documented tools for sessions, playbooks, knowledge, schedules and repository documentation",
          "Dated release notes several times a week, the newest on 7 October 2026, and a separate API release notes page"
        ],
        "weaknesses": [
          "www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026",
          "No rate limit figures, Retry-After or backoff guidance found in the API docs, and v3 session creation has no idempotency key",
          "Customer data may be used for model training by default on self-serve plans. The opt-out is for paid plans only, per section 3.3.1 of the platform terms",
          "A person must sign up and provision the service user in the web app. No key-creation route exists for an agent starting from nothing",
          "No official SDK found, and the Devin MCP server was not found in the official MCP registry"
        ],
        "agentNotes": [
          "Use a `cog_` service-user key with the Member role. Legacy `apk_` keys fail against v3 and the MCP server with 401 or 403",
          "Set `max_acu_limit` on every session you create. Usage is metered by the work done and has no published unit rate",
          "Session creation is not idempotent in v3. After a timeout, list sessions by tag before creating again",
          "Enterprise keys and personal access tokens must send `X-Org-Id` to the MCP server. Organisation-scoped keys resolve it automatically",
          "Create scheduled work as an automation. POST to the schedules endpoint returns 403 for migrated organisations since 24 September 2026"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.7
          }
        ],
        "editorialScores": {
          "ergonomics": 62,
          "maintenance": 63,
          "payments": 20,
          "reliability": 30,
          "schema": 80,
          "security": 72,
          "transparency": 61
        },
        "provenanceScore": 77
      },
      "connect": {
        "http": "curl -X POST \"https://api.devin.ai/v3/organizations/$DEVIN_ORG_ID/sessions\" -H \"Authorization: Bearer $DEVIN_API_KEY\" -H \"Content-Type: application/json\" -d '{\"prompt\": \"Create a simple Python script that prints Hello World\"}'",
        "config": {
          "mcpServers": {
            "devin": {
              "headers": {
                "Authorization": "Bearer \u003cAPI_KEY\u003e",
                "X-Org-Id": "\u003cYOUR_ORG_ID\u003e"
              },
              "serverUrl": "https://mcp.devin.ai/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/devin"
      },
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 20,
          "note": "one user, daily and weekly usage quota"
        },
        {
          "item": "Max plan",
          "unit": "month",
          "usd": 200,
          "note": "one user, larger weekly quota"
        },
        {
          "item": "Teams full seat",
          "unit": "seat-month",
          "usd": 40,
          "note": "$80 a month minimum per team, flex seats free and billed from shared credits"
        }
      ],
      "provenance": {
        "legalEntity": "Cognition AI, Inc.",
        "domain": "devin.ai",
        "domainRegistered": "2022-12-06",
        "endpointOnVendorDomain": true,
        "terms": "https://cognition.com/legal/platform-terms-of-service",
        "privacy": "https://cognition.com/legal/privacy-policy",
        "statusPage": "https://www.devinstatus.com",
        "changelog": "https://docs.devin.ai/release-notes/overview",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Platform Terms of Service (last updated 30 June 2026) name Cognition AI, Inc. and govern the Cognition Platform for customers who register and use the services. Enterprise customers sign separate Enterprise Terms of Service.",
          "The privacy policy (last updated 9 March 2026) names Cognition AI, Inc and covers Devin and Windsurf as well as cognition.com. The data processing agreement gives the address 550 Third Street, San Francisco, CA 94107.",
          "devin.ai, cognition.com and api.devin.ai all return 404 for /.well-known/security.txt. The docs give security@cognition.ai for vulnerability reports.",
          "The API answers at api.devin.ai and the MCP server at mcp.devin.ai. status.devin.ai redirects to www.devinstatus.com.",
          "RDAP for devin.ai gives a registration date of 2022-12-06."
        ],
        "score": 77
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/devin.json",
      "live": {
        "slug": "devin",
        "probe": {
          "target": "https://mcp.devin.ai/mcp",
          "method": "get",
          "lastAt": "2026-10-08T23:09:06.378005796Z",
          "lastOk": true,
          "lastStatus": 406,
          "lastMs": 450,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 449,
          "p95ms24h": 470,
          "samples24h": 61,
          "samples30d": 61,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 61,
              "ok": 61
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.devinstatus.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T23:13:21.510722479Z"
        },
        "pages": [
          {
            "url": "https://docs.devin.ai/release-notes/overview",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:39.860758812Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a85f82787c20"
          },
          {
            "url": "https://cognition.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:28.045423959Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0ab177a921b1"
          },
          {
            "url": "https://cognition.com/legal/platform-terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:26.004141328Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e794136b2fe5"
          }
        ],
        "updatedAt": "2026-10-08T23:13:21.510722479Z"
      }
    },
    "answer": "Pi scores 68.4 (B) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth and transparency \u0026 trust.",
    "b": {
      "slug": "earendil-pi",
      "name": "Pi",
      "vendor": "Earendil",
      "vendorUrl": "https://pi.dev",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Pi is an open-source terminal coding agent from Earendil, run on the owner's machine with any of 15 or more model providers. It has interactive, print, JSON and RPC modes, a TypeScript SDK and a built-in MCP client.",
      "url": "https://www.anchorterminal.com/tools/earendil-pi",
      "markdownUrl": "https://www.anchorterminal.com/tools/earendil-pi.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/earendil-pi.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/earendil-pi.json",
      "repo": "https://github.com/earendil-works/pi",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@earendil-works/pi-coding-agent"
        }
      ],
      "auth": "none",
      "authNotes": "No Pi account needed. Model providers are connected with `/login` (a subscription or an API key, stored in `~/.pi/agent/auth.json`) or with environment variables such as `ANTHROPIC_API_KEY`. MCP servers take headers, bearer tokens from the environment or OAuth, with tokens kept in `~/.pi/agent/mcp-auth.json`. Radius, the optional hosted gateway, needs its own sign-in or `RADIUS_API_KEY`.",
      "pricing": "free",
      "pricingNotes": "Free and MIT, with no paid edition of the harness. The owner pays the model provider. Radius, Earendil's optional hosted gateway, is an early alpha sold by prepaid credits, and no public price list was found (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the repository or the docs (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 113417,
        "npmWeekly": 5201697,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://pi.dev/docs/latest",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client"
      ],
      "tags": [
        "open-source",
        "local",
        "free",
        "no-card",
        "typescript",
        "mcp",
        "json-output",
        "rpc",
        "no-sandbox"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68.4,
        "grade": "B",
        "agentReady": false,
        "rank": 180,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 76,
          "maintenance": 87,
          "payments": 60,
          "reliability": 75,
          "schema": 84,
          "security": 61,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -4,
        "negativeNotes": [
          "2026-06-08. GHSA-jfgx-wxx8-mp94 (CVE-2026-54328, high). Temporary extension installs used predictable paths under the system temp directory, so another local user on a shared Linux host could plant extension code that Pi then loaded. Fixed in 0.78.1. Fixed, published and four months old, -2. https://github.com/earendil-works/pi/security/advisories/GHSA-jfgx-wxx8-mp94",
          "2026-06-08. GHSA-mqxh-6gq7-558m (CVE-2026-54325, medium). Before 0.79.0 Pi loaded a repository's `.pi` settings and extensions without asking, so starting it in a cloned repository could run that repository's code. Fixed in 0.79.0 with project trust. Fixed and published, -2. https://github.com/earendil-works/pi/security/advisories/GHSA-mqxh-6gq7-558m",
          "2026-06-08. GHSA-7v5m-pr3q-6453 (CVE-2026-54326, low, XSS in HTML session exports) and GHSA-r95r-rj6r-c39x (CVE-2026-54327, low, a race in `auth.json` permissions). Both fixed in 0.78.1. Recorded without a deduction. https://github.com/earendil-works/pi/security/advisories"
        ],
        "verdict": "Four default tools, a JSONL event stream, an RPC mode and MCP tools kept out of the model's declarations by default keep context small and scripting simple. Pi has no permission system or sandbox and doesn't ask before tool calls, so isolation is the operator's job. Version 1.0.0 is dated 1 October 2026.",
        "bestFor": "Developers and pipelines that want a small, scriptable coding agent they can extend in TypeScript and drive over JSONL or RPC, inside their own container.",
        "strengths": [
          "Four default tools (read, bash, edit, write), with MCP tools reachable through codemode scripts and not declared to the model by default",
          "`--mode json` streams JSONL events and `--mode rpc` takes JSONL commands, both documented record by record, with a Python client example",
          "Built-in MCP client for stdio and streamable HTTP servers with OAuth, per-tool exposure settings and a conformance job in CI",
          "Project trust stops a repository's `.pi` settings, extensions and MCP servers loading until approved, and non-interactive modes skip them by default",
          "npm releases carry SLSA provenance from GitHub Actions trusted publishing, and the installer pins transitive dependencies"
        ],
        "weaknesses": [
          "No permission system or sandbox. Tool calls run with the user's rights and without an approval prompt",
          "An anonymous install and update ping to pi.dev and a latest-version request are on by default",
          "Four advisories published on 8 June 2026, one rated high and one medium, all fixed by 0.79.0",
          "No privacy policy for pi.dev or the CLI found, and pi.dev has no security.txt",
          "Eight of the last 15 CI runs on main failed on 7 and 8 October 2026, and a breaking provider rename shipped in patch release 1.0.3"
        ],
        "agentNotes": [
          "Run Pi inside a container or VM for unattended work. It has no sandbox and doesn't ask before running shell commands",
          "Use `pi --mode json` and wait for `agent_settled`. A failed response doesn't set a nonzero exit code in JSON mode",
          "Split the JSONL stream on LF only. Node's `readline` also splits on U+2028 and U+2029, which are valid inside JSON strings",
          "Pass `--no-approve` or `--approve` in scripts to make the project trust decision explicit",
          "Set `PI_TELEMETRY=0` and `PI_SKIP_VERSION_CHECK=1`, or `PI_OFFLINE=1`, to stop the default requests to pi.dev"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68.4
          }
        ],
        "editorialScores": {
          "ergonomics": 76,
          "maintenance": 87,
          "payments": 60,
          "reliability": 75,
          "schema": 84,
          "security": 61,
          "transparency": 64
        },
        "provenanceScore": 63
      },
      "connect": {
        "install": "curl -fsSL https://pi.dev/install.sh | sh   # or: npm install -g --ignore-scripts @earendil-works/pi-coding-agent",
        "headless": {
          "command": "pi --mode json --no-session --no-approve \"$TASK\"",
          "env": {
            "PI_SKIP_VERSION_CHECK": "1",
            "PI_TELEMETRY": "0"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/earendil-pi"
      },
      "area": "frameworks",
      "provenance": {
        "legalEntity": "Earendil Inc.",
        "domain": "pi.dev",
        "domainRegistered": "2024-01-30",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://pi.dev/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The pi.dev and earendil.com footers read Earendil Inc. The Radius alpha terms of 1 September 2026 name Earendil Works Co., and the README calls the company Earendil Works.",
          "We found no terms or privacy page for pi.dev or the CLI. pi.dev/terms, pi.dev/privacy and earendil.com/privacy return 404. Terms exist only for Radius, at radius.earendil.com/terms.",
          "pi.dev/.well-known/security.txt and earendil.com/.well-known/security.txt return 404. SECURITY.md gives security@earendil.com and GitHub private reporting.",
          "RDAP for pi.dev gives a registration date of 2024-01-30 with Cloudflare as registrar. The README says the domain was donated by exe.dev.",
          "The repository moved from badlogic/pi-mono to earendil-works/pi, and the npm package from @mariozechner/pi-coding-agent to @earendil-works/pi-coding-agent at 0.74.0, per the advisories."
        ],
        "score": 63
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/earendil-pi.json",
      "live": {
        "slug": "earendil-pi",
        "versions": [
          {
            "registry": "github",
            "name": "earendil-works/pi",
            "version": "v1.1.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:09:44.573412777Z"
          },
          {
            "registry": "npm",
            "name": "@earendil-works/pi-coding-agent",
            "version": "1.1.0",
            "seenAt": "2026-10-08T16:09:41.369786574Z"
          }
        ],
        "githubStars": 113482,
        "npmWeekly": 5201697,
        "securityTxt": {
          "url": "https://pi.dev/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:42.51766104Z"
        },
        "pages": [
          {
            "url": "https://pi.dev/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:53.741589246Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "82f9cb8bddf7"
          }
        ],
        "updatedAt": "2026-10-08T18:22:53.741589246Z"
      }
    },
    "facts": [
      {
        "a": "Agent harness",
        "b": "Agent harness",
        "name": "Kind"
      },
      {
        "a": "Cognition AI, Inc.",
        "b": "Earendil",
        "name": "Vendor"
      },
      {
        "a": "https://mcp.devin.ai/mcp",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "None",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Cognition's Platform Terms of Service",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "13",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-07",
        "b": "2026-10-07",
        "name": "Last release"
      },
      {
        "a": "2026-06-30",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2026-03-09",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes, with an opt-out",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "none",
        "b": "113k stars, 5.2M npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Pi scores 68.4 (B) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Devin or Pi?"
      },
      {
        "answer": "No open-source release is listed for Devin. Pi is open source (MIT).",
        "question": "Are Devin and Pi open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Security \u0026 auth, 72 against 61",
          "Transparency \u0026 trust, 69 against 64"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "No incidents deducted, where Pi loses 4 points for them"
        ],
        "goodFor": "A team that wants to hand whole tasks to a cloud agent and collect pull requests, driven from a pipeline or another agent.",
        "slug": "devin",
        "watchFor": "www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026"
      },
      {
        "aheadOn": [
          "Reliability, 75 against 30",
          "Agent ergonomics, 76 against 62",
          "Payments \u0026 pricing, 60 against 20",
          "Maintenance \u0026 community, 87 against 63"
        ],
        "also": [
          "No key needed to call it",
          "Free to start without a card",
          "Open source"
        ],
        "goodFor": "Developers and pipelines that want a small, scriptable coding agent they can extend in TypeScript and drive over JSONL or RPC, inside their own container.",
        "slug": "earendil-pi",
        "watchFor": "No permission system or sandbox. Tool calls run with the user's rights and without an approval prompt"
      }
    ],
    "job": {
      "capability": "agent.harness",
      "name": "Agent harness"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aider-vs-devin.json",
        "title": "Aider vs Devin",
        "url": "https://www.anchorterminal.com/compare/aider-vs-devin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aider-vs-earendil-pi.json",
        "title": "Aider vs Pi",
        "url": "https://www.anchorterminal.com/compare/aider-vs-earendil-pi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amp-vs-devin.json",
        "title": "Amp vs Devin",
        "url": "https://www.anchorterminal.com/compare/amp-vs-devin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amp-vs-earendil-pi.json",
        "title": "Amp vs Pi",
        "url": "https://www.anchorterminal.com/compare/amp-vs-earendil-pi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/claude-code-vs-devin.json",
        "title": "Claude Code vs Devin",
        "url": "https://www.anchorterminal.com/compare/claude-code-vs-devin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/claude-code-vs-earendil-pi.json",
        "title": "Claude Code vs Pi",
        "url": "https://www.anchorterminal.com/compare/claude-code-vs-earendil-pi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cline-vs-devin.json",
        "title": "Cline vs Devin",
        "url": "https://www.anchorterminal.com/compare/cline-vs-devin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cline-vs-earendil-pi.json",
        "title": "Cline vs Pi",
        "url": "https://www.anchorterminal.com/compare/cline-vs-earendil-pi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-devin.json",
        "title": "Cursor CLI vs Devin",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-devin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-earendil-pi.json",
        "title": "Cursor CLI vs Pi",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-earendil-pi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-gemini-cli.json",
        "title": "Devin vs Gemini CLI",
        "url": "https://www.anchorterminal.com/compare/devin-vs-gemini-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-github-copilot-cli.json",
        "title": "Devin vs GitHub Copilot CLI",
        "url": "https://www.anchorterminal.com/compare/devin-vs-github-copilot-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-goose.json",
        "title": "Devin vs goose",
        "url": "https://www.anchorterminal.com/compare/devin-vs-goose"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-kiro-cli.json",
        "title": "Devin vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/devin-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-openai-codex.json",
        "title": "Devin vs OpenAI Codex",
        "url": "https://www.anchorterminal.com/compare/devin-vs-openai-codex"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-opencode.json",
        "title": "Devin vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/devin-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-openhands.json",
        "title": "Devin vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/devin-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-prime-agent.json",
        "title": "Devin vs Prime Agent",
        "url": "https://www.anchorterminal.com/compare/devin-vs-prime-agent"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-qwen-code.json",
        "title": "Devin vs Qwen Code",
        "url": "https://www.anchorterminal.com/compare/devin-vs-qwen-code"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-gemini-cli.json",
        "title": "Pi vs Gemini CLI",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-gemini-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-github-copilot-cli.json",
        "title": "Pi vs GitHub Copilot CLI",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-github-copilot-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-goose.json",
        "title": "Pi vs goose",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-goose"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-kiro-cli.json",
        "title": "Pi vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-openai-codex.json",
        "title": "Pi vs OpenAI Codex",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-openai-codex"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-opencode.json",
        "title": "Pi vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-openhands.json",
        "title": "Pi vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-prime-agent.json",
        "title": "Pi vs Prime Agent",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-prime-agent"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-qwen-code.json",
        "title": "Pi vs Qwen Code",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-qwen-code"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-paperclip.json",
        "title": "Devin vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/devin-vs-paperclip"
      }
    ],
    "scores": [
      {
        "by": 45,
        "devin": 30,
        "earendil-pi": 75,
        "edge": "earendil-pi",
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 4,
        "devin": 80,
        "earendil-pi": 84,
        "edge": "earendil-pi",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 14,
        "devin": 62,
        "earendil-pi": 76,
        "edge": "earendil-pi",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 11,
        "devin": 72,
        "earendil-pi": 61,
        "edge": "devin",
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 40,
        "devin": 20,
        "earendil-pi": 60,
        "edge": "earendil-pi",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 24,
        "devin": 63,
        "earendil-pi": 87,
        "edge": "earendil-pi",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 5,
        "devin": 69,
        "earendil-pi": 64,
        "edge": "devin",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Pi scores 68.4 (B) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth and transparency \u0026 trust. Both do agent harness.",
    "verdicts": {
      "devin": "The v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation.",
      "earendil-pi": "Four default tools, a JSONL event stream, an RPC mode and MCP tools kept out of the model's declarations by default keep context small and scripting simple. Pi has no permission system or sandbox and doesn't ask before tool calls, so isolation is the operator's job. Version 1.0.0 is dated 1 October 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/devin-vs-earendil-pi",
    "json": "https://www.anchorterminal.com/compare/devin-vs-earendil-pi.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/devin-vs-earendil-pi.md",
    "slim": "https://www.anchorterminal.com/compare/devin-vs-earendil-pi.min.md"
  },
  "markdown": "Pi scores 68.4 (B) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth and transparency \u0026 trust. Both do agent harness.\n\n- Devin: grade C, 55.7/100, rank #505 of 722. Markdown https://www.anchorterminal.com/tools/devin.md · JSON https://www.anchorterminal.com/api/v1/tools/devin.json\n- Pi: grade B, 68.4/100, rank #180 of 722. Markdown https://www.anchorterminal.com/tools/earendil-pi.md · JSON https://www.anchorterminal.com/api/v1/tools/earendil-pi.json\n\n## Which one, for what\n\n### Devin (C)\n\nGood for: A team that wants to hand whole tasks to a cloud agent and collect pull requests, driven from a pipeline or another agent.\n\nAhead on:\n- Security \u0026 auth, 72 against 61\n- Transparency \u0026 trust, 69 against 64\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- No incidents deducted, where Pi loses 4 points for them\n\nWatch for: www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026\n\n### Pi (B)\n\nGood for: Developers and pipelines that want a small, scriptable coding agent they can extend in TypeScript and drive over JSONL or RPC, inside their own container.\n\nAhead on:\n- Reliability, 75 against 30\n- Agent ergonomics, 76 against 62\n- Payments \u0026 pricing, 60 against 20\n- Maintenance \u0026 community, 87 against 63\n\nAlso in its favour:\n- No key needed to call it\n- Free to start without a card\n- Open source\n\nWatch for: No permission system or sandbox. Tool calls run with the user's rights and without an approval prompt\n\n\n## Score by category\n\n| Category | Weight | Devin | Pi | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 30 | 75 | Pi +45 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 80 | 84 | Pi +4 |\n| Agent ergonomics | 13% (16.2 this run) | 62 | 76 | Pi +14 |\n| Security \u0026 auth | 14% (17.5 this run) | 72 | 61 | Devin +11 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 60 | Pi +40 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 63 | 87 | Pi +24 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 69 | 64 | Devin +5 |\n| Negative events | ≤15 | 0 | -4 | |\n| **Total** | | **55.7 · C** | **68.4 · B** | |\n\n## Facts side by side\n\n| Fact | Devin | Pi |\n| --- | --- | --- |\n| Kind | Agent harness | Agent harness |\n| Vendor | Cognition AI, Inc. | Earendil |\n| Hosted endpoint | `https://mcp.devin.ai/mcp` | no (local only) |\n| Transports | HTTP |  |\n| Auth | API key | None |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | Proprietary service under Cognition's Platform Terms of Service | MIT |\n| Tools exposed | 13 | none |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | no |\n| Last release | 2026-10-07 | 2026-10-07 |\n| Terms last updated | 2026-06-30 | no document linked |\n| Privacy policy last updated | 2026-03-09 | no document linked |\n| Customer content may train models | yes, with an opt-out |  |\n| Terms restrict automated access | not found in the text |  |\n| Terms restrict benchmarking | yes |  |\n| Terms or service can change without notice | not found in the text |  |\n| Arbitration or class-action waiver | yes |  |\n| Popularity | none | 113k stars, 5.2M npm/wk |\n\n## Verdicts\n\n**Devin.** The v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation.\n\n**Pi.** Four default tools, a JSONL event stream, an RPC mode and MCP tools kept out of the model's declarations by default keep context small and scripting simple. Pi has no permission system or sandbox and doesn't ask before tool calls, so isolation is the operator's job. Version 1.0.0 is dated 1 October 2026.\n\n## Before you call either\n\n### Devin\n\n1. Use a `cog_` service-user key with the Member role. Legacy `apk_` keys fail against v3 and the MCP server with 401 or 403\n2. Set `max_acu_limit` on every session you create. Usage is metered by the work done and has no published unit rate\n3. Session creation is not idempotent in v3. After a timeout, list sessions by tag before creating again\n4. Enterprise keys and personal access tokens must send `X-Org-Id` to the MCP server. Organisation-scoped keys resolve it automatically\n5. Create scheduled work as an automation. POST to the schedules endpoint returns 403 for migrated organisations since 24 September 2026\n\n### Pi\n\n1. Run Pi inside a container or VM for unattended work. It has no sandbox and doesn't ask before running shell commands\n2. Use `pi --mode json` and wait for `agent_settled`. A failed response doesn't set a nonzero exit code in JSON mode\n3. Split the JSONL stream on LF only. Node's `readline` also splits on U+2028 and U+2029, which are valid inside JSON strings\n4. Pass `--no-approve` or `--approve` in scripts to make the project trust decision explicit\n5. Set `PI_TELEMETRY=0` and `PI_SKIP_VERSION_CHECK=1`, or `PI_OFFLINE=1`, to stop the default requests to pi.dev\n\n## Questions\n\n### Which is better for AI agents, Devin or Pi?\n\nPi scores 68.4 (B) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth and transparency \u0026 trust.\n\n### Are Devin and Pi open source?\n\nNo open-source release is listed for Devin. Pi is open source (MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/devin-vs-earendil-pi.json, and with the fewest tokens: https://www.anchorterminal.com/compare/devin-vs-earendil-pi.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"devin\", \"b\": \"earendil-pi\"}`. From a terminal: `anchor compare devin earendil-pi`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/devin.json and https://www.anchorterminal.com/api/v1/tools/earendil-pi.json\n\n## Other comparisons with Devin or Pi\n\n- [Aider vs Devin](https://www.anchorterminal.com/compare/aider-vs-devin.md)\n- [Aider vs Pi](https://www.anchorterminal.com/compare/aider-vs-earendil-pi.md)\n- [Amp vs Devin](https://www.anchorterminal.com/compare/amp-vs-devin.md)\n- [Amp vs Pi](https://www.anchorterminal.com/compare/amp-vs-earendil-pi.md)\n- [Claude Code vs Devin](https://www.anchorterminal.com/compare/claude-code-vs-devin.md)\n- [Claude Code vs Pi](https://www.anchorterminal.com/compare/claude-code-vs-earendil-pi.md)\n- [Cline vs Devin](https://www.anchorterminal.com/compare/cline-vs-devin.md)\n- [Cline vs Pi](https://www.anchorterminal.com/compare/cline-vs-earendil-pi.md)\n- [Cursor CLI vs Devin](https://www.anchorterminal.com/compare/cursor-cli-vs-devin.md)\n- [Cursor CLI vs Pi](https://www.anchorterminal.com/compare/cursor-cli-vs-earendil-pi.md)\n- [Devin vs Gemini CLI](https://www.anchorterminal.com/compare/devin-vs-gemini-cli.md)\n- [Devin vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/devin-vs-github-copilot-cli.md)\n- [Devin vs goose](https://www.anchorterminal.com/compare/devin-vs-goose.md)\n- [Devin vs Kiro CLI](https://www.anchorterminal.com/compare/devin-vs-kiro-cli.md)\n- [Devin vs OpenAI Codex](https://www.anchorterminal.com/compare/devin-vs-openai-codex.md)\n- [Devin vs OpenCode](https://www.anchorterminal.com/compare/devin-vs-opencode.md)\n- [Devin vs OpenHands](https://www.anchorterminal.com/compare/devin-vs-openhands.md)\n- [Devin vs Prime Agent](https://www.anchorterminal.com/compare/devin-vs-prime-agent.md)\n- [Devin vs Qwen Code](https://www.anchorterminal.com/compare/devin-vs-qwen-code.md)\n- [Pi vs Gemini CLI](https://www.anchorterminal.com/compare/earendil-pi-vs-gemini-cli.md)\n- [Pi vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/earendil-pi-vs-github-copilot-cli.md)\n- [Pi vs goose](https://www.anchorterminal.com/compare/earendil-pi-vs-goose.md)\n- [Pi vs Kiro CLI](https://www.anchorterminal.com/compare/earendil-pi-vs-kiro-cli.md)\n- [Pi vs OpenAI Codex](https://www.anchorterminal.com/compare/earendil-pi-vs-openai-codex.md)\n- [Pi vs OpenCode](https://www.anchorterminal.com/compare/earendil-pi-vs-opencode.md)\n- [Pi vs OpenHands](https://www.anchorterminal.com/compare/earendil-pi-vs-openhands.md)\n- [Pi vs Prime Agent](https://www.anchorterminal.com/compare/earendil-pi-vs-prime-agent.md)\n- [Pi vs Qwen Code](https://www.anchorterminal.com/compare/earendil-pi-vs-qwen-code.md)\n- [Devin vs Paperclip](https://www.anchorterminal.com/compare/devin-vs-paperclip.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Devin vs Pi",
        "url": ""
      }
    ],
    "description": "Pi scores 68.4 (B) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth and transparency \u0026 trust. Both do agent harness. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Devin C 55.7",
      "Pi B 68.4",
      "scores"
    ],
    "h1": "Devin vs Pi",
    "image": "https://www.anchorterminal.com/assets/og/compare-devin-vs-earendil-pi.png",
    "path": "/compare/devin-vs-earendil-pi",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Devin vs Pi for AI agents, C 55.7 vs B 68.4 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/devin-vs-earendil-pi"
  },
  "tokens": {
    "markdown": 2350,
    "slim": 680
  },
  "version": 1
}
