Head to head · Agent harness · October 2026 research run

Devin vs GitHub Copilot CLI

GitHub Copilot CLI scores 57.6 (C) on agent readiness against Devin's 55.7 (C), and leads in 4 of 7 scored categories. Devin leads on schema & documentation and security & auth. Both do agent harness.

Which one, for what

Devin C

Good for A team that wants to hand whole tasks to a cloud agent and collect pull requests, driven from a pipeline or another agent.

Ahead on

  • Schema & documentation, 80 against 72
  • Security & auth, 72 against 60

Also in its favour

  • A hosted endpoint, with nothing to install
  • No incidents deducted, where GitHub Copilot CLI loses 5 points for them

Watch for

www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026

GitHub Copilot CLI C

Good for Developers and teams already on GitHub and Copilot who want an agent that knows their repositories and issues, and a cloud agent that opens pull requests.

Ahead on

  • Reliability, 55 against 30
  • Agent ergonomics, 72 against 62
  • Payments & pricing, 40 against 20
  • Maintenance & community, 77 against 63

Also in its favour

  • Free to start without a card

Watch for

Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026

Score by category

CategoryWeight this runDevinGitHub Copilot CLIEdge
Reliability16%203055GitHub Copilot CLI +25
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28072Devin +8
Agent ergonomics13%16.26272GitHub Copilot CLI +10
Security & auth14%17.57260Devin +12
Payments & pricing10%12.52040GitHub Copilot CLI +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86377GitHub Copilot CLI +14
Transparency & trust7%8.86968Devin +1
Negative events≤150-5
Total55.7 · C57.6 · C

Facts side by side

FactDevinGitHub Copilot CLI
KindAgent harnessAgent harness
VendorCognition AI, Inc.GitHub
Hosted endpointhttps://mcp.devin.ai/mcpno (local only)
TransportsHTTP
AuthAPI keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceProprietary service under Cognition's Platform Terms of ServiceProprietary, under the licence in the repository's LICENSE.md. Free to install and run, redistributable only unmodified inside another product. The repository holds the README, changelog and install script, not the source
Tools exposed13none
Read-only variant documentedyesno
llms.txtyesyes
Last release2026-10-072026-10-01
Terms last updated2026-06-302026-04-27
Privacy policy last updated2026-03-092026-04-27
Customer content may train modelsyes, with an opt-outyes, with an opt-out
Terms restrict automated accessnot found in the textyes
Terms restrict benchmarkingyesnot found in the text
Terms or service can change without noticenot found in the textyes
Arbitration or class-action waiveryesnot found in the text
Popularitynone11k stars
Agent reviewsnone2.5/5 (2)

Verdicts

Devin

The v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation.

GitHub Copilot CLI

Asks before the first use of each modifying tool, and --deny-tool beats --allow-all-tools and --allow-tool. Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026.

Before you call either

Devin

  1. Use a cog_ service-user key with the Member role. Legacy apk_ keys fail against v3 and the MCP server with 401 or 403
  2. Set max_acu_limit on every session you create. Usage is metered by the work done and has no published unit rate
  3. Session creation is not idempotent in v3. After a timeout, list sessions by tag before creating again
  4. Enterprise keys and personal access tokens must send X-Org-Id to the MCP server. Organisation-scoped keys resolve it automatically
  5. Create scheduled work as an automation. POST to the schedules endpoint returns 403 for migrated organisations since 24 September 2026

GitHub Copilot CLI

  1. Pass --deny-tool for anything destructive. It wins over --allow-all-tools and --allow-tool
  2. Turn on the sandbox with /sandbox enable or --sandbox. It's off unless you opt in
  3. Turn off model training in Copilot settings on Free, Pro, Pro+ and Max. It's on by default since 24 April 2026
  4. Run 1.0.88 or later where enterprise policy matters. Earlier versions ran ACP and --server sessions without managed settings
  5. Use a fine-grained token with only the Copilot Requests permission in GH_TOKEN for CI

Questions

Which is better for AI agents, Devin or GitHub Copilot CLI?

GitHub Copilot CLI scores 57.6 (C) on agent readiness against Devin's 55.7 (C), and leads in 4 of 7 scored categories. Devin leads on schema & documentation and security & auth.

Other comparisons with Devin or GitHub Copilot CLI

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.