{
  "data": {
    "a": {
      "slug": "devin",
      "name": "Devin",
      "vendor": "Cognition AI, Inc.",
      "vendorUrl": "https://devin.ai",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Devin is Cognition's hosted coding agent. It works in its own cloud virtual machine to plan, edit code, run commands and open pull requests. Outside agents start and steer sessions through a REST API and a remote MCP server.",
      "url": "https://www.anchorterminal.com/tools/devin",
      "markdownUrl": "https://www.anchorterminal.com/tools/devin.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/devin.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/devin.json",
      "license": "Proprietary service under Cognition's Platform Terms of Service",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://mcp.devin.ai/mcp",
      "packages": [],
      "auth": "api-key",
      "authNotes": "A Bearer token with the `cog_` prefix on every request to https://api.devin.ai/v3. Service-user keys are provisioned by a person in Settings \u003e Devin API, shown once, and carry a role (Admin or Member on Teams, custom roles on Enterprise). Personal access tokens act as the user who made them and can expire. Legacy `apk_` keys work only with the deprecated v1 and v2 APIs. The MCP server takes the same keys, and enterprise keys and personal tokens add an `X-Org-Id` header. Access is self-serve, with no app review or sales approval for Teams.",
      "pricing": "freemium",
      "pricingNotes": "Free $0, Pro $20 a month, Max $200 a month, Teams $80 a month minimum with full seats at $40 each, Enterprise by quote (devin.ai/pricing, checked 2026-10-08). Paid plans include a daily or weekly usage quota, then prepaid on-demand credits described as usage at API pricing, with no unit rate on the page. The pricing page lists cloud agents from Pro upward, while the docs say Free includes limited Devin usage. Whether the API works on Free, and whether signup needs a card, wasn't established.",
      "priceSummary": "$20 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the v3 OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 13,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.devin.ai",
      "llmsTxt": "https://docs.devin.ai/llms.txt",
      "openapi": "https://docs.devin.ai/v3-openapi.yaml",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "hosted",
        "cloud-agent",
        "closed-source",
        "api-key",
        "rbac",
        "openapi",
        "llms-txt",
        "mcp",
        "status-page",
        "soc2",
        "freemium"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.7,
        "grade": "C",
        "agentReady": false,
        "rank": 447,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 15,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 62,
          "maintenance": 63,
          "payments": 20,
          "reliability": 30,
          "schema": 80,
          "security": 72,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation.",
        "bestFor": "A team that wants to hand whole tasks to a cloud agent and collect pull requests, driven from a pipeline or another agent.",
        "strengths": [
          "Public OpenAPI 3.1 spec for the v3 API with 239 operations, each declaring 401, 403, 404, 409, 422 and 429 responses in RFC 9457 problem+json",
          "Service-user keys carry a role, every endpoint except GET /v3/self names the permission it needs, and audit logs list service users separately from people",
          "Security profiles can limit a session to a network allowlist, an MCP server allowlist, read-only git and a read-only Devin MCP",
          "Remote MCP server at mcp.devin.ai/mcp with 13 documented tools for sessions, playbooks, knowledge, schedules and repository documentation",
          "Dated release notes several times a week, the newest on 7 October 2026, and a separate API release notes page"
        ],
        "weaknesses": [
          "www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026",
          "No rate limit figures, Retry-After or backoff guidance found in the API docs, and v3 session creation has no idempotency key",
          "Customer data may be used for model training by default on self-serve plans. The opt-out is for paid plans only, per section 3.3.1 of the platform terms",
          "A person must sign up and provision the service user in the web app. No key-creation route exists for an agent starting from nothing",
          "No official SDK found, and the Devin MCP server was not found in the official MCP registry"
        ],
        "agentNotes": [
          "Use a `cog_` service-user key with the Member role. Legacy `apk_` keys fail against v3 and the MCP server with 401 or 403",
          "Set `max_acu_limit` on every session you create. Usage is metered by the work done and has no published unit rate",
          "Session creation is not idempotent in v3. After a timeout, list sessions by tag before creating again",
          "Enterprise keys and personal access tokens must send `X-Org-Id` to the MCP server. Organisation-scoped keys resolve it automatically",
          "Create scheduled work as an automation. POST to the schedules endpoint returns 403 for migrated organisations since 24 September 2026"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.7
          }
        ],
        "editorialScores": {
          "ergonomics": 62,
          "maintenance": 63,
          "payments": 20,
          "reliability": 30,
          "schema": 80,
          "security": 72,
          "transparency": 61
        },
        "provenanceScore": 77
      },
      "connect": {
        "http": "curl -X POST \"https://api.devin.ai/v3/organizations/$DEVIN_ORG_ID/sessions\" -H \"Authorization: Bearer $DEVIN_API_KEY\" -H \"Content-Type: application/json\" -d '{\"prompt\": \"Create a simple Python script that prints Hello World\"}'",
        "config": {
          "mcpServers": {
            "devin": {
              "headers": {
                "Authorization": "Bearer \u003cAPI_KEY\u003e",
                "X-Org-Id": "\u003cYOUR_ORG_ID\u003e"
              },
              "serverUrl": "https://mcp.devin.ai/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/devin"
      },
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 20,
          "note": "one user, daily and weekly usage quota"
        },
        {
          "item": "Max plan",
          "unit": "month",
          "usd": 200,
          "note": "one user, larger weekly quota"
        },
        {
          "item": "Teams full seat",
          "unit": "seat-month",
          "usd": 40,
          "note": "$80 a month minimum per team, flex seats free and billed from shared credits"
        }
      ],
      "provenance": {
        "legalEntity": "Cognition AI, Inc.",
        "domain": "devin.ai",
        "domainRegistered": "2022-12-06",
        "endpointOnVendorDomain": true,
        "terms": "https://cognition.com/legal/platform-terms-of-service",
        "privacy": "https://cognition.com/legal/privacy-policy",
        "statusPage": "https://www.devinstatus.com",
        "changelog": "https://docs.devin.ai/release-notes/overview",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Platform Terms of Service (last updated 30 June 2026) name Cognition AI, Inc. and govern the Cognition Platform for customers who register and use the services. Enterprise customers sign separate Enterprise Terms of Service.",
          "The privacy policy (last updated 9 March 2026) names Cognition AI, Inc and covers Devin and Windsurf as well as cognition.com. The data processing agreement gives the address 550 Third Street, San Francisco, CA 94107.",
          "devin.ai, cognition.com and api.devin.ai all return 404 for /.well-known/security.txt. The docs give security@cognition.ai for vulnerability reports.",
          "The API answers at api.devin.ai and the MCP server at mcp.devin.ai. status.devin.ai redirects to www.devinstatus.com.",
          "RDAP for devin.ai gives a registration date of 2022-12-06."
        ],
        "score": 77
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/devin.json",
      "live": {
        "slug": "devin",
        "probe": {
          "target": "https://mcp.devin.ai/mcp",
          "method": "get",
          "lastAt": "2026-10-08T19:08:45.013833265Z",
          "lastOk": true,
          "lastStatus": 406,
          "lastMs": 426,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 450,
          "p95ms24h": 579,
          "samples24h": 19,
          "samples30d": 19,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 19,
              "ok": 19
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.devinstatus.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:06:34.332954915Z"
        },
        "pages": [
          {
            "url": "https://docs.devin.ai/release-notes/overview",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:39.860758812Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a85f82787c20"
          },
          {
            "url": "https://cognition.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:28.045423959Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0ab177a921b1"
          },
          {
            "url": "https://cognition.com/legal/platform-terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:26.004141328Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e794136b2fe5"
          }
        ],
        "updatedAt": "2026-10-08T19:08:45.013833265Z"
      }
    },
    "answer": "OpenHands scores 70.8 (BB) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth.",
    "b": {
      "slug": "openhands",
      "name": "OpenHands",
      "vendor": "All Hands AI",
      "vendorUrl": "https://openhands.dev",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Open-source coding agent with a self-hosted web interface, local and remote execution, and scheduled or webhook-driven automation.",
      "url": "https://www.anchorterminal.com/tools/openhands",
      "markdownUrl": "https://www.anchorterminal.com/tools/openhands.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/openhands.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/openhands.json",
      "repo": "https://github.com/OpenHands/OpenHands",
      "license": "MIT (Agent Canvas, SDK, tools and Agent Server). OpenHands Cloud is a hosted service",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@openhands/agent-canvas"
        },
        {
          "registry": "pypi",
          "name": "openhands-sdk"
        },
        {
          "registry": "pypi",
          "name": "openhands-agent-server"
        },
        {
          "registry": "oci",
          "name": "ghcr.io/openhands/agent-canvas"
        }
      ],
      "auth": "mixed",
      "authNotes": "Local installs bind to 127.0.0.1 and inject a session key into the page. Public mode (`--public`) needs `LOCAL_BACKEND_API_KEY`, sent as `X-Session-API-Key` on every API call. Model credentials are your own provider keys or an OpenHands LLM key, and OpenHands Cloud has its own sign-in and API keys.",
      "pricing": "freemium",
      "pricingNotes": "Agent Canvas, the SDK and the Agent Server are free and MIT. OpenHands Cloud has a free Individual plan of 10 conversations a day with your own model key or the OpenHands LLM provider, which the docs say bills model calls at provider rates with no markup. Enterprise (SaaS, or self-hosted in your VPC) is priced by sales.",
      "priceSummary": "Freemium",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing page or the source (checked 2026-10-01).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 89800,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-01"
      },
      "docsUrl": "https://docs.openhands.dev",
      "llmsTxt": "https://docs.openhands.dev/llms.txt",
      "openapi": "https://raw.githubusercontent.com/OpenHands/docs/main/openapi/agent-sdk.json",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "open-source",
        "local",
        "self-hosted",
        "hosted",
        "freemium",
        "python",
        "typescript",
        "docker",
        "openapi",
        "llms-txt",
        "telemetry-default-on",
        "beta"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 70.8,
        "grade": "BB",
        "agentReady": true,
        "rank": 120,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 78,
          "maintenance": 85,
          "payments": 60,
          "reliability": 83,
          "schema": 87,
          "security": 66,
          "transparency": 67
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "Current behaviour, checked 2026-10-02. Agent Canvas sends a `canvas_install` event with platform, user agent, referrer and origin to PostHog through OpenHands' proxy at z.openhands.dev on first use, before the consent prompt, opting the client in for that one event. The source comment says the proxy is there to get past ad blockers, the consent prompt's box is ticked by default, and no user-facing doc mentions the early event. Undisclosed telemetry, -3. https://github.com/OpenHands/OpenHands/blob/main/src/services/telemetry.ts",
          "2026-03-23. GHSA-7h8w-hj9j-8rjw (CVE-2026-33718, 7.6 in the advisory, 9.9 at NVD), command injection through the `path` parameter of the git diff endpoint let an authenticated user run commands in the agent sandbox. Fixed in 1.5.0 and published, a little over six months old, -1. https://github.com/OpenHands/OpenHands/security/advisories/GHSA-7h8w-hj9j-8rjw",
          "2026-08-06. CVE-2026-19022 (6.3), command injection in `initialize_repo` in the pull request resolver of OpenHands 0.62.0 and earlier, the V0 line the V1 rewrite replaced. No GitHub advisory found, -1. https://nvd.nist.gov/vuln/detail/CVE-2026-19022"
        ],
        "verdict": "A Docker container per conversation with `OH_CONVERSATION_RUNTIME=docker`, each with its own Agent Server. Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem.",
        "bestFor": "Teams that want to self-host a coding agent with a web UI, per-conversation Docker sandboxes and scheduled or webhook automations, or embed the agent through a Python SDK and REST API.",
        "strengths": [
          "A Docker container per conversation with `OH_CONVERSATION_RUNTIME=docker`, each with its own Agent Server",
          "Typed Python SDK and an Agent Server REST API with an OpenAPI 3.1 spec, plus a TypeScript client",
          "Confirmation policies (always, never, at or above a risk level) with LLM, Invariant and GraySwan risk analysers",
          "Any model through LiteLLM, local ones included, and MCP over stdio, SSE and streamable HTTP with OAuth",
          "21 Agent Canvas releases between 24 July and 25 September 2026, with CI passing on main"
        ],
        "weaknesses": [
          "Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem",
          "One anonymous install event goes to PostHog before the consent prompt, whose opt-in box is pre-ticked",
          "The terminal CLI has been unmaintained since 11 August 2026 and the Docker-based local GUI is deprecated, yet both fill much of the docs",
          "Agent Canvas carries a beta badge, and its CHANGELOG.md stops at 1.0.0-alpha.2",
          "The privacy policy (3 September 2025) allows training on Cloud content and gives no retention period"
        ],
        "agentNotes": [
          "Set `AGENT_CANVAS_DISABLE_TELEMETRY=1` and `DO_NOT_TRACK=1` before the first start",
          "Start Canvas with `OH_CONVERSATION_RUNTIME=docker` or use the Docker image. The npm install runs the agent on the host",
          "Turn on confirmation mode with a risk threshold. Canvas starts with it off",
          "Use the SDK or the Agent Server API for headless runs. The `openhands --headless` CLI is no longer maintained",
          "Set `filter_tools_regex` on the agent to keep unneeded MCP tool definitions out of the context"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 70.8
          }
        ],
        "editorialScores": {
          "ergonomics": 78,
          "maintenance": 85,
          "payments": 60,
          "reliability": 83,
          "schema": 87,
          "security": 66,
          "transparency": 67
        },
        "provenanceScore": 66
      },
      "connect": {
        "install": "npm install -g @openhands/agent-canvas   # Node 24+ and uv; or: pip install openhands-sdk openhands-tools",
        "headless": {
          "env": {
            "DO_NOT_TRACK": "1",
            "LLM_API_KEY": "\u003ckey\u003e",
            "LLM_MODEL": "\u003cprovider/model\u003e"
          },
          "sdk": "pip install openhands-sdk openhands-tools",
          "server": "OH_CONVERSATION_RUNTIME=docker AGENT_CANVAS_DISABLE_TELEMETRY=1 agent-canvas --backend-only"
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/openhands"
      },
      "area": "frameworks",
      "provenance": {
        "legalEntity": "All Hands AI",
        "domain": "openhands.dev",
        "domainRegistered": "",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "https://openhands.dev/privacy",
        "statusPage": "",
        "changelog": "https://github.com/OpenHands/OpenHands/releases",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The privacy policy (effective 3 September 2025) names All Hands AI, 24 Oak Street, Unit 2, Cambridge, MA 02139. We found no terms of service link on the pricing or privacy pages.",
          "openhands.dev/.well-known/security.txt lists security@openhands.dev and a responsible-disclosure policy, and expires on 2026-10-28.",
          "The SDK's LLM proxy still runs on llm-proxy.app.all-hands.dev, the company's older domain.",
          "We didn't check for a status page or the domain's registration date."
        ],
        "score": 66
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/openhands.json",
      "live": {
        "slug": "openhands",
        "versions": [
          {
            "registry": "github",
            "name": "OpenHands/OpenHands",
            "version": "v1.25.0",
            "released": "2026-10-06",
            "seenAt": "2026-10-08T16:24:11.333688688Z"
          },
          {
            "registry": "npm",
            "name": "@openhands/agent-canvas",
            "version": "1.25.0",
            "seenAt": "2026-10-08T16:24:08.391240484Z"
          },
          {
            "registry": "pypi",
            "name": "openhands-agent-server",
            "version": "1.53.0",
            "released": "2026-10-05",
            "seenAt": "2026-10-08T16:24:09.446438548Z"
          },
          {
            "registry": "pypi",
            "name": "openhands-sdk",
            "version": "1.53.0",
            "released": "2026-10-05",
            "seenAt": "2026-10-08T16:24:09.248506175Z"
          }
        ],
        "githubStars": 90281,
        "npmWeekly": 3432,
        "pypiWeekly": 1579833,
        "securityTxt": {
          "url": "https://openhands.dev/.well-known/security.txt",
          "state": "valid",
          "expires": "2026-10-28T17:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:58.056526129Z"
        },
        "llmsTxt": {
          "url": "https://docs.openhands.dev/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:43.374166906Z"
        },
        "domain": {
          "domain": "openhands.dev",
          "registered": "2025-07-23",
          "source": "https://pubapi.registry.google/rdap/domain/openhands.dev",
          "checkedAt": "2026-10-04T13:04:38.037291667Z"
        },
        "pages": [
          {
            "url": "https://openhands.dev/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:37.29100302Z",
            "changedAt": "2026-10-08T18:22:37.29100302Z",
            "fingerprint": "9b8b8341d3b4"
          }
        ],
        "updatedAt": "2026-10-08T18:22:37.29100302Z"
      }
    },
    "facts": [
      {
        "a": "Agent harness",
        "b": "Agent harness",
        "name": "Kind"
      },
      {
        "a": "Cognition AI, Inc.",
        "b": "All Hands AI",
        "name": "Vendor"
      },
      {
        "a": "https://mcp.devin.ai/mcp",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Cognition's Platform Terms of Service",
        "b": "MIT (Agent Canvas, SDK, tools and Agent Server). OpenHands Cloud is a hosted service",
        "name": "Licence"
      },
      {
        "a": "13",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-07",
        "b": "2026-09-30",
        "name": "Last release"
      },
      {
        "a": "2026-06-30",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2026-03-09",
        "b": "2025-09-03",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes, with an opt-out",
        "b": "yes",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "none",
        "b": "90k stars",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "2.5/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "OpenHands scores 70.8 (BB) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth.",
        "question": "Which is better for AI agents, Devin or OpenHands?"
      },
      {
        "answer": "No open-source release is listed for Devin. OpenHands is open source (MIT (Agent Canvas, SDK, tools and Agent Server). OpenHands Cloud is a hosted service).",
        "question": "Are Devin and OpenHands open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Security \u0026 auth, 72 against 66"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "No incidents deducted, where OpenHands loses 5 points for them"
        ],
        "goodFor": "A team that wants to hand whole tasks to a cloud agent and collect pull requests, driven from a pipeline or another agent.",
        "slug": "devin",
        "watchFor": "www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026"
      },
      {
        "aheadOn": [
          "Reliability, 83 against 30",
          "Schema \u0026 documentation, 87 against 80",
          "Agent ergonomics, 78 against 62",
          "Payments \u0026 pricing, 60 against 20",
          "Maintenance \u0026 community, 85 against 63"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "Open source"
        ],
        "goodFor": "Teams that want to self-host a coding agent with a web UI, per-conversation Docker sandboxes and scheduled or webhook automations, or embed the agent through a Python SDK and REST API.",
        "slug": "openhands",
        "watchFor": "Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem"
      }
    ],
    "job": {
      "capability": "agent.harness",
      "name": "Agent harness"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/aider-vs-devin.json",
        "title": "Aider vs Devin",
        "url": "https://www.anchorterminal.com/compare/aider-vs-devin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/aider-vs-openhands.json",
        "title": "Aider vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/aider-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amp-vs-devin.json",
        "title": "Amp vs Devin",
        "url": "https://www.anchorterminal.com/compare/amp-vs-devin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amp-vs-openhands.json",
        "title": "Amp vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/amp-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/claude-code-vs-devin.json",
        "title": "Claude Code vs Devin",
        "url": "https://www.anchorterminal.com/compare/claude-code-vs-devin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/claude-code-vs-openhands.json",
        "title": "Claude Code vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/claude-code-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cline-vs-devin.json",
        "title": "Cline vs Devin",
        "url": "https://www.anchorterminal.com/compare/cline-vs-devin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cline-vs-openhands.json",
        "title": "Cline vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/cline-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-devin.json",
        "title": "Cursor CLI vs Devin",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-devin"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cursor-cli-vs-openhands.json",
        "title": "Cursor CLI vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/cursor-cli-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-earendil-pi.json",
        "title": "Devin vs Pi",
        "url": "https://www.anchorterminal.com/compare/devin-vs-earendil-pi"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-gemini-cli.json",
        "title": "Devin vs Gemini CLI",
        "url": "https://www.anchorterminal.com/compare/devin-vs-gemini-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-github-copilot-cli.json",
        "title": "Devin vs GitHub Copilot CLI",
        "url": "https://www.anchorterminal.com/compare/devin-vs-github-copilot-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-goose.json",
        "title": "Devin vs goose",
        "url": "https://www.anchorterminal.com/compare/devin-vs-goose"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-kiro-cli.json",
        "title": "Devin vs Kiro CLI",
        "url": "https://www.anchorterminal.com/compare/devin-vs-kiro-cli"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-openai-codex.json",
        "title": "Devin vs OpenAI Codex",
        "url": "https://www.anchorterminal.com/compare/devin-vs-openai-codex"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-opencode.json",
        "title": "Devin vs OpenCode",
        "url": "https://www.anchorterminal.com/compare/devin-vs-opencode"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-prime-agent.json",
        "title": "Devin vs Prime Agent",
        "url": "https://www.anchorterminal.com/compare/devin-vs-prime-agent"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-qwen-code.json",
        "title": "Devin vs Qwen Code",
        "url": "https://www.anchorterminal.com/compare/devin-vs-qwen-code"
      },
      {
        "json": "https://www.anchorterminal.com/compare/earendil-pi-vs-openhands.json",
        "title": "Pi vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/earendil-pi-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/gemini-cli-vs-openhands.json",
        "title": "Gemini CLI vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/gemini-cli-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-openhands.json",
        "title": "GitHub Copilot CLI vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/goose-vs-openhands.json",
        "title": "goose vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/goose-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/kiro-cli-vs-openhands.json",
        "title": "Kiro CLI vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/kiro-cli-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openai-codex-vs-openhands.json",
        "title": "OpenAI Codex vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/openai-codex-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/opencode-vs-openhands.json",
        "title": "OpenCode vs OpenHands",
        "url": "https://www.anchorterminal.com/compare/opencode-vs-openhands"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openhands-vs-prime-agent.json",
        "title": "OpenHands vs Prime Agent",
        "url": "https://www.anchorterminal.com/compare/openhands-vs-prime-agent"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openhands-vs-qwen-code.json",
        "title": "OpenHands vs Qwen Code",
        "url": "https://www.anchorterminal.com/compare/openhands-vs-qwen-code"
      },
      {
        "json": "https://www.anchorterminal.com/compare/devin-vs-paperclip.json",
        "title": "Devin vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/devin-vs-paperclip"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openhands-vs-paperclip.json",
        "title": "OpenHands vs Paperclip",
        "url": "https://www.anchorterminal.com/compare/openhands-vs-paperclip"
      }
    ],
    "scores": [
      {
        "by": 53,
        "devin": 30,
        "edge": "openhands",
        "key": "reliability",
        "name": "Reliability",
        "openhands": 83,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 7,
        "devin": 80,
        "edge": "openhands",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "openhands": 87,
        "weight": 13
      },
      {
        "by": 16,
        "devin": 62,
        "edge": "openhands",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "openhands": 78,
        "weight": 13
      },
      {
        "by": 6,
        "devin": 72,
        "edge": "devin",
        "key": "security",
        "name": "Security \u0026 auth",
        "openhands": 66,
        "weight": 14
      },
      {
        "by": 40,
        "devin": 20,
        "edge": "openhands",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "openhands": 60,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 22,
        "devin": 63,
        "edge": "openhands",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "openhands": 85,
        "weight": 7
      },
      {
        "by": 2,
        "devin": 69,
        "edge": "devin",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "openhands": 67,
        "weight": 7
      }
    ],
    "summary": "OpenHands scores 70.8 (BB) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth. Both do agent harness.",
    "verdicts": {
      "devin": "The v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation.",
      "openhands": "A Docker container per conversation with `OH_CONVERSATION_RUNTIME=docker`, each with its own Agent Server. Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/devin-vs-openhands",
    "json": "https://www.anchorterminal.com/compare/devin-vs-openhands.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/devin-vs-openhands.md",
    "slim": "https://www.anchorterminal.com/compare/devin-vs-openhands.min.md"
  },
  "markdown": "OpenHands scores 70.8 (BB) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth. Both do agent harness.\n\n- Devin: grade C, 55.7/100, rank #447 of 629. Markdown https://www.anchorterminal.com/tools/devin.md · JSON https://www.anchorterminal.com/api/v1/tools/devin.json\n- OpenHands: grade BB, 70.8/100, rank #120 of 629. Markdown https://www.anchorterminal.com/tools/openhands.md · JSON https://www.anchorterminal.com/api/v1/tools/openhands.json\n\n## Which one, for what\n\n### Devin (C)\n\nGood for: A team that wants to hand whole tasks to a cloud agent and collect pull requests, driven from a pipeline or another agent.\n\nAhead on:\n- Security \u0026 auth, 72 against 66\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- No incidents deducted, where OpenHands loses 5 points for them\n\nWatch for: www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026\n\n### OpenHands (BB)\n\nGood for: Teams that want to self-host a coding agent with a web UI, per-conversation Docker sandboxes and scheduled or webhook automations, or embed the agent through a Python SDK and REST API.\n\nAhead on:\n- Reliability, 83 against 30\n- Schema \u0026 documentation, 87 against 80\n- Agent ergonomics, 78 against 62\n- Payments \u0026 pricing, 60 against 20\n- Maintenance \u0026 community, 85 against 63\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- Open source\n\nWatch for: Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem\n\n\n## Score by category\n\n| Category | Weight | Devin | OpenHands | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 30 | 83 | OpenHands +53 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 80 | 87 | OpenHands +7 |\n| Agent ergonomics | 13% (16.2 this run) | 62 | 78 | OpenHands +16 |\n| Security \u0026 auth | 14% (17.5 this run) | 72 | 66 | Devin +6 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 60 | OpenHands +40 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 63 | 85 | OpenHands +22 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 69 | 67 | Devin +2 |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **55.7 · C** | **70.8 · BB** | |\n\n## Facts side by side\n\n| Fact | Devin | OpenHands |\n| --- | --- | --- |\n| Kind | Agent harness | Agent harness |\n| Vendor | Cognition AI, Inc. | All Hands AI |\n| Hosted endpoint | `https://mcp.devin.ai/mcp` | no (local only) |\n| Transports | HTTP |  |\n| Auth | API key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Cognition's Platform Terms of Service | MIT (Agent Canvas, SDK, tools and Agent Server). OpenHands Cloud is a hosted service |\n| Tools exposed | 13 | none |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-07 | 2026-09-30 |\n| Terms last updated | 2026-06-30 | no document linked |\n| Privacy policy last updated | 2026-03-09 | 2025-09-03 |\n| Customer content may train models | yes, with an opt-out | yes |\n| Terms restrict automated access | not found in the text |  |\n| Terms restrict benchmarking | yes |  |\n| Terms or service can change without notice | not found in the text |  |\n| Arbitration or class-action waiver | yes |  |\n| Popularity | none | 90k stars |\n| Agent reviews | none | 2.5/5 (2) |\n\n## Verdicts\n\n**Devin.** The v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation.\n\n**OpenHands.** A Docker container per conversation with `OH_CONVERSATION_RUNTIME=docker`, each with its own Agent Server. Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem.\n\n## Before you call either\n\n### Devin\n\n1. Use a `cog_` service-user key with the Member role. Legacy `apk_` keys fail against v3 and the MCP server with 401 or 403\n2. Set `max_acu_limit` on every session you create. Usage is metered by the work done and has no published unit rate\n3. Session creation is not idempotent in v3. After a timeout, list sessions by tag before creating again\n4. Enterprise keys and personal access tokens must send `X-Org-Id` to the MCP server. Organisation-scoped keys resolve it automatically\n5. Create scheduled work as an automation. POST to the schedules endpoint returns 403 for migrated organisations since 24 September 2026\n\n### OpenHands\n\n1. Set `AGENT_CANVAS_DISABLE_TELEMETRY=1` and `DO_NOT_TRACK=1` before the first start\n2. Start Canvas with `OH_CONVERSATION_RUNTIME=docker` or use the Docker image. The npm install runs the agent on the host\n3. Turn on confirmation mode with a risk threshold. Canvas starts with it off\n4. Use the SDK or the Agent Server API for headless runs. The `openhands --headless` CLI is no longer maintained\n5. Set `filter_tools_regex` on the agent to keep unneeded MCP tool definitions out of the context\n\n## Questions\n\n### Which is better for AI agents, Devin or OpenHands?\n\nOpenHands scores 70.8 (BB) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth.\n\n### Are Devin and OpenHands open source?\n\nNo open-source release is listed for Devin. OpenHands is open source (MIT (Agent Canvas, SDK, tools and Agent Server). OpenHands Cloud is a hosted service).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/devin-vs-openhands.json, and with the fewest tokens: https://www.anchorterminal.com/compare/devin-vs-openhands.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"devin\", \"b\": \"openhands\"}`. From a terminal: `anchor compare devin openhands`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/devin.json and https://www.anchorterminal.com/api/v1/tools/openhands.json\n\n## Other comparisons with Devin or OpenHands\n\n- [Aider vs Devin](https://www.anchorterminal.com/compare/aider-vs-devin.md)\n- [Aider vs OpenHands](https://www.anchorterminal.com/compare/aider-vs-openhands.md)\n- [Amp vs Devin](https://www.anchorterminal.com/compare/amp-vs-devin.md)\n- [Amp vs OpenHands](https://www.anchorterminal.com/compare/amp-vs-openhands.md)\n- [Claude Code vs Devin](https://www.anchorterminal.com/compare/claude-code-vs-devin.md)\n- [Claude Code vs OpenHands](https://www.anchorterminal.com/compare/claude-code-vs-openhands.md)\n- [Cline vs Devin](https://www.anchorterminal.com/compare/cline-vs-devin.md)\n- [Cline vs OpenHands](https://www.anchorterminal.com/compare/cline-vs-openhands.md)\n- [Cursor CLI vs Devin](https://www.anchorterminal.com/compare/cursor-cli-vs-devin.md)\n- [Cursor CLI vs OpenHands](https://www.anchorterminal.com/compare/cursor-cli-vs-openhands.md)\n- [Devin vs Pi](https://www.anchorterminal.com/compare/devin-vs-earendil-pi.md)\n- [Devin vs Gemini CLI](https://www.anchorterminal.com/compare/devin-vs-gemini-cli.md)\n- [Devin vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/devin-vs-github-copilot-cli.md)\n- [Devin vs goose](https://www.anchorterminal.com/compare/devin-vs-goose.md)\n- [Devin vs Kiro CLI](https://www.anchorterminal.com/compare/devin-vs-kiro-cli.md)\n- [Devin vs OpenAI Codex](https://www.anchorterminal.com/compare/devin-vs-openai-codex.md)\n- [Devin vs OpenCode](https://www.anchorterminal.com/compare/devin-vs-opencode.md)\n- [Devin vs Prime Agent](https://www.anchorterminal.com/compare/devin-vs-prime-agent.md)\n- [Devin vs Qwen Code](https://www.anchorterminal.com/compare/devin-vs-qwen-code.md)\n- [Pi vs OpenHands](https://www.anchorterminal.com/compare/earendil-pi-vs-openhands.md)\n- [Gemini CLI vs OpenHands](https://www.anchorterminal.com/compare/gemini-cli-vs-openhands.md)\n- [GitHub Copilot CLI vs OpenHands](https://www.anchorterminal.com/compare/github-copilot-cli-vs-openhands.md)\n- [goose vs OpenHands](https://www.anchorterminal.com/compare/goose-vs-openhands.md)\n- [Kiro CLI vs OpenHands](https://www.anchorterminal.com/compare/kiro-cli-vs-openhands.md)\n- [OpenAI Codex vs OpenHands](https://www.anchorterminal.com/compare/openai-codex-vs-openhands.md)\n- [OpenCode vs OpenHands](https://www.anchorterminal.com/compare/opencode-vs-openhands.md)\n- [OpenHands vs Prime Agent](https://www.anchorterminal.com/compare/openhands-vs-prime-agent.md)\n- [OpenHands vs Qwen Code](https://www.anchorterminal.com/compare/openhands-vs-qwen-code.md)\n- [Devin vs Paperclip](https://www.anchorterminal.com/compare/devin-vs-paperclip.md)\n- [OpenHands vs Paperclip](https://www.anchorterminal.com/compare/openhands-vs-paperclip.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Devin vs OpenHands",
        "url": ""
      }
    ],
    "description": "OpenHands scores 70.8 (BB) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security \u0026 auth. Both do agent harness. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Devin C 55.7",
      "OpenHands BB 70.8",
      "scores"
    ],
    "h1": "Devin vs OpenHands",
    "image": "https://www.anchorterminal.com/assets/og/compare-devin-vs-openhands.png",
    "path": "/compare/devin-vs-openhands",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Devin vs OpenHands for AI agents, C 55.7 vs BB 70.8 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/devin-vs-openhands"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 730
  },
  "version": 1
}
