Head to head · Agent multi agent · October 2026 research run

Devin vs Paperclip

Paperclip scores 59 (C) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security & auth. Both do agent multi agent.

Which one, for what

Devin C

Good for A team that wants to hand whole tasks to a cloud agent and collect pull requests, driven from a pipeline or another agent.

Ahead on

  • Security & auth, 72 against 64

Also in its favour

  • A hosted endpoint, with nothing to install
  • No incidents deducted, where Paperclip loses 10 points for them

Watch for

www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026

Paperclip C

Good for Someone running several coding or operations agents who wants one place for tasks, budgets, approvals and history across harnesses.

Ahead on

  • Reliability, 66 against 30
  • Agent ergonomics, 70 against 62
  • Payments & pricing, 60 against 20
  • Maintenance & community, 78 against 63

Also in its favour

  • Free to start without a card
  • Open source

Watch for

claude_local defaults dangerouslySkipPermissions to true and codex_local defaults to bypassing approvals and the sandbox, with agents running on the host

Score by category

CategoryWeight this runDevinPaperclipEdge
Reliability16%203066Paperclip +36
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28081Paperclip +1
Agent ergonomics13%16.26270Paperclip +8
Security & auth14%17.57264Devin +8
Payments & pricing10%12.52060Paperclip +40
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86378Paperclip +15
Transparency & trust7%8.86965Devin +4
Negative events≤150-10
Total55.7 · C59 · C

Facts side by side

FactDevinPaperclip
KindAgent harnessAgent harness
VendorCognition AI, Inc.Paperclip Labs, Inc.
Hosted endpointhttps://mcp.devin.ai/mcpno (local only)
TransportsHTTP
AuthAPI keyOAuth or key
PricingFreemiumFree
x402nono
LicenceProprietary service under Cognition's Platform Terms of ServiceMIT
Tools exposed13none
Read-only variant documentedyesno
llms.txtyesyes
Last release2026-10-072026-10-05
Terms last updated2026-06-302026-07-23
Privacy policy last updated2026-03-092026-07-23
Customer content may train modelsyes, with an opt-outyes, with an opt-out
Terms restrict automated accessnot found in the textnot found in the text
Terms restrict benchmarkingyesnot found in the text
Terms or service can change without noticenot found in the textnot found in the text
Arbitration or class-action waiveryesyes
Popularitynone99k stars, 60k npm/wk

Verdicts

Devin

The v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation.

Paperclip

Board approvals, budgets with a hard stop and an activity log sit above whichever harnesses do the work, and eleven stable versions shipped in 90 days. The Claude Code and Codex adapters skip permission prompts and the sandbox by default, and twelve security advisories, five of them critical, have been published since April 2026.

Before you call either

Devin

  1. Use a cog_ service-user key with the Member role. Legacy apk_ keys fail against v3 and the MCP server with 401 or 403
  2. Set max_acu_limit on every session you create. Usage is metered by the work done and has no published unit rate
  3. Session creation is not idempotent in v3. After a timeout, list sessions by tag before creating again
  4. Enterprise keys and personal access tokens must send X-Org-Id to the MCP server. Organisation-scoped keys resolve it automatically
  5. Create scheduled work as an automation. POST to the schedules endpoint returns 403 for migrated organisations since 24 September 2026

Paperclip

  1. Set PAPERCLIP_TELEMETRY_DISABLED=1 or DO_NOT_TRACK=1 before the first start. Telemetry is on by default
  2. Set dangerouslySkipPermissions and dangerouslyBypassApprovalsAndSandbox to false on agents that read untrusted input, or run them in a sandbox provider
  3. Install with Node.js 24.11 or newer, and install and sign in to each harness CLI on the host first. Paperclip assumes they are there
  4. Use --bind lan or --bind tailnet at onboarding for anything beyond one machine. The default local_trusted mode treats every request as the board admin
  5. Treat 409 on task checkout as owned by another agent and pick different work. The API docs say not to retry

Questions

Which is better for AI agents, Devin or Paperclip?

Paperclip scores 59 (C) on agent readiness against Devin's 55.7 (C), and leads in 5 of 7 scored categories. Devin leads on security & auth.

Are Devin and Paperclip open source?

No open-source release is listed for Devin. Paperclip is open source (MIT).

Other comparisons with Devin or Paperclip

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.