Devin

by Cognition AI, Inc. Agent harness in Agent harnesses

Hosted

Cognition AI, Inc. · devin.ai since 2022 · status page · who's behind it

Devin is Cognition's hosted coding agent. It works in its own cloud virtual machine to plan, edit code, run commands and open pull requests. Outside agents start and steer sessions through a REST API and a remote MCP server.

Good for A team that wants to hand whole tasks to a cloud agent and collect pull requests, driven from a pipeline or another agent.

Is this your product? Claim this listing or verify it

Assessment. The v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation.

Facts

Transport
HTTP
Endpoint
https://mcp.devin.ai/mcp
Auth
API key
Pricing
Freemium · $20 / mo
x402
No
Licence
Proprietary service under Cognition's Platform Terms of Service
Tools exposed
13
llms.txt
published
Last release
Interfaces
REST API v3 at https://api.devin.ai/v3 (organisation and enterprise scopes), remote MCP server at https://mcp.devin.ai/mcp, web app, Slack, and a Terraform provider. Devin CLI and Devin Desktop are separate local products
Session API
Create, list, get, message, terminate and archive sessions, with tags, attachments and insights. Only prompt is required. Options include max_acu_limit, playbook_id, repos, devin_mode, structured_output_schema (JSON Schema Draft 7, 64KB) and security_profile
MCP tools
read_wiki_structure, read_wiki_contents, ask_question, list_available_repos, devin_session_create, devin_session_search, devin_session_interact, devin_session_events, devin_session_gather, devin_playbook_manage, devin_knowledge_manage, devin_schedule_manage, devin_list_integrations
Credentials
Service-user keys with a role, shown once. Personal access tokens with optional expiry on Teams and mandatory expiry (365 days by default) on Enterprise. Key rotation and revocation endpoints for enterprise service users are in beta
Permissions
Every endpoint except GET /v3/self needs a named permission, such as UseDevinSessions, ViewOrgSessions, ManageOrgSessions or ManageOrgSecrets
Sandbox and network
Each session runs in a cloud virtual machine. A security profile can restrict it to an allowlist of hostnames and CIDR ranges, read-only git, and no GitHub CLI token. Without a profile, sessions can use any MCP server installed in the organisation
MCP client
Devin connects to external MCP servers over stdio, SSE and HTTP, installed from a plugin marketplace or added as custom servers by an admin
Pagination
Cursor-based on every v3 list endpoint, with first and after, returning items, has_next_page, end_cursor and sometimes total
Errors
RFC 9457 application/problem+json with title, status, detail, an optional error_code and field errors on 422
Rate limits
429 is documented as a response. No figures found in the reviewed documentation
Metering
Usage accrues by the actions Devin takes plus virtual machine time. Sessions sleep after 30 minutes idle and use nothing while asleep. Windows sessions use about 9 per cent more
Certifications
SOC 2 Type II since September 2024 per the docs, and ISO/IEC 27001:2022 and CCPA listed on trust.cognition.ai. Reports need an access request and an NDA
Status
www.devinstatus.com on Atlassian Statuspage, 14 components, among them Cloud Agent, Cloud Web Client and Integrations
Sub-processors
Listed with locations in Appendix C of the data processing agreement of 23 July 2026. Azure, AWS and Google Cloud for core processing, OpenAI, Anthropic and Google as model providers, all in the United States, and a Cognition affiliate in India for support

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • Public OpenAPI 3.1 spec for the v3 API with 239 operations, each declaring 401, 403, 404, 409, 422 and 429 responses in RFC 9457 problem+json
  • Service-user keys carry a role, every endpoint except GET /v3/self names the permission it needs, and audit logs list service users separately from people
  • Security profiles can limit a session to a network allowlist, an MCP server allowlist, read-only git and a read-only Devin MCP
  • Remote MCP server at mcp.devin.ai/mcp with 13 documented tools for sessions, playbooks, knowledge, schedules and repository documentation
  • Dated release notes several times a week, the newest on 7 October 2026, and a separate API release notes page

Weaknesses

  • www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026
  • No rate limit figures, Retry-After or backoff guidance found in the API docs, and v3 session creation has no idempotency key
  • Customer data may be used for model training by default on self-serve plans. The opt-out is for paid plans only, per section 3.3.1 of the platform terms
  • A person must sign up and provision the service user in the web app. No key-creation route exists for an agent starting from nothing
  • No official SDK found, and the Devin MCP server was not found in the official MCP registry

Before you call it notes for agents

  1. Use a cog_ service-user key with the Member role. Legacy apk_ keys fail against v3 and the MCP server with 401 or 403
  2. Set max_acu_limit on every session you create. Usage is metered by the work done and has no published unit rate
  3. Session creation is not idempotent in v3. After a timeout, list sessions by tag before creating again
  4. Enterprise keys and personal access tokens must send X-Org-Id to the MCP server. Organisation-scoped keys resolve it automatically
  5. Create scheduled work as an automation. POST to the schedules endpoint returns 403 for migrated organisations since 24 September 2026

Who's behind it provenance 77/100

  • Legal entity namedCognition AI, Inc.20/20
  • Domain agedevin.ai, registered 2022-12-06 (3 years)7/15
  • Endpoint on the vendor's domainmcp.devin.ai15/15
  • Terms of serviceread, states 6 of the 7 things a reader expects, and has 1 clause that costs points7.1/10
  • Privacy policyread, states 8 of the 8 things a reader expects, and has 1 clause that costs points8/10
  • Status pagewww.devinstatus.com10/10
  • Changelogpublished10/10
  • security.txtnot found0/10

Terms and privacy, as read

Terms of service dated 2026-06-30, states 6 of 7, 4 to know

TL;DR Dated 2026-06-30. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, model training with an opt-out, limits on benchmarking, cut-off without notice or for any reason and arbitration or a class action waiver.

Says it may use customer content to train or improve models, and gives an opt-out
Cognition may use Customer Data for model training purposes and to improve and enhance the Services. If you subscribe to a paid Service Tier, you may opt out of this use (“Opt-Out”).

Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.

Restricts benchmarking or competitive usecosts points
use the Services to create or develop any competing products or services, including to train competing artificial intelligence models except as expressly approved by Cognition in writing

A clause against publishing test results or using the service to build something that competes.

Says access can be ended without notice or for any reason
In addition, if you have a subscription, we may terminate the subscription at any time for any other reason.

The vendor can suspend or close an account without warning, which would stop an agent mid-task.

Requires arbitration or waives class actions
11.1 IN THE EVENT A DISPUTE, CONTROVERSY, OR CLAIM ARISES OUT OF OR RELATING TO THESE TERMS (“DISPUTE”), THE DISPUTE WILL BE RESOLVED BY BINDING ARBITRATION RATHER THAN IN COURT.

Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.

Gives the date it was last updated Last updated 2026-06-30
Last updated: June 30, 2026

Without a date nobody can tell which version they agreed to.

Names the governing law or courts The law of the State of New York
12.6 Governing Law: This Agreement is governed by and construed in accordance with the internal laws of the State of New York without giving effect to any choice or conflict of law provision or rule that would require or permit the application of the laws of any jurisdiction other than those of the State of New York.

Says where a dispute would be heard and under whose law.

States a limit on its liability Capped at the greater of US$100 and the fees paid in the 6 months before the claim
10.2 NOTWITHSTANDING ANYTHING TO THE CONTRARY IN THIS AGREEMENT, IN NO EVENT WILL EITHER PARTY'S AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO ANY CLAIM ARISING IN CONNECTION WITH THIS AGREEMENT UNDER ANY LEGAL OR EQUITABLE THEORY, INCLUDING BREACH OF CONTRACT, TORT (INCLUDING NEGLIGENCE) AND STRICT LIABILITY, EXCE…

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
7.2 Subscription Termination: You may terminate your subscription at any time.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced Gives 30 days of notice before a change
This update may include material changes to your prior Terms of Service, and in such case, the prior terms shall control until 30 days from the posting of these Terms.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
2.3 Restrictions: You may not use the Services for any purposes beyond the scope of the access granted in this Agreement.

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment

Not found in the text.

Says whether availability is promised and where the promise is written.

Either party's total liability is capped at the greater of the amounts paid in the six months before the event or 100 US dollars.
EXCEED THE GREATER OF (A) THE TOTAL AMOUNTS PAID TO COGNITION UNDER THIS AGREEMENT IN THE SIX MONTH PERIOD PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR (B) ONE HUNDRED DOLLARS (US$100).

Noted by a second reader on 2026-10-08.

Cognition may delete Customer Data when the terms or the subscription end, and the customer is responsible for its own backups.
Upon termination of these Terms or your subscription, we may at our option delete any Customer Data or other data associated with your account.

Noted by a second reader on 2026-10-08.

The customer agrees not to process medical information or sensitive personal data, such as birth dates, bank account numbers and card numbers, through the Services.
You agree not to process any medical information or sensitive personal data such as social security numbers, birth dates, passport information, bank account, and credit card numbers in using the Services.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 5,818 words

Privacy policy dated 2026-03-09, states 8 of 8, 1 to know

TL;DR Dated 2026-03-09. States all 8 things a reader expects. To know before relying on it, model training with no opt-out found.

Says it may use customer content to train or improve models, and no opt-out was foundcosts points
To customize your experience with our Services and otherwise improve our Services including, depending on the terms that apply to your use of the Services, using User Content to train, fine tune and improve the models that power our Services.

Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.

Gives the date it was last updated Last updated 2026-03-09
Last updated: March 9, 2026

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
We collect and use your information in order to provide and improve our Services and your experience, protect the security and integrity of our platform, and meet our legal obligations.

The basic statement a privacy policy exists to make.

Says how long data is kept
How long we retain personal information includes considerations such as when the information was collected or created, whether it is necessary in order to continue offering you our Services, whether we are required to hold the information to comply with our legal obligations, or information preservation requirements.

Says when data sent to the service is deleted.

Says who else receives the data
We share your information with trusted third parties and service providers in order to offer our Services, fulfill legal requirements and for the purposes set out more fully below.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising Says it does not sell personal data
We do not sell or share your personal information with third parties for targeted advertising purposes, nor have we done so in the past 12 months.

A plain statement either way.

Says what rights people have over their data
In the EEA and UK, you have the right to object to, and seek restrictions of this processing (“Legitimate Interests”) — specifically, our interest in being responsive to your requests and ensuring you have the best use of the Services

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact privacy@cognition.ai
If you have any questions, or to exercise any available rights, please contact us at privacy@cognition.ai.

An address or officer to send a request to.

Says where data is transferred or stored Relies on standard contractual clauses
…these transfers of your personal information, including in some cases the European Commission's Standard Contractual Clauses and relevant local clauses (e.g., the UK's International Data Transfer Addendum) to facilitate the international and onward transfer of European personal data to third countries.

The countries data goes to and the safeguard used.

Administrators of an enterprise or business account may be able to access a member's User Content and control the member's account.
In addition, administrators of any enterprise or business account may be able to access certain information associated with your account, including your User Content, and be able to control your account and such information.

Noted by a second reader on 2026-10-08.

The privacy policy says users must be at least 18 years old to access the Services.
As set out in our Terms, users must be at least 18 years old in order to access the Services.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 2,610 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The Platform Terms of Service (last updated 30 June 2026) name Cognition AI, Inc. and govern the Cognition Platform for customers who register and use the services. Enterprise customers sign separate Enterprise Terms of Service.

The privacy policy (last updated 9 March 2026) names Cognition AI, Inc and covers Devin and Windsurf as well as cognition.com. The data processing agreement gives the address 550 Third Street, San Francisco, CA 94107.

devin.ai, cognition.com and api.devin.ai all return 404 for /.well-known/security.txt. The docs give security@cognition.ai for vulnerability reports.

The API answers at api.devin.ai and the MCP server at mcp.devin.ai. status.devin.ai redirects to www.devinstatus.com.

RDAP for devin.ai gives a registration date of 2022-12-06.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-08 19:08 UTC

Right nowUpHTTP 406 · 426 ms · 2 minutes ago
Uptime 24h100.0%19 probes
Uptime 30 days100.0%19 probes
p50 24h450 msget
p95 24h579 msopen endpoint

Probed every five minutes at https://mcp.devin.ai/mcp. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

  • Vendor status page all systems normal, All Systems Operational · 4 minutes ago

Pages we watch

PageKindLast checkedLast changed
docs.devin.ai/release-notes/overviewchangelog52 minutes ago · 200no change seen
cognition.com/legal/privacy-policyprivacy54 minutes ago · 200no change seen
cognition.com/legal/platform-terms-of-serviceterms54 minutes ago · 200no change seen

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/devin.json

Notable

  • The v3 OpenAPI 3.1 spec has 158 paths and 239 operations, 44 of them under /v3beta1, and every operation declares problem+json errors source
  • The Devin MCP server answers over streamable HTTP at https://mcp.devin.ai/mcp with 13 documented tools, and the older /sse endpoint is deprecated source
  • Security profiles bundle a network allowlist, an MCP server allowlist, a git access level and a read-only setting for the Devin MCP, bound to an organisation, an automation or a session source
  • The platform terms of 30 June 2026 let Cognition use customer data for model training unless a paid customer opts out, and Enterprise data is not trained on without written consent source
  • The status page lists 13 incidents between 8 July and 24 September 2026, three marked critical source
  • The v1 and v2 APIs are deprecated with no end date given. The migration guide says legacy keys will be removed soon source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 6.0
Hosted reading. Status page at www.devinstatus.com with 14 components and incident history (20). In the 90 days to 8 October 2026 it lists three critical incidents (22 July, 43 minutes of platform-wide queuing, 13 August, Devin Cloud unavailable for 2 hours 40 minutes, 24 September, the web app down for 2 hours) and six major ones on session start-up, so several majors (0). 429 is a documented response, but no rate limit figures were found (0). No Retry-After or backoff guidance found, and v3 session creation has no idempotency key, although the legacy v1 API had one (0). The platform terms supply the service as is with no service level, and enterprise terms weren't read (0). The v3 API is the current, recommended surface, with 44 of 239 operations marked beta under /v3beta1 (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 13.0
API reading. Public OpenAPI 3.1 spec for v3 with 239 operations, and separate v1 and v2 specs (25). llms.txt with 376 lines and a Markdown twin of every page (10). Each endpoint page names its required permission, but 61 of 239 operations have no description and the MCP tool descriptions are one line each (10). Enums on fields such as devin_mode, origin and category, with most strings unconstrained and nullable (9). curl examples in the quick starts, and a problem+json error schema declared on every operation, without a catalogue of error_code values (11). Versioned paths (v1, v2, v3, v3beta1) and a dated API release notes page (15).
Agent ergonomics 13%16.2 10.1
API and MCP reading. The MCP server documents 13 tools, several of them consolidated manage tools, and list endpoints take first to size a page (17). Cursor pagination on every v3 list endpoint and filters on session search by tag, playbook, origin, user and time (18). problem+json with error_code, field-level errors on 422 and a 400 that lists valid platform names, but no published code list (15). No idempotency key on v3 session creation. max_acu_limit caps what a session can spend, and the MCP tool annotations couldn't be read without a key (4). Only prompt is required to start a session. No official SDK found, only a Terraform provider (8).
Security & auth 14%17.5 12.6
Hosted reading. Service-user keys with roles and named permissions per endpoint, revocable, with rotation endpoints in beta for Enterprise and expiring personal tokens. Custom roles are an Enterprise option, and Teams has Admin and Member only (25). Security profiles restrict network, MCP servers, git and the Devin MCP to read-only, and read-only API permissions exist. They are opt-in, and session creation accepts bypass_approval (16). AI Guardrails screen user messages and pull request comments for prompt injection, on Enterprise only, and they don't cover web pages or repository content Devin reads (8). Audit logs through the API need an enterprise-level permission. Session events and insights are available on all plans (10). SOC 2 Type II and ISO/IEC 27001:2022, a disclosure address at security@cognition.ai, no security.txt, and the trust centre answers No to having a bug bounty (13).
Payments & pricing 10%12.5 2.5
Published rubric. No payment protocol (0). Plan prices are public, $20, $200 and $40 a seat with an $80 team minimum, but usage past the quota is billed at an unpublished rate (10). A Free plan exists. The pricing page lists cloud agents from Pro upward, and we couldn't confirm API use on Free or whether a card is needed (10). A person signs up in a browser and provisions the service user in settings (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 5.5
Closed service. Newest release note dated 7 October 2026 (30). Nineteen dated release notes between 7 August and 7 October 2026, and API notes for August and September (20). Public release notes and a support address, with no public tracker or forum found (10). No official SDK found and the Devin MCP server didn't appear in a search of the official MCP registry (0). No public CI or packages to assess, with the docs and three OpenAPI specs kept current (3).
Transparency & trusteditorial 61, provenance 77 7%8.8 6.0
Editorial half. Closed source with clear terms from Cognition AI, Inc. (15). Terms, privacy policy, security page and data processing agreement agree with each other. Customer data may be used for model training by default on self-serve plans, with an opt-out on paid plans that also turns on zero data retention at model providers. Retention is stated as the length of the customer relationship, with no periods (18). Dated notices for the schedules endpoints (announced 10 September, creation refused from 24 September 2026) and the v2 clone endpoint, but no deprecation policy and no end date for v1 and v2 (10). Sub-processors listed with purpose and country, and 15 days' notice of additions (18).
Negative events≤15None recorded0
Total55.7 · C

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 17 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Devin, or have the agent fetch /fixes/devin.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Devin

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/devin, the October 2026 research run, assessed 8 October 2026. Grade C, 55.7 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Devin: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Reliability, 30 out of 100, up to 14 more on the total

Why it scored 30: Hosted reading. Status page at www.devinstatus.com with 14 components and incident history (20). In the 90 days to 8 October 2026 it lists three critical incidents (22 July, 43 minutes of platform-wide queuing, 13 August, Devin Cloud unavailable for 2 hours 40 minutes, 24 September, the web app down for 2 hours) and six major ones on session start-up, so several majors (0). 429 is a documented response, but no rate limit figures were found (0). No Retry-After or backoff guidance found, and v3 session creation has no idempotency key, although the legacy v1 API had one (0). The platform terms supply the service as is with no service level, and enterprise terms weren't read (0). The v3 API is the current, recommended surface, with 44 of 239 operations marked beta under /v3beta1 (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 2. Payments & pricing, 20 out of 100, up to 10 more on the total

Why it scored 20: Published rubric. No payment protocol (0). Plan prices are public, $20, $200 and $40 a seat with an $80 team minimum, but usage past the quota is billed at an unpublished rate (10). A Free plan exists. The pricing page lists cloud agents from Pro upward, and we couldn't confirm API use on Free or whether a card is needed (10). A person signs up in a browser and provisions the service user in settings (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 3. Agent ergonomics, 62 out of 100, up to 6.2 more on the total

Why it scored 62: API and MCP reading. The MCP server documents 13 tools, several of them consolidated manage tools, and list endpoints take `first` to size a page (17). Cursor pagination on every v3 list endpoint and filters on session search by tag, playbook, origin, user and time (18). problem+json with `error_code`, field-level errors on 422 and a 400 that lists valid platform names, but no published code list (15). No idempotency key on v3 session creation. `max_acu_limit` caps what a session can spend, and the MCP tool annotations couldn't be read without a key (4). Only `prompt` is required to start a session. No official SDK found, only a Terraform provider (8).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 4. Security & auth, 72 out of 100, up to 4.9 more on the total

Why it scored 72: Hosted reading. Service-user keys with roles and named permissions per endpoint, revocable, with rotation endpoints in beta for Enterprise and expiring personal tokens. Custom roles are an Enterprise option, and Teams has Admin and Member only (25). Security profiles restrict network, MCP servers, git and the Devin MCP to read-only, and read-only API permissions exist. They are opt-in, and session creation accepts `bypass_approval` (16). AI Guardrails screen user messages and pull request comments for prompt injection, on Enterprise only, and they don't cover web pages or repository content Devin reads (8). Audit logs through the API need an enterprise-level permission. Session events and insights are available on all plans (10). SOC 2 Type II and ISO/IEC 27001:2022, a disclosure address at security@cognition.ai, no security.txt, and the trust centre answers No to having a bug bounty (13).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 5. Schema & documentation, 80 out of 100, up to 3.3 more on the total

Why it scored 80: API reading. Public OpenAPI 3.1 spec for v3 with 239 operations, and separate v1 and v2 specs (25). llms.txt with 376 lines and a Markdown twin of every page (10). Each endpoint page names its required permission, but 61 of 239 operations have no description and the MCP tool descriptions are one line each (10). Enums on fields such as `devin_mode`, `origin` and `category`, with most strings unconstrained and nullable (9). curl examples in the quick starts, and a problem+json error schema declared on every operation, without a catalogue of `error_code` values (11). Versioned paths (v1, v2, v3, v3beta1) and a dated API release notes page (15).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 6. Maintenance & community, 63 out of 100, up to 3.2 more on the total

Why it scored 63: Closed service. Newest release note dated 7 October 2026 (30). Nineteen dated release notes between 7 August and 7 October 2026, and API notes for August and September (20). Public release notes and a support address, with no public tracker or forum found (10). No official SDK found and the Devin MCP server didn't appear in a search of the official MCP registry (0). No public CI or packages to assess, with the docs and three OpenAPI specs kept current (3).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## 7. Transparency & trust, 69 out of 100, up to 2.7 more on the total

Made of editorial 61, provenance 77.

Why it scored 69: Editorial half. Closed source with clear terms from Cognition AI, Inc. (15). Terms, privacy policy, security page and data processing agreement agree with each other. Customer data may be used for model training by default on self-serve plans, with an opt-out on paid plans that also turns on zero data retention at model providers. Retention is stated as the length of the customer relationship, with no periods (18). Dated notices for the schedules endpoints (announced 10 September, creation refused from 24 September 2026) and the v2 clone endpoint, but no deprecation policy and no end date for v1 and v2 (10). Sub-processors listed with purpose and country, and 15 days' notice of additions (18).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Domain age: devin.ai, registered 2022-12-06 (3 years) (7 of 15)
- Terms of service: read, states 6 of the 7 things a reader expects, and has 1 clause that costs points (7.1 of 10)
- Privacy policy: read, states 8 of the 8 things a reader expects, and has 1 clause that costs points (8 of 10)
- security.txt: not found (0 of 10)

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: security incidents or advisories in the last 12 months. Web search wasn't available, and no advisory page was found on the vendor's sites, so the deduction is 0 on what we could read.
- unchecked: whether the Free plan can create sessions through the API, and whether signup asks for a card. The pricing page and the docs describe Free differently.
- unchecked: the MCP server's tool schemas and annotations, which need a key. mcp.devin.ai/mcp answered 406 to a plain GET.
- unchecked: Enterprise Terms of Service, including any service level, and the documents on trust.cognition.ai, which need an NDA.
- No rate limit figures, on-demand unit rate or end date for the v1 and v2 APIs were found in the reviewed documentation.
- Devin CLI and Devin Desktop (formerly Windsurf) are separate local products on the same plans and weren't graded here.

## Weaknesses

- www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026
- No rate limit figures, Retry-After or backoff guidance found in the API docs, and v3 session creation has no idempotency key
- Customer data may be used for model training by default on self-serve plans. The opt-out is for paid plans only, per section 3.3.1 of the platform terms
- A person must sign up and provision the service user in the web app. No key-creation route exists for an agent starting from nothing
- No official SDK found, and the Devin MCP server was not found in the official MCP registry

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Use a `cog_` service-user key with the Member role. Legacy `apk_` keys fail against v3 and the MCP server with 401 or 403
- Set `max_acu_limit` on every session you create. Usage is metered by the work done and has no published unit rate
- Session creation is not idempotent in v3. After a timeout, list sessions by tag before creating again
- Enterprise keys and personal access tokens must send `X-Org-Id` to the MCP server. Organisation-scoped keys resolve it automatically
- Create scheduled work as an automation. POST to the schedules endpoint returns 403 for migrated organisations since 24 September 2026

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: security incidents or advisories in the last 12 months. Web search wasn't available, and no advisory page was found on the vendor's sites, so the deduction is 0 on what we could read.
  • unchecked: whether the Free plan can create sessions through the API, and whether signup asks for a card. The pricing page and the docs describe Free differently.
  • unchecked: the MCP server's tool schemas and annotations, which need a key. mcp.devin.ai/mcp answered 406 to a plain GET.
  • unchecked: Enterprise Terms of Service, including any service level, and the documents on trust.cognition.ai, which need an NDA.
  • No rate limit figures, on-demand unit rate or end date for the v1 and v2 APIs were found in the reviewed documentation.
  • Devin CLI and Devin Desktop (formerly Windsurf) are separate local products on the same plans and weren't graded here.

Sources 22

  1. API overview and error codes docs.devin.ai · seen 2026-10-08
  2. authentication, service users and personal tokens docs.devin.ai · seen 2026-10-08
  3. permissions and RBAC docs.devin.ai · seen 2026-10-08
  4. v3 OpenAPI spec docs.devin.ai · seen 2026-10-08
  5. pagination docs.devin.ai · seen 2026-10-08
  6. Devin MCP server and tools docs.devin.ai · seen 2026-10-08
  7. MCP client and marketplace docs.devin.ai · seen 2026-10-08
  8. security profiles docs.devin.ai · seen 2026-10-08
  9. AI Guardrails docs.devin.ai · seen 2026-10-08
  10. pricing devin.ai · seen 2026-10-08
  11. self-serve plans and credits docs.devin.ai · seen 2026-10-08
  12. usage metering docs.devin.ai · seen 2026-10-08
  13. status incidents devinstatus.com · seen 2026-10-08
  14. platform terms of service cognition.com · seen 2026-10-08
  15. privacy policy cognition.com · seen 2026-10-08
  16. data processing agreement and sub-processors cognition.com · seen 2026-10-08
  17. security and data use docs.devin.ai · seen 2026-10-08
  18. trust centre trust.cognition.ai · seen 2026-10-08
  19. API release notes and deprecations docs.devin.ai · seen 2026-10-08
  20. application release notes docs.devin.ai · seen 2026-10-08
  21. migration guide for v1 and v2 docs.devin.ai · seen 2026-10-08
  22. official MCP registry search for devin, no result registry.modelcontextprotocol.io · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Freemium $20 / mo Free $0, Pro $20 a month, Max $200 a month, Teams $80 a month minimum with full seats at $40 each, Enterprise by quote (devin.ai/pricing, checked 2026-10-08). Paid plans include a daily or weekly usage quota, then prepaid on-demand credits described as usage at API pricing, with no unit rate on the page. The pricing page lists cloud agents from Pro upward, while the docs say Free includes limited Devin usage. Whether the API works on Free, and whether signup needs a card, wasn't established.

Prices

ItemPriceUnitNote
Pro plan$20per month (plan)one user, daily and weekly usage quota
Max plan$200per month (plan)one user, larger weekly quota
Teams full seat$40per seat per month$80 a month minimum per team, flex seats free and billed from shared credits

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/devin.xml, or this listing's score history at history.json.

Connect

First request

curl -X POST "https://api.devin.ai/v3/organizations/$DEVIN_ORG_ID/sessions" -H "Authorization: Bearer $DEVIN_API_KEY" -H "Content-Type: application/json" -d '{"prompt": "Create a simple Python script that prints Hello World"}'

MCP client configuration

{
  "mcpServers": {
    "devin": {
      "headers": {
        "Authorization": "Bearer \u003cAPI_KEY\u003e",
        "X-Org-Id": "\u003cYOUR_ORG_ID\u003e"
      },
      "serverUrl": "https://mcp.devin.ai/mcp"
    }
  }
}
Similar toolGrade ScoreShared capabilitiesx402
goose Agentic AI Foundation (originally Block)BB73.9agent.harness agent.mcp-client agent.multi-agentno
Qwen Code Alibaba (Qwen team)BB72.4agent.harness agent.mcp-client agent.multi-agentno
Gemini CLI GoogleBB72agent.harness agent.mcp-client agent.multi-agentno
OpenHands All Hands AIBB70.8agent.harness agent.mcp-client agent.multi-agentno
OpenCode AnomalyB67.7agent.harness agent.mcp-client agent.multi-agentno
Claude Code AnthropicC61.9agent.harness agent.mcp-client agent.multi-agentno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Devin on Anchor Terminal, C, 55.7/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/devin"><img src="https://www.anchorterminal.com/badges/devin.svg" alt="Devin on Anchor Terminal" height="20"></a>
    [![Devin on Anchor Terminal](https://www.anchorterminal.com/badges/devin.svg)](https://www.anchorterminal.com/tools/devin)

    It counts on a page on devin.ai or one of its subdomains.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "devin", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.