{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/goose.json",
        "name": "goose",
        "score": 73.9,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "goose"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/qwen-code.json",
        "name": "Qwen Code",
        "score": 72.4,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "qwen-code"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/gemini-cli.json",
        "name": "Gemini CLI",
        "score": 72,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "gemini-cli"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/openhands.json",
        "name": "OpenHands",
        "score": 70.8,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "openhands"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/opencode.json",
        "name": "OpenCode",
        "score": 67.7,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "opencode"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/claude-code.json",
        "name": "Claude Code",
        "score": 61.9,
        "shared": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "slug": "claude-code"
      }
    ],
    "tool": {
      "slug": "devin",
      "name": "Devin",
      "vendor": "Cognition AI, Inc.",
      "vendorUrl": "https://devin.ai",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Devin is Cognition's hosted coding agent. It works in its own cloud virtual machine to plan, edit code, run commands and open pull requests. Outside agents start and steer sessions through a REST API and a remote MCP server.",
      "url": "https://www.anchorterminal.com/tools/devin",
      "markdownUrl": "https://www.anchorterminal.com/tools/devin.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/devin.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/devin.json",
      "license": "Proprietary service under Cognition's Platform Terms of Service",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://mcp.devin.ai/mcp",
      "packages": [],
      "auth": "api-key",
      "authNotes": "A Bearer token with the `cog_` prefix on every request to https://api.devin.ai/v3. Service-user keys are provisioned by a person in Settings \u003e Devin API, shown once, and carry a role (Admin or Member on Teams, custom roles on Enterprise). Personal access tokens act as the user who made them and can expire. Legacy `apk_` keys work only with the deprecated v1 and v2 APIs. The MCP server takes the same keys, and enterprise keys and personal tokens add an `X-Org-Id` header. Access is self-serve, with no app review or sales approval for Teams.",
      "pricing": "freemium",
      "pricingNotes": "Free $0, Pro $20 a month, Max $200 a month, Teams $80 a month minimum with full seats at $40 each, Enterprise by quote (devin.ai/pricing, checked 2026-10-08). Paid plans include a daily or weekly usage quota, then prepaid on-demand credits described as usage at API pricing, with no unit rate on the page. The pricing page lists cloud agents from Pro upward, while the docs say Free includes limited Devin usage. Whether the API works on Free, and whether signup needs a card, wasn't established.",
      "priceSummary": "$20 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, the v3 OpenAPI spec or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 13,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.devin.ai",
      "llmsTxt": "https://docs.devin.ai/llms.txt",
      "openapi": "https://docs.devin.ai/v3-openapi.yaml",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "hosted",
        "cloud-agent",
        "closed-source",
        "api-key",
        "rbac",
        "openapi",
        "llms-txt",
        "mcp",
        "status-page",
        "soc2",
        "freemium"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.7,
        "grade": "C",
        "agentReady": false,
        "rank": 505,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 15,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 62,
          "maintenance": 63,
          "payments": 20,
          "reliability": 30,
          "schema": 80,
          "security": 72,
          "transparency": 69
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 30,
            "points": 6,
            "reason": "Hosted reading. Status page at www.devinstatus.com with 14 components and incident history (20). In the 90 days to 8 October 2026 it lists three critical incidents (22 July, 43 minutes of platform-wide queuing, 13 August, Devin Cloud unavailable for 2 hours 40 minutes, 24 September, the web app down for 2 hours) and six major ones on session start-up, so several majors (0). 429 is a documented response, but no rate limit figures were found (0). No Retry-After or backoff guidance found, and v3 session creation has no idempotency key, although the legacy v1 API had one (0). The platform terms supply the service as is with no service level, and enterprise terms weren't read (0). The v3 API is the current, recommended surface, with 44 of 239 operations marked beta under /v3beta1 (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 80,
            "points": 13,
            "reason": "API reading. Public OpenAPI 3.1 spec for v3 with 239 operations, and separate v1 and v2 specs (25). llms.txt with 376 lines and a Markdown twin of every page (10). Each endpoint page names its required permission, but 61 of 239 operations have no description and the MCP tool descriptions are one line each (10). Enums on fields such as `devin_mode`, `origin` and `category`, with most strings unconstrained and nullable (9). curl examples in the quick starts, and a problem+json error schema declared on every operation, without a catalogue of `error_code` values (11). Versioned paths (v1, v2, v3, v3beta1) and a dated API release notes page (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 62,
            "points": 10.07,
            "reason": "API and MCP reading. The MCP server documents 13 tools, several of them consolidated manage tools, and list endpoints take `first` to size a page (17). Cursor pagination on every v3 list endpoint and filters on session search by tag, playbook, origin, user and time (18). problem+json with `error_code`, field-level errors on 422 and a 400 that lists valid platform names, but no published code list (15). No idempotency key on v3 session creation. `max_acu_limit` caps what a session can spend, and the MCP tool annotations couldn't be read without a key (4). Only `prompt` is required to start a session. No official SDK found, only a Terraform provider (8)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 72,
            "points": 12.6,
            "reason": "Hosted reading. Service-user keys with roles and named permissions per endpoint, revocable, with rotation endpoints in beta for Enterprise and expiring personal tokens. Custom roles are an Enterprise option, and Teams has Admin and Member only (25). Security profiles restrict network, MCP servers, git and the Devin MCP to read-only, and read-only API permissions exist. They are opt-in, and session creation accepts `bypass_approval` (16). AI Guardrails screen user messages and pull request comments for prompt injection, on Enterprise only, and they don't cover web pages or repository content Devin reads (8). Audit logs through the API need an enterprise-level permission. Session events and insights are available on all plans (10). SOC 2 Type II and ISO/IEC 27001:2022, a disclosure address at security@cognition.ai, no security.txt, and the trust centre answers No to having a bug bounty (13)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 20,
            "points": 2.5,
            "reason": "Published rubric. No payment protocol (0). Plan prices are public, $20, $200 and $40 a seat with an $80 team minimum, but usage past the quota is billed at an unpublished rate (10). A Free plan exists. The pricing page lists cloud agents from Pro upward, and we couldn't confirm API use on Free or whether a card is needed (10). A person signs up in a browser and provisions the service user in settings (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 63,
            "points": 5.51,
            "reason": "Closed service. Newest release note dated 7 October 2026 (30). Nineteen dated release notes between 7 August and 7 October 2026, and API notes for August and September (20). Public release notes and a support address, with no public tracker or forum found (10). No official SDK found and the Devin MCP server didn't appear in a search of the official MCP registry (0). No public CI or packages to assess, with the docs and three OpenAPI specs kept current (3)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 69,
            "points": 6.04,
            "note": "editorial 61, provenance 77",
            "reason": "Editorial half. Closed source with clear terms from Cognition AI, Inc. (15). Terms, privacy policy, security page and data processing agreement agree with each other. Customer data may be used for model training by default on self-serve plans, with an opt-out on paid plans that also turns on zero data retention at model providers. Retention is stated as the length of the customer relationship, with no periods (18). Dated notices for the schedules endpoints (announced 10 September, creation refused from 24 September 2026) and the v2 clone endpoint, but no deprecation policy and no end date for v1 and v2 (10). Sub-processors listed with purpose and country, and 15 days' notice of additions (18)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "API and MCP reading. The MCP server documents 13 tools, several of them consolidated manage tools, and list endpoints take `first` to size a page (17). Cursor pagination on every v3 list endpoint and filters on session search by tag, playbook, origin, user and time (18). problem+json with `error_code`, field-level errors on 422 and a 400 that lists valid platform names, but no published code list (15). No idempotency key on v3 session creation. `max_acu_limit` caps what a session can spend, and the MCP tool annotations couldn't be read without a key (4). Only `prompt` is required to start a session. No official SDK found, only a Terraform provider (8).",
            "maintenance": "Closed service. Newest release note dated 7 October 2026 (30). Nineteen dated release notes between 7 August and 7 October 2026, and API notes for August and September (20). Public release notes and a support address, with no public tracker or forum found (10). No official SDK found and the Devin MCP server didn't appear in a search of the official MCP registry (0). No public CI or packages to assess, with the docs and three OpenAPI specs kept current (3).",
            "payments": "Published rubric. No payment protocol (0). Plan prices are public, $20, $200 and $40 a seat with an $80 team minimum, but usage past the quota is billed at an unpublished rate (10). A Free plan exists. The pricing page lists cloud agents from Pro upward, and we couldn't confirm API use on Free or whether a card is needed (10). A person signs up in a browser and provisions the service user in settings (0).",
            "reliability": "Hosted reading. Status page at www.devinstatus.com with 14 components and incident history (20). In the 90 days to 8 October 2026 it lists three critical incidents (22 July, 43 minutes of platform-wide queuing, 13 August, Devin Cloud unavailable for 2 hours 40 minutes, 24 September, the web app down for 2 hours) and six major ones on session start-up, so several majors (0). 429 is a documented response, but no rate limit figures were found (0). No Retry-After or backoff guidance found, and v3 session creation has no idempotency key, although the legacy v1 API had one (0). The platform terms supply the service as is with no service level, and enterprise terms weren't read (0). The v3 API is the current, recommended surface, with 44 of 239 operations marked beta under /v3beta1 (10).",
            "schema": "API reading. Public OpenAPI 3.1 spec for v3 with 239 operations, and separate v1 and v2 specs (25). llms.txt with 376 lines and a Markdown twin of every page (10). Each endpoint page names its required permission, but 61 of 239 operations have no description and the MCP tool descriptions are one line each (10). Enums on fields such as `devin_mode`, `origin` and `category`, with most strings unconstrained and nullable (9). curl examples in the quick starts, and a problem+json error schema declared on every operation, without a catalogue of `error_code` values (11). Versioned paths (v1, v2, v3, v3beta1) and a dated API release notes page (15).",
            "security": "Hosted reading. Service-user keys with roles and named permissions per endpoint, revocable, with rotation endpoints in beta for Enterprise and expiring personal tokens. Custom roles are an Enterprise option, and Teams has Admin and Member only (25). Security profiles restrict network, MCP servers, git and the Devin MCP to read-only, and read-only API permissions exist. They are opt-in, and session creation accepts `bypass_approval` (16). AI Guardrails screen user messages and pull request comments for prompt injection, on Enterprise only, and they don't cover web pages or repository content Devin reads (8). Audit logs through the API need an enterprise-level permission. Session events and insights are available on all plans (10). SOC 2 Type II and ISO/IEC 27001:2022, a disclosure address at security@cognition.ai, no security.txt, and the trust centre answers No to having a bug bounty (13).",
            "transparency": "Editorial half. Closed source with clear terms from Cognition AI, Inc. (15). Terms, privacy policy, security page and data processing agreement agree with each other. Customer data may be used for model training by default on self-serve plans, with an opt-out on paid plans that also turns on zero data retention at model providers. Retention is stated as the length of the customer relationship, with no periods (18). Dated notices for the schedules endpoints (announced 10 September, creation refused from 24 September 2026) and the v2 clone endpoint, but no deprecation policy and no end date for v1 and v2 (10). Sub-processors listed with purpose and country, and 15 days' notice of additions (18)."
          },
          "sources": [
            {
              "what": "API overview and error codes",
              "url": "https://docs.devin.ai/api-reference/overview",
              "seen": "2026-10-08"
            },
            {
              "what": "authentication, service users and personal tokens",
              "url": "https://docs.devin.ai/api-reference/authentication",
              "seen": "2026-10-08"
            },
            {
              "what": "permissions and RBAC",
              "url": "https://docs.devin.ai/api-reference/v3/overview",
              "seen": "2026-10-08"
            },
            {
              "what": "v3 OpenAPI spec",
              "url": "https://docs.devin.ai/v3-openapi.yaml",
              "seen": "2026-10-08"
            },
            {
              "what": "pagination",
              "url": "https://docs.devin.ai/api-reference/concepts/pagination",
              "seen": "2026-10-08"
            },
            {
              "what": "Devin MCP server and tools",
              "url": "https://docs.devin.ai/work-with-devin/devin-mcp",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP client and marketplace",
              "url": "https://docs.devin.ai/work-with-devin/mcp",
              "seen": "2026-10-08"
            },
            {
              "what": "security profiles",
              "url": "https://docs.devin.ai/product-guides/security-profiles",
              "seen": "2026-10-08"
            },
            {
              "what": "AI Guardrails",
              "url": "https://docs.devin.ai/enterprise/features/ai-guardrails",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://devin.ai/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "self-serve plans and credits",
              "url": "https://docs.devin.ai/admin/billing/self-serve",
              "seen": "2026-10-08"
            },
            {
              "what": "usage metering",
              "url": "https://docs.devin.ai/admin/billing/usage",
              "seen": "2026-10-08"
            },
            {
              "what": "status incidents",
              "url": "https://www.devinstatus.com/api/v2/incidents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "platform terms of service",
              "url": "https://cognition.com/legal/platform-terms-of-service",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://cognition.com/legal/privacy-policy",
              "seen": "2026-10-08"
            },
            {
              "what": "data processing agreement and sub-processors",
              "url": "https://cognition.com/legal/data-processing-statement",
              "seen": "2026-10-08"
            },
            {
              "what": "security and data use",
              "url": "https://docs.devin.ai/admin/security",
              "seen": "2026-10-08"
            },
            {
              "what": "trust centre",
              "url": "https://trust.cognition.ai/",
              "seen": "2026-10-08"
            },
            {
              "what": "API release notes and deprecations",
              "url": "https://docs.devin.ai/api-reference/release-notes",
              "seen": "2026-10-08"
            },
            {
              "what": "application release notes",
              "url": "https://docs.devin.ai/release-notes/2026",
              "seen": "2026-10-08"
            },
            {
              "what": "migration guide for v1 and v2",
              "url": "https://docs.devin.ai/api-reference/getting-started/migration-guide",
              "seen": "2026-10-08"
            },
            {
              "what": "official MCP registry search for devin, no result",
              "url": "https://registry.modelcontextprotocol.io/v0/servers?search=devin",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: security incidents or advisories in the last 12 months. Web search wasn't available, and no advisory page was found on the vendor's sites, so the deduction is 0 on what we could read.",
            "unchecked: whether the Free plan can create sessions through the API, and whether signup asks for a card. The pricing page and the docs describe Free differently.",
            "unchecked: the MCP server's tool schemas and annotations, which need a key. mcp.devin.ai/mcp answered 406 to a plain GET.",
            "unchecked: Enterprise Terms of Service, including any service level, and the documents on trust.cognition.ai, which need an NDA.",
            "No rate limit figures, on-demand unit rate or end date for the v1 and v2 APIs were found in the reviewed documentation.",
            "Devin CLI and Devin Desktop (formerly Windsurf) are separate local products on the same plans and weren't graded here."
          ]
        },
        "negative": 0,
        "verdict": "The v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation.",
        "bestFor": "A team that wants to hand whole tasks to a cloud agent and collect pull requests, driven from a pipeline or another agent.",
        "strengths": [
          "Public OpenAPI 3.1 spec for the v3 API with 239 operations, each declaring 401, 403, 404, 409, 422 and 429 responses in RFC 9457 problem+json",
          "Service-user keys carry a role, every endpoint except GET /v3/self names the permission it needs, and audit logs list service users separately from people",
          "Security profiles can limit a session to a network allowlist, an MCP server allowlist, read-only git and a read-only Devin MCP",
          "Remote MCP server at mcp.devin.ai/mcp with 13 documented tools for sessions, playbooks, knowledge, schedules and repository documentation",
          "Dated release notes several times a week, the newest on 7 October 2026, and a separate API release notes page"
        ],
        "weaknesses": [
          "www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026",
          "No rate limit figures, Retry-After or backoff guidance found in the API docs, and v3 session creation has no idempotency key",
          "Customer data may be used for model training by default on self-serve plans. The opt-out is for paid plans only, per section 3.3.1 of the platform terms",
          "A person must sign up and provision the service user in the web app. No key-creation route exists for an agent starting from nothing",
          "No official SDK found, and the Devin MCP server was not found in the official MCP registry"
        ],
        "agentNotes": [
          "Use a `cog_` service-user key with the Member role. Legacy `apk_` keys fail against v3 and the MCP server with 401 or 403",
          "Set `max_acu_limit` on every session you create. Usage is metered by the work done and has no published unit rate",
          "Session creation is not idempotent in v3. After a timeout, list sessions by tag before creating again",
          "Enterprise keys and personal access tokens must send `X-Org-Id` to the MCP server. Organisation-scoped keys resolve it automatically",
          "Create scheduled work as an automation. POST to the schedules endpoint returns 403 for migrated organisations since 24 September 2026"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.7
          }
        ],
        "editorialScores": {
          "ergonomics": 62,
          "maintenance": 63,
          "payments": 20,
          "reliability": 30,
          "schema": 80,
          "security": 72,
          "transparency": 61
        },
        "provenanceScore": 77
      },
      "connect": {
        "http": "curl -X POST \"https://api.devin.ai/v3/organizations/$DEVIN_ORG_ID/sessions\" -H \"Authorization: Bearer $DEVIN_API_KEY\" -H \"Content-Type: application/json\" -d '{\"prompt\": \"Create a simple Python script that prints Hello World\"}'",
        "config": {
          "mcpServers": {
            "devin": {
              "headers": {
                "Authorization": "Bearer \u003cAPI_KEY\u003e",
                "X-Org-Id": "\u003cYOUR_ORG_ID\u003e"
              },
              "serverUrl": "https://mcp.devin.ai/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/devin"
      },
      "notable": [
        "The v3 OpenAPI 3.1 spec has 158 paths and 239 operations, 44 of them under /v3beta1, and every operation declares problem+json errors (https://docs.devin.ai/v3-openapi.yaml)",
        "The Devin MCP server answers over streamable HTTP at https://mcp.devin.ai/mcp with 13 documented tools, and the older /sse endpoint is deprecated (https://docs.devin.ai/work-with-devin/devin-mcp)",
        "Security profiles bundle a network allowlist, an MCP server allowlist, a git access level and a read-only setting for the Devin MCP, bound to an organisation, an automation or a session (https://docs.devin.ai/product-guides/security-profiles)",
        "The platform terms of 30 June 2026 let Cognition use customer data for model training unless a paid customer opts out, and Enterprise data is not trained on without written consent (https://cognition.com/legal/platform-terms-of-service, https://docs.devin.ai/admin/security)",
        "The status page lists 13 incidents between 8 July and 24 September 2026, three marked critical (https://www.devinstatus.com/history)",
        "The v1 and v2 APIs are deprecated with no end date given. The migration guide says legacy keys will be removed soon (https://docs.devin.ai/api-reference/getting-started/migration-guide)"
      ],
      "area": "frameworks",
      "details": [
        {
          "label": "Interfaces",
          "value": "REST API v3 at https://api.devin.ai/v3 (organisation and enterprise scopes), remote MCP server at https://mcp.devin.ai/mcp, web app, Slack, and a Terraform provider. Devin CLI and Devin Desktop are separate local products"
        },
        {
          "label": "Session API",
          "value": "Create, list, get, message, terminate and archive sessions, with tags, attachments and insights. Only `prompt` is required. Options include `max_acu_limit`, `playbook_id`, `repos`, `devin_mode`, `structured_output_schema` (JSON Schema Draft 7, 64KB) and `security_profile`"
        },
        {
          "label": "MCP tools",
          "value": "read_wiki_structure, read_wiki_contents, ask_question, list_available_repos, devin_session_create, devin_session_search, devin_session_interact, devin_session_events, devin_session_gather, devin_playbook_manage, devin_knowledge_manage, devin_schedule_manage, devin_list_integrations"
        },
        {
          "label": "Credentials",
          "value": "Service-user keys with a role, shown once. Personal access tokens with optional expiry on Teams and mandatory expiry (365 days by default) on Enterprise. Key rotation and revocation endpoints for enterprise service users are in beta"
        },
        {
          "label": "Permissions",
          "value": "Every endpoint except GET /v3/self needs a named permission, such as UseDevinSessions, ViewOrgSessions, ManageOrgSessions or ManageOrgSecrets"
        },
        {
          "label": "Sandbox and network",
          "value": "Each session runs in a cloud virtual machine. A security profile can restrict it to an allowlist of hostnames and CIDR ranges, read-only git, and no GitHub CLI token. Without a profile, sessions can use any MCP server installed in the organisation"
        },
        {
          "label": "MCP client",
          "value": "Devin connects to external MCP servers over stdio, SSE and HTTP, installed from a plugin marketplace or added as custom servers by an admin"
        },
        {
          "label": "Pagination",
          "value": "Cursor-based on every v3 list endpoint, with `first` and `after`, returning `items`, `has_next_page`, `end_cursor` and sometimes `total`"
        },
        {
          "label": "Errors",
          "value": "RFC 9457 application/problem+json with `title`, `status`, `detail`, an optional `error_code` and field errors on 422"
        },
        {
          "label": "Rate limits",
          "value": "429 is documented as a response. No figures found in the reviewed documentation"
        },
        {
          "label": "Metering",
          "value": "Usage accrues by the actions Devin takes plus virtual machine time. Sessions sleep after 30 minutes idle and use nothing while asleep. Windows sessions use about 9 per cent more"
        },
        {
          "label": "Certifications",
          "value": "SOC 2 Type II since September 2024 per the docs, and ISO/IEC 27001:2022 and CCPA listed on trust.cognition.ai. Reports need an access request and an NDA"
        },
        {
          "label": "Status",
          "value": "www.devinstatus.com on Atlassian Statuspage, 14 components, among them Cloud Agent, Cloud Web Client and Integrations"
        },
        {
          "label": "Sub-processors",
          "value": "Listed with locations in Appendix C of the data processing agreement of 23 July 2026. Azure, AWS and Google Cloud for core processing, OpenAI, Anthropic and Google as model providers, all in the United States, and a Cognition affiliate in India for support"
        }
      ],
      "unitPrices": [
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 20,
          "note": "one user, daily and weekly usage quota"
        },
        {
          "item": "Max plan",
          "unit": "month",
          "usd": 200,
          "note": "one user, larger weekly quota"
        },
        {
          "item": "Teams full seat",
          "unit": "seat-month",
          "usd": 40,
          "note": "$80 a month minimum per team, flex seats free and billed from shared credits"
        }
      ],
      "provenance": {
        "legalEntity": "Cognition AI, Inc.",
        "domain": "devin.ai",
        "domainRegistered": "2022-12-06",
        "endpointOnVendorDomain": true,
        "terms": "https://cognition.com/legal/platform-terms-of-service",
        "privacy": "https://cognition.com/legal/privacy-policy",
        "statusPage": "https://www.devinstatus.com",
        "changelog": "https://docs.devin.ai/release-notes/overview",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Platform Terms of Service (last updated 30 June 2026) name Cognition AI, Inc. and govern the Cognition Platform for customers who register and use the services. Enterprise customers sign separate Enterprise Terms of Service.",
          "The privacy policy (last updated 9 March 2026) names Cognition AI, Inc and covers Devin and Windsurf as well as cognition.com. The data processing agreement gives the address 550 Third Street, San Francisco, CA 94107.",
          "devin.ai, cognition.com and api.devin.ai all return 404 for /.well-known/security.txt. The docs give security@cognition.ai for vulnerability reports.",
          "The API answers at api.devin.ai and the MCP server at mcp.devin.ai. status.devin.ai redirects to www.devinstatus.com.",
          "RDAP for devin.ai gives a registration date of 2022-12-06."
        ],
        "score": 77,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Cognition AI, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "devin.ai, registered 2022-12-06 (3 years)",
            "points": 7,
            "max": 15,
            "state": "part"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "mcp.devin.ai",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 1 clause that costs points",
            "points": 7.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects, and has 1 clause that costs points",
            "points": 8,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "www.devinstatus.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://cognition.com/legal/platform-terms-of-service",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-06-30",
            "words": 5818,
            "points": 7.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated: June 30, 2026",
                "says": "Last updated 2026-06-30"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "12.6 Governing Law: This Agreement is governed by and construed in accordance with the internal laws of the State of New York without giving effect to any choice or conflict of law provision or rule that would require or permit the application of the laws of any jurisdiction other than those of the State of New York.",
                "says": "The law of the State of New York"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "10.2 NOTWITHSTANDING ANYTHING TO THE CONTRARY IN THIS AGREEMENT, IN NO EVENT WILL EITHER PARTY'S AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO ANY CLAIM ARISING IN CONNECTION WITH THIS AGREEMENT UNDER ANY LEGAL OR EQUITABLE THEORY, INCLUDING BREACH OF CONTRACT, TORT (INCLUDING NEGLIGENCE) AND STRICT LIABILITY, EXCE…",
                "says": "Capped at the greater of US$100 and the fees paid in the 6 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "7.2 Subscription Termination: You may terminate your subscription at any time."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "This update may include material changes to your prior Terms of Service, and in such case, the prior terms shall control until 30 days from the posting of these Terms.",
                "says": "Gives 30 days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "2.3 Restrictions: You may not use the Services for any purposes beyond the scope of the access granted in this Agreement."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "training.optout",
                "label": "Says it may use customer content to train or improve models, and gives an opt-out",
                "found": true,
                "quote": "Cognition may use Customer Data for model training purposes and to improve and enhance the Services. If you subscribe to a paid Service Tier, you may opt out of this use (“Opt-Out”)."
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "use the Services to create or develop any competing products or services, including to train competing artificial intelligence models except as expressly approved by Cognition in writing",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "In addition, if you have a subscription, we may terminate the subscription at any time for any other reason."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "11.1 IN THE EVENT A DISPUTE, CONTROVERSY, OR CLAIM ARISES OUT OF OR RELATING TO THESE TERMS (“DISPUTE”), THE DISPUTE WILL BE RESOLVED BY BINDING ARBITRATION RATHER THAN IN COURT."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Either party's total liability is capped at the greater of the amounts paid in the six months before the event or 100 US dollars.",
                "quote": "EXCEED THE GREATER OF (A) THE TOTAL AMOUNTS PAID TO COGNITION UNDER THIS AGREEMENT IN THE SIX MONTH PERIOD PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR (B) ONE HUNDRED DOLLARS (US$100)."
              },
              {
                "date": "2026-10-08",
                "text": "Cognition may delete Customer Data when the terms or the subscription end, and the customer is responsible for its own backups.",
                "quote": "Upon termination of these Terms or your subscription, we may at our option delete any Customer Data or other data associated with your account."
              },
              {
                "date": "2026-10-08",
                "text": "The customer agrees not to process medical information or sensitive personal data, such as birth dates, bank account numbers and card numbers, through the Services.",
                "quote": "You agree not to process any medical information or sensitive personal data such as social security numbers, birth dates, passport information, bank account, and credit card numbers in using the Services."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://cognition.com/legal/privacy-policy",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-03-09",
            "words": 2610,
            "points": 8,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated: March 9, 2026",
                "says": "Last updated 2026-03-09"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "We collect and use your information in order to provide and improve our Services and your experience, protect the security and integrity of our platform, and meet our legal obligations."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "How long we retain personal information includes considerations such as when the information was collected or created, whether it is necessary in order to continue offering you our Services, whether we are required to hold the information to comply with our legal obligations, or information preservation requirements."
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "We share your information with trusted third parties and service providers in order to offer our Services, fulfill legal requirements and for the purposes set out more fully below."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "We do not sell or share your personal information with third parties for targeted advertising purposes, nor have we done so in the past 12 months.",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "In the EEA and UK, you have the right to object to, and seek restrictions of this processing (“Legitimate Interests”) — specifically, our interest in being responsive to your requests and ensuring you have the best use of the Services"
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "If you have any questions, or to exercise any available rights, please contact us at privacy@cognition.ai.",
                "says": "privacy@cognition.ai"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "…these transfers of your personal information, including in some cases the European Commission's Standard Contractual Clauses and relevant local clauses (e.g., the UK's International Data Transfer Addendum) to facilitate the international and onward transfer of European personal data to third countries.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "toKnow": [
              {
                "key": "training",
                "label": "Says it may use customer content to train or improve models, and no opt-out was found",
                "found": true,
                "quote": "To customize your experience with our Services and otherwise improve our Services including, depending on the terms that apply to your use of the Services, using User Content to train, fine tune and improve the models that power our Services.",
                "costsPoints": true
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Administrators of an enterprise or business account may be able to access a member's User Content and control the member's account.",
                "quote": "In addition, administrators of any enterprise or business account may be able to access certain information associated with your account, including your User Content, and be able to control your account and such information."
              },
              {
                "date": "2026-10-08",
                "text": "The privacy policy says users must be at least 18 years old to access the Services.",
                "quote": "As set out in our Terms, users must be at least 18 years old in order to access the Services."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/devin.json",
      "live": {
        "slug": "devin",
        "probe": {
          "target": "https://mcp.devin.ai/mcp",
          "method": "get",
          "lastAt": "2026-10-08T19:52:49.506512958Z",
          "lastOk": true,
          "lastStatus": 406,
          "lastMs": 452,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 450,
          "p95ms24h": 463,
          "samples24h": 27,
          "samples30d": 27,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 27,
              "ok": 27
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.devinstatus.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:50:34.776261792Z"
        },
        "pages": [
          {
            "url": "https://docs.devin.ai/release-notes/overview",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:39.860758812Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a85f82787c20"
          },
          {
            "url": "https://cognition.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:28.045423959Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0ab177a921b1"
          },
          {
            "url": "https://cognition.com/legal/platform-terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:26.004141328Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e794136b2fe5"
          }
        ],
        "updatedAt": "2026-10-08T19:52:49.506512958Z"
      }
    },
    "verify": {
      "accepts": "a page on devin.ai or one of its subdomains",
      "badgeUrl": "https://www.anchorterminal.com/badges/devin.svg",
      "body": {
        "slug": "devin",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/devin",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/devin\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/devin.svg\" alt=\"Devin on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Devin on Anchor Terminal](https://www.anchorterminal.com/badges/devin.svg)](https://www.anchorterminal.com/tools/devin)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/devin\"\u003eDevin on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/devin",
    "json": "https://www.anchorterminal.com/tools/devin.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/devin.md",
    "slim": "https://www.anchorterminal.com/tools/devin.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 55.7/100 · rank #505 of 722 · #15 in Agent harnesses · not agent-ready · confidence medium**\n\n\n## Assessment\n\nThe v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Cognition AI, Inc. (https://devin.ai) |\n| Kind | Agent harness |\n| Category | Agent harnesses (https://www.anchorterminal.com/categories/agent-harnesses) |\n| Transport | HTTP |\n| Endpoint | `https://mcp.devin.ai/mcp` |\n| Auth | API key · A Bearer token with the `cog_` prefix on every request to https://api.devin.ai/v3. Service-user keys are provisioned by a person in Settings \u003e Devin API, shown once, and carry a role (Admin or Member on Teams, custom roles on Enterprise). Personal access tokens act as the user who made them and can expire. Legacy `apk_` keys work only with the deprecated v1 and v2 APIs. The MCP server takes the same keys, and enterprise keys and personal tokens add an `X-Org-Id` header. Access is self-serve, with no app review or sales approval for Teams. |\n| Pricing | Freemium ($20 / mo) · Free $0, Pro $20 a month, Max $200 a month, Teams $80 a month minimum with full seats at $40 each, Enterprise by quote (devin.ai/pricing, checked 2026-10-08). Paid plans include a daily or weekly usage quota, then prepaid on-demand credits described as usage at API pricing, with no unit rate on the page. The pricing page lists cloud agents from Pro upward, while the docs say Free includes limited Devin usage. Whether the API works on Free, and whether signup needs a card, wasn't established. |\n| x402 | No · No x402, MPP or L402 in the docs index, the v3 OpenAPI spec or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under Cognition's Platform Terms of Service |\n| Tools exposed | 13 |\n| Docs | https://docs.devin.ai |\n| llms.txt | https://docs.devin.ai/llms.txt |\n| Last release | 2026-10-07 |\n| Interfaces | REST API v3 at https://api.devin.ai/v3 (organisation and enterprise scopes), remote MCP server at https://mcp.devin.ai/mcp, web app, Slack, and a Terraform provider. Devin CLI and Devin Desktop are separate local products |\n| Session API | Create, list, get, message, terminate and archive sessions, with tags, attachments and insights. Only `prompt` is required. Options include `max_acu_limit`, `playbook_id`, `repos`, `devin_mode`, `structured_output_schema` (JSON Schema Draft 7, 64KB) and `security_profile` |\n| MCP tools | read_wiki_structure, read_wiki_contents, ask_question, list_available_repos, devin_session_create, devin_session_search, devin_session_interact, devin_session_events, devin_session_gather, devin_playbook_manage, devin_knowledge_manage, devin_schedule_manage, devin_list_integrations |\n| Credentials | Service-user keys with a role, shown once. Personal access tokens with optional expiry on Teams and mandatory expiry (365 days by default) on Enterprise. Key rotation and revocation endpoints for enterprise service users are in beta |\n| Permissions | Every endpoint except GET /v3/self needs a named permission, such as UseDevinSessions, ViewOrgSessions, ManageOrgSessions or ManageOrgSecrets |\n| Sandbox and network | Each session runs in a cloud virtual machine. A security profile can restrict it to an allowlist of hostnames and CIDR ranges, read-only git, and no GitHub CLI token. Without a profile, sessions can use any MCP server installed in the organisation |\n| MCP client | Devin connects to external MCP servers over stdio, SSE and HTTP, installed from a plugin marketplace or added as custom servers by an admin |\n| Pagination | Cursor-based on every v3 list endpoint, with `first` and `after`, returning `items`, `has_next_page`, `end_cursor` and sometimes `total` |\n| Errors | RFC 9457 application/problem+json with `title`, `status`, `detail`, an optional `error_code` and field errors on 422 |\n| Rate limits | 429 is documented as a response. No figures found in the reviewed documentation |\n| Metering | Usage accrues by the actions Devin takes plus virtual machine time. Sessions sleep after 30 minutes idle and use nothing while asleep. Windows sessions use about 9 per cent more |\n| Certifications | SOC 2 Type II since September 2024 per the docs, and ISO/IEC 27001:2022 and CCPA listed on trust.cognition.ai. Reports need an access request and an NDA |\n| Status | www.devinstatus.com on Atlassian Statuspage, 14 components, among them Cloud Agent, Cloud Web Client and Integrations |\n| Sub-processors | Listed with locations in Appendix C of the data processing agreement of 23 July 2026. Azure, AWS and Google Cloud for core processing, OpenAI, Anthropic and Google as model providers, all in the United States, and a Cognition affiliate in India for support |\n| Capabilities | agent.harness, agent.mcp-client, agent.multi-agent |\n| Tags | hosted, cloud-agent, closed-source, api-key, rbac, openapi, llms-txt, mcp, status-page, soc2, freemium |\n| JSON | https://www.anchorterminal.com/api/v1/tools/devin.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 30 | 6.0 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 80 | 13.0 |\n| Agent ergonomics | 13% | 16.2 | 62 | 10.1 |\n| Security \u0026 auth | 14% | 17.5 | 72 | 12.6 |\n| Payments \u0026 pricing | 10% | 12.5 | 20 | 2.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 63 | 5.5 |\n| Transparency \u0026 trust (editorial 61, provenance 77) | 7% | 8.8 | 69 | 6.0 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **55.7 → C** |\n\n### Why each score\n\n- Reliability 30: Hosted reading. Status page at www.devinstatus.com with 14 components and incident history (20). In the 90 days to 8 October 2026 it lists three critical incidents (22 July, 43 minutes of platform-wide queuing, 13 August, Devin Cloud unavailable for 2 hours 40 minutes, 24 September, the web app down for 2 hours) and six major ones on session start-up, so several majors (0). 429 is a documented response, but no rate limit figures were found (0). No Retry-After or backoff guidance found, and v3 session creation has no idempotency key, although the legacy v1 API had one (0). The platform terms supply the service as is with no service level, and enterprise terms weren't read (0). The v3 API is the current, recommended surface, with 44 of 239 operations marked beta under /v3beta1 (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 80: API reading. Public OpenAPI 3.1 spec for v3 with 239 operations, and separate v1 and v2 specs (25). llms.txt with 376 lines and a Markdown twin of every page (10). Each endpoint page names its required permission, but 61 of 239 operations have no description and the MCP tool descriptions are one line each (10). Enums on fields such as `devin_mode`, `origin` and `category`, with most strings unconstrained and nullable (9). curl examples in the quick starts, and a problem+json error schema declared on every operation, without a catalogue of `error_code` values (11). Versioned paths (v1, v2, v3, v3beta1) and a dated API release notes page (15).\n- Agent ergonomics 62: API and MCP reading. The MCP server documents 13 tools, several of them consolidated manage tools, and list endpoints take `first` to size a page (17). Cursor pagination on every v3 list endpoint and filters on session search by tag, playbook, origin, user and time (18). problem+json with `error_code`, field-level errors on 422 and a 400 that lists valid platform names, but no published code list (15). No idempotency key on v3 session creation. `max_acu_limit` caps what a session can spend, and the MCP tool annotations couldn't be read without a key (4). Only `prompt` is required to start a session. No official SDK found, only a Terraform provider (8).\n- Security \u0026 auth 72: Hosted reading. Service-user keys with roles and named permissions per endpoint, revocable, with rotation endpoints in beta for Enterprise and expiring personal tokens. Custom roles are an Enterprise option, and Teams has Admin and Member only (25). Security profiles restrict network, MCP servers, git and the Devin MCP to read-only, and read-only API permissions exist. They are opt-in, and session creation accepts `bypass_approval` (16). AI Guardrails screen user messages and pull request comments for prompt injection, on Enterprise only, and they don't cover web pages or repository content Devin reads (8). Audit logs through the API need an enterprise-level permission. Session events and insights are available on all plans (10). SOC 2 Type II and ISO/IEC 27001:2022, a disclosure address at security@cognition.ai, no security.txt, and the trust centre answers No to having a bug bounty (13).\n- Payments \u0026 pricing 20: Published rubric. No payment protocol (0). Plan prices are public, $20, $200 and $40 a seat with an $80 team minimum, but usage past the quota is billed at an unpublished rate (10). A Free plan exists. The pricing page lists cloud agents from Pro upward, and we couldn't confirm API use on Free or whether a card is needed (10). A person signs up in a browser and provisions the service user in settings (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 63: Closed service. Newest release note dated 7 October 2026 (30). Nineteen dated release notes between 7 August and 7 October 2026, and API notes for August and September (20). Public release notes and a support address, with no public tracker or forum found (10). No official SDK found and the Devin MCP server didn't appear in a search of the official MCP registry (0). No public CI or packages to assess, with the docs and three OpenAPI specs kept current (3).\n- Transparency \u0026 trust 69: Editorial half. Closed source with clear terms from Cognition AI, Inc. (15). Terms, privacy policy, security page and data processing agreement agree with each other. Customer data may be used for model training by default on self-serve plans, with an opt-out on paid plans that also turns on zero data retention at model providers. Retention is stated as the length of the customer relationship, with no periods (18). Dated notices for the schedules endpoints (announced 10 September, creation refused from 24 September 2026) and the v2 clone endpoint, but no deprecation policy and no end date for v1 and v2 (10). Sub-processors listed with purpose and country, and 15 days' notice of additions (18).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (17 items): https://www.anchorterminal.com/fixes/devin.md (JSON https://www.anchorterminal.com/fixes/devin.json)\n\n### What we couldn't check\n\n- unchecked: security incidents or advisories in the last 12 months. Web search wasn't available, and no advisory page was found on the vendor's sites, so the deduction is 0 on what we could read.\n- unchecked: whether the Free plan can create sessions through the API, and whether signup asks for a card. The pricing page and the docs describe Free differently.\n- unchecked: the MCP server's tool schemas and annotations, which need a key. mcp.devin.ai/mcp answered 406 to a plain GET.\n- unchecked: Enterprise Terms of Service, including any service level, and the documents on trust.cognition.ai, which need an NDA.\n- No rate limit figures, on-demand unit rate or end date for the v1 and v2 APIs were found in the reviewed documentation.\n- Devin CLI and Devin Desktop (formerly Windsurf) are separate local products on the same plans and weren't graded here.\n\n### Sources\n\n- API overview and error codes: \u003chttps://docs.devin.ai/api-reference/overview\u003e (seen 2026-10-08)\n- authentication, service users and personal tokens: \u003chttps://docs.devin.ai/api-reference/authentication\u003e (seen 2026-10-08)\n- permissions and RBAC: \u003chttps://docs.devin.ai/api-reference/v3/overview\u003e (seen 2026-10-08)\n- v3 OpenAPI spec: \u003chttps://docs.devin.ai/v3-openapi.yaml\u003e (seen 2026-10-08)\n- pagination: \u003chttps://docs.devin.ai/api-reference/concepts/pagination\u003e (seen 2026-10-08)\n- Devin MCP server and tools: \u003chttps://docs.devin.ai/work-with-devin/devin-mcp\u003e (seen 2026-10-08)\n- MCP client and marketplace: \u003chttps://docs.devin.ai/work-with-devin/mcp\u003e (seen 2026-10-08)\n- security profiles: \u003chttps://docs.devin.ai/product-guides/security-profiles\u003e (seen 2026-10-08)\n- AI Guardrails: \u003chttps://docs.devin.ai/enterprise/features/ai-guardrails\u003e (seen 2026-10-08)\n- pricing: \u003chttps://devin.ai/pricing\u003e (seen 2026-10-08)\n- self-serve plans and credits: \u003chttps://docs.devin.ai/admin/billing/self-serve\u003e (seen 2026-10-08)\n- usage metering: \u003chttps://docs.devin.ai/admin/billing/usage\u003e (seen 2026-10-08)\n- status incidents: \u003chttps://www.devinstatus.com/api/v2/incidents.json\u003e (seen 2026-10-08)\n- platform terms of service: \u003chttps://cognition.com/legal/platform-terms-of-service\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://cognition.com/legal/privacy-policy\u003e (seen 2026-10-08)\n- data processing agreement and sub-processors: \u003chttps://cognition.com/legal/data-processing-statement\u003e (seen 2026-10-08)\n- security and data use: \u003chttps://docs.devin.ai/admin/security\u003e (seen 2026-10-08)\n- trust centre: \u003chttps://trust.cognition.ai/\u003e (seen 2026-10-08)\n- API release notes and deprecations: \u003chttps://docs.devin.ai/api-reference/release-notes\u003e (seen 2026-10-08)\n- application release notes: \u003chttps://docs.devin.ai/release-notes/2026\u003e (seen 2026-10-08)\n- migration guide for v1 and v2: \u003chttps://docs.devin.ai/api-reference/getting-started/migration-guide\u003e (seen 2026-10-08)\n- official MCP registry search for devin, no result: \u003chttps://registry.modelcontextprotocol.io/v0/servers?search=devin\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 77/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Cognition AI, Inc. | 20/20 |\n| Domain age | devin.ai, registered 2022-12-06 (3 years) | 7/15 |\n| Endpoint on the vendor's domain | mcp.devin.ai | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 1 clause that costs points | 7.1/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects, and has 1 clause that costs points | 8/10 |\n| Status page | www.devinstatus.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe Platform Terms of Service (last updated 30 June 2026) name Cognition AI, Inc. and govern the Cognition Platform for customers who register and use the services. Enterprise customers sign separate Enterprise Terms of Service.\n\nThe privacy policy (last updated 9 March 2026) names Cognition AI, Inc and covers Devin and Windsurf as well as cognition.com. The data processing agreement gives the address 550 Third Street, San Francisco, CA 94107.\n\ndevin.ai, cognition.com and api.devin.ai all return 404 for /.well-known/security.txt. The docs give security@cognition.ai for vulnerability reports.\n\nThe API answers at api.devin.ai and the MCP server at mcp.devin.ai. status.devin.ai redirects to www.devinstatus.com.\n\nRDAP for devin.ai gives a registration date of 2022-12-06.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://cognition.com/legal/platform-terms-of-service), read 2026-10-08, dated 2026-06-30, states 6 of the 7 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and gives an opt-out. \"Cognition may use Customer Data for model training purposes and to improve and enhance the Services. If you subscribe to a paid Service Tier, you may opt out of this use (“Opt-Out”).\"\n- To know. Restricts benchmarking or competitive use (costs points). \"use the Services to create or develop any competing products or services, including to train competing artificial intelligence models except as expressly approved by Cognition in writing\"\n- To know. Says access can be ended without notice or for any reason. \"In addition, if you have a subscription, we may terminate the subscription at any time for any other reason.\"\n- To know. Requires arbitration or waives class actions. \"11.1 IN THE EVENT A DISPUTE, CONTROVERSY, OR CLAIM ARISES OUT OF OR RELATING TO THESE TERMS (“DISPUTE”), THE DISPUTE WILL BE RESOLVED BY BINDING ARBITRATION RATHER THAN IN COURT.\"\n- Gives the date it was last updated. Last updated 2026-06-30.\n- Names the governing law or courts. The law of the State of New York.\n- States a limit on its liability. Capped at the greater of US$100 and the fees paid in the 6 months before the claim.\n- Says how changes to the terms are announced. Gives 30 days of notice before a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Either party's total liability is capped at the greater of the amounts paid in the six months before the event or 100 US dollars. \"EXCEED THE GREATER OF (A) THE TOTAL AMOUNTS PAID TO COGNITION UNDER THIS AGREEMENT IN THE SIX MONTH PERIOD PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR (B) ONE HUNDRED DOLLARS (US$100).\"\n- Also in the text (2026-10-08). Cognition may delete Customer Data when the terms or the subscription end, and the customer is responsible for its own backups. \"Upon termination of these Terms or your subscription, we may at our option delete any Customer Data or other data associated with your account.\"\n- Also in the text (2026-10-08). The customer agrees not to process medical information or sensitive personal data, such as birth dates, bank account numbers and card numbers, through the Services. \"You agree not to process any medical information or sensitive personal data such as social security numbers, birth dates, passport information, bank account, and credit card numbers in using the Services.\"\n\n**Privacy policy** (https://cognition.com/legal/privacy-policy), read 2026-10-08, dated 2026-03-09, states 8 of the 8 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). \"To customize your experience with our Services and otherwise improve our Services including, depending on the terms that apply to your use of the Services, using User Content to train, fine tune and improve the models that power our Services.\"\n- Gives the date it was last updated. Last updated 2026-03-09.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. privacy@cognition.ai.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). Administrators of an enterprise or business account may be able to access a member's User Content and control the member's account. \"In addition, administrators of any enterprise or business account may be able to access certain information associated with your account, including your User Content, and be able to control your account and such information.\"\n- Also in the text (2026-10-08). The privacy policy says users must be at least 18 years old to access the Services. \"As set out in our Terms, users must be at least 18 years old in order to access the Services.\"\n\n## Live (updated 2026-10-08 19:52 UTC)\n\n- Right now: up, HTTP 406, 452 ms, checked 2026-10-08 19:52 UTC (get on `https://mcp.devin.ai/mcp`)\n- Uptime 24h 100.0% (27 probes) · 30 days 100.0% (27 probes) · p50 450 ms · p95 463 ms\n- Vendor status page: none, All Systems Operational\n- Watching changelog \u003chttps://docs.devin.ai/release-notes/overview\u003e\n- Watching privacy \u003chttps://cognition.com/legal/privacy-policy\u003e\n- Watching terms \u003chttps://cognition.com/legal/platform-terms-of-service\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/devin.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Pro plan | $20 | per month (plan) | one user, daily and weekly usage quota |\n| Max plan | $200 | per month (plan) | one user, larger weekly quota |\n| Teams full seat | $40 | per seat per month | $80 a month minimum per team, flex seats free and billed from shared credits |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Public OpenAPI 3.1 spec for the v3 API with 239 operations, each declaring 401, 403, 404, 409, 422 and 429 responses in RFC 9457 problem+json\n- Service-user keys carry a role, every endpoint except GET /v3/self names the permission it needs, and audit logs list service users separately from people\n- Security profiles can limit a session to a network allowlist, an MCP server allowlist, read-only git and a read-only Devin MCP\n- Remote MCP server at mcp.devin.ai/mcp with 13 documented tools for sessions, playbooks, knowledge, schedules and repository documentation\n- Dated release notes several times a week, the newest on 7 October 2026, and a separate API release notes page\n\n## Weaknesses\n\n- www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026\n- No rate limit figures, Retry-After or backoff guidance found in the API docs, and v3 session creation has no idempotency key\n- Customer data may be used for model training by default on self-serve plans. The opt-out is for paid plans only, per section 3.3.1 of the platform terms\n- A person must sign up and provision the service user in the web app. No key-creation route exists for an agent starting from nothing\n- No official SDK found, and the Devin MCP server was not found in the official MCP registry\n\n## Before you call it (notes for agents)\n\n1. Use a `cog_` service-user key with the Member role. Legacy `apk_` keys fail against v3 and the MCP server with 401 or 403\n2. Set `max_acu_limit` on every session you create. Usage is metered by the work done and has no published unit rate\n3. Session creation is not idempotent in v3. After a timeout, list sessions by tag before creating again\n4. Enterprise keys and personal access tokens must send `X-Org-Id` to the MCP server. Organisation-scoped keys resolve it automatically\n5. Create scheduled work as an automation. POST to the schedules endpoint returns 403 for migrated organisations since 24 September 2026\n\n## Connect\n\nFirst request:\n\n```bash\ncurl -X POST \"https://api.devin.ai/v3/organizations/$DEVIN_ORG_ID/sessions\" -H \"Authorization: Bearer $DEVIN_API_KEY\" -H \"Content-Type: application/json\" -d '{\"prompt\": \"Create a simple Python script that prints Hello World\"}'\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"devin\": {\n      \"headers\": {\n        \"Authorization\": \"Bearer \\u003cAPI_KEY\\u003e\",\n        \"X-Org-Id\": \"\\u003cYOUR_ORG_ID\\u003e\"\n      },\n      \"serverUrl\": \"https://mcp.devin.ai/mcp\"\n    }\n  }\n}\n```\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| goose | BB | 73.9 | 72 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/goose.md |\n| Qwen Code | BB | 72.4 | 93 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/qwen-code.md |\n| Gemini CLI | BB | 72 | 99 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/gemini-cli.md |\n| OpenHands | BB | 70.8 | 126 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/openhands.md |\n| OpenCode | B | 67.7 | 200 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/opencode.md |\n| Claude Code | C | 61.9 | 354 | agent.harness, agent.mcp-client, agent.multi-agent | no | https://www.anchorterminal.com/tools/claude-code.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The v3 OpenAPI 3.1 spec has 158 paths and 239 operations, 44 of them under /v3beta1, and every operation declares problem+json errors (source: \u003chttps://docs.devin.ai/v3-openapi.yaml\u003e)\n- The Devin MCP server answers over streamable HTTP at https://mcp.devin.ai/mcp with 13 documented tools, and the older /sse endpoint is deprecated (source: \u003chttps://docs.devin.ai/work-with-devin/devin-mcp\u003e)\n- Security profiles bundle a network allowlist, an MCP server allowlist, a git access level and a read-only setting for the Devin MCP, bound to an organisation, an automation or a session (source: \u003chttps://docs.devin.ai/product-guides/security-profiles\u003e)\n- The platform terms of 30 June 2026 let Cognition use customer data for model training unless a paid customer opts out, and Enterprise data is not trained on without written consent (source: \u003chttps://cognition.com/legal/platform-terms-of-service, https://docs.devin.ai/admin/security\u003e)\n- The status page lists 13 incidents between 8 July and 24 September 2026, three marked critical (source: \u003chttps://www.devinstatus.com/history\u003e)\n- The v1 and v2 APIs are deprecated with no end date given. The migration guide says legacy keys will be removed soon (source: \u003chttps://docs.devin.ai/api-reference/getting-started/migration-guide\u003e)\n\n## Compare\n\n- [Aider vs Devin](https://www.anchorterminal.com/compare/aider-vs-devin.md): D 46.9 vs C 55.7\n- [Amp vs Devin](https://www.anchorterminal.com/compare/amp-vs-devin.md): C 57.1 vs C 55.7\n- [Claude Code vs Devin](https://www.anchorterminal.com/compare/claude-code-vs-devin.md): C 61.9 vs C 55.7\n- [Cline vs Devin](https://www.anchorterminal.com/compare/cline-vs-devin.md): C 60.4 vs C 55.7\n- [Cursor CLI vs Devin](https://www.anchorterminal.com/compare/cursor-cli-vs-devin.md): F 35.3 vs C 55.7\n- [Devin vs Pi](https://www.anchorterminal.com/compare/devin-vs-earendil-pi.md): C 55.7 vs B 68.4\n- [Devin vs Gemini CLI](https://www.anchorterminal.com/compare/devin-vs-gemini-cli.md): C 55.7 vs BB 72\n- [Devin vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/devin-vs-github-copilot-cli.md): C 55.7 vs C 57.6\n- [Devin vs goose](https://www.anchorterminal.com/compare/devin-vs-goose.md): C 55.7 vs BB 73.9\n- [Devin vs Kiro CLI](https://www.anchorterminal.com/compare/devin-vs-kiro-cli.md): C 55.7 vs C 59.9\n- [Devin vs OpenAI Codex](https://www.anchorterminal.com/compare/devin-vs-openai-codex.md): C 55.7 vs BB 73\n- [Devin vs OpenCode](https://www.anchorterminal.com/compare/devin-vs-opencode.md): C 55.7 vs B 67.7\n- [Devin vs OpenHands](https://www.anchorterminal.com/compare/devin-vs-openhands.md): C 55.7 vs BB 70.8\n- [Devin vs Prime Agent](https://www.anchorterminal.com/compare/devin-vs-prime-agent.md): C 55.7 vs C 60.5\n- [Devin vs Qwen Code](https://www.anchorterminal.com/compare/devin-vs-qwen-code.md): C 55.7 vs BB 72.4\n- [Devin vs Paperclip](https://www.anchorterminal.com/compare/devin-vs-paperclip.md): C 55.7 vs C 59\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on devin.ai or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"devin\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/devin\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/devin.svg\" alt=\"Devin on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Devin on Anchor Terminal](https://www.anchorterminal.com/badges/devin.svg)](https://www.anchorterminal.com/tools/devin)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/devin\"\u003eDevin on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Devin is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/devin-dark.png\n- Light: https://www.anchorterminal.com/assets/share/devin-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Agent harnesses",
        "url": "https://www.anchorterminal.com/categories/agent-harnesses"
      },
      {
        "name": "Devin",
        "url": ""
      }
    ],
    "description": "Devin is Cognition's hosted coding agent. It works in its own cloud virtual machine to plan, edit code, run commands and open pull requests. Outside agents start and steer sessions through a REST API and a remote MCP server.",
    "facts": [
      "rank #505 of 722",
      "API key auth",
      "0 desk reviews"
    ],
    "h1": "Devin",
    "image": "https://www.anchorterminal.com/assets/og/tools-devin.png",
    "path": "/tools/devin",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Devin review for AI agents, grade C (55.7/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/devin"
  },
  "tokens": {
    "markdown": 7700,
    "slim": 1730
  },
  "version": 1
}
