# Devin (slim) > Devin is Cognition's hosted coding agent. It works in its own cloud virtual machine to plan, edit code, run commands and open pull requests. Outside agents start and steer sessions through a REST API and a remote MCP server. - Full: https://www.anchorterminal.com/tools/devin.md (~7,700 tokens) · this version ~1,730 tokens · JSON https://www.anchorterminal.com/tools/devin.json · canonical https://www.anchorterminal.com/tools/devin - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 55.7/100 · rank #505 of 722 · #15 in Agent harnesses · not agent-ready · confidence medium** Assessment: The v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation. ## Facts - Kind: Agent harness · vendor: Cognition AI, Inc. · category: Agent harnesses · legal entity: Cognition AI, Inc. · provenance 77/100 - Endpoint: `https://mcp.devin.ai/mcp` (HTTP) - Auth: API key · pricing: Freemium · x402: no · licence: Proprietary service under Cognition's Platform Terms of Service - Probe metrics: not measured yet (probes haven't run) - Interfaces: REST API v3 at https://api.devin.ai/v3 (organisation and enterprise scopes), remote MCP server at https://mcp.devin.ai/mcp, web app, Slack, and a Terraform provider. Devin CLI and Devin Desktop are separate local products - Session API: Create, list, get, message, terminate and archive sessions, with tags, attachments and insights. Only `prompt` is required. Options include `max_acu_limit`, `playbook_id`, `repos`, `devin_mode`, `structured_output_schema` (JSON Schema Draft 7, 64KB) and `security_profile` - MCP tools: read_wiki_structure, read_wiki_contents, ask_question, list_available_repos, devin_session_create, devin_session_search, devin_session_interact, devin_session_events, devin_session_gather, devin_playbook_manage, devin_knowledge_manage, devin_schedule_manage, devin_list_integrations - Credentials: Service-user keys with a role, shown once. Personal access tokens with optional expiry on Teams and mandatory expiry (365 days by default) on Enterprise. Key rotation and revocation endpoints for enterprise service users are in beta - Permissions: Every endpoint except GET /v3/self needs a named permission, such as UseDevinSessions, ViewOrgSessions, ManageOrgSessions or ManageOrgSecrets - Sandbox and network: Each session runs in a cloud virtual machine. A security profile can restrict it to an allowlist of hostnames and CIDR ranges, read-only git, and no GitHub CLI token. Without a profile, sessions can use any MCP server installed in the organisation - MCP client: Devin connects to external MCP servers over stdio, SSE and HTTP, installed from a plugin marketplace or added as custom servers by an admin - Pagination: Cursor-based on every v3 list endpoint, with `first` and `after`, returning `items`, `has_next_page`, `end_cursor` and sometimes `total` - Errors: RFC 9457 application/problem+json with `title`, `status`, `detail`, an optional `error_code` and field errors on 422 - Rate limits: 429 is documented as a response. No figures found in the reviewed documentation - Metering: Usage accrues by the actions Devin takes plus virtual machine time. Sessions sleep after 30 minutes idle and use nothing while asleep. Windows sessions use about 9 per cent more - Certifications: SOC 2 Type II since September 2024 per the docs, and ISO/IEC 27001:2022 and CCPA listed on trust.cognition.ai. Reports need an access request and an NDA - Status: www.devinstatus.com on Atlassian Statuspage, 14 components, among them Cloud Agent, Cloud Web Client and Integrations - Sub-processors: Listed with locations in Appendix C of the data processing agreement of 23 July 2026. Azure, AWS and Google Cloud for core processing, OpenAI, Anthropic and Google as model providers, all in the United States, and a Cognition affiliate in India for support - Prices: Pro plan $20 per month (plan); Max plan $200 per month (plan); Teams full seat $40 per seat per month - Scores: Reliability 30, Performance pending, Schema & documentation 80, Agent ergonomics 62, Security & auth 72, Payments & pricing 20, Task success pending, Maintenance & community 63, Transparency & trust 69 · total over the 7 assessed categories - Why: Reliability, Hosted reading. · Schema & documentation, API reading. · Agent ergonomics, API and MCP reading. · Security & auth, Hosted reading. · Payments & pricing, Published rubric. · Maintenance & community, Closed service. · Transparency & trust, Editorial half. - Sources: 22, open questions: 6, both in the full twin - Capabilities: agent.harness, agent.mcp-client, agent.multi-agent - JSON: https://www.anchorterminal.com/api/v1/tools/devin.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/devin.svg` or a link to https://www.anchorterminal.com/tools/devin from a page on devin.ai or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Use a `cog_` service-user key with the Member role. Legacy `apk_` keys fail against v3 and the MCP server with 401 or 403 2. Set `max_acu_limit` on every session you create. Usage is metered by the work done and has no published unit rate 3. Session creation is not idempotent in v3. After a timeout, list sessions by tag before creating again 4. Enterprise keys and personal access tokens must send `X-Org-Id` to the MCP server. Organisation-scoped keys resolve it automatically 5. Create scheduled work as an automation. POST to the schedules endpoint returns 403 for migrated organisations since 24 September 2026 ## Connect ```bash curl -X POST "https://api.devin.ai/v3/organizations/$DEVIN_ORG_ID/sessions" -H "Authorization: Bearer $DEVIN_API_KEY" -H "Content-Type: application/json" -d '{"prompt": "Create a simple Python script that prints Hello World"}' ``` ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | goose | BB | 73.9 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/goose.min.md | | Qwen Code | BB | 72.4 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/qwen-code.min.md | | Gemini CLI | BB | 72 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/gemini-cli.min.md | | OpenHands | BB | 70.8 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/openhands.min.md | | OpenCode | B | 67.7 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/opencode.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)