@kentcdodds/devin
Start, monitor, and manage Devin sessions, knowledge, playbooks, and schedules via the Devin v3 API
AGENTS.md
133 lines · 4.7 KB · Markdown@kentcdodds/devin — agent notes
Human setup and intent live in README.md. This file is for
agents: imports, smoke execute snippets, and edge cases. Secrets by name
only — never paste key values. Do not disable live webhooks or jobs.
Secrets / settings
| Name | Kind | Required | Notes |
|---|---|---|---|
devinServiceUserKey | user secret | Yes | v3 service user key (cog_…); host api.devin.ai |
devinOrgId | package storage | Yes* | org-… id; *or pass orgId on every helper |
Placeholder: {{secret:devinServiceUserKey}}. Update org without republish:
import destSettings from 'kody:@kentcdodds/devin/settings'
export default async function main() {
return await destSettings({ orgId: 'org-…' })
}Import paths
| Export | Import | Default |
|---|---|---|
| overview | kody:@kentcdodds/devin | describe package |
| self | kody:@kentcdodds/devin/self | whoami |
| sessions | kody:@kentcdodds/devin/sessions | listSessions |
| knowledge | kody:@kentcdodds/devin/knowledge | listNotes |
| playbooks | kody:@kentcdodds/devin/playbooks | listPlaybooks |
| schedules | kody:@kentcdodds/devin/schedules | listSchedules |
| reviews | kody:@kentcdodds/devin/reviews | getPrReview |
| usage | kody:@kentcdodds/devin/usage | dailyConsumption |
| request | kody:@kentcdodds/devin/request | devinRequest |
| settings | kody:@kentcdodds/devin/settings | read/update devinOrgId |
| migrate-from-values | kody:@kentcdodds/devin/migrate-from-values | one-shot value → storage |
Prefer static kody:@kentcdodds/devin/... imports from execute. Do not lead
with packages.invoke.
Named helpers on namespaces: createSession, getSessionStatus, sendMessage,
listNotes, createNote, getPrReview, createPrReview, dailyConsumption,
etc. (see overview export map).
Smoke test (read-only)
import { whoami } from 'kody:@kentcdodds/devin/self'
export default async function main() {
return await whoami()
// cheapest auth/permissions check against /v3/self
}Optional read-only follow-ups: listSessions({ first: 5 }),
listNotes({ first: 5 }), or destSettings() (read settings).
Session id field: devinId (not sessionId)
Per-session helpers (getSession, listMessages, sendMessage,
getSessionStatus, terminate/archive/tags/attachments) take { devinId }.
Use session.session_id from create/list/get responses:
await listMessages({ devinId: session.session_id })
// not listMessages({ sessionId: session.session_id }) — Devin returns 403A 403 on these calls is most often the wrong field name, not missing RBAC.
requireDevinId throws if sessionId is passed.
Costly / destructive calls
Confirm intent (and ids) before:
- ACU:
createSession,createPrReview,generateSessionInsights - Destructive:
terminateSession,deleteNote,deletePlaybook,deleteSchedule
Prefer updateSchedule({ enabled: false }) over deleting a schedule.
import { createSession, getSessionStatus, sendMessage } from 'kody:@kentcdodds/devin/sessions'
export default async function main() {
// Only after explicit user approval — consumes ACUs
const session = await createSession({
prompt: 'Fix the flaky auth test and open a PR',
repos: ['owner/repo'],
tags: ['kody'],
maxAcuLimit: 10,
})
await sendMessage({
devinId: session.session_id,
message: 'Also update the changelog',
})
return await getSessionStatus({ devinId: session.session_id })
}Raw escape hatch (non-2xx returned, not thrown):
import { devinRequest } from 'kody:@kentcdodds/devin/request'
export default async function main() {
return await devinRequest({
path: '/v3beta1/organizations/{org_id}/repositories',
})
}Edge cases
- v3 only: legacy
apk_keys 403 on/v3/*. Needcog_…service user keys. - 403 usually means missing RBAC on the service user role, not a bad key —
start with
whoami. - Cursor pagination: pass
after: page.end_cursorwhilepage.has_next_page, or uselistAllSessions(capped bymaxPages). Schedules uselimit/offsetinstead. - Session list filters are flat repeated query params (
?tags=a&tags=b); Devin ignores nestedqsfrom the OpenAPI spec. - Timestamps are Unix seconds;
scheduledAtis an ISO date-time string. getPrReviewreturnsnullfor an unreviewed PR (404) instead of throwing.- Typed helpers throw
DevinApiError(status,body) on non-2xx;devinRequestreturns{ status, body }unwrapped. - Unwrapped surface (enterprise admin, code scans, snapshot blueprints, repo
indexing, org secrets): use
./request. - Never paste
devinServiceUserKeyvalues into chat or logs.