Devin Api Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Devin Api Mcp (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP servers providing full Devin API coverage — manage sessions, knowledge, playbooks, secrets, schedules, and attachments programmatically from any MCP client — plus a documentation-only DeepWiki proxy.
The hosted Devin MCP server bundles documentation lookups together with session/platform management in one server. This package splits those concerns: the devin-api-* servers give you everything except docs, and the deepwiki proxy gives you docs only (so it can't be confused for a delegation tool).
This package exposes three MCP servers:
apk_user_ prefix).cog_ prefix). Auto-discovers your org_id at startup via /v3/self.https://mcp.devin.ai/mcp, personal key) that re-exposes ONLY ask_question, read_wiki_structure, and read_wiki_contents. Private repos work (it authenticates with your personal key), but session/platform tools are filtered out — there is no way to create or manage a Devin session through it. Set the upstream with DEEPWIKI_UPSTREAM_URL (default https://mcp.devin.ai/mcp) and optionally DEVIN_ORG_ID. {
"mcpServers": {
"deepwiki": {
"command": "npx",
"args": ["-y", "-p", "@jsklan/devin-api-mcp", "deepwiki"],
"env": { "DEVIN_PERSONAL_API_KEY": "your_personal_key_here" }
}
}
}Follow the Devin API authentication guide to generate your keys:
| Server | Environment Variable | Key Prefix | Where to Get It |
|---|---|---|---|
| v1 | DEVIN_PERSONAL_API_KEY | apk_user_ | Devin account settings |
| v3 | DEVIN_SERVICE_API_KEY | cog_ | Devin organization settings |
Note: The v1 server also accepts DEVIN_API_KEY as a fallback for backward compatibility.# v1 (personal API — sessions, knowledge, playbooks, secrets, attachments)
claude mcp add -s user -e DEVIN_PERSONAL_API_KEY=<your-personal-key> -- devin-api-v1 npx -y -p @jsklan/devin-api-mcp devin-api-v1
# v3 (organization API — adds schedules, more session tools)
claude mcp add -s user -e DEVIN_SERVICE_API_KEY=<your-service-key> -- devin-api-v3 npx -y -p @jsklan/devin-api-mcp devin-api-v3/plugin in Claude Codejsklan/devin-api-mcpMake sure DEVIN_PERSONAL_API_KEY and/or DEVIN_SERVICE_API_KEY are set in your environment. The plugin will start the MCP servers automatically and stay up to date.
Add to your MCP config (e.g. mcp.json):
{
"mcpServers": {
"devin-api-v1": {
"command": "npx",
"args": ["-y", "-p", "@jsklan/devin-api-mcp", "devin-api-v1"],
"env": {
"DEVIN_PERSONAL_API_KEY": "your_personal_key_here"
}
},
"devin-api-v3": {
"command": "npx",
"args": ["-y", "-p", "@jsklan/devin-api-mcp", "devin-api-v3"],
"env": {
"DEVIN_SERVICE_API_KEY": "your_service_key_here"
}
}
}
}#### Sessions
| Tool | Description |
|---|---|
create_session | Start a new Devin session with a prompt (supports playbooks, tags, knowledge, secrets, structured output) |
list_sessions | List recent sessions with status and metadata (filterable by tags, user) |
get_session | Get session details including messages and structured output |
send_message | Send a follow-up message to a running session |
terminate_session | Stop a running session |
update_session_tags | Replace tags on a session |
#### Knowledge
| Tool | Description |
|---|---|
list_knowledge | List all knowledge entries and folders |
create_knowledge | Create a knowledge entry (teaches Devin domain-specific info) |
update_knowledge | Update an existing knowledge entry |
delete_knowledge | Permanently delete a knowledge entry |
#### Playbooks
| Tool | Description |
|---|---|
list_playbooks | List available playbooks (titles and IDs) |
get_playbook | Get full playbook details |
create_playbook | Create a new team playbook |
update_playbook | Update an existing playbook |
delete_playbook | Delete a team playbook |
#### Secrets
| Tool | Description |
|---|---|
list_secrets | List secret metadata (values are never returned) |
create_secret | Create a new encrypted secret |
delete_secret | Permanently delete a secret |
#### Attachments
| Tool | Description |
|---|---|
upload_attachment | Upload a file for use in sessions (returns URL for ATTACHMENT:"<url>" format) |
The v3 server includes all the same categories as v1 (with expanded session tools) plus schedules and an additional attachment tool. All operations are scoped to your organization.
#### Sessions (14 tools) Expanded session management including listing by status, bulk operations, and session events.
#### Knowledge (4 tools) Same as v1 — list, create, update, delete.
#### Playbooks (5 tools) Same as v1 — list, get, create, update, delete.
#### Secrets (3 tools) Same as v1 — list, create, delete.
#### Schedules (5 tools)
| Tool | Description |
|---|---|
list_schedules | List scheduled Devin sessions |
get_schedule | Get schedule details |
create_schedule | Create a recurring scheduled session |
update_schedule | Update an existing schedule |
delete_schedule | Delete a schedule |
#### Attachments (2 tools) Upload and manage files for use in sessions.
/v3/enterprise/...) and beta (/v3beta1/...) endpoints are intentionally excluded.Written in TypeScript with Zod schema validation.
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.