curl --request POST \
--url https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans/ingestion \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"profile_id": "<string>",
"attachment_urls": [
"<string>"
],
"host": "<string>",
"platform": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
'import requests
url = "https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans/ingestion"
payload = {
"profile_id": "<string>",
"attachment_urls": ["<string>"],
"host": "<string>",
"platform": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
profile_id: '<string>',
attachment_urls: ['<string>'],
host: '<string>',
platform: '<string>',
repo_name: '<string>',
repos: [{repo_name: '<string>', host: '<string>'}]
})
};
fetch('https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans/ingestion', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans/ingestion",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'profile_id' => '<string>',
'attachment_urls' => [
'<string>'
],
'host' => '<string>',
'platform' => '<string>',
'repo_name' => '<string>',
'repos' => [
[
'repo_name' => '<string>',
'host' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans/ingestion"
payload := strings.NewReader("{\n \"profile_id\": \"<string>\",\n \"attachment_urls\": [\n \"<string>\"\n ],\n \"host\": \"<string>\",\n \"platform\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans/ingestion")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"profile_id\": \"<string>\",\n \"attachment_urls\": [\n \"<string>\"\n ],\n \"host\": \"<string>\",\n \"platform\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans/ingestion")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"profile_id\": \"<string>\",\n \"attachment_urls\": [\n \"<string>\"\n ],\n \"host\": \"<string>\",\n \"platform\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"created_at": 123,
"effort": "normal",
"host": "<string>",
"org_id": "<string>",
"profile": {
"name": "<string>",
"profile_id": "<string>"
},
"repo_name": "<string>",
"scan_id": "<string>",
"scan_type": "security",
"status": "waiting",
"url": "<string>",
"outpost_pool_id": "<string>",
"platform": "<string>",
"repo_full_name": "<string>"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}Start Ingestion Scan (Devin API)
Start an ingestion-mode Devin code scan that triages findings from an external scanner using an ingest profile via the v3 enterprise API
curl --request POST \
--url https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans/ingestion \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"profile_id": "<string>",
"attachment_urls": [
"<string>"
],
"host": "<string>",
"platform": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
'import requests
url = "https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans/ingestion"
payload = {
"profile_id": "<string>",
"attachment_urls": ["<string>"],
"host": "<string>",
"platform": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
profile_id: '<string>',
attachment_urls: ['<string>'],
host: '<string>',
platform: '<string>',
repo_name: '<string>',
repos: [{repo_name: '<string>', host: '<string>'}]
})
};
fetch('https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans/ingestion', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans/ingestion",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'profile_id' => '<string>',
'attachment_urls' => [
'<string>'
],
'host' => '<string>',
'platform' => '<string>',
'repo_name' => '<string>',
'repos' => [
[
'repo_name' => '<string>',
'host' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans/ingestion"
payload := strings.NewReader("{\n \"profile_id\": \"<string>\",\n \"attachment_urls\": [\n \"<string>\"\n ],\n \"host\": \"<string>\",\n \"platform\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans/ingestion")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"profile_id\": \"<string>\",\n \"attachment_urls\": [\n \"<string>\"\n ],\n \"host\": \"<string>\",\n \"platform\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans/ingestion")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"profile_id\": \"<string>\",\n \"attachment_urls\": [\n \"<string>\"\n ],\n \"host\": \"<string>\",\n \"platform\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"created_at": 123,
"effort": "normal",
"host": "<string>",
"org_id": "<string>",
"profile": {
"name": "<string>",
"profile_id": "<string>"
},
"repo_name": "<string>",
"scan_id": "<string>",
"scan_type": "security",
"status": "waiting",
"url": "<string>",
"outpost_pool_id": "<string>",
"platform": "<string>",
"repo_full_name": "<string>"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}Permissions
Requires a service user or personal access token with theUseAccountCodeScans permission at the enterprise level.
Behavior
Enqueues an ingestion-mode code scan. Instead of discovering issues from scratch, an ingestion scan takes findings produced elsewhere (for example a SAST report) and has Devin triage and validate them against the repository. The scan is launched asynchronously by the scan dispatcher and attributed to the calling principal.Request fields
Provide exactly one ofrepo_name or repos.
repo_name: full repository name, e.g.owner/repo.repos: repositories covered by one multi-repo scan, as a list of objects withrepo_nameand an optionalhost(up to 200). The first entry is the scan’s primary repository.profile_id(required): aningest-mode scan profile. Adiscover-mode profile is rejected with400.host: Git host of the repository, if it cannot be inferred.attachment_urls: Devin attachment URLs (for example an exported scanner report) to provide to the scan. Upload files first with the attachments API.effort:normal(default) uses lower model reasoning effort with larger triage and validation batches;deepruns the full pipeline.platform: where the scan’s sessions run, either a platform label configured for the organization (for examplelinux,windows, ormacos) or the name of an outpost pool, case-insensitive. Platforms take priority when a name matches both. Defaults to the organization default.
Errors
400whenprofile_idis not an ingestion-mode profile, orplatformdoes not match a configured platform label or outpost pool (the error body lists the available values).404when the organization, repository, or profile is not visible to the enterprise account.409when the organization’s scan backlog is at capacity. Retry later.422when both or neither ofrepo_nameandreposare provided, orreposis empty.
Authorizations
Service User credential (prefix: cog_)
Path Parameters
Organization ID (prefix: org-)
"org-abc123def456"
Body
Request body for starting an ingestion-mode code scan.
Only accepts an ingestion (ingest-mode) scan profile: the profile is run against the given repository (or repositories).
Ingestion-mode scan profile to run. Must be an ingest profile; non-ingest profiles are rejected with 400.
Devin attachment URLs to provide to the scan, e.g. files uploaded via the attachments API. The attachments must belong to the organization being scanned.
101 - 2083Scan effort: 'normal' (default) uses lower model reasoning effort with larger triage and validation batches; 'deep' runs the full pipeline.
normal, deep Git host of the repository, if known.
Where the scan's sessions run: a platform label configured for the organization (e.g. 'linux', 'windows', 'macos') or the name of an outpost (BYOB) pool, case-insensitive; platforms take priority when a name matches both. Omitted means the organization default. Unrecognized values are rejected with a 400 whose error body lists the available platform labels and outpost pool names.
128Full name of the repository to scan. Provide exactly one of repo_name or repos.
Repositories covered by one scan; the first entry is the scan's primary repository. Provide exactly one of repo_name or repos.
200Show child attributes
Show child attributes
Response
Successful Response
A single code scan.
When the scan was created (unix seconds).
Scan effort: 'normal' uses lower model reasoning effort with larger investigation batches; 'deep' runs the full pipeline.
normal, deep Git host of the repository, if known.
Organization the scan belongs to.
Profile the scan ran under, if any.
Show child attributes
Show child attributes
Primary repository of the scan. Multi-repo scans cover additional repositories not listed here.
Unique identifier for the scan.
Type of scan, stamped at creation.
security, performance, db-queries, test-coverage, dead-code, code-quality, cleanup, telemetry, accessibility, compliance, general, migration-docs Scan status: waiting, pending, running, awaiting_user_input, completed, failed, or cancelled.
waiting, pending, running, awaiting_user_input, completed, failed, cancelled URL of the scan's page in the Devin webapp.
Outpost pool the scan's sessions run on, if one is set.
Hosted platform label the scan's sessions run on. Null when the scan runs on an outpost pool or the organization default.
Host-qualified identity of the primary repository (e.g. github.com/org/repo). Null for Perforce depots, which have no git host.

