curl --request POST \
--url https://api.devin.ai/v3/organizations/{org_id}/code-scans \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"commit_sha": "<string>",
"host": "<string>",
"interactive": false,
"new_budget": {
"acu_limit": 500000
},
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
'import requests
url = "https://api.devin.ai/v3/organizations/{org_id}/code-scans"
payload = {
"commit_sha": "<string>",
"host": "<string>",
"interactive": False,
"new_budget": { "acu_limit": 500000 },
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
commit_sha: '<string>',
host: '<string>',
interactive: false,
new_budget: {acu_limit: 500000},
platform: '<string>',
profile_id: '<string>',
repo_name: '<string>',
repos: [{repo_name: '<string>', host: '<string>'}]
})
};
fetch('https://api.devin.ai/v3/organizations/{org_id}/code-scans', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.devin.ai/v3/organizations/{org_id}/code-scans",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'commit_sha' => '<string>',
'host' => '<string>',
'interactive' => false,
'new_budget' => [
'acu_limit' => 500000
],
'platform' => '<string>',
'profile_id' => '<string>',
'repo_name' => '<string>',
'repos' => [
[
'repo_name' => '<string>',
'host' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.devin.ai/v3/organizations/{org_id}/code-scans"
payload := strings.NewReader("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.devin.ai/v3/organizations/{org_id}/code-scans")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.devin.ai/v3/organizations/{org_id}/code-scans")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"created_at": 123,
"effort": "normal",
"host": "<string>",
"org_id": "<string>",
"profile": {
"name": "<string>",
"profile_id": "<string>"
},
"repo_name": "<string>",
"scan_id": "<string>",
"scan_type": "security",
"status": "waiting",
"url": "<string>",
"outpost_pool_id": "<string>",
"platform": "<string>",
"repo_full_name": "<string>"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}Start Code Scan (Devin API)
Start a new Devin code scan on one or more repositories via the v3 organization API, optionally with a scan profile, commit SHA, or effort
curl --request POST \
--url https://api.devin.ai/v3/organizations/{org_id}/code-scans \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"commit_sha": "<string>",
"host": "<string>",
"interactive": false,
"new_budget": {
"acu_limit": 500000
},
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
'import requests
url = "https://api.devin.ai/v3/organizations/{org_id}/code-scans"
payload = {
"commit_sha": "<string>",
"host": "<string>",
"interactive": False,
"new_budget": { "acu_limit": 500000 },
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
commit_sha: '<string>',
host: '<string>',
interactive: false,
new_budget: {acu_limit: 500000},
platform: '<string>',
profile_id: '<string>',
repo_name: '<string>',
repos: [{repo_name: '<string>', host: '<string>'}]
})
};
fetch('https://api.devin.ai/v3/organizations/{org_id}/code-scans', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.devin.ai/v3/organizations/{org_id}/code-scans",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'commit_sha' => '<string>',
'host' => '<string>',
'interactive' => false,
'new_budget' => [
'acu_limit' => 500000
],
'platform' => '<string>',
'profile_id' => '<string>',
'repo_name' => '<string>',
'repos' => [
[
'repo_name' => '<string>',
'host' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.devin.ai/v3/organizations/{org_id}/code-scans"
payload := strings.NewReader("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.devin.ai/v3/organizations/{org_id}/code-scans")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.devin.ai/v3/organizations/{org_id}/code-scans")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"created_at": 123,
"effort": "normal",
"host": "<string>",
"org_id": "<string>",
"profile": {
"name": "<string>",
"profile_id": "<string>"
},
"repo_name": "<string>",
"scan_id": "<string>",
"scan_type": "security",
"status": "waiting",
"url": "<string>",
"outpost_pool_id": "<string>",
"platform": "<string>",
"repo_full_name": "<string>"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}Permissions
Requires a service user or personal access token with theUseCodeScans permission at the organization level.
Behavior
Enqueues a new code scan for the given repository (repo_name) or repositories (repos) in the organization. The scan is launched asynchronously by the scan dispatcher; the response is the scan record with an initial status of waiting or pending. Poll List Code Scans to track progress, and List Code Scan Findings (filtered by scan_id) to read results once the scan reaches completed.
The scan is attributed to the calling principal (the service user or PAT that made the request). The enterprise-scoped equivalent is Start Code Scan (Enterprise).
Request fields
Provide exactly one ofrepo_name or repos.
repo_name: full repository name, e.g.owner/repo. The repository must already be accessible through the organization’s Git integration.host: Git host of the repository, if it cannot be inferred.repos: repositories covered by one multi-repo scan, as a list of objects withrepo_nameand an optionalhost(up to 200). The first entry is the scan’s primary repository.profile_id: a scan profile to apply. Use Start Ingestion Scan foringest-mode profiles.scan_type: type of scan to run. Must match the profile’s scan type whenprofile_idis given. Defaults to the profile’s type, orsecurityfor profile-less scans. Non-security scan types require a profile.commit_sha: commit to check out before scanning. Defaults to the repository’s default branch head.effort:normal(default) uses lower model reasoning effort with larger investigation batches;deepruns the full pipeline.interactive: whentrue, the scan pauses inawaiting_user_inputfor user review between threat modeling and investigation. Defaults tofalse. Only security scans support interactive review; other scan types run unattended.platform: where the scan’s sessions run, either a platform label configured for the organization (for examplelinux,windows, ormacos) or the name of an outpost pool, case-insensitive. Platforms take priority when a name matches both. Defaults to the organization default.
Errors
400whenscan_typeconflicts with the profile, a non-securityscan_typeis given without a profile, orplatformdoes not match a configured platform label or outpost pool (the error body lists the available values).403when the organization is restricted to ingestion-only scans and noingest-mode profile is given.404when the repository or profile is not visible to the organization.409when the organization’s scan backlog is at capacity. Retry later.422when both or neither ofrepo_nameandreposare provided, orreposis empty.
Authorizations
Service User credential (prefix: cog_)
Path Parameters
Organization ID (prefix: org-)
"org-abc123def456"
Body
Request body for starting a new code scan.
Commit to check out before scanning.
Scan effort: 'normal' (default) uses lower model reasoning effort with larger investigation batches; 'deep' runs the full pipeline.
normal, deep Git host of the repository, if known.
When true, the scan pauses for user review between threat modeling and investigation.
Give the scan its own ACU budget. Requires the ManageAccountServiceUsers and ManageAcuLimits permissions.
Show child attributes
Show child attributes
Where the scan's sessions run: a platform label configured for the organization (e.g. 'linux', 'windows', 'macos') or the name of an outpost (BYOB) pool, case-insensitive; platforms take priority when a name matches both. Omitted means the organization default. Unrecognized values are rejected with a 400 whose error body lists the available platform labels and outpost pool names.
128Scan profile to apply to the scan.
Full name of the repository to scan. Provide exactly one of repo_name or repos.
Repositories covered by one scan; the first entry is the scan's primary repository. Provide exactly one of repo_name or repos.
200Show child attributes
Show child attributes
Type of scan to run. Must match the profile's scan type when a profile is given; defaults to the profile's type, or 'security' for profile-less scans. Non-security types require a profile and are rejected without one.
security, performance, db-queries, test-coverage, dead-code, code-quality, cleanup, telemetry, accessibility, compliance, general, migration-docs Response
Successful Response
A single code scan.
When the scan was created (unix seconds).
Scan effort: 'normal' uses lower model reasoning effort with larger investigation batches; 'deep' runs the full pipeline.
normal, deep Git host of the repository, if known.
Organization the scan belongs to.
Profile the scan ran under, if any.
Show child attributes
Show child attributes
Primary repository of the scan. Multi-repo scans cover additional repositories not listed here.
Unique identifier for the scan.
Type of scan, stamped at creation.
security, performance, db-queries, test-coverage, dead-code, code-quality, cleanup, telemetry, accessibility, compliance, general, migration-docs Scan status: waiting, pending, running, awaiting_user_input, completed, failed, or cancelled.
waiting, pending, running, awaiting_user_input, completed, failed, cancelled URL of the scan's page in the Devin webapp.
Outpost pool the scan's sessions run on, if one is set.
Hosted platform label the scan's sessions run on. Null when the scan runs on an outpost pool or the organization default.
Host-qualified identity of the primary repository (e.g. github.com/org/repo). Null for Perforce depots, which have no git host.

