Skip to main content

Command in the terminal

Use our Command modality in the terminal (Cmd/Ctrl+I) to generate the proper CLI syntax from prompts in natural language.

Send terminal selection to the agent

Highlight a portion of the stack trace and press Cmd/Ctrl+L to send it to the agent panel, where you can reference this selection in your next prompt.

@-mention your terminal

Chat with the agent about your active terminals.

Auto-executed agent commands

The agent has the ability to run terminal commands on its own with user permission. You can configure how the agent handles command execution through four distinct auto-execution levels, and certain terminal commands can be accepted or rejected automatically through the Allow and Deny lists.

Auto-Execution Levels

Auto-execution levels apply to Cascade. The Devin Local agent replaces them with its own permissions model, which controls command execution with allow, ask, and deny rules instead.
Devin Desktop provides four levels of command auto-execution, giving you control over how the agent runs terminal commands: You can select your preferred auto-execution level via the Devin Settings panel in the bottom right corner of the editor.

Admin-Controlled Maximum Level (Teams & Enterprise)

For Teams and Enterprise users, administrators can set a maximum allowed auto-execution level for their organization. This setting restricts which levels are available to team members, allowing admins to enforce security policies while still giving users flexibility within those bounds. When an admin sets a maximum level, users can select any level up to and including that maximum. For example, if an admin sets the maximum to “Auto”, users can choose between Disabled, Allowlist Only, or Auto, but cannot enable Turbo mode. Administrators can configure this setting in the Admin Portal under Team Settings.

Team-Wide Command Lists (Teams & Enterprise)

Administrators can configure team-wide allowlist and denylist for terminal commands that apply to all team members. These lists work in addition to individual user allow/deny lists. Key behaviors:
  • Team and user configs are merged: Team-level lists are combined with each user’s individual allow list and deny list. A command matching either the team or user allowlist will be auto-executed (unless blocked by a denylist).
  • The denylist takes precedence over the allowlist—if a command matches both lists (at either team or user level), it will require approval
To configure team-wide command lists, go to the Admin Portal → Team Settings → Terminal Commands → Manage Lists.

Allow list

An allow list defines a set of terminal commands that will always auto-execute. Entries ending in * match every command that starts with the same tokens; other entries match only that exact command. For example, if git * is on your allow list, then the agent will always accept git add -A. You manage your allow list from the agent’s terminal command cards:
  • When the agent is waiting for approval, open the dropdown next to Run. Under Allowlist, choose Prefix to auto-run every command that starts with the base command (for example, git *), or Allow to auto-run only that exact command.
  • On a command that has already run, open Auto-run settings (the settings icon on the command card) and choose the same options.
Select the highlighted entry again to remove it from your allow list.

Deny list

A deny list defines a set of terminal commands that will never auto-execute. For example, if rm * is on your deny list, then the agent will always ask for permission to run rm index.py. To add a command to your deny list, open the same dropdown next to Run (or Auto-run settings on a command that has already run) and choose Deny. This denies every command that starts with the base command. Select Deny again to remove it.
These per-user allow and deny lists apply to Cascade. For the Devin Local agent, configure command patterns in Devin Local settings under Allow, Deny, and Ask instead. See permissions for the rule syntax. Team-wide lists are managed separately in the Admin Portal, as described in Team-Wide Command Lists above.

Dedicated terminal

Devin Desktop provides a dedicated terminal for the agent to use for running commands on macOS and Linux. This dedicated terminal is separate from your default terminal and uses a fixed shell for each platform: zsh on macOS and bash on Linux.
The dedicated terminal will use your configuration for that shell, so aliases and environment variables will be available from your shell configuration files (for example, .zshrc on macOS or .bashrc on Linux). If your default terminal uses a different shell, and you want Devin Desktop to use shared environment variables, we recommend creating a shared configuration file that both shells can source.

Troubleshooting

If you have issues with the dedicated terminal, you can revert to the legacy terminal by enabling the Legacy Terminal Profile option in Devin Desktop settings.