- Connection: the REST API key Devin uses to post incident notes and updates.
- Webhook: sends incident events to Devin to trigger automations.
- App registration: sets up the PagerDuty MCP server, and lets members connect their PagerDuty accounts.
Setting up the integration
- In PagerDuty, go to Integrations > API Access Keys and click “Create New API Key”. Create a General Access key with full access, and copy it. User API tokens are not accepted.
- In your Devin account at app.devin.ai, go to Settings > Connections > PagerDuty, and click “Connect”.
- Select your API region (US or EU), then enter:
- Actor email: the PagerDuty user that Devin’s incident notes and updates are attributed to. We recommend a dedicated service user.
- General Access REST API key: the key you created in step 1.
- Click “Connect”. Devin automatically creates a webhook subscription in PagerDuty so it can receive incident events.
Configure webhook subscriptions
When you connect, Devin creates one account-wide webhook subscription in PagerDuty. It sends these events to Devin:incident.triggeredincident.acknowledgedincident.resolvedincident.priority_updatedincident.reassignedincident.service_updated
- In the Webhook section, click “Add webhook” and copy the webhook URL.
- In PagerDuty, go to Integrations > Generic Webhooks (v3), and add a webhook that points at that URL with Account scope.
- Select the incident event types listed above.
- Copy the signing secret PagerDuty shows once, paste it into Devin, and click “Save”.
Disconnecting PagerDuty stops incident events and deletes the webhook subscription Devin created. It does not remove the app registration or the PagerDuty MCP server.
Register Devin as an OAuth app
The PagerDuty MCP server signs in each member with OAuth. PagerDuty doesn’t support automatic OAuth client registration, so an admin registers Devin as an OAuth app in PagerDuty and adds it under App registration in Connections. Saving the app registration sets up the PagerDuty MCP server for you.Create the app in PagerDuty
- In Settings > Connections > PagerDuty, copy the Redirect URI shown in the App registration section.
- In PagerDuty, go to Integrations > App Registration and click “New App”. Enter a name, such as
Devin, and select OAuth 2.0. - Select Scoped OAuth, and add the redirect URI from Devin as a Redirect URL.
- Under permission scopes, select the scopes you want Devin to have. We recommend
abilities.read,escalation_policies.read,incidents.read,incidents.write,oncalls.read,priorities.read,schedules.read,services.read,teams.read, andusers.read. - Register the app, then copy the client ID and client secret.
Add the app registration in Devin
- In the App registration section, enter the Client ID and Client secret from your PagerDuty app.
- Select the API region of your PagerDuty account (US or EU).
- Leave Scopes empty to use the permissions configured on your PagerDuty app. To request only some of them, enter a space-separated list of scopes that are enabled on the app.
- Click “Save”.
Changing the client ID or region disconnects every member’s PagerDuty account. Each member needs to connect again.
Existing PagerDuty MCP servers
A PagerDuty MCP server installed with its own OAuth client ID and secret keeps working, and members who already connected through it stay connected. The App registration section shows a warning that it isn’t fully connected. To switch it over, add the app registration, then click “Use app registration” in the warning. Members then connect their PagerDuty accounts again through the app registration.Shared access with client credentials
Enterprise admins can instead add PagerDuty as an enterprise MCP server with the Client credentials grant type, so sessions use one shared app token and members don’t sign in. PagerDuty requires the OAuth scope field for this grant, and it must start with your account selector:<region> is us or eu and <subdomain> is the part of your PagerDuty URL before .pagerduty.com, followed by a space-separated list of scopes enabled on the app. The PagerDuty MCP server requires users.read to accept the token, so the app must have that scope and it must be in the list. For example: as_account-us.acme users.read incidents.read oncalls.read schedules.read services.read. If the scope is missing or malformed, the token can’t be minted and the server shows Connect in Customize.
Client credentials is read-only. PagerDuty rejects write operations (for example
manage_incidents) from an app token even when *.write scopes are granted, because writes require a user identity. Request only *.read scopes. For write access, use personal connections or an organization-level Authorization code server connected as a dedicated PagerDuty bot user.Connecting your PagerDuty user account
In addition to the organization-level integration, each team member links their own PagerDuty account to their Devin account. This lets Devin use the PagerDuty MCP server as that member. It’s also required to create PagerDuty automations. To connect your user account, go to Personal Connections, click “Connect” next to PagerDuty, and approve access in PagerDuty. Use a PagerDuty user from the PagerDuty account your organization connected.Members can only connect once an admin has added the app registration. PagerDuty MCP access through the app registration is always personal: Devin never uses a shared organization token for it, so each member must connect their own PagerDuty user account before Devin can use PagerDuty tools in their sessions. The exception is an enterprise MCP server using client credentials.
Triggering Devin from PagerDuty
Devin starts working on PagerDuty incidents through automations. Once PagerDuty is connected, you don’t need to set up a separate webhook for each automation.- Go to Automations and create a new automation.
- Add a trigger, choose PagerDuty, and pick an event:
- Incident triggered: a new incident opens.
- Incident acknowledged: someone acknowledges an incident.
- Incident resolved: an incident is resolved.
- Incident updated: an incident’s priority, assignment, or service changes.
- Optionally add conditions to narrow which incidents match:
- Service, Team, and Priority: options load from your PagerDuty account.
- Urgency (
highorlow) and Status. - Title, Escalation policy, and Assignee.
- Change (
priority,assignment, orservice): for Incident updated only.
- Add a Start session action with instructions for Devin, and save.
checkout-api and Urgency is high. Then add a prompt such as: “Investigate this incident. Check recent deploys and error logs for checkout-api, and find the likely root cause.”
To create or edit an automation with a PagerDuty trigger, you must connect your PagerDuty user account first. Your PagerDuty user must belong to the PagerDuty account your organization connected.

