---
title: Devin Provider
---

# Devin Provider

## What it is

Omniscio can run **Cognition's Devin** — a remote cloud coding agent — as one of its selectable session providers, alongside `claude` (the default), `codex`, `grok`, `gemini`, and the rest of the pickable set. Unlike the local-CLI providers, Devin runs entirely on Cognition's cloud: Omniscio drives it over Devin's public **v1 REST API** and there is **no binary to install**. Devin **shipped as a first-class provider on 2026-08-25** — it appears in the provider picker for everyone; you just add your own Devin API key to use it.

### What the user sees

A Devin session looks like any other in the sidebar and main pane — same status dots, same message bubbles, same Ctrl+Enter to send — with a few Devin-specific differences:

- The session header shows the **Devin** engine mark next to the title, like every non-default provider.
- Replies stream in as Omniscio **polls** Devin's cloud (Devin has no webhooks/streaming), so progress appears as each new Devin message lands rather than token-by-token.
- **Cost shows as "cost not reported," not $0.** Devin's session API doesn't return a per-turn dollar/token figure (Devin bills in **ACUs** on its own consumption endpoints), so Omniscio honestly reports no cost rather than a misleading zero. Wiring live ACU spend is a tracked follow-up.
- A Devin session **does not re-attach after an Omniscio restart** (v1). If you restart the app mid-run, the remote session keeps going on Devin's side but Omniscio won't reconnect to it automatically.

## Where to find it

### How to enable

> **Master toggle required first.** Devin is an alternative provider — by default Omniscio ships as a Claude-only product. Flip **Settings → Accounts → Show alternative AI providers** to ON and the alternative-provider section (including the Devin card) appears. With the master off, the per-project "Default provider" radio collapses to a single Claude row and the provider switcher hides Devin.

Two things in **Settings → Accounts → Devin (Cognition)**:

1. **Allow Devin sessions in any project** — off by default (the same security stance as every provider's spawn gate). Turning it on reveals the API-key field.
2. **Devin API key** — paste an `apk_` key from your **Devin dashboard** (the card's **Get your Devin API key** button opens <https://app.devin.ai/settings/api-keys>). The key is stored encrypted in a main-only credential store and is redacted before it ever reaches the renderer. An optional, non-secret **Devin org id** may be provided for display; the v1 API derives the org from the key, so it is not required.

There is **no API-key-on-the-command-line and no binary check** — Devin is remote, so the card has no install/recheck bits. Usage is **billed in ACUs on your own Devin account**, and Omniscio always sends a hard per-session ACU cap on create so a runaway remote session can't drain your account.

Once the toggle is on and a key is saved, you can launch a Devin session three ways:

- **Per-launch override** — on a fresh (zero-message) session, pick Devin in the new session's provider switcher before sending the first message.
- **Per-project default** — the Edit Project dialog's "Default provider" section has a radio for Devin; the project's "+ New Session" button then spawns Devin automatically.
- **Programmatically** — anything that creates a session with `provider: 'devin'` (recipes, agent-driven sessions, the CLI control API). The same readiness gates apply on the backend.

## How it behaves

### First-message length limit

Devin's `POST /v1/sessions` **rejects a prompt of 30,000+ characters** (HTTP 400 "Prompt is too long"). So a Devin session's **first message is length-budgeted to 29,000 characters**: Omniscio drops the auto skills-index and fits the auto-attached docs to the budget while always keeping Omniscio's own bundle plus your actual task, and warns you if it still had to trim. Follow-up messages are not budgeted.

### Limitations (v1)

- **No cost reporting yet** — "cost not reported" until live ACU wiring lands.
- **No restart re-attach** — a running Devin session is not re-established after an Omniscio restart.
- **No images, no MCP servers, no permission prompts** — Devin runs autonomously in its own cloud; these capabilities are off for the Devin engine.

## For agents

### How it works under the hood

- **Transport is HTTP polling, not a local process.** `DevinClient` ([devin-client.ts](../../src/main/services/engines/devin-client.ts)) calls `createSession` / `getSession` / `sendMessage` against `https://api.devin.ai/v1/...`; `DevinSessionManager` ([devin-session-manager.ts](../../src/main/services/engines/devin-session-manager.ts)) extends `BaseExternalSessionManager` and runs the poll loop (a 4-second cadence, with a jittered exponential backoff up to 32 s after consecutive failures so a down `api.devin.ai` isn't hammered in lock-step).
- **A successful poll is the liveness signal.** Each tick refreshes the session's last-output time, so the shared output-silence stall watchdog never force-recovers a Devin session that is legitimately quiet while working in its own cloud VM. Genuine trouble is still bounded: the 4-hour turn cap, a lost-contact threshold (consecutive `getSession` failures), and Devin's own `expired` status each end the turn honestly.
- **Status mapping.** Devin `working`/transitional → keep polling; `blocked`/`finished` → conclude the turn and hand back to you (needs-you); `expired` → an honest error row. Only Devin's own `devin_message` output is surfaced as streaming text — the operator's echoed prompt is filtered out.
- **Honest errors.** A rejected key (401/403) says to check the key in Settings → Accounts; a 429 says Devin is rate-limiting; a connection failure says Devin couldn't be reached — never a blanket "check your API key" that masks the real cause, and never the raw provider body (that is logged only).
- **Credentials are main-only.** The `apk_` key lives in `devinApiKey` (encrypted at rest, redacted from the renderer); readiness requires only the key.

### Cost

Devin is billed in **ACUs on your own Devin account**, and its session API exposes no per-turn cost/token figure, so Omniscio reports **"cost not reported"** for Devin turns (never a misleading $0). Wiring live ACU spend from Devin's consumption endpoints into the Omniscio spend ledger is a tracked follow-up. Omniscio always sends a hard per-session ACU limit on create as a runaway guard.

### Files

- [src/main/services/engines/devin-session-manager.ts](../../src/main/services/engines/devin-session-manager.ts) — poll-loop orchestration (create/continue, status mapping, honest turn conclusion)
- [src/main/services/engines/devin-client.ts](../../src/main/services/engines/devin-client.ts) — the v1 REST client (`createSession` / `getSession` / `sendMessage`, humanized throws)
- [src/main/services/engines/devin-credential-store.ts](../../src/main/services/engines/devin-credential-store.ts) — main-only `apk_` key + optional org id
- [src/renderer/src/features/settings/sections/accounts/DevinSection.tsx](../../src/renderer/src/features/settings/sections/accounts/DevinSection.tsx) — Settings → Accounts key-entry card
- [src/shared/providers/registry.ts](../../src/shared/providers/registry.ts) — the `devin` provider descriptor (pickerOrder 17, `costReporting: 'none'`, 29k first-message budget)

## Related

- [grok-provider.md](grok-provider.md) — another first-class alternative provider that also reports no per-turn cost
- [openclaw-provider.md](openclaw-provider.md) — the other remote, no-local-process engine (a WebSocket gateway rather than REST polling)
- [antigravity-provider.md](antigravity-provider.md) — another alternative provider (Google's local `agy` CLI), for contrast with Devin's remote model
