> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cantina.security/llms.txt
> Use this file to discover all available pages before exploring further.

# Devin

> Connect a Devin Teams organization so Clarion agents can read and write org skills, search sessions, ask Devin to investigate a question, and, with an Admin service user, look up members.

This guide walks you through connecting a Devin Teams organization to Clarion. Once connected, agents on the workspace can read and write org skills, search sessions, read a session's recent messages, and start a Devin session that investigates a question and reports back. Listing and reading organization members is available only when the service user has the Admin role.

<Note>
  **Estimated time:** 5 minutes. You need access to **Settings > Devin API** in a **Devin Teams** organization so you can create a service user.
</Note>

## Prerequisites

* A **Devin Teams** organization
* Permission to create a **service user** under **Settings > Devin API**
* A **Clarion workspace** with the Devin integration page open

<Warning>
  One Clarion workspace connects one Devin organization. The key you paste acts as that service user. Personal access tokens and legacy `apk_` or `apk_user_` keys are rejected. Create a service-user key that starts with `cog_`.
</Warning>

***

## Step 1 — Create a service-user key in Devin

1. Sign in to Devin for the Teams organization you want to connect.
2. Open **Settings > Devin API**.
3. Create a **service user**. Choose **Member** if agents only need skills and sessions. Agents need the service user to hold `ViewOrgSessions` to read sessions and `ManageOrgSessions` to start them. Choose **Admin** if they also need to list and read organization members.
4. Copy the key. It begins with `cog_`.

<Warning>
  Copy the key immediately and store it securely. Devin shows it once. A personal access token, or a legacy `apk_` / `apk_user_` key, will be rejected.
</Warning>

***

## Step 2 — Enter the key in Clarion

1. In Clarion, open **Integrations** and find **Devin** under Development & Planning.
2. Paste the **service-user API key**.
3. Click **Connect**.

Clarion checks the key with Devin before saving it, and checks whether that service user can list organization members. If the key is a personal token, a legacy key, or does not belong to one organization, you'll see a clear error and nothing is stored.

After it connects, the page shows the organization id and the service user's name. Those values are read-only. To replace the key, paste a new one and save. Saving re-runs the member-access check. If the check fails, skills and sessions still work, and member tools stay unavailable until you save an Admin-role key.

***

## What agents can do

| Tool | What it does |
| - | - |
| `get_devin_skill` | Read one org skill by name, or list the skill names Clarion itself has written |
| `create_devin_skill` | Create an org skill that does not exist yet. Asks for approval by default |
| `update_devin_skill` | Replace one org skill's full document. Asks for approval by default |
| `delete_devin_skill` | Delete one org skill by name. Asks for approval by default |
| `search_devin_sessions` | Search sessions in this organization. Returns titles and status, not message text |
| `create_devin_session` | Start a session that investigates a question and reports its findings. Asks for approval by default. Returns only the session id, URL, and status |
| `get_devin_session` | Read one session's status, so the agent knows when the answer is ready |
| `get_devin_session_messages` | Read the most recent messages of one session, up to 200. For a session longer than 2000 messages, the result is flagged and holds the tail of the first 2000, not the latest. |
| `list_users` | List organization members. Requires an Admin-role service user |
| `get_user` | Read one organization member. Requires an Admin-role service user |

A Member role is enough for skills and sessions. `list_users` and `get_user` need an Admin role.

Skill writes and session creation ask for approval by default. A workspace can turn that off the same way it does for other write tools.

### Asking Devin to investigate

`create_devin_session` is for gathering information, not for authoring content. Clarion adds an instruction to every prompt telling Devin to report its findings as a message in the session and not to open pull requests, push commits, or change external systems. The prompt is limited to 4,000 characters, and prompts, titles, or tags that look like secrets are rejected.

By default, a person approves each session before it starts. If a workspace turns that approval off, the instruction Clarion adds to the prompt is the only limit on what the session is asked to do, and Devin acts with the access its organization grants. Sessions run asynchronously: the create call returns right away with the session id, URL, and status. The agent then checks `get_devin_session` until the session is finished or waiting for input, and reads the answer with `get_devin_session_messages`.

Clarion only knows skills it wrote. Devin has no skill list endpoint, so a skill created outside Clarion does not appear in that list. An agent can still read or update it if you already know the name.

***

## Disconnect

To remove the integration:

1. In Clarion, open **Integrations → Devin**.
2. Click **Disconnect**.

This deletes the stored key. Agents lose the Devin tools, and any saved skills that reference the Devin action will surface the integration as missing until you reconnect.

***

## Troubleshooting

### "Devin rejected the key"

The key is malformed, unknown, or revoked, or it is not a `cog_` service-user key. Create a fresh service-user key in **Settings > Devin API** and connect again. Personal access tokens and legacy `apk_` keys are not accepted.

### "Devin connect requires a service-user API key"

The key authenticated as a person rather than a service user. Create a service user in **Settings > Devin API** and paste that key.

### Member tools are missing

The connected service user is not an Admin, so it cannot list organization members. Skills and sessions still work. Create an Admin-role service user, paste its key, and save. Saving re-runs the check.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.