curl --request POST \
--url https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"commit_sha": "<string>",
"host": "<string>",
"interactive": false,
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
'import requests
url = "https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans"
payload = {
"commit_sha": "<string>",
"host": "<string>",
"interactive": False,
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
commit_sha: '<string>',
host: '<string>',
interactive: false,
platform: '<string>',
profile_id: '<string>',
repo_name: '<string>',
repos: [{repo_name: '<string>', host: '<string>'}]
})
};
fetch('https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'commit_sha' => '<string>',
'host' => '<string>',
'interactive' => false,
'platform' => '<string>',
'profile_id' => '<string>',
'repo_name' => '<string>',
'repos' => [
[
'repo_name' => '<string>',
'host' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans"
payload := strings.NewReader("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"created_at": 123,
"effort": "normal",
"host": "<string>",
"org_id": "<string>",
"profile": {
"name": "<string>",
"profile_id": "<string>"
},
"repo_name": "<string>",
"scan_id": "<string>",
"scan_type": "security",
"status": "waiting",
"url": "<string>",
"outpost_pool_id": "<string>",
"platform": "<string>",
"repo_full_name": "<string>"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}Code-Scan starten (Devin API)
Starten Sie über die v3 Enterprise API einen neuen Devin-Code-Scan für ein Repository in einer Organisation, optional mit einem Scan-Profil oder einem Commit
curl --request POST \
--url https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"commit_sha": "<string>",
"host": "<string>",
"interactive": false,
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
'import requests
url = "https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans"
payload = {
"commit_sha": "<string>",
"host": "<string>",
"interactive": False,
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
commit_sha: '<string>',
host: '<string>',
interactive: false,
platform: '<string>',
profile_id: '<string>',
repo_name: '<string>',
repos: [{repo_name: '<string>', host: '<string>'}]
})
};
fetch('https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'commit_sha' => '<string>',
'host' => '<string>',
'interactive' => false,
'platform' => '<string>',
'profile_id' => '<string>',
'repo_name' => '<string>',
'repos' => [
[
'repo_name' => '<string>',
'host' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans"
payload := strings.NewReader("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.devin.ai/v3/enterprise/organizations/{org_id}/code-scans")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"created_at": 123,
"effort": "normal",
"host": "<string>",
"org_id": "<string>",
"profile": {
"name": "<string>",
"profile_id": "<string>"
},
"repo_name": "<string>",
"scan_id": "<string>",
"scan_type": "security",
"status": "waiting",
"url": "<string>",
"outpost_pool_id": "<string>",
"platform": "<string>",
"repo_full_name": "<string>"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}Berechtigungen
Erfordert einen Service-Benutzer oder ein Personal Access Token mit der BerechtigungUseAccountCodeScans auf Unternehmensebene.
Verhalten
Stellt einen neuen Code-Scan für das angegebene Repository (repo_name) bzw. die angegebenen Repositorys (repos) in der angegebenen Organisation in die Warteschlange. Der Scan wird vom Scan-Dispatcher asynchron gestartet; die Antwort enthält den Scan-Datensatz mit dem anfänglichen status waiting oder pending. Rufen Sie regelmäßig Code-Scans auflisten auf, um den Fortschritt zu verfolgen, und verwenden Sie Code-Scan-Befunde auflisten (gefiltert nach scan_id), um die Ergebnisse abzurufen, sobald der Scan den Status completed erreicht.
Der Scan wird dem aufrufenden Principal zugeordnet (dem Service-Benutzer oder PAT, der die Anfrage gestellt hat).
Anfragefelder
Geben Sie genau eines der Felderrepo_name oder repos an.
repo_name: vollständiger Repository-Name, z. B.owner/repo. Das Repository muss bereits über die Git-Integration der Organisation zugänglich sein.host: Git-Host des Repositorys, falls er nicht automatisch ermittelt werden kann.repos: Repositorys, die von einem einzelnen Multi-Repo-Scan abgedeckt werden, als Liste von Objekten mitrepo_nameund optionalemhost(bis zu 200). Der erste Eintrag ist das primäre Repository des Scans.profile_id: ein anzuwendendes Scan-Profil. Verwenden Sie Ingestion-Scan starten für Profile im Modusingest.scan_type: Typ des auszuführenden Scans. Bei Angabe vonprofile_idmuss er dem Scan-Typ des Profils entsprechen. Standardmäßig wird der Typ des Profils verwendet, bei Scans ohne Profilsecurity. Nicht sicherheitsbezogene Scan-Typen erfordern ein Profil.commit_sha: Commit, der vor dem Scan ausgecheckt werden soll. Standardmäßig wird der HEAD des Standard-Branches des Repositorys verwendet.effort:normal(Standard) nutzt einen geringeren Reasoning-Aufwand des Modells bei größeren Untersuchungs-Batches;deepführt die vollständige Pipeline aus.interactive: Beitruehält der Scan zwischen Threat Modeling und Untersuchung im Statusawaiting_user_inputan, damit der Nutzer ein Review durchführen kann. Standardmäßigfalse. Interaktive Reviews werden nur von Sicherheits-Scans unterstützt; andere Scan-Typen laufen ohne Eingriff durch.platform: Ort, an dem die Sitzungen des Scans ausgeführt werden – entweder ein für die Organisation konfiguriertes Plattform-Label (zum Beispiellinux,windowsodermacos) oder der Name eines Outpost-Pools, ohne Beachtung der Groß-/Kleinschreibung. Passt ein Name auf beides, haben Plattformen Vorrang. Standardmäßig wird der Standardwert der Organisation verwendet.
Fehler
400, wennscan_typenicht mit dem Profil übereinstimmt, ein nicht sicherheitsbezogenerscan_typeohne Profil angegeben wird oderplatformkeinem konfigurierten Plattform-Label und keinem Outpost-Pool entspricht (der Fehlertext listet die verfügbaren Werte auf).403, wenn die Organisation auf reine Ingestion-Scans beschränkt ist und kein Profil imingest-Modus angegeben wird.404, wenn die Organisation, das Repository oder das Profil für das Enterprise-Konto nicht sichtbar ist.409, wenn das Scan-Backlog der Organisation seine Kapazitätsgrenze erreicht hat. Versuchen Sie es später erneut.422, wenn entweder sowohlrepo_nameals auchreposoder keines von beiden angegeben wird oder wennreposleer ist.
Autorisierungen
Servicebenutzer-Anmeldedaten (Präfix: cog_)
Pfadparameter
Organisations-ID (Präfix: org-)
"org-abc123def456"
Body
Request-Body zum Starten eines neuen Code-Scans.
Commit, der vor dem Scan ausgecheckt werden soll.
Scan-Aufwand: 'normal' (Standard) verwendet einen geringeren Reasoning-Aufwand des Modells und größere Untersuchungspakete; 'deep' führt die vollständige Pipeline aus.
normal, deep Git-Host des Repositorys, falls bekannt.
Bei true wird der Scan zwischen Bedrohungsmodellierung und Untersuchung für ein Review durch den Nutzer angehalten.
Wo die Sitzungen des Scans ausgeführt werden: eine für die Organisation konfigurierte Plattformbezeichnung (z. B. 'linux', 'windows', 'macos') oder der Name eines Outpost-Pools (BYOB), unabhängig von der Groß-/Kleinschreibung. Wenn ein Name sowohl einer Plattform als auch einem Pool entspricht, hat die Plattform Vorrang. Wird der Wert weggelassen, gilt der Standard der Organisation. Unbekannte Werte werden mit dem HTTP-Statuscode 400 abgelehnt; die Fehlerantwort listet die verfügbaren Plattformbezeichnungen und Outpost-Pool-Namen auf.
128Scan-Profil, das auf den Scan angewendet werden soll.
Vollständiger Name des zu scannenden Repositorys. Geben Sie entweder repo_name oder repos an, aber nicht beide.
Repositorys, die von einem Scan erfasst werden; der erste Eintrag ist das primäre Repository des Scans. Geben Sie entweder repo_name oder repos an, aber nicht beide.
200Show child attributes
Show child attributes
Art des auszuführenden Scans. Muss dem Scan-Typ des Profils entsprechen, wenn ein Profil angegeben ist; standardmäßig wird der Typ des Profils verwendet, oder 'security' für Scans ohne Profil. Nicht sicherheitsbezogene Typen erfordern ein Profil und werden ohne eines abgelehnt.
security, performance, db-queries, test-coverage, dead-code, code-quality, cleanup, telemetry, accessibility, compliance, general, migration-docs Antwort
Erfolgreiche Antwort
Ein einzelner Code-Scan.
Zeitpunkt, zu dem der Scan erstellt wurde (Unix-Sekunden).
Scan-Aufwand: 'normal' nutzt einen geringeren Reasoning-Aufwand des Modells und größere Untersuchungspakete; 'deep' führt die vollständige Pipeline aus.
normal, deep Git-Host des Repositorys, falls bekannt.
Organisation, zu der der Scan gehört.
Profil, unter dem der Scan ausgeführt wurde, falls vorhanden.
Show child attributes
Show child attributes
Primäres Repository des Scans. Multi-Repo-Scans umfassen zusätzliche Repositorys, die hier nicht aufgeführt sind.
Eindeutige Kennung des Scans.
Typ des Scans, bei der Erstellung festgelegt.
security, performance, db-queries, test-coverage, dead-code, code-quality, cleanup, telemetry, accessibility, compliance, general, migration-docs Scan-Status: waiting, pending, running, awaiting_user_input, completed, failed oder cancelled.
waiting, pending, running, awaiting_user_input, completed, failed, cancelled URL der Scan-Seite in der Devin-Webapp.
Outpost-Pool, auf dem die Sitzungen des Scans ausgeführt werden, sofern festgelegt.
Bezeichnung der gehosteten Plattform, auf der die Sitzungen des Scans ausgeführt werden. Null, wenn der Scan auf einem Outpost-Pool oder mit der Standardeinstellung der Organisation ausgeführt wird.
Kennung des primären Repositorys einschließlich Host (z. B. github.com/org/repo). Null für Perforce-Depots, die keinen Git-Host haben.

