curl --request POST \
--url https://api.devin.ai/v3/organizations/{org_id}/code-scans \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"commit_sha": "<string>",
"host": "<string>",
"interactive": false,
"new_budget": {
"acu_limit": 500000
},
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
'import requests
url = "https://api.devin.ai/v3/organizations/{org_id}/code-scans"
payload = {
"commit_sha": "<string>",
"host": "<string>",
"interactive": False,
"new_budget": { "acu_limit": 500000 },
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
commit_sha: '<string>',
host: '<string>',
interactive: false,
new_budget: {acu_limit: 500000},
platform: '<string>',
profile_id: '<string>',
repo_name: '<string>',
repos: [{repo_name: '<string>', host: '<string>'}]
})
};
fetch('https://api.devin.ai/v3/organizations/{org_id}/code-scans', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.devin.ai/v3/organizations/{org_id}/code-scans",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'commit_sha' => '<string>',
'host' => '<string>',
'interactive' => false,
'new_budget' => [
'acu_limit' => 500000
],
'platform' => '<string>',
'profile_id' => '<string>',
'repo_name' => '<string>',
'repos' => [
[
'repo_name' => '<string>',
'host' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.devin.ai/v3/organizations/{org_id}/code-scans"
payload := strings.NewReader("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.devin.ai/v3/organizations/{org_id}/code-scans")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.devin.ai/v3/organizations/{org_id}/code-scans")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"created_at": 123,
"effort": "normal",
"host": "<string>",
"org_id": "<string>",
"profile": {
"name": "<string>",
"profile_id": "<string>"
},
"repo_name": "<string>",
"scan_id": "<string>",
"scan_type": "security",
"status": "waiting",
"url": "<string>",
"outpost_pool_id": "<string>",
"platform": "<string>",
"repo_full_name": "<string>"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}Code-Scan starten (Devin API)
Starten Sie über die v3-Organisations-API einen neuen Devin-Code-Scan für ein oder mehrere Repositorys, optional mit einem Scan-Profil, Commit-SHA oder Aufwand
curl --request POST \
--url https://api.devin.ai/v3/organizations/{org_id}/code-scans \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"commit_sha": "<string>",
"host": "<string>",
"interactive": false,
"new_budget": {
"acu_limit": 500000
},
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
'import requests
url = "https://api.devin.ai/v3/organizations/{org_id}/code-scans"
payload = {
"commit_sha": "<string>",
"host": "<string>",
"interactive": False,
"new_budget": { "acu_limit": 500000 },
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
commit_sha: '<string>',
host: '<string>',
interactive: false,
new_budget: {acu_limit: 500000},
platform: '<string>',
profile_id: '<string>',
repo_name: '<string>',
repos: [{repo_name: '<string>', host: '<string>'}]
})
};
fetch('https://api.devin.ai/v3/organizations/{org_id}/code-scans', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.devin.ai/v3/organizations/{org_id}/code-scans",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'commit_sha' => '<string>',
'host' => '<string>',
'interactive' => false,
'new_budget' => [
'acu_limit' => 500000
],
'platform' => '<string>',
'profile_id' => '<string>',
'repo_name' => '<string>',
'repos' => [
[
'repo_name' => '<string>',
'host' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.devin.ai/v3/organizations/{org_id}/code-scans"
payload := strings.NewReader("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.devin.ai/v3/organizations/{org_id}/code-scans")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.devin.ai/v3/organizations/{org_id}/code-scans")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"created_at": 123,
"effort": "normal",
"host": "<string>",
"org_id": "<string>",
"profile": {
"name": "<string>",
"profile_id": "<string>"
},
"repo_name": "<string>",
"scan_id": "<string>",
"scan_type": "security",
"status": "waiting",
"url": "<string>",
"outpost_pool_id": "<string>",
"platform": "<string>",
"repo_full_name": "<string>"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}Berechtigungen
Erfordert einen Service-Benutzer oder ein persönliches Zugriffstoken mit der BerechtigungUseCodeScans auf Organisationsebene.
Verhalten
Stellt einen neuen Code-Scan für das angegebene Repository (repo_name) oder die angegebenen Repositorys (repos) in der Organisation in die Warteschlange. Der Scan wird vom Scan-Dispatcher asynchron gestartet; die Antwort enthält den Scan-Datensatz mit dem anfänglichen status waiting oder pending. Rufen Sie Code-Scans auflisten auf, um den Fortschritt zu verfolgen, und Code-Scan-Befunde auflisten (gefiltert nach scan_id), um die Ergebnisse abzurufen, sobald der Scan den Status completed erreicht.
Der Scan wird dem aufrufenden Principal zugeordnet (dem Service-Benutzer oder PAT, der die Anfrage gestellt hat). Das Äquivalent mit Enterprise-Geltungsbereich ist Code-Scan starten (Enterprise).
Anfragefelder
Geben Sie genau eines der Felderrepo_name oder repos an.
repo_name: vollständiger Repository-Name, z. B.owner/repo. Das Repository muss bereits über die Git-Integration der Organisation zugänglich sein.host: Git-Host des Repositorys, falls er nicht abgeleitet werden kann.repos: Repositorys, die ein einzelner Multi-Repo-Scan abdeckt, als Liste von Objekten mitrepo_nameund optionalemhost(maximal 200). Der erste Eintrag ist das primäre Repository des Scans.profile_id: anzuwendendes Scan-Profil. Verwenden Sie Ingestion-Scan starten für Profile imingest-Modus.scan_type: Typ des auszuführenden Scans. Wennprofile_idangegeben ist, muss er dem Scan-Typ des Profils entsprechen. Standardmäßig wird der Typ des Profils verwendet, bei Scans ohne Profilsecurity. Nicht sicherheitsbezogene Scan-Typen erfordern ein Profil.commit_sha: Commit, der vor dem Scannen ausgecheckt werden soll. Standardmäßig wird der aktuelle Stand des Standard-Branches des Repositorys verwendet.effort:normal(Standard) arbeitet mit geringerem Reasoning-Aufwand des Modells und größeren Untersuchungs-Batches;deepdurchläuft die vollständige Pipeline.interactive: Beitruehält der Scan zwischen Threat Modeling und Untersuchung im Statusawaiting_user_inputan, damit Nutzer ein Review durchführen können. Standardmäßigfalse. Interaktives Review wird nur von Sicherheits-Scans unterstützt; andere Scan-Typen laufen ohne Eingriff durch.platform: wo die Sitzungen des Scans ausgeführt werden – entweder ein für die Organisation konfiguriertes Plattform-Label (zum Beispiellinux,windowsodermacos) oder der Name eines Outpost-Pools; Groß-/Kleinschreibung wird nicht berücksichtigt. Passt ein Name auf beides, hat die Plattform Vorrang. Standardmäßig gilt die Standardeinstellung der Organisation.
Fehler
400, wennscan_typemit dem Profil in Konflikt steht, ein nicht sicherheitsbezogenerscan_typeohne Profil angegeben wird oderplatformkeinem konfigurierten Plattform-Label und keinem Outpost-Pool entspricht (der Fehlertext listet die verfügbaren Werte auf).403, wenn die Organisation auf reine Ingestion-Scans beschränkt ist und kein Profil imingest-Modus angegeben wird.404, wenn das Repository oder Profil für die Organisation nicht sichtbar ist.409, wenn der Scan-Backlog der Organisation ausgelastet ist. Versuchen Sie es später erneut.422, wenn entweder sowohlrepo_nameals auchreposoder keiner der beiden Parameter angegeben wird oder wennreposleer ist.
Autorisierungen
Servicebenutzer-Anmeldedaten (Präfix: cog_)
Pfadparameter
Organisations-ID (Präfix: org-)
"org-abc123def456"
Body
Anfragebody zum Starten eines neuen Code-Scans.
Commit, der vor dem Scan ausgecheckt werden soll.
Scan-Aufwand: 'normal' (Standard) verwendet einen geringeren Reasoning-Aufwand des Modells und größere Untersuchungspakete; 'deep' führt die vollständige Pipeline aus.
normal, deep Git-Host des Repositorys, sofern bekannt.
Bei true pausiert der Scan zwischen Bedrohungsmodellierung und Untersuchung, damit der Nutzer die Ergebnisse überprüfen kann.
Weisen Sie dem Scan ein eigenes ACU-Budget zu. Erfordert die Berechtigungen ManageAccountServiceUsers und ManageAcuLimits.
Show child attributes
Show child attributes
Ausführungsort der Scan-Sitzungen: eine für die Organisation konfigurierte Plattformbezeichnung (z. B. 'linux', 'windows', 'macos') oder der Name eines Outpost-Pools (BYOB). Groß- und Kleinschreibung werden nicht berücksichtigt; bei gleichnamigen Plattformen und Pools haben Plattformen Vorrang. Ohne Angabe gilt der Organisationsstandard. Unbekannte Werte werden mit dem HTTP-Statuscode 400 abgelehnt; die Fehlerantwort listet die verfügbaren Plattformbezeichnungen und Outpost-Pool-Namen auf.
128Scan-Profil, das auf den Scan angewendet werden soll.
Vollständiger Name des zu scannenden Repositorys. Geben Sie entweder repo_name oder repos an, nicht beides.
Repositorys, die ein Scan abdeckt; der erste Eintrag ist das primäre Repository des Scans. Geben Sie entweder repo_name oder repos an, nicht beides.
200Show child attributes
Show child attributes
Typ des auszuführenden Scans. Muss bei Angabe eines Profils dessen Scan-Typ entsprechen. Standardmäßig wird der Typ des Profils verwendet, bei Scans ohne Profil 'security'. Andere Typen als 'security' erfordern ein Profil und werden ohne Profil abgelehnt.
security, performance, db-queries, test-coverage, dead-code, code-quality, cleanup, telemetry, accessibility, compliance, general, migration-docs Antwort
Erfolgreiche Antwort
Ein einzelner Code-Scan.
Zeitpunkt, zu dem der Scan erstellt wurde (Unix-Sekunden).
Scan-Aufwand: 'normal' nutzt einen geringeren Reasoning-Aufwand des Modells und größere Untersuchungspakete; 'deep' führt die vollständige Pipeline aus.
normal, deep Git-Host des Repositorys, falls bekannt.
Organisation, zu der der Scan gehört.
Profil, unter dem der Scan ausgeführt wurde, falls vorhanden.
Show child attributes
Show child attributes
Primäres Repository des Scans. Multi-Repo-Scans umfassen zusätzliche Repositorys, die hier nicht aufgeführt sind.
Eindeutige Kennung des Scans.
Typ des Scans, bei der Erstellung festgelegt.
security, performance, db-queries, test-coverage, dead-code, code-quality, cleanup, telemetry, accessibility, compliance, general, migration-docs Scan-Status: waiting, pending, running, awaiting_user_input, completed, failed oder cancelled.
waiting, pending, running, awaiting_user_input, completed, failed, cancelled URL der Scan-Seite in der Devin-Webapp.
Outpost-Pool, auf dem die Sitzungen des Scans ausgeführt werden, sofern festgelegt.
Bezeichnung der gehosteten Plattform, auf der die Sitzungen des Scans ausgeführt werden. Null, wenn der Scan auf einem Outpost-Pool oder mit der Standardeinstellung der Organisation ausgeführt wird.
Kennung des primären Repositorys einschließlich Host (z. B. github.com/org/repo). Null für Perforce-Depots, die keinen Git-Host haben.

