curl --request POST \
--url https://api.devin.ai/v3/organizations/{org_id}/code-scans \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"commit_sha": "<string>",
"host": "<string>",
"interactive": false,
"new_budget": {
"acu_limit": 500000
},
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
'import requests
url = "https://api.devin.ai/v3/organizations/{org_id}/code-scans"
payload = {
"commit_sha": "<string>",
"host": "<string>",
"interactive": False,
"new_budget": { "acu_limit": 500000 },
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
commit_sha: '<string>',
host: '<string>',
interactive: false,
new_budget: {acu_limit: 500000},
platform: '<string>',
profile_id: '<string>',
repo_name: '<string>',
repos: [{repo_name: '<string>', host: '<string>'}]
})
};
fetch('https://api.devin.ai/v3/organizations/{org_id}/code-scans', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.devin.ai/v3/organizations/{org_id}/code-scans",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'commit_sha' => '<string>',
'host' => '<string>',
'interactive' => false,
'new_budget' => [
'acu_limit' => 500000
],
'platform' => '<string>',
'profile_id' => '<string>',
'repo_name' => '<string>',
'repos' => [
[
'repo_name' => '<string>',
'host' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.devin.ai/v3/organizations/{org_id}/code-scans"
payload := strings.NewReader("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.devin.ai/v3/organizations/{org_id}/code-scans")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.devin.ai/v3/organizations/{org_id}/code-scans")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"created_at": 123,
"effort": "normal",
"host": "<string>",
"org_id": "<string>",
"profile": {
"name": "<string>",
"profile_id": "<string>"
},
"repo_name": "<string>",
"scan_id": "<string>",
"scan_type": "security",
"status": "waiting",
"url": "<string>",
"outpost_pool_id": "<string>",
"platform": "<string>",
"repo_full_name": "<string>"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}启动代码扫描 (Devin API)
通过 v3 组织 API 对一个或多个代码仓库启动新的 Devin 代码扫描,也可指定扫描 Profile、提交 SHA 或扫描强度
curl --request POST \
--url https://api.devin.ai/v3/organizations/{org_id}/code-scans \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"commit_sha": "<string>",
"host": "<string>",
"interactive": false,
"new_budget": {
"acu_limit": 500000
},
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
'import requests
url = "https://api.devin.ai/v3/organizations/{org_id}/code-scans"
payload = {
"commit_sha": "<string>",
"host": "<string>",
"interactive": False,
"new_budget": { "acu_limit": 500000 },
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
commit_sha: '<string>',
host: '<string>',
interactive: false,
new_budget: {acu_limit: 500000},
platform: '<string>',
profile_id: '<string>',
repo_name: '<string>',
repos: [{repo_name: '<string>', host: '<string>'}]
})
};
fetch('https://api.devin.ai/v3/organizations/{org_id}/code-scans', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.devin.ai/v3/organizations/{org_id}/code-scans",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'commit_sha' => '<string>',
'host' => '<string>',
'interactive' => false,
'new_budget' => [
'acu_limit' => 500000
],
'platform' => '<string>',
'profile_id' => '<string>',
'repo_name' => '<string>',
'repos' => [
[
'repo_name' => '<string>',
'host' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.devin.ai/v3/organizations/{org_id}/code-scans"
payload := strings.NewReader("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.devin.ai/v3/organizations/{org_id}/code-scans")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.devin.ai/v3/organizations/{org_id}/code-scans")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"created_at": 123,
"effort": "normal",
"host": "<string>",
"org_id": "<string>",
"profile": {
"name": "<string>",
"profile_id": "<string>"
},
"repo_name": "<string>",
"scan_id": "<string>",
"scan_type": "security",
"status": "waiting",
"url": "<string>",
"outpost_pool_id": "<string>",
"platform": "<string>",
"repo_full_name": "<string>"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}权限
需要服务用户或个人访问令牌,并在组织级别拥有UseCodeScans 权限。
行为
将组织中指定代码仓库 (repo_name) 或多个代码仓库 (repos) 的新代码扫描加入队列。扫描调度程序会异步启动扫描;响应将返回扫描记录,其初始 status 为 waiting 或 pending。轮询列出代码扫描以跟踪进度,并在扫描状态变为 completed 后,通过列出代码扫描发现项 (按 scan_id 过滤) 查看结果。
该扫描归属于调用主体 (即发出请求的服务用户或 PAT) 。Enterprise 作用域内的等效操作为启动代码扫描 (Enterprise)。
请求字段
repo_name 和 repos 必须且只能提供其中一个。
repo_name:完整的代码仓库名称,例如owner/repo。该代码仓库必须已通过组织的 Git 集成获得访问权限。host:代码仓库所在的 Git 主机 (如果无法自动推断) 。repos:单次多仓库扫描所涵盖的代码仓库,格式为对象列表,每个对象包含repo_name和可选的host(最多 200 个) 。第一个条目即为该扫描的主代码仓库。profile_id:要应用的扫描 Profile。对于ingest模式的 Profile,请使用启动摄取扫描。scan_type:要运行的扫描类型。指定profile_id时,必须与该 Profile 的扫描类型一致。默认使用 Profile 的类型;未指定 Profile 的扫描则默认使用security。非安全扫描类型必须指定 Profile。commit_sha:扫描前要检出的提交。默认使用代码仓库默认分支的最新提交。effort:normal(默认) 采用较低的模型推理强度,并使用更大的调查批次;deep则运行完整流水线。interactive:设为true时,扫描会在威胁建模与调查之间暂停,进入awaiting_user_input状态,等待用户审查。默认为false。仅安全扫描支持交互式审查;其他扫描类型均以无人值守方式运行。platform:扫描会话的运行位置,可以是为组织配置的平台标签 (例如linux、windows或macos) ,也可以是 outpost 池的名称,不区分大小写。若某个名称同时匹配两者,则优先匹配平台。默认使用组织的默认设置。
错误
- 当
scan_type与 Profile 不匹配、未提供 Profile 却指定了非安全类scan_type,或platform与任何已配置的平台标签或 outpost 池均不匹配时 (错误响应体中会列出可用值) ,返回400。 - 当组织仅允许摄取模式扫描,且未提供
ingest模式的 Profile 时,返回403。 - 当代码仓库或 Profile 对组织不可见时,返回
404。 - 当组织的扫描待办列表已满时,返回
409。请稍后重试。 - 当
repo_name和repos同时提供或均未提供,或repos为空时,返回422。
授权
服务用户凭据(前缀:cog_)
路径参数
组织 ID(前缀:org-)
"org-abc123def456"
请求体
用于启动新代码扫描的请求体。
扫描前要检出的 commit。
扫描强度:'normal'(默认)使用较低的模型推理强度,并采用较大的调查批次;'deep' 运行完整流水线。
normal, deep 代码仓库的 Git 托管平台(如已知)。
为 true 时,扫描会在威胁建模完成后、调查开始前暂停,供用户审核。
为扫描分配独立的 ACU 预算。需要 ManageAccountServiceUsers 和 ManageAcuLimits 权限。
Show child attributes
Show child attributes
扫描会话的运行位置:为组织配置的平台标签(例如 'linux'、'windows'、'macos')或 outpost(BYOB)资源池的名称,不区分大小写;当名称同时匹配两者时,平台优先。省略时使用组织默认设置。无法识别的值会被拒绝,并返回 400,错误响应体中会列出可用的平台标签和 outpost 资源池名称。
128应用于此次扫描的扫描 Profile。
要扫描的代码仓库的完整名称。repo_name 和 repos 必须且只能提供一个。
一次扫描涵盖的仓库;第一项为此次扫描的主代码仓库。repo_name 和 repos 必须且只能提供一个。
200Show child attributes
Show child attributes
要运行的 scan type。提供 Profile 时,必须与其 scan type 一致,默认使用 Profile 的类型;未提供 Profile 时,默认为 'security'。非安全类型的扫描必须提供 Profile,否则请求会被拒绝。
security, performance, db-queries, test-coverage, dead-code, code-quality, cleanup, telemetry, accessibility, compliance, general, migration-docs 响应
成功响应
一次代码扫描。
扫描的创建时间(Unix 秒)。
扫描强度:'normal' 使用较低的模型推理强度,并以较大的批次进行调查;'deep' 运行完整流水线。
normal, deep 代码仓库的 Git 托管平台(如已知)。
该扫描所属的组织。
扫描所使用的 Profile(如有)。
Show child attributes
Show child attributes
扫描的主代码仓库。多代码仓库扫描还会涵盖此处未列出的其他代码仓库。
扫描的唯一标识符。
扫描类型,在创建时确定。
security, performance, db-queries, test-coverage, dead-code, code-quality, cleanup, telemetry, accessibility, compliance, general, migration-docs 扫描状态:waiting、pending、running、awaiting_user_input、completed、failed 或 cancelled。
waiting, pending, running, awaiting_user_input, completed, failed, cancelled Devin webapp 中扫描页面的 URL。
运行扫描会话的 outpost 资源池(若已设置)。
运行扫描会话的托管平台标签。扫描在 outpost 资源池或组织默认环境中运行时为 Null。
包含主机名的主要代码仓库标识(例如 github.com/org/repo)。Perforce depot 没有 Git 主机,因此为 Null。

