Benefits of connecting Devin to Windmill
- Track Agent Compute Unit (ACU) consumption, sessions, and pull request outcomes by employee
- Understand how your team uses Devin across products, session origins, and task sizes
- Bring AI adoption data into stats, performance reviews, and 1:1s
- Sync analytics automatically without asking employees to connect individually
How to connect Devin
Devin Teams and Enterprise accounts use different service-user roles. Follow the instructions for your plan.Teams setup
Create an Admin service user
Generate and copy the API key
cog_-prefixed key immediately. Devin only displays it once.See Devin’s Teams quick start for more information about service users and API keys.Open the Devin integration in Windmill
Enter the API key and connect
https://api.devin.ai, then click Connect.Windmill detects your Devin organization automatically. You don’t need to enter an organization ID or select a plan.Enterprise setup
Create a least-privilege role
Create an Enterprise service user
Generate and copy the API key
cog_-prefixed key immediately. Devin only displays it once.See Devin’s Enterprise quick start for more information about Enterprise service users and roles.Confirm the API base URL
https://api.devin.ai.If your company has a dedicated Devin deployment, ask your Devin administrator or Cognition support for its API domain. Enter the HTTPS origin, such as https://api.your-company.devinenterprise.com, without a path, query, credentials, or trailing content.Connect Devin in Windmill
Connected data
Windmill syncs Devin’s direct and IDP-managed user rosters for employee matching. For matched users, Windmill imports daily ACU consumption, session metrics, and pull request metrics.ACU consumption
Sessions
Pull requests
Data Windmill doesn’t access
Windmill uses Devin’s read-only analytics and membership endpoints. It doesn’t read or store:- Session prompts, messages, or other conversation content
- Source code, files, or repository contents
- Playbook or knowledge content
- Audit logs, secrets, or account settings
Visibility and access
Devin stats in Windmill follow the manager hierarchy visibility model:- Employees can see their own Devin stats
- Managers can see Devin stats for their direct reports and anyone in their reporting chain
- Admins can see Devin stats for everyone in the organization
- Peers can’t see each other’s Devin stats
Permissions
Windmill calls only read-only Devin endpoints, even when a Teams service user has the Admin role. For Teams, the Admin role is required to read the complete roster and analytics. For Enterprise, the custom role only needs account metadata, membership, metrics, and consumption permissions. Windmill validates the key and confirms that it belongs to a service user when you connect. Devin checks roster and analytics permissions during the first sync.User matching
Windmill matches Devin users to employees by email address. It reads both directly assigned users and users whose membership comes from an identity provider group. If a user isn’t matched, confirm that their Devin email address matches their employee email in Windmill.Troubleshooting
Why is my API key invalid?
Why is my API key invalid?
cog_-prefixed service-user key. Personal tokens and legacy apk_ keys aren’t supported.If the key was revoked, generate a replacement key and reauthenticate the integration. Don’t revoke the current key until Windmill accepts its replacement.What if I left Devin without copying the key?
What if I left Devin without copying the key?
Why can't Windmill read the Teams roster?
Why can't Windmill read the Teams roster?
org.membership.view or ViewOrgMembership means the service user can’t read the roster. Change the Windmill Analytics service user from Member to Admin, then run the sync again.Why can't Windmill read the Enterprise roster?
Why can't Windmill read the Enterprise roster?
ViewAccountMembership to the service user’s custom role. Windmill needs this permission to read both directly assigned and IDP-managed users.Why are session or pull request stats missing?
Why are session or pull request stats missing?
ViewAccountMetrics to its custom role. Then run the sync again.Why is ACU consumption missing?
Why is ACU consumption missing?
ViewAccountConsumption to its custom role. Then run the sync again.Why doesn't my dedicated deployment connect?
Why doesn't my dedicated deployment connect?
https://api.your-company.devinenterprise.com. Don’t include a path, query, fragment, or credentials. Standard Cognition-hosted accounts should use the default https://api.devin.ai.What happens when Devin rate-limits a sync?
What happens when Devin rate-limits a sync?
FAQs
Do I need to enter a Devin organization ID?
Do I need to enter a Devin organization ID?
Does each employee need to connect Devin?
Does each employee need to connect Devin?
How often does data sync?
How often does data sync?
Can coworkers see each other's Devin stats?
Can coworkers see each other's Devin stats?
What happens when an employee leaves?
What happens when an employee leaves?