Skip to main content
Connect Devin to bring team AI usage into Windmill without giving Windmill access to session content, prompts, code, or repositories. The integration supports Devin Teams and Enterprise accounts.

Benefits of connecting Devin to Windmill

  • Track Agent Compute Unit (ACU) consumption, sessions, and pull request outcomes by employee
  • Understand how your team uses Devin across products, session origins, and task sizes
  • Bring AI adoption data into stats, performance reviews, and 1:1s
  • Sync analytics automatically without asking employees to connect individually

How to connect Devin

Devin Teams and Enterprise accounts use different service-user roles. Follow the instructions for your plan.

Teams setup

1

Create an Admin service user

In Devin, go to Settings → Service users and click Create service user. Name the service user Windmill Analytics and assign the Admin role.The Admin role is required because Windmill must read the complete member roster to match Devin users to employees. The Teams Member role doesn’t include this access.
2

Generate and copy the API key

Open the new service user and click Generate API key. Copy the cog_-prefixed key immediately. Devin only displays it once.See Devin’s Teams quick start for more information about service users and API keys.
3

Open the Devin integration in Windmill

Go to Settings > Integrations, find Devin, and click Connect.
4

Enter the API key and connect

Paste the API key into API key. Leave API base URL at the default https://api.devin.ai, then click Connect.Windmill detects your Devin organization automatically. You don’t need to enter an organization ID or select a plan.

Enterprise setup

1

Create a least-privilege role

In Devin, go to Enterprise settings → Roles and create a custom role named Windmill Analytics with these permissions:
2

Create an Enterprise service user

Go to Enterprise settings → Service users and click Create service user. Name it Windmill Analytics and assign the custom role.
3

Generate and copy the API key

Open the new service user and click Generate API key. Copy the cog_-prefixed key immediately. Devin only displays it once.See Devin’s Enterprise quick start for more information about Enterprise service users and roles.
4

Confirm the API base URL

Most Enterprise accounts use Devin’s standard API and should leave API base URL at https://api.devin.ai.If your company has a dedicated Devin deployment, ask your Devin administrator or Cognition support for its API domain. Enter the HTTPS origin, such as https://api.your-company.devinenterprise.com, without a path, query, credentials, or trailing content.
5

Connect Devin in Windmill

Go to Settings > Integrations, find Devin, and click Connect. Enter the API key and, only for a dedicated deployment, the API base URL. Then click Connect.Windmill detects Enterprise scope automatically. You don’t need to enter an organization ID or select a plan.
Devin is an account-level integration. An admin connects it once for the company, and individual employees don’t need to connect it themselves.

Connected data

Windmill syncs Devin’s direct and IDP-managed user rosters for employee matching. For matched users, Windmill imports daily ACU consumption, session metrics, and pull request metrics.

ACU consumption

Sessions

Pull requests

All stats are tracked per employee and per completed Devin billing day. Windmill checks for new data hourly, and the latest completed day appears after Devin makes it available.

Data Windmill doesn’t access

Windmill uses Devin’s read-only analytics and membership endpoints. It doesn’t read or store:
  • Session prompts, messages, or other conversation content
  • Source code, files, or repository contents
  • Playbook or knowledge content
  • Audit logs, secrets, or account settings
Windmill never creates or modifies sessions, users, repositories, or other data in Devin.

Visibility and access

Devin stats in Windmill follow the manager hierarchy visibility model:
  • Employees can see their own Devin stats
  • Managers can see Devin stats for their direct reports and anyone in their reporting chain
  • Admins can see Devin stats for everyone in the organization
  • Peers can’t see each other’s Devin stats

Permissions

Windmill calls only read-only Devin endpoints, even when a Teams service user has the Admin role. For Teams, the Admin role is required to read the complete roster and analytics. For Enterprise, the custom role only needs account metadata, membership, metrics, and consumption permissions. Windmill validates the key and confirms that it belongs to a service user when you connect. Devin checks roster and analytics permissions during the first sync.

User matching

Windmill matches Devin users to employees by email address. It reads both directly assigned users and users whose membership comes from an identity provider group. If a user isn’t matched, confirm that their Devin email address matches their employee email in Windmill.

Troubleshooting

Confirm that you pasted the complete cog_-prefixed service-user key. Personal tokens and legacy apk_ keys aren’t supported.If the key was revoked, generate a replacement key and reauthenticate the integration. Don’t revoke the current key until Windmill accepts its replacement.
Devin displays a service-user API key only once. Generate a new key, copy it immediately, and paste it into Windmill. Revoke the unseen key if it remains active.
A 403 error that mentions org.membership.view or ViewOrgMembership means the service user can’t read the roster. Change the Windmill Analytics service user from Member to Admin, then run the sync again.
Add ViewAccountMembership to the service user’s custom role. Windmill needs this permission to read both directly assigned and IDP-managed users.
On Teams, confirm that the service user has the Admin role. On Enterprise, add ViewAccountMetrics to its custom role. Then run the sync again.
On Teams, confirm that the service user has the Admin role. On Enterprise, add ViewAccountConsumption to its custom role. Then run the sync again.
Only Enterprise dedicated deployments should use API base URL. Confirm the exact domain with your Devin administrator or Cognition support.Enter an HTTPS origin such as https://api.your-company.devinenterprise.com. Don’t include a path, query, fragment, or credentials. Standard Cognition-hosted accounts should use the default https://api.devin.ai.
If Devin returns a 429 rate-limit response, Windmill waits and retries automatically. Data will appear after a later retry succeeds. If the issue continues, contact Windmill support.

FAQs

No. Windmill identifies your organization or Enterprise account from the service-user key. There is no organization ID or plan selector in the connection flow.
No. Devin is an account-level integration. An admin connects it once for the company.
Windmill checks Devin hourly and imports newly completed Devin billing days. The current, incomplete day isn’t imported until it closes.
No. Employees can see their own stats, managers can see stats within their reporting hierarchy, and admins can see stats for the company. Peers can’t see each other’s usage.
Their historical Devin stats remain for context, but Windmill stops attributing new activity once they are an Archived user.