Skip to main content
Use Devin to investigate vulnerabilities and prepare fixes. Your service receives an Antigen webhook, retrieves the vulnerability and its evidence, and creates a Devin session with instructions for the work. Devin works in its own environment. Your service follows the session and updates the vulnerability’s status and assignment through the Antigen API.

Before you start

Connect the relevant repository to Devin and configure the environment it needs to work on your code. For automation, create a Devin service user with permission to create and read sessions. Generate its API key and copy your organization ID from Settings → Service users. See Devin API authentication for service user setup. You also need an Antigen API key and a service that can receive webhooks. Store the API keys in your service’s secret storage.

Set up the workflow

1. Register a webhook

Point an Antigen webhook at your service and choose the status or assignment changes it should receive. Your handler decides which events should create a Devin session. For example, it can handle assignment events only when the new assignee is your agent. If you are replacing a default workflow, disable its hook in the platform or via the API. You can replace remediation while keeping the default triage and verification hooks. See Assigning to your own agents.

2. Create a Devin session

Retrieve the vulnerability and its evidence through the Antigen API. Include the affected repository, the observed behavior, and the requested outcome in the session prompt. For remediation, the request might be to reproduce the issue, prepare a fix, run the relevant tests, and open a pull request. Use Devin’s Create Session API and keep the session ID associated with the Antigen vulnerability ID.

3. Return the result

Your service reads session progress and results through the Devin API. Create a human task through the Antigen API to request your team’s review, including the pull request or proposed infrastructure change. Your team reviews and deploys the change. Once it is deployed, move the vulnerability to Remediated to start verification if the default verification hook is enabled.

Request a human task

If Devin needs more access or a human decision, the agent or your service can create a human task through the Antigen API. The assigned person receives the request through your connected messaging or issue tracking tool. Your service can read the task’s updates and send the response back to the Devin session.

Troubleshooting

A session cannot be created

Check the service user’s role, organization membership, and API key. Confirm that the request uses the intended Devin organization ID.

Devin cannot work on the repository

Check the repository connection and environment in Devin, including the dependencies needed to reproduce the issue and run tests.