openapi: 3.0.3 info: title: Devin API (Cognition Labs) Attachments Messages API description: The Devin API lets you create and drive Devin, Cognition's autonomous AI software engineer, programmatically. This document models the legacy v1 surface (api.devin.ai/v1, still live and documented, authenticated with apk_user_*/apk_* keys) in full - sessions, messages, attachments, knowledge, playbooks, and secrets - plus representative endpoints from the current v3 organizations/enterprise surface (api.devin.ai/v3, authenticated with cog_ service-user or personal access tokens) and the v2/v3 consumption (ACU usage) endpoints. The v2/v3 enterprise surface has additional organization, member, and API-key management endpoints not exhaustively modeled here; see the humanURL/APIReference links in apis.yml for the full documented set. All endpoints are transcribed from Cognition's public documentation at https://docs.devin.ai and have not been exercised against production credentials, which require an active paid Devin plan or Enterprise contract. version: '1.0' contact: name: Cognition url: https://cognition.ai license: name: Proprietary url: https://docs.devin.ai/admin/security servers: - url: https://api.devin.ai/v1 description: Legacy v1 API (apk_user_*/apk_* keys) - url: https://api.devin.ai/v3 description: Current v3 organizations/enterprise API (cog_ keys) security: - bearerAuth: [] tags: - name: Messages description: Send and read messages within a running session. paths: /sessions/{session_id}/message: parameters: - $ref: '#/components/parameters/SessionId' post: operationId: sendMessage tags: - Messages summary: Send a message to a session description: Sends a follow-up message into a running session. The session must be in a running state to receive it; sending a message also wakes a sleeping session. requestBody: required: true content: application/json: schema: type: object required: - message properties: message: type: string responses: '200': description: Message accepted, or a detail note if the session was already suspended. content: application/json: schema: type: object nullable: true properties: detail: type: string '422': $ref: '#/components/responses/ValidationError' components: parameters: SessionId: name: session_id in: path required: true description: The unique identifier of the session. schema: type: string schemas: ValidationErrorBody: type: object properties: detail: type: array items: type: object properties: loc: type: array items: type: string msg: type: string type: type: string responses: ValidationError: description: The request payload failed validation. content: application/json: schema: $ref: '#/components/schemas/ValidationErrorBody' securitySchemes: bearerAuth: type: http scheme: bearer description: 'v1/v2 keys are prefixed apk_user_* (personal) or apk_* (service). The current v3 API uses service-user or personal access tokens prefixed cog_. Passed as `Authorization: Bearer YOUR_API_KEY`.'