Cognition Labs Secrets API

Encrypted credentials Devin can use inside sessions.

Business capability
Configuration & Secrets Management BC-4210.60

Operations 6

GET /secrets List all secrets #
POST /secrets Create a secret #
DELETE /secrets/{secret_id} Delete a secret #
GET /v1/secrets List all secrets metadata #
POST /v1/secrets Create a new secret #
DELETE /v1/secrets/{secret_id} Delete a secret #

Documentation

📖
Documentation
https://docs.devin.ai/api-reference/overview
📖
APIReference
https://docs.devin.ai/api-reference/v1/sessions/create-a-new-devin-session
📖
APIReference
https://docs.devin.ai/api-reference/v1/sessions/send-a-message-to-an-existing-devin-session
📖
APIReference
https://docs.devin.ai/api-reference/v3/sessions/post-organizations-sessions-messages
📖
APIReference
https://docs.devin.ai/api-reference/v1/attachments/upload-files-for-devin-to-work-with
📖
APIReference
https://docs.devin.ai/api-reference/v1/attachments/download-attachment-files
📖
APIReference
https://docs.devin.ai/api-reference/v1/knowledge/list-knowledge
📖
APIReference
https://docs.devin.ai/api-reference/v1/knowledge/create-knowledge
📖
APIReference
https://docs.devin.ai/api-reference/v1/playbooks/list-playbooks
📖
APIReference
https://docs.devin.ai/api-reference/v1/playbooks/create-playbook
📖
APIReference
https://docs.devin.ai/api-reference/v1/secrets/list-secrets
📖
APIReference
https://docs.devin.ai/api-reference/v1/secrets/create-secret
📖
Documentation
https://docs.devin.ai/admin/security
📖
Documentation
https://docs.devin.ai/api-reference/v3/overview
📖
Documentation
https://docs.devin.ai/api-reference/getting-started/teams-quickstart
📖
APIReference
https://docs.devin.ai/api-reference/v3/users/members-users
📖
Documentation
https://docs.devin.ai/api-reference/getting-started/enterprise-quickstart
📖
APIReference
https://docs.devin.ai/api-reference/v2/organizations/list-organizations
📖
APIReference
https://docs.devin.ai/api-reference/v2/api-keys/list-enterprise-api-keys
📖
Documentation
https://docs.devin.ai/admin/billing/usage
📖
Documentation
https://docs.devin.ai/admin/billing/enterprise
📖
APIReference
https://docs.devin.ai/api-reference/v3/consumption/consumption-daily

Specifications

Schemas & Data

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cognition-labs-secrets-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cognition-labs-secrets-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Cognition Labs Secrets API
  version: '1.0'
  description: 'Operations tagged Secrets across 2 of this provider''s published API definitions: cognition-labs-openapi.yml, cognition-labs-openapi.yaml. Each path carries the servers of the definition it was published in.'
servers:
- url: https://api.devin.ai/v1
  description: Legacy v1 API (apk_user_*/apk_* keys)
- url: https://api.devin.ai/v3
  description: Current v3 organizations/enterprise API (cog_ keys)
- url: https://api.devin.ai
  description: Devin Production Server
security:
- bearerAuth: []
tags:
- name: Secrets
  description: Encrypted credentials Devin can use inside sessions.
paths:
  /secrets:
    get:
      operationId: listSecrets
      tags:
      - Secrets
      summary: List all secrets
      description: Returns secret metadata only, never secret values.
      responses:
        '200':
          description: The organization's secret metadata.
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/SecretMetadata'
    post:
      operationId: createSecret
      tags:
      - Secrets
      summary: Create a secret
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SecretInput'
      responses:
        '200':
          description: The created secret's identifier.
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
        '422':
          $ref: '#/components/responses/ValidationError'
    servers:
    - url: https://api.devin.ai/v1
      description: Legacy v1 API (apk_user_*/apk_* keys)
    - url: https://api.devin.ai/v3
      description: Current v3 organizations/enterprise API (cog_ keys)
  /secrets/{secret_id}:
    parameters:
    - name: secret_id
      in: path
      required: true
      schema:
        type: string
    delete:
      operationId: deleteSecret
      tags:
      - Secrets
      summary: Delete a secret
      responses:
        '200':
          description: Deletion confirmation.
          content:
            application/json:
              schema:
                type: object
                properties:
                  detail:
                    type: string
        '422':
          $ref: '#/components/responses/ValidationError'
    servers:
    - url: https://api.devin.ai/v1
      description: Legacy v1 API (apk_user_*/apk_* keys)
    - url: https://api.devin.ai/v3
      description: Current v3 organizations/enterprise API (cog_ keys)
  /v1/secrets:
    get:
      tags:
      - Secrets
      summary: List all secrets metadata
      description: 'Get a list of all secrets metadata. This endpoint only returns non-sensitive

        information about the secrets, not the secret values themselves.'
      responses:
        '200':
          description: List of secrets metadata
          content:
            application/json:
              schema:
                type: object
                properties:
                  secrets:
                    type: array
                    items:
                      $ref: '#/components/schemas/SecretMetadata_2'
                required:
                - secrets
              examples:
                list-secrets-response:
                  summary: Example response listing secrets
                  value:
                    secrets:
                    - secret_id: sec_xxx
                      secret_type: key-value
                      secret_name: API Access Token
                      created_at: '2024-01-01T00:00:00Z'
        '401':
          $ref: '#/components/responses/UnauthorizedError'
        '500':
          $ref: '#/components/responses/InternalServerError'
      operationId: getV1Secrets
      x-operation-id-source: derived
    post:
      tags:
      - Secrets
      summary: Create a new secret
      description: Create a new secret in your organization. The secret value will be encrypted and stored securely.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateSecretRequest'
            examples:
              create-secret-example:
                summary: Example creating a new secret
                value:
                  type: key-value
                  key: API_TOKEN
                  value: sk-1234567890abcdef
                  sensitive: true
                  note: Production API token for external service
      responses:
        '201':
          description: Secret created successfully
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                    description: The unique identifier of the created secret
                required:
                - id
              examples:
                create-secret-response:
                  summary: Example response for creating a secret
                  value:
                    id: sec_abc123def456
        '400':
          $ref: '#/components/responses/BadRequestError'
        '401':
          $ref: '#/components/responses/UnauthorizedError'
        '409':
          description: Conflict - Secret name already exists
          content:
            application/json:
              schema:
                type: object
                properties:
                  detail:
                    type: string
                    example: Secret name is not unique
        '500':
          $ref: '#/components/responses/InternalServerError'
      operationId: postV1Secrets
      x-operation-id-source: derived
    servers:
    - url: https://api.devin.ai
      description: Devin Production Server
  /v1/secrets/{secret_id}:
    delete:
      tags:
      - Secrets
      summary: Delete a secret
      description: Permanently delete a secret by its ID. This action cannot be undone.
      parameters:
      - name: secret_id
        in: path
        required: true
        description: The ID of the secret to delete
        schema:
          type: string
      responses:
        '204':
          description: Secret successfully deleted
        '401':
          $ref: '#/components/responses/UnauthorizedError'
        '404':
          $ref: '#/components/responses/NotFoundError'
        '500':
          $ref: '#/components/responses/InternalServerError'
      operationId: deleteV1SecretsBySecretId
      x-operation-id-source: derived
    servers:
    - url: https://api.devin.ai
      description: Devin Production Server
components:
  schemas:
    SecretMetadata:
      type: object
      properties:
        id:
          type: string
        type:
          type: string
          enum:
          - cookie
          - key-value
          - dictionary
          - totp
        key:
          type:
          - string
          - 'null'
        created_at:
          type:
          - string
          - 'null'
          format: date-time
    SecretInput:
      type: object
      required:
      - type
      - key
      - value
      properties:
        type:
          type: string
          enum:
          - cookie
          - key-value
          - dictionary
          - totp
        key:
          type: string
          description: Unique name for the secret within the organization.
        value:
          type: string
          description: The secret value to store. Encrypted at rest.
        sensitive:
          type: boolean
          description: Whether the value is redacted in logs.
        note:
          type: string
    ValidationErrorBody:
      type: object
      properties:
        detail:
          type: array
          items:
            type: object
            properties:
              loc:
                type: array
                items:
                  type: string
              msg:
                type: string
              type:
                type: string
    SecretMetadata_2:
      type: object
      properties:
        secret_id:
          type: string
          description: Unique identifier for the secret
        secret_type:
          type: string
          description: Type of secret
          enum:
          - cookie
          - key-value
          - dictionary
          - totp
        secret_name:
          type: string
          description: User-defined name for the secret
        created_at:
          type: string
          format: date-time
          description: Creation timestamp (ISO 8601)
      required:
      - secret_id
      - secret_type
      - secret_name
      - created_at
      description: Metadata about a stored secret
    CreateSecretRequest:
      type: object
      properties:
        type:
          type: string
          description: Type of secret
          enum:
          - cookie
          - key-value
          - totp
        key:
          type: string
          description: User-defined name for the secret
        value:
          type: string
          description: The secret value to store
        sensitive:
          type: boolean
          description: Whether the secret should be treated as sensitive
        note:
          type: string
          description: Optional note about the secret
      required:
      - type
      - key
      - value
      - sensitive
      - note
      description: Request body for creating a new secret
  responses:
    ValidationError:
      description: The request payload failed validation.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ValidationErrorBody'
    BadRequestError:
      description: Bad Request
      content:
        application/json:
          schema:
            type: object
            properties:
              detail:
                type: string
                example: Invalid input or request
    UnauthorizedError:
      description: Unauthorized - Invalid or missing API key
      content:
        application/json:
          schema:
            type: object
            properties:
              detail:
                type: string
                example: Missing or invalid Authorization header
    InternalServerError:
      description: Internal Server Error
      content:
        application/json:
          schema:
            type: object
            properties:
              detail:
                type: string
                example: Something went wrong
    NotFoundError:
      description: Resource not found
      content:
        application/json:
          schema:
            type: object
            properties:
              detail:
                type: string
                example: The requested resource does not exist
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'v1/v2 keys are prefixed apk_user_* (personal) or apk_* (service). The current v3 API uses service-user or personal access tokens prefixed cog_. Passed as `Authorization: Bearer YOUR_API_KEY`.'
externalDocs:
  description: Visit Devin's documentation page for more info
  url: https://docs.devin.ai
x-refined-from:
- cognition-labs-openapi.yml
- cognition-labs-openapi.yaml