devin worker process that connects to Devin Cloud over outbound HTTPS, claims sessions from the queue, and runs them locally. It doesn’t require inbound ports, a public IP address, or a virtual private network (VPN). Here, one sandbox runs one worker, and that worker serves sessions one after another for as long as the sandbox lives.
Each worker serves one active session at a time. Additional sessions wait until a worker becomes available. This guide starts a fixed number of workers. It doesn’t create more sandboxes when sessions queue. Start more workers manually or use an orchestrator to provision them automatically.
Prerequisites
Before you begin, make sure you have the following:- Une organisation Devin dans laquelle les Outposts sont activés. Si Outposts n’apparaît pas sous Settings > Environment dans Devin Cloud, contactez votre administrateur Devin.
- Une clé API W&B. Ces exemples utilisent l’authentification W&B.
- Pour utiliser directement le kit de développement logiciel (SDK), Python 3.11 ou version ultérieure avec
uv, ou Node.js 22 ou version ultérieure.
cws-agent sélectionne l’authentification W&B :
Create an outpost in Devin Cloud
To create an outpost and get its token, follow these steps:- In Devin Cloud, go to Settings > Environment > Outposts.
- Click Create Outpost, enter a name, and select Linux.
- Copy the outpost token. Devin Cloud shows it once.
cws-agent or the Sandbox SDK to start its worker, then run the verification session.
Quick start with cws-agent
Suivez les instructions d’installation decws-agent. L’outil configure un volume d’instantané pour sauvegarder et restaurer votre workspace à l’aide d’instantanés du système de fichiers.
Replace [OUTPOST-TOKEN] with the token you copied, [OUTPOST-NAME] with your outpost name, and [SANDBOX-NAME] with a cws-agent session name for this sandbox. For the session name, use 1 to 40 lowercase letters, digits, or hyphens, starting with a letter or digit:
--agent devin.
Set up with the Sandbox SDK
Use this alternative to launch a worker directly, withoutcws-agent. It doesn’t configure persistent storage.
Run Python snippets in the virtual environment created in Configure credentials and install the client. Save TypeScript snippets as .mts files in the project where you install the client, then run them with npx tsx [FILENAME].mts.
Configure credentials and install the client
Export the token you copied when creating the outpost in the terminal where you run the script:- Python
- TypeScript
Utilisez Python 3.11 ou une version ultérieure, avec
uv :Start the worker
The following script creates a sandbox from Cognition’s official worker image and runsdevin worker as the sandbox’s main command. The client reads DEVIN_OUTPOSTS_TOKEN from your local environment and passes its value in the sandbox request to set the worker’s environment variable. The worker’s output becomes the sandbox log. If the worker exits with an error, the platform restarts the container up to a retry limit.
- Python
- TypeScript
start_outpost_worker.py
- Python
- TypeScript
sandbox.wait() returns when the sandbox is running or has already completed. Installation and worker authentication can still be in progress, so check the worker before submitting a task. The worker starts from /workspace. A session for your-org/app checks out its repository under /workspace/repos/app.
The script doesn’t use a with block, so a running sandbox continues after the script exits.
Facultatif : utiliser un magasin de secrets
Vous pouvez transmettre une référence de secret W&B à la place de la valeur du jeton de l’outpost. Les exemples du SDK utilisent déjà l’authentification W&B. Enregistrez le jeton dans le Secret Manager de votre équipe W&B, puis sélectionnez cette équipe avecWANDB_ENTITY s’il ne s’agit pas de votre entity par défaut.
Remplacez [SECRET-NAME] par le nom du secret de l’équipe :
- Python
- TypeScript
Importez
Secret depuis cwsandbox, supprimez DEVIN_OUTPOSTS_TOKEN de environment_variables, puis ajoutez secrets=[Secret(store="wandb", name="[SECRET-NAME]", env_var="DEVIN_OUTPOSTS_TOKEN")] à Sandbox.run().Run and verify a Devin session
Use an outpost with only this worker and no other queued or active sessions for the test. Choose a unique, non-secret value for this test and replace[PROOF-VALUE] in the following task. In Devin Cloud, start a new session and select your outpost under Configuration > Virtual environment. Submit the following task, beginning with Write the exact text. Or, in Slack, send the full message:
[SANDBOX-NAME] with your cws-agent workspace name or [SANDBOX-ID] with the ID printed by the SDK script:
- cws-agent
- SDK Sandbox
Check the worker and stop it
Forcws-agent, attach to the worker terminal as shown in the quick start. For the SDK path, inspect its status and recent logs. Replace [SANDBOX-ID] with the printed ID:
- Python
- TypeScript
account.outposts.write). Correct the credential, then create the sandbox again.
A sandbox can report running while its worker repeatedly exits and restarts. Inspect its logs and, with the Python client, the per-container details shown in the preceding example.
Stop a worker that keeps failing authentication before creating its replacement. If startup fails without a useful reason, retain the sandbox ID and logs for CoreWeave Support.
Stop the sandbox when you no longer need the worker. For serverless setup, see Get started.
Wait for the active Devin session to finish and save its results, then stop compute using the command for your setup:
- cws-agent
- SDK Sandbox
down crée un instantané du workspace avant l’arrêt. Si la capture échoue, examinez l’erreur signalée ainsi que la sortie de cws-agent status [SANDBOX-NAME], puis corrigez le problème avant de réessayer. Si vous pouvez renoncer aux modifications non enregistrées, utilisez cws-agent down [SANDBOX-NAME] --no-snapshot.cws-agent workspace, see its Devin Outposts guide.
Optional: Customize the environment
You can customize the worker environment in the following ways:-
Bring your own image. The official image contains the
devinCLI and little else. Build an image from it that adds your toolchain, and pass it ascontainer_imagein Python orcontainerImagein TypeScript. Devin requiresgit. Screen recording requiresffmpeg, and the browser and computer-use tools require a compatible browser binary. For amd64 images based on the official Ubuntu image, install Google Chrome. Ubuntu’schromiumpackage is a snap stub that doesn’t work in containers. See Devin’s container setup. Computer use also requires a running graphical display, such as Xvfb, withDISPLAYset for the worker. The worker searches standard install locations. If it doesn’t find your binary, setDEVIN_CHROME_PATHto its absolute path. See the Devin Outposts reference. - Configure GPUs. See sandbox GPU configuration for the available options. This guide’s worker example uses CPU resources only.
- Run more workers. A worker serves one session at a time. Run the script again with the same outpost name to start another worker for the queue.
- Create one sandbox per session. The worker here reuses its sandbox across sessions. For a fresh sandbox per session, see Devin’s orchestration guide.