sha256:6ca2c5cafca7…
2 Bytes
v2
about 2 hours ago
Devin CLI by Cognition, pinned to a Devin Enterprise deployment (<org>.devinenterprise.com). The sibling `devin` kit targets Cognition's public SaaS; this fork repoints auth, API, and model backends at the enterprise endpoints and takes the org slug as a kit argument.
| Name | Required | Default | Description |
|---|---|---|---|
org | Required | — | Enterprise org slug — "acme" for acme.devinenterprise.com |
*.devinenterprise.com
*.enterprise.windsurf.com
windsurf.com
server.codeium.com
unleash.codeium.com
cli.devin.ai
static.devin.ai
archive.ubuntu.com
security.ubuntu.com
ports.ubuntu.com
download.docker.com
sbx run sbx/devin-enterprise-kit:latest --set org=<org>Run the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbxDevin CLI by Cognition, pinned to a Devin Enterprise deployment (<org>.devinenterprise.com) rather than Cognition's public SaaS. Forked from the sibling devin kit.
sbx run --kit "docker.io/sbx/devin-enterprise-kit:latest" --kit-arg "devin-enterprise.org=<your-org>" devin-enterprise
Or from a git URL targeting this repo:
sbx run --kit "git+https://github.com/docker/sbx-kits-contrib.git#dir=devin-enterprise" --kit-arg "devin-enterprise.org=<your-org>" devin-enterprise
Or with a local clone of this repo:
sbx run --kit ./devin-enterprise/ --kit-arg "devin-enterprise.org=<your-org>" devin-enterprise
<your-org> is the slug in your deployment's URL — acme for acme.devinenterprise.com. First run in each sandbox prints a https://<org>.devinenterprise.com/auth/cli/continue?... URL — open it, sign in, and paste the code back. Credentials persist across sandbox restarts; a recreated sandbox signs in again.
Unlike the devin kit, this kit does not use the proxy-managed credential (credentials[] + oauth block + the devin-proxy-managed sentinel). On enterprise deployments that model fails: the OAuth token endpoint at api.devinenterprise.com/auth/cli/token returns only the short-lived PKCE intermediate token, and the proxy's durable-key credential handoff never fires for non-SaaS resourceHosts — so after sign-in succeeds, the sentinel can never authenticate and the stock devin wrapper exits 1. See docker/sbx-releases#683.
Instead, this kit passes the credential through: the enterprise devin wrapper keeps the base wrapper’s credential-state checks and login validation, but omits the proxy-sentinel rewrite. It clears an empty key before running devin-cli auth login --force-manual-token-flow, then execs devin-cli. The real durable key stays in the container at ~/.local/share/devin/credentials.toml and requests carry it verbatim.
Trade-off: the durable key is readable by the agent inside the sandbox. The managed model exists precisely to avoid that; this kit should switch to it once the handoff works for enterprise hosts.
devin/etc/devin/system.json pins {"enterprise_host": "<org>.devinenterprise.com"} at every container start, so devin auth login produces the enterprise sign-in URL (skips the login-method menu).permissions.network.allow lists *.devinenterprise.com and *.enterprise.windsurf.com instead of the SaaS hosts, plus server.codeium.com — login-time account verification still probes the SaaS backend even on enterprise deployments.docker.io/sbx/devin-image), same --permission-mode dangerous --respect-workspace-trust=false arguments — see the devin README for why.