Devin
Devin is a bot operated by Devin AI that pulls documentation and examples while an AI writes code. Devin is a software engineering AI assistant that can browse websites and perform web-based tasks, functioning as a collaborative AI teammate for engineering teams. It is documented as honouring robots.txt, but no IP range list or reverse-DNS convention is published, so a request carrying this user agent cannot be proven genuine.
Devin at a glance
| User agent | DevinToken only. The operator has not published a full user-agent string, so match on the substring rather than an exact header. |
|---|---|
| Operator | Devin AI |
| Purpose | Coding agents |
| Respects robots.txt | Yes, documented |
| Verification method | None published, user agent only No IP range file and no reverse-DNS convention have been published for this agent. The user-agent string is the only signal, and any client can send it, so treat a match as a claim rather than proof. |
| Crawl pattern | Not published |
| Robots.txt tokens | Devin |
| Operator documentation | None published |
Devin is a software engineering AI assistant that can browse websites and perform web-based tasks, functioning as a collaborative AI teammate for engineering teams.
Allow or block Devin
Paste one of these into the robots.txt file at the root of your domain. Rules are per token, so a block on one crawler leaves every other bot untouched.
User-agent: Devin
Disallow: /Blocks every path for this crawler only.
User-agent: Devin
Allow: /Explicit allow. Useful when a wildcard rule above it would otherwise catch this crawler.
User-agent: Devin
Allow: /
Disallow: /account/
Disallow: /checkout/
Disallow: /searchEdit the Disallow paths to match your own account, checkout and search URLs.
What blocking actually costs you
Blocking Devin mainly affects developers reading your documentation through an AI tool. Most sites want that traffic.
Block every crawler in the directory at onceIs that really Devin?
A user-agent header is a string the client chooses. Scrapers copy Devin precisely because site owners allow it. No IP range file and no reverse-DNS convention have been published for this agent. The user-agent string is the only signal, and any client can send it, so treat a match as a claim rather than proof.
Paste the IP address from your access log below. You will see whether it belongs to a hosting provider, a residential proxy pool or a Tor exit, plus the ASN that announces it, which is what tells you whether the claim holds up.
Related crawlers
Identify crawlers automatically instead of by hand
Agentscan checks a request against published crawler ranges, reverse DNS and hosting data, then returns a verdict your edge can act on. One call per request, no range files to keep up to date.