Mercari's AI Security team describes how they scaled Devin Enterprise across multiple teams by building a custom Terraform provider, automated secret rotation, Google Cloud service account key rotation, audit log integration, and API key lifecycle management — all powered by Devin's v2 and v3 Enterprise APIs and orchestrated via GitHub Actions. The post covers specific challenges like multi-organization permission management, credential rotation across many orgs, and enforcing API key expiration that Devin doesn't natively support, along with concrete Terraform and Go implementation details.
Table of contents
IntroductionChallenges of Enterprise OperationsOverview of the Devin API1. Custom Terraform Provider2. Bulk Secret Rotation3. Google Cloud Service Account Key Rotation4. Integration with the Security Monitoring Platform5. Periodic Invalidation of API Keys Issued by Users6. API Key Management for Internal Agent Access to Devin WikiCI Pipeline for Unified OrchestrationConclusion142 Impressions