Git AutoReview logo
Code Review Testing · Security Code Scanning

Git AutoReview

A VS Code extension that reviews pull requests on GitHub, GitLab and Bitbucket, running Claude, Gemini and GPT in parallel. Reviews use your own API key, and every comment is a draft: nothing is published without your approval.

Active GDPR compliant Free plan Freemium No public API 16+ Verified by Guidaio
Overview

What is Git AutoReview?

Git AutoReview is a VS Code extension that reviews pull requests with AI and then deliberately stops before publishing anything. Its tagline, AI suggests. You decide., describes the whole product: every comment the AI writes lands in a draft panel where you approve, edit or reject it one by one, and only what you approved is posted to the pull request. It runs inside VS Code 1.85 or later on Windows, macOS and Linux, and installs from the VS Code Marketplace (publisher vitalii4reva) or from Open VSX for Cursor, VSCodium and Devin Desktop — same extension ID, same version, 1.21.9 at the time of this review. On the Git side it covers GitHub Cloud and Enterprise, GitLab Cloud, Self-Managed and Dedicated, and Bitbucket Cloud, Server and Data Center, all handled natively from the sidebar: no webhook, no bot account, no server component. Reviews run on three model families — Claude from Anthropic, Gemini from Google, GPT from OpenAI — which can be launched in parallel on the same diff, with overlapping findings merged. Bringing your own key is mandatory on every plan, including the free one: your code leaves VS Code for the provider you chose, under your own account, and never passes through the publisher's servers. Keys live in VS Code's SecretStorage, backed by the operating system keychain, and the publisher puts the AI cost at roughly 2 to 5 US dollars a month, paid directly to the provider. Beyond the standard pass, a Deep Review agent mode sends an agent into the repository to read files, run the linter, check tests and trace data flows, usually in two to five minutes. Review Profiles store named setups — models, keys, prompts, rules, repositories — switchable from the status bar, and a .gitautoreview.md file at the repository root versions team review rules in git the way an .eslintrc does. Jira integration reads the ticket and checks its acceptance criteria one by one. The publisher's argument for the human gate is a study it cites, finding that developers accept AI suggestions 96.8% of the time without verifying them. Claimed traction — 5,500+ downloads, a 5.0 Marketplace rating, teams in 8+ countries — rests on the site alone.

What it does

  • Analyse the diff of a pull request or merge request and write review comments on it
  • Run Claude, Gemini and GPT in parallel on the same diff, then merge the findings they share
  • Put every suggestion through human approval — approve, edit or reject — before anything is published
  • Publish only the approved comments to GitHub, GitLab or Bitbucket
  • Scan for security flaws with 20+ built-in rules plus a dedicated AI pass
  • Explore the repository in Deep Review agent mode: read files, run the linter, check tests, trace data flows
  • Score each finding from 0 to 100% confidence and rate code quality across six categories
Audience

When to use Git AutoReview / When not to

A quick filter to help you decide if Git AutoReview is the right fit.

When to use Git AutoReview

  • Solo developers, freelancers and solo founders who have nobody to review their pull requests
  • Code reviewers facing a long queue who want to move faster without handing over the final say
  • Privacy-conscious teams that need their source code to stay out of a vendor's servers
  • Bitbucket Server and Data Center teams, including those working behind a corporate firewall
  • Small teams on a tight budget: the Team plan is a flat monthly fee for up to 25 members, not a per-seat charge

When not to use Git AutoReview

  • Developers who work outside VS Code and its forks: there is no JetBrains plugin, no web app and no mobile app
  • Teams that want fully automated review with zero human involvement, since nothing is posted until someone clicks approve
  • Anyone unwilling to open an Anthropic, Google or OpenAI account: bring-your-own-key is mandatory, even on the free plan
  • Organizations that require enterprise SSO, an SLA or a signed data processing agreement, none of which come with the published plans
  • Teams whose code lives anywhere other than GitHub, GitLab or Bitbucket
Get started

How to use Git AutoReview

A typical end-to-end flow, from setup to results.

  1. Install the extension from the VS Code Marketplace by searching for Git AutoReview, or from Open VSX if you use Cursor, VSCodium or Devin Desktop
  2. Open the settings panel with Cmd+Shift+P, then Git AutoReview: Open Settings, and go to the General tab
  3. Paste an Anthropic, Google or OpenAI API key, or point the extension at a Claude Code subscription
  4. Switch to the Repositories tab, click Add Repository, choose GitHub, GitLab or Bitbucket, then enter the repository and an access token
  5. Open a pull request from the sidebar
  6. Click Review and let the AI analyse the diff
  7. Pick a model from the sidebar selector, or launch several models in parallel to compare what they find
  8. Go through the suggestions one by one and approve, edit or reject each of them
  9. Click Publish to PR: only the comments you approved are sent to the platform
  10. Optionally drop a .gitautoreview.md file at the root of the repository to enforce team review rules
Quick read

Pros & Cons

Pros

  • Nothing reaches the pull request without a human clicking approve, the differentiator the publisher claims against CodeRabbit and Qodo, which post automatically
  • Three model families run in parallel rather than one, and where they disagree the disagreement is surfaced instead of averaged away
  • Bring-your-own-key on every plan, free one included: no lock-in on the AI side, and you pay the provider at cost, around 2 to 5 US dollars a month
  • Code never transits the publisher's servers and is never cached, where competitors cited on the site keep 7-day and 48-hour caches; API keys stay in the operating system keychain
  • Flat team pricing at 14.99 US dollars a month for up to 25 members instead of a per-seat charge
  • Bitbucket Server and Data Center covered natively in VS Code, which the publisher claims is unique on this market
  • A permanent free plan that is genuinely usable: 10 reviews a day, one repository, no credit card, plus telemetry that can be switched off

Cons

  • No legal entity, no postal address and no named director anywhere on the site: the terms are signed simply Git AutoReview, with no company form, and liability is capped at the higher of twelve months of subscription or 100 US dollars
  • No legal notice and no contact page, /contact returning a 404, and the only contact details are email addresses injected by JavaScript, so several pages show loading... to anyone without it
  • The home page structured data advertises a LinkedIn company page and a GitHub repository that both return 404 when checked, which casts doubt on the site's other unverifiable figures
  • Bring-your-own-key is mandatory: you have to open an account with Anthropic, Google or OpenAI, manage a key, and budget roughly 2 to 5 US dollars a month on top of the subscription
  • No data processing agreement published or offered, no Article 27 EU representative and no SOC 2 or ISO 27001 certification claimed by the publisher, a likely blocker for enterprise procurement
  • The site contradicts itself from page to page: the model lists differ between the home FAQ, the facts page and llms.txt, the Team plan shows unlimited repositories on the pricing page but 10 elsewhere, and customer countries are 8+ on the home page but 5+ on the pricing page
  • A very young product from a very small publisher, with the domain registered in January 2026, Ukrainian law and Ukrainian courts governing any dispute, and refunds limited to seven days on a first purchase
Pricing

Pricing & Plans

Git AutoReview offers a permanent free plan, covering 10 AI reviews per day on a single repository with no credit card required. The lowest paid entry point is the Developer plan at USD 8.33 per month on annual billing (USD 99.90 per year), or USD 9.99 per month on monthly billing. AI usage is billed separately by the model provider under the customer's own API key, which the publisher estimates at USD 2 to 5 per month. A refund may be requested within seven days of a first purchase.

Free — USD 0 per month
  • 10 AI reviews per day
  • 1 repository
  • bring your own key
  • basic approval workflow
Team — USD 12.49 per month billed annually (USD 149.90 per year) or USD 14.99 per month billed monthly
  • unlimited AI reviews
  • unlimited repositories
  • up to 25 members
  • BYOK
  • Deep Review
  • Review Profiles
  • full Jira integration
  • 20 custom rules
Annual billing is presented as 2 months free
  • pay for ten months
  • get twelve
Plan 5
  • SSO
  • an SLA or repository volumes beyond the Team plan require contacting the publisher
  • no price is published for them
Plan 6
  • Payment and licence delivery are handled through Whop
Special offers — Annual billing is presented as 2 months free: ten months paid for twelve months of service (Developer USD 99.90 per year, Team USD 149.90 per year) · Early adopter pricing announced on the pricing page: the rate is locked for as long as the subscription runs, while the publisher warns that future subscribers may pay more · Refund available within 7 days of a first purchase, with cancellation possible at any time
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Git AutoReview handles your data.

GDPR overview

Git AutoReview never calls itself “GDPR compliant” in so many words, but its privacy policy is built around the regulation. Effective 5 January 2026, it names a legal basis for each purpose — contract performance for the licence, legitimate interest for improvement and security, consent where required — and splits the roles explicitly: the publisher is controller for the website and the licensing system, and processor for the code review itself. Section 7.1 lists seven data subject rights (access, rectification, erasure, restriction, portability, objection, withdrawal of consent), exercised via privacy@gitautoreview.com and answered within 30 days; CCPA and CPRA rights are covered as well, and under-16s are excluded. Transfers outside the EEA rely on Standard Contractual Clauses, the main infrastructure sitting in the EU. Missing: no Article 27 EU representative, no named DPO, no DPA, and no SOC 2 or ISO 27001 certification claimed by the publisher.

Who owns the data?

Under the terms you keep every ownership right in the code you submit; the publisher claims no ownership interest in it (8.2). It also assigns you all rights in the Output, the generated review comments and suggestions (8.3), while noting that similar code may produce similar or identical Output for other users. The publisher takes only a limited, non-exclusive licence to process your code for the sole purpose of delivering the service (8.4), and states that it never uses your code to train AI models. The extension, the website and the documentation remain its property (8.1). Under the GDPR it is controller for the website and the licensing system, and processor for the code review itself.

Reuse rights

The review comments and suggestions generated from your own code are assigned to you, so you can read, edit, publish and ship them without asking permission, in commercial work included. The restrictions apply to the product rather than to the Output: your licence to the extension is limited, non-exclusive, non-transferable and revocable, and covers installation, internal use and use of the Outputs (clause 5.1). You may not reverse-engineer the service, create derivative works from it, resell or sublicense it, use it to build a competing product, or share your licence key (5.2). The assignment covers only Output derived from your own inputs, and you warrant that you hold the rights to the code you submit (6.2).

Data retention & training

Retention summary
Source code is not stored at all: it is processed in memory and discarded once the review is finished. Your API keys are never stored by the publisher either, staying locally in VS Code. Everything else follows a published retention table: account information is kept until you delete your account, plus 30 days; usage statistics are kept for 90 days in aggregated, anonymised form; payment records are kept for as long as the law requires, typically seven years; support conversations are kept for two years after the last exchange. Deletion requests go to privacy@gitautoreview.com and get an answer within 30 days. One caveat: once your code reaches the AI provider, that provider's own rules apply, and the security documentation notes that Anthropic keeps data for 30 days for trust and safety purposes.
Trains on customer data
No
Subprocessors disclosed
Yes

Hosting summary

Source code is never hosted. It leaves VS Code for the AI provider you selected and is discarded once the review is done, with no cache on the publisher's side. API keys and Git tokens also stay local, in VS Code's SecretStorage backed by the operating system keychain. What is hosted is the surrounding service: Supabase, located in the EU, handles licence validation and usage tracking; Render hosts the website and web services; Whop processes payments and licence delivery; Google Analytics with IP anonymisation and Microsoft Clarity session recordings provide analytics. All data in transit is encrypted with TLS 1.3. International transfers are possible, since the AI providers may process data in the United States, and they rely on Standard Contractual Clauses, with the main infrastructure in the EU. No specific hosting country is named; only the EU region is stated. The website's IP resolves to a Cloudflare anycast node, which says nothing about where anything is actually hosted. The governing law is Ukrainian (terms 14).

Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Git AutoReview.

  • Rubber-stamping: the publisher itself cites a study finding that developers accept AI suggestions 96.8% of the time without checking them. The human gate only protects you if the human actually reads each draft, and bulk approval turns the safeguard into a formality
  • The tool does not guarantee that it will find every bug or vulnerability (terms 10.1) and does not replace human review, so treating a clean report as proof of quality is a mistake
  • Skill erosion: junior developers who let the AI be their only reviewer may never build the review reflexes a career depends on. Confidence scores are a statistical filter, not a guarantee, and false positives create noise
  • Bring-your-own-key shifts responsibility onto you: your code travels to Anthropic, Google or OpenAI under your own contract, and their policies apply. The security documentation notes that Anthropic retains data for 30 days for trust and safety
  • The AI bill is variable and not capped by the publisher, so heavy use goes well beyond the 2 to 5 US dollars a month the site estimates, and looking after your API keys and Git access tokens is your responsibility (terms 7)
  • If something goes wrong there is no identifiable legal entity to turn to: Ukrainian law applies, liability is capped at 100 US dollars or twelve months of subscription, and with no DPA and no EU representative, reviewing code that contains personal data becomes a compliance question
  • Continuity risk: a very young extension from a very small publisher, with terms that allow the service to be modified or discontinued without notice. Telemetry is also on by default and has to be switched off explicitly
Setup

Setup & Integrations

Technical difficulty

Low for a developer, but not zero. The site claims a 30-second install and two to five minutes to a first review: install the extension, paste an API key, connect a repository with an access token, then review. No server, no webhook, no bot account. Prerequisites: VS Code 1.85 or later, an account with Anthropic, Google or OpenAI, and a Git platform token. The site concedes the friction of pasting a key on first install. Bitbucket is the fiddliest case, with workspace token permissions and App Passwords, while GitLab Self-Managed supports custom URLs and self-signed certificates.

Deployment

PluginDesktop app

Integrations

GitHub GitLab Bitbucket Jira VS Code Cursor VSCodium Devin Desktop Claude Gemini OpenAI Claude Code

Supported languages

English
Company

Behind Git AutoReview

Company name
Git AutoReview
Founded
08/01/2026
Country of origin
🇺🇦 Ukraine
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States
Legal contact
Support contact
Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement Git AutoReview.

A Augment CodeC CodeRabbitC Cursor BugbotC CodeAnt AIG GreptileP Panto AIQ QodoB BitoZ ZencoderS SourceryG GitHub CopilotC CodeQLS SonarQube
FAQ

Frequently asked questions

Which Git platforms does Git AutoReview support?
GitHub (Cloud and Enterprise), GitLab (Cloud, Self-Managed and Dedicated) and Bitbucket (Cloud, Server and Data Center). All of them are handled natively from the VS Code sidebar, with no webhook and no bot account to create.
Does my source code go through Git AutoReview's servers?
No. Your code leaves VS Code for the AI provider you selected, under your own API key, and is discarded after the review. The publisher only tracks usage metrics for billing, and states that it never caches your code.
Do I need my own API key?
Yes. Bring-your-own-key applies to every plan, the free one included. You need an account with Anthropic, Google or OpenAI, though a Claude Code subscription works too, and you should budget roughly 2 to 5 US dollars a month paid directly to that provider.
Which AI models can it run?
Claude from Anthropic, Gemini from Google and GPT from OpenAI. They can be launched in parallel on the same diff so you can compare what each one finds, and overlapping findings are merged.
What happens when the AI gets something wrong?
Nothing is published automatically. Every comment arrives as a draft in the review panel, and you approve, edit or reject it before it reaches the pull request.
Is there a free plan?
Yes, and it is permanent rather than a time-limited trial: 10 AI reviews per day, one repository, bring your own key, no credit card required.
How does it differ from CodeRabbit?
According to the publisher's own comparison: human approval instead of automatic posting, three model families instead of one, native Bitbucket Server and Data Center support, and a flat 14.99 US dollars per month for a team rather than 24 US dollars per user per month. These are the publisher's claims and were not verified independently.
What is the difference between Deep Review and a standard review?
A standard review sends the diff and its context to the model API and takes 5 to 15 seconds. Deep Review launches an agent that explores the repository, reads files, runs the linter and checks tests, and typically takes 2 to 5 minutes.
Where are my API keys stored?
In VS Code's SecretStorage, which is backed by the operating system keychain: macOS Keychain, Windows Credential Manager or the Linux Secret Service. The publisher does not store them.
Does it work with Cursor or VSCodium?
Yes, through Open VSX, with the same extension ID and the same version as the Marketplace build. Cursor, VSCodium and Devin Desktop are supported, and VS Code 1.85 or later is required in all cases.
Conclusion

Should you pick Git AutoReview?

Git AutoReview takes a clear and defensible position on a crowded market: the AI proposes, a human decides. Where CodeRabbit, Qodo and most review bots post their findings straight onto the pull request, nothing leaves this extension until someone has read the draft and clicked approve. The privacy architecture follows the same logic and is structural rather than cosmetic: bring your own key on every plan including the free one, code going from VS Code straight to the AI provider without touching the publisher's servers, no cache, keys held in the operating system keychain. Flat team pricing at 14.99 US dollars a month for up to 25 members is aggressive against a market that charges per seat, and native Bitbucket Server and Data Center coverage is rare. The price of admission is that mandatory key: an account to open with Anthropic, Google or OpenAI, a key to manage, and a variable AI bill on top of the subscription. Transparency is oddly lopsided. Documentation is unusually open, with a dated facts page and a detailed llms.txt, while corporate transparency is close to zero: no legal entity, no address, no named director, no contact page. Two profiles announced in the site's own structured data, LinkedIn and GitHub, return 404. Figures shift from page to page on repositories, customer countries and model versions. The product is very young, the domain registered in January 2026, and carried by a very small team, with Ukrainian law governing any dispute and liability capped at 100 US dollars or twelve months of subscription. For a solo developer, a freelancer or a small privacy-conscious team, the free plan costs nothing to test and the proposition is strong. For enterprise procurement, the absence of a DPA, an Article 27 representative and any certification will likely be decisive.