
Git AutoReview
A VS Code extension that reviews pull requests on GitHub, GitLab and Bitbucket, running Claude, Gemini and GPT in parallel. Reviews use your own API key, and every comment is a draft: nothing is published without your approval.
What is Git AutoReview?
Git AutoReview is a VS Code extension that reviews pull requests with AI and then deliberately stops before publishing anything. Its tagline, AI suggests. You decide., describes the whole product: every comment the AI writes lands in a draft panel where you approve, edit or reject it one by one, and only what you approved is posted to the pull request. It runs inside VS Code 1.85 or later on Windows, macOS and Linux, and installs from the VS Code Marketplace (publisher vitalii4reva) or from Open VSX for Cursor, VSCodium and Devin Desktop — same extension ID, same version, 1.21.9 at the time of this review. On the Git side it covers GitHub Cloud and Enterprise, GitLab Cloud, Self-Managed and Dedicated, and Bitbucket Cloud, Server and Data Center, all handled natively from the sidebar: no webhook, no bot account, no server component. Reviews run on three model families — Claude from Anthropic, Gemini from Google, GPT from OpenAI — which can be launched in parallel on the same diff, with overlapping findings merged. Bringing your own key is mandatory on every plan, including the free one: your code leaves VS Code for the provider you chose, under your own account, and never passes through the publisher's servers. Keys live in VS Code's SecretStorage, backed by the operating system keychain, and the publisher puts the AI cost at roughly 2 to 5 US dollars a month, paid directly to the provider. Beyond the standard pass, a Deep Review agent mode sends an agent into the repository to read files, run the linter, check tests and trace data flows, usually in two to five minutes. Review Profiles store named setups — models, keys, prompts, rules, repositories — switchable from the status bar, and a .gitautoreview.md file at the repository root versions team review rules in git the way an .eslintrc does. Jira integration reads the ticket and checks its acceptance criteria one by one. The publisher's argument for the human gate is a study it cites, finding that developers accept AI suggestions 96.8% of the time without verifying them. Claimed traction — 5,500+ downloads, a 5.0 Marketplace rating, teams in 8+ countries — rests on the site alone.
What it does
- Analyse the diff of a pull request or merge request and write review comments on it
- Run Claude, Gemini and GPT in parallel on the same diff, then merge the findings they share
- Put every suggestion through human approval — approve, edit or reject — before anything is published
- Publish only the approved comments to GitHub, GitLab or Bitbucket
- Scan for security flaws with 20+ built-in rules plus a dedicated AI pass
- Explore the repository in Deep Review agent mode: read files, run the linter, check tests, trace data flows
- Score each finding from 0 to 100% confidence and rate code quality across six categories
When to use Git AutoReview / When not to
A quick filter to help you decide if Git AutoReview is the right fit.
When to use Git AutoReview
- Solo developers, freelancers and solo founders who have nobody to review their pull requests
- Code reviewers facing a long queue who want to move faster without handing over the final say
- Privacy-conscious teams that need their source code to stay out of a vendor's servers
- Bitbucket Server and Data Center teams, including those working behind a corporate firewall
- Small teams on a tight budget: the Team plan is a flat monthly fee for up to 25 members, not a per-seat charge
When not to use Git AutoReview
- Developers who work outside VS Code and its forks: there is no JetBrains plugin, no web app and no mobile app
- Teams that want fully automated review with zero human involvement, since nothing is posted until someone clicks approve
- Anyone unwilling to open an Anthropic, Google or OpenAI account: bring-your-own-key is mandatory, even on the free plan
- Organizations that require enterprise SSO, an SLA or a signed data processing agreement, none of which come with the published plans
- Teams whose code lives anywhere other than GitHub, GitLab or Bitbucket
How to use Git AutoReview
A typical end-to-end flow, from setup to results.
- Install the extension from the VS Code Marketplace by searching for Git AutoReview, or from Open VSX if you use Cursor, VSCodium or Devin Desktop
- Open the settings panel with Cmd+Shift+P, then Git AutoReview: Open Settings, and go to the General tab
- Paste an Anthropic, Google or OpenAI API key, or point the extension at a Claude Code subscription
- Switch to the Repositories tab, click Add Repository, choose GitHub, GitLab or Bitbucket, then enter the repository and an access token
- Open a pull request from the sidebar
- Click Review and let the AI analyse the diff
- Pick a model from the sidebar selector, or launch several models in parallel to compare what they find
- Go through the suggestions one by one and approve, edit or reject each of them
- Click Publish to PR: only the comments you approved are sent to the platform
- Optionally drop a .gitautoreview.md file at the root of the repository to enforce team review rules
Pros & Cons
Pros
- Nothing reaches the pull request without a human clicking approve, the differentiator the publisher claims against CodeRabbit and Qodo, which post automatically
- Three model families run in parallel rather than one, and where they disagree the disagreement is surfaced instead of averaged away
- Bring-your-own-key on every plan, free one included: no lock-in on the AI side, and you pay the provider at cost, around 2 to 5 US dollars a month
- Code never transits the publisher's servers and is never cached, where competitors cited on the site keep 7-day and 48-hour caches; API keys stay in the operating system keychain
- Flat team pricing at 14.99 US dollars a month for up to 25 members instead of a per-seat charge
- Bitbucket Server and Data Center covered natively in VS Code, which the publisher claims is unique on this market
- A permanent free plan that is genuinely usable: 10 reviews a day, one repository, no credit card, plus telemetry that can be switched off
Cons
- No legal entity, no postal address and no named director anywhere on the site: the terms are signed simply Git AutoReview, with no company form, and liability is capped at the higher of twelve months of subscription or 100 US dollars
- No legal notice and no contact page, /contact returning a 404, and the only contact details are email addresses injected by JavaScript, so several pages show loading... to anyone without it
- The home page structured data advertises a LinkedIn company page and a GitHub repository that both return 404 when checked, which casts doubt on the site's other unverifiable figures
- Bring-your-own-key is mandatory: you have to open an account with Anthropic, Google or OpenAI, manage a key, and budget roughly 2 to 5 US dollars a month on top of the subscription
- No data processing agreement published or offered, no Article 27 EU representative and no SOC 2 or ISO 27001 certification claimed by the publisher, a likely blocker for enterprise procurement
- The site contradicts itself from page to page: the model lists differ between the home FAQ, the facts page and llms.txt, the Team plan shows unlimited repositories on the pricing page but 10 elsewhere, and customer countries are 8+ on the home page but 5+ on the pricing page
- A very young product from a very small publisher, with the domain registered in January 2026, Ukrainian law and Ukrainian courts governing any dispute, and refunds limited to seven days on a first purchase
Pricing & Plans
Git AutoReview offers a permanent free plan, covering 10 AI reviews per day on a single repository with no credit card required. The lowest paid entry point is the Developer plan at USD 8.33 per month on annual billing (USD 99.90 per year), or USD 9.99 per month on monthly billing. AI usage is billed separately by the model provider under the customer's own API key, which the publisher estimates at USD 2 to 5 per month. A refund may be requested within seven days of a first purchase.
- 10 AI reviews per day
- 1 repository
- bring your own key
- basic approval workflow
- 100 AI reviews per day
- up to 10 repositories
- BYOK for Claude
- Gemini and GPT
- Deep Review agent mode
- Review Profiles
- 5 custom review rules
- email support
- unlimited AI reviews
- unlimited repositories
- up to 25 members
- BYOK
- Deep Review
- Review Profiles
- full Jira integration
- 20 custom rules
- pay for ten months
- get twelve
- SSO
- an SLA or repository volumes beyond the Team plan require contacting the publisher
- no price is published for them
- Payment and licence delivery are handled through Whop
Data, GDPR & hosting
A consolidated view of how Git AutoReview handles your data.
GDPR overview
Git AutoReview never calls itself “GDPR compliant” in so many words, but its privacy policy is built around the regulation. Effective 5 January 2026, it names a legal basis for each purpose — contract performance for the licence, legitimate interest for improvement and security, consent where required — and splits the roles explicitly: the publisher is controller for the website and the licensing system, and processor for the code review itself. Section 7.1 lists seven data subject rights (access, rectification, erasure, restriction, portability, objection, withdrawal of consent), exercised via privacy@gitautoreview.com and answered within 30 days; CCPA and CPRA rights are covered as well, and under-16s are excluded. Transfers outside the EEA rely on Standard Contractual Clauses, the main infrastructure sitting in the EU. Missing: no Article 27 EU representative, no named DPO, no DPA, and no SOC 2 or ISO 27001 certification claimed by the publisher.
Who owns the data?
Under the terms you keep every ownership right in the code you submit; the publisher claims no ownership interest in it (8.2). It also assigns you all rights in the Output, the generated review comments and suggestions (8.3), while noting that similar code may produce similar or identical Output for other users. The publisher takes only a limited, non-exclusive licence to process your code for the sole purpose of delivering the service (8.4), and states that it never uses your code to train AI models. The extension, the website and the documentation remain its property (8.1). Under the GDPR it is controller for the website and the licensing system, and processor for the code review itself.
Reuse rights
The review comments and suggestions generated from your own code are assigned to you, so you can read, edit, publish and ship them without asking permission, in commercial work included. The restrictions apply to the product rather than to the Output: your licence to the extension is limited, non-exclusive, non-transferable and revocable, and covers installation, internal use and use of the Outputs (clause 5.1). You may not reverse-engineer the service, create derivative works from it, resell or sublicense it, use it to build a competing product, or share your licence key (5.2). The assignment covers only Output derived from your own inputs, and you warrant that you hold the rights to the code you submit (6.2).
Data retention & training
Hosting summary
Source code is never hosted. It leaves VS Code for the AI provider you selected and is discarded once the review is done, with no cache on the publisher's side. API keys and Git tokens also stay local, in VS Code's SecretStorage backed by the operating system keychain. What is hosted is the surrounding service: Supabase, located in the EU, handles licence validation and usage tracking; Render hosts the website and web services; Whop processes payments and licence delivery; Google Analytics with IP anonymisation and Microsoft Clarity session recordings provide analytics. All data in transit is encrypted with TLS 1.3. International transfers are possible, since the AI providers may process data in the United States, and they rely on Standard Contractual Clauses, with the main infrastructure in the EU. No specific hosting country is named; only the EU region is stated. The website's IP resolves to a Cloudflare anycast node, which says nothing about where anything is actually hosted. The governing law is Ukrainian (terms 14).
Things to keep in mind
Risks and trade-offs to weigh before adopting Git AutoReview.
- Rubber-stamping: the publisher itself cites a study finding that developers accept AI suggestions 96.8% of the time without checking them. The human gate only protects you if the human actually reads each draft, and bulk approval turns the safeguard into a formality
- The tool does not guarantee that it will find every bug or vulnerability (terms 10.1) and does not replace human review, so treating a clean report as proof of quality is a mistake
- Skill erosion: junior developers who let the AI be their only reviewer may never build the review reflexes a career depends on. Confidence scores are a statistical filter, not a guarantee, and false positives create noise
- Bring-your-own-key shifts responsibility onto you: your code travels to Anthropic, Google or OpenAI under your own contract, and their policies apply. The security documentation notes that Anthropic retains data for 30 days for trust and safety
- The AI bill is variable and not capped by the publisher, so heavy use goes well beyond the 2 to 5 US dollars a month the site estimates, and looking after your API keys and Git access tokens is your responsibility (terms 7)
- If something goes wrong there is no identifiable legal entity to turn to: Ukrainian law applies, liability is capped at 100 US dollars or twelve months of subscription, and with no DPA and no EU representative, reviewing code that contains personal data becomes a compliance question
- Continuity risk: a very young extension from a very small publisher, with terms that allow the service to be modified or discontinued without notice. Telemetry is also on by default and has to be switched off explicitly
Setup & Integrations
Technical difficulty
Low for a developer, but not zero. The site claims a 30-second install and two to five minutes to a first review: install the extension, paste an API key, connect a repository with an access token, then review. No server, no webhook, no bot account. Prerequisites: VS Code 1.85 or later, an account with Anthropic, Google or OpenAI, and a Git platform token. The site concedes the friction of pasting a key on first install. Bitbucket is the fiddliest case, with workspace token permissions and App Passwords, while GitLab Self-Managed supports custom URLs and self-signed certificates.
Deployment
Integrations
Supported languages
Behind Git AutoReview
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Git AutoReview.
Frequently asked questions
Which Git platforms does Git AutoReview support?
Does my source code go through Git AutoReview's servers?
Do I need my own API key?
Which AI models can it run?
What happens when the AI gets something wrong?
Is there a free plan?
How does it differ from CodeRabbit?
What is the difference between Deep Review and a standard review?
Where are my API keys stored?
Does it work with Cursor or VSCodium?
Should you pick Git AutoReview?
Git AutoReview takes a clear and defensible position on a crowded market: the AI proposes, a human decides. Where CodeRabbit, Qodo and most review bots post their findings straight onto the pull request, nothing leaves this extension until someone has read the draft and clicked approve. The privacy architecture follows the same logic and is structural rather than cosmetic: bring your own key on every plan including the free one, code going from VS Code straight to the AI provider without touching the publisher's servers, no cache, keys held in the operating system keychain. Flat team pricing at 14.99 US dollars a month for up to 25 members is aggressive against a market that charges per seat, and native Bitbucket Server and Data Center coverage is rare. The price of admission is that mandatory key: an account to open with Anthropic, Google or OpenAI, a key to manage, and a variable AI bill on top of the subscription. Transparency is oddly lopsided. Documentation is unusually open, with a dated facts page and a detailed llms.txt, while corporate transparency is close to zero: no legal entity, no address, no named director, no contact page. Two profiles announced in the site's own structured data, LinkedIn and GitHub, return 404. Figures shift from page to page on repositories, customer countries and model versions. The product is very young, the domain registered in January 2026, and carried by a very small team, with Ukrainian law governing any dispute and liability capped at 100 US dollars or twelve months of subscription. For a solo developer, a freelancer or a small privacy-conscious team, the free plan costs nothing to test and the proposition is strong. For enterprise procurement, the absence of a DPA, an Article 27 representative and any certification will likely be decisive.
- Choosing a selection results in a full page refresh.
- Opens in a new window.