Reviews every eligible PR
Severity-ranked inline findings with evidence quotes โ not drive-by nitpicks. Suggestions render as committable patches.
Two-pass AI review ยท validator-gated findings ยท learns from your team
CodeBeaver reads the diff, gathers real repository context, runs deterministic checks and a two-pass AI review, then posts inline findings it can actually defend โ and learns from the way your team replies.
Hosted runs on our Worker with your own model keys (BYOK). Self-hosting is free for your whole organisation.
Not another diff summariser. A reviewer that shows its evidence, respects your merge gate, and gets less wrong over time.
Severity-ranked inline findings with evidence quotes โ not drive-by nitpicks. Suggestions render as committable patches.
Secret-leak blocking, custom pre-merge checks, and critical-severity check runs gate the merge before a human ever looks.
Accepted and disputed findings become learned rules the reviewer applies on your next pull request โ per repository.
@codebeaver autofix prepares verified follow-up PRs that only merge after your configured checks pass.
PR descriptions, changelogs, walkthroughs by concern and file, and unit-test generation from the diff.
Vectorize-backed semantic search scoped per repository, plus import graphs, likely tests, and linked-issue scope checks.
From install to merge in three steps. No pipeline changes, no new CI runners.
Install the app with its webhook pointed at the hosted Worker โ or run pnpm selfhost:init to stand up the identical stack in your own Cloudflare account.
Deterministic gates run first, bounded repository context is gathered, then the primary pass and the independent validator review the change. Findings post inline with evidence.
Reply to findings to teach the reviewer, ask @codebeaver anything, accept an autofix PR, and merge when the check turns green.
Honest today, not aspirational. The hosted tier is in early access; self-hosting is not a trial.
Early access
Your model keyswe run everything else
Forever free
Freeyour whole organisation
No install
Freeyour provider key
Same code, same reviewer โ the difference is who holds the keys and the ops pager.
| โ๏ธ Hosted (we run it) | ๐ก Self-host (you run it) | |
|---|---|---|
| Setup | Install and go | pnpm selfhost:init |
| Review data lives in | Our Cloudflare account | Your Cloudflare account |
| LLM keys | Yours โ BYOK is the hosted model | Yours, in your own secret manager |
| Dashboard | Hosted dashboard | Your own URL |
| Price | Per-seat BYOK tiers (roadmap) | Free |
| Best for | Teams that want zero ops | Teams with strong feelings about their keys |
The Worker fetches your diff and bounded repository context, sends them to the model provider you configure, and stores findings and review state in the KV namespace of whichever account runs it โ ours on hosted, yours when self-hosted. Nothing is retained by model providers beyond their own API policies, and the self-hosted build keeps every byte in your account.
The primary pass reviews with full context; an independent validator then re-examines each candidate finding and drops the ones it can't confirm before anything reaches your PR. That second pass is why CodeBeaver findings arrive with evidence instead of apologies โ and each published finding is marked validator-confirmed.
When you accept a finding, dispute it, or resolve a thread, the reviewer records a bounded correction for that repository. Future reviews apply those rules โ so the bot that annoys your team about tabs stops, and the one that missed your house pattern for error handling learns it.
Yes โ BUSL-1.1 with a permanent grant: run it on your own repositories, with your own keys, for as long as you like. The only thing that needs a commercial license is running CodeBeaver for other organisations as a service or product.
Not for the hosted tier โ GitHub plus a model key is enough. A Cloudflare account (Workers Paid recommended at production volume) is only for self-hosting.
Any OpenRouter-compatible endpoint, with a registry-driven provider chain, per-purpose model overrides (review, validator, autofix, chat, describe, changelog), and fallback routes when a provider is down.
Install the hosted app today, or audit every line it runs by self-hosting it tomorrow.
๐ด Critical: auth token cached without expiry check ยท โ validator-confirmed
Evidence: refresh path writes
cache.set(user.id, token); the read path on line 61 never validates expiry.Suggested fix: gate the cache read on
expiresAt > Date.now()and fall through to refresh otherwise.Human review effort: ๐ก Medium (~20 min) ยท Next action: address the findings before merging ยท 6 candidates generated โ 2 survived validation and policy filters