CodeRabbit

AI pull request reviewer layering 57 third-party linters and a separately metered AI Deep Scan, plus IDE extension and CLI.

Free tier availableLast verified 2026-09-06

Deployment

Cloud · Self-Hosted

Languages

9+

Pricing model

Per developer seat, Usage-based credits, Quote-based / Enterprise

Free tier

Yes

Workflow coverage

Where in the development lifecycle CodeRabbit operates.

Real-Time IDE FeedbackPartial

VS Code, Cursor, Windsurf extension reviews on local commit or on demand, not as-you-type

AI Agent Guardrail (MCP)Yes

CLI plugin and Skills for Claude Code, Codex, Cursor, Gemini CLI; --agent JSON output

Local CLI / Pre-CommitYes

cr CLI reviews committed, staged, unstaged and untracked local changes; 3 reviews/hour on Free

PR Inline ReviewYesPro

Full inline PR reviews require Pro; Free plan gets PR summarization only

Merge Gate BlockingYes

Pre-merge checks in error mode block merges via Request Changes Workflow; custom checks Pro+

Full Repo ScanYesadd-on

AI Deep Scan analyzes full committed source and IaC; separately billed usage-based product

Scheduled / Continuous RescanYesadd-on

Weekly recurring Dependencies, SBOM, Secrets scans; requires Security trial or paid add-on

Runtime / Production MonitoringNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Analysis & detection

Every detection and code-analysis capability tracked for CodeRabbit.

SASTYesPro

Catalog includes Semgrep, OpenGrep, Brakeman, PHPStan, fbinfer, PMD, detekt; tool support from Pro

Taint / Data-Flow AnalysisYesadd-on

AI Deep Scan traces untrusted input to sensitive sinks with call stacks; separately billed

Secrets DetectionYesPro

Gitleaks, Betterleaks, TruffleHog, Presidio in tool catalog; dedicated Secrets scan needs add-on

Secrets ValidationYesadd-on

Verifies detected credentials against service providers by default; requires Security trial or add-on

SCA (Dependencies)YesPro

OSV Scanner and Trivy in tool catalog; dedicated Dependencies scan requires Security add-on

Reachability AnalysisYesadd-on

Deep Scan findings carry reachability and exploitability signals with call stacks when available

Malicious Package DetectionNo

Not offered in vendor documentation reviewed as of 2026-09-05.

License ComplianceNo

Not offered in vendor documentation reviewed as of 2026-09-05.

SBOM GenerationYesadd-on

Generates SBOM as a dedicated scan type; requires Security trial or paid add-on.

IaC ScanningYesPro

Checkov, TFLint, Hadolint, zizmor, actionlint; Deep Scan covers Terraform, Kubernetes, Helm, ARM

Container ScanningPartialPro

Trivy and Hadolint cover Dockerfiles in-repo; no container registry or image scanning described

Cloud Posture (CSPM)No

Not offered in vendor documentation reviewed as of 2026-09-05.

DAST / API ScanningNo
Code Smells & MaintainabilityYesPro

Maintainability & Code Quality review category plus ESLint, PHPMD, Pylint, RuboCop, detekt

Complexity MetricsNo

Not documented. Dashboard-metrics reference is exhaustive; no cyclomatic/complexity metric exists

Duplication DetectionYesPro

Maintainability & Code Quality category explicitly names duplication; tracked in dashboard metrics

Dead / Unused CodeNo

Not documented on the exhaustive dashboard-metrics or reports reference pages

Test Coverage TrackingNo

Not documented; no coverage ingestion/reporting metric in the metrics reference

Diff / New-Code CoverageNo

Not documented; same absence basis as overall test coverage tracking

Architecture GovernancePartialPro+

Cross-repo breaking-change detection and natural-language Custom Checks; no dependency-rule enforcement engine

Technical Debt QuantificationNo

Technical debt appears only as example prompt text in a report template, not a metric

Behavioral Delivery AnalyticsPartialPro

Analytics and custom reports with organization-wide PR statistics; no delivery or behavioral code metrics

AI Logic Bug DetectionYesPro

Functional Correctness review category; AI reasoning finds logic and correctness defects

PR Summaries & WalkthroughsYes

Summary plus Walkthrough with Mermaid diagrams, review-effort score, related issues; Free includes summaries

Custom Rule AuthoringYesPro

ast-grep YAML rules and shareable packages; natural-language Custom Checks require Pro+

Autofix SuggestionsYesPro

One-click fixes for linter findings and committable code suggestions; autofix listed under Pro

Autofix via Agentic PRsYesadd-on

Fix with AI opens fix PRs for security findings (add-on); IDE routes complex fixes to external agents

AI Triage / False-Positive FilteringYesPro

Deep Scan Verify stage rejects duplicate, mitigated, speculative, test-only findings; Learnings suppress noise

Monorepo SupportPartialPro

Glob path filters/instructions and hierarchical per-directory config; monorepos never named explicitly

AI capabilities

AI Review EngineYesPro

LLM-based reasoning engine with 57 static analysis tools layered on top

BYO Model / BYOKYesEnterprise

Bring-your-own-LLM provider available only in self-hosted Enterprise deployments

MCP ServerPartialPro

Acts as MCP client consuming external servers (Pro 5, Pro+ 15, Enterprise 20); exposes none

AI Usage GovernanceNo

Deep Scan detects LLM app risks (prompt injection, excessive agency); no AI usage inventory

Chat With ReviewerYesPro

Context-aware chat in PR comments; 50 messages/hour Pro, 100 on Pro+ and Enterprise

Learns From FeedbackYesPro

Learnings database built from chat replies; editable, scoped, optional admin approval delay

Code Excluded From TrainingYes

Trust Center: code never used to train models; models trained solely on public datasets

Compliance & governance

Audit LogsYesEnterprise

Searchable admin change history plus REST API for SIEM export; Enterprise plan only

SSO / SAMLYesEnterprise

Enterprise SSO workspaces with IdP-member to Git-identity linking; Enterprise plan only

Role-Based Access ControlYes

Built-in Admin, Member, Billing Admin roles; custom per-resource RBAC requires Enterprise

Compliance Reporting ExportsYesEnterprise

Custom report templates and audit-log REST API support compliance reporting; no framework-mapped reports.

Standards mapping

CWE

Integrations

GitHubYes
GitHub Enterprise ServerYes
GitLabYes
GitLab Self-ManagedYes
BitbucketYes
Bitbucket Data CenterPartial
Azure DevOpsYes
REST APIPartial
CLIYes
WebhooksPartial

CI/CD systems

GitHub ActionsGitLab CICircleCIAzure DevOps Pipelines

IDEs

VS CodeCursorWindsurf

Issue trackers

GitHub IssuesGitLab IssuesAzure DevOps BoardsJiraLinear

Chat & notifications

SlackDiscord

Pricing & plans

$24/mo/user billed annually ($30/mo/user billed monthly)

Minimum seats: None documented for Pro/Pro+ (per-seat, no floor); Enterprise self-hosted requires 500+ seats

Trial: 14-day Pro+ trial, no credit card, capped at 3 PR/IDE/CLI reviews per developer per hour and 50 chat messages per hour; a separate 14-day Security trial covers Dependencies, SBOM and Secrets scans

Free$0, no credit cardIndividuals and teams evaluating CodeRabbit
  • Unlimited public and private repositories
  • PR summarization
  • Full code reviews via VS Code extension and CLI
  • 150 files per review
  • Includes a 14-day Pro+ trial
  • No full PR reviews in the pull request itself
  • No PR review rate allowance (3/hour IDE, 3/hour CLI only)
  • No chat messages
  • No linter/SAST tool catalog, Knowledge Base or integrations
  • No usage-based add-on access
Open Source (OSS)$0, no credit cardOpen-source projects on public repositories
  • Unlimited public repositories
  • Pro+ features free
  • 25 chat messages per hour
  • Rate-limit tier scales with project popularity and community size
  • Public repositories only
  • PR review limit of 1 per hour, per-repo scoped
  • Files-per-review limit not stated
Pro$24/developer/month annual, $30 month-to-monthTeams wanting full AI PR review
  • Full PR reviews
  • 57-tool linter and SAST catalog
  • Knowledge Base and Learnings
  • Analytics, docstrings, autofix
  • Usage-based add-on access
  • Up to 5 connected MCP servers
  • 5 PR / 5 IDE / 5 CLI reviews per developer per hour
  • 150 files per review
  • 50 chat messages per hour
  • No CodeRabbit Plan, unit test generation or Custom Checks
  • Security scanning still requires the add-on
Pro+$48/developer/month annual, $60 month-to-monthTeams wanting planning, test generation and higher throughput
  • Everything in Pro
  • CodeRabbit Plan issue planning
  • Unit test generation
  • Merge conflict resolution and pre/post-merge actions
  • Custom Checks
  • Up to 15 connected MCP servers
  • 10 PR / 10 IDE / 10 CLI reviews per developer per hour
  • 300 files per review
  • 100 chat messages per hour
  • No self-hosting, SSO, custom RBAC or audit logs
EnterpriseContact salesOrganizations needing self-hosting and governance controls
  • Everything in Pro+
  • Self-hosting and Reverse Tunnel
  • Multi-organization support and SSO
  • Custom RBAC and audit logging
  • API access and SLA support with a dedicated CSM
  • Up to 20 connected MCP servers
  • 12 PR / 12 IDE / 12 CLI reviews per developer per hour
  • 300 files per review
  • Self-hosting is not self-serve
  • Quote-only pricing

Who it's for

Notable strengths

  • 57 individually configurable third-party linters and SAST tools, auto-skipped when already in CI
  • Surfaces beyond PRs: VS Code/Cursor/Windsurf extension, CLI, Slack and Discord agents
  • Native agent loops with Claude Code, Codex, Cursor and Gemini CLI plus open-source Skills packages
  • Learnings memory plus auto-detection of CLAUDE.md, .cursorrules and copilot-instructions as review guidance
  • AI Deep Scan maps entry points and traces untrusted input to sinks, and can open fix PRs

Notable limitations

  • Free plan is PR summarization only; full in-PR reviews start at Pro ($24/dev/month annual)
  • Hourly per-developer review rate limits (5 Pro, 10 Pro+, 12 Enterprise) plus fair-usage throttling
  • Security scanning is a paid add-on and AI Deep Scan is metered separately on top of it
  • No compliance certifications named anywhere in the documentation; Trust Center referenced instead
  • Self-hosting, SSO, custom RBAC and audit logs are Enterprise-only and not self-serve

Similar tools

Other PR Review tools in the directory.

FAQ

When should you choose CodeRabbit?

CodeRabbit best fits Indie developers, Startups, Mid-market teams, Enterprise. 57 individually configurable third-party linters and SAST tools, auto-skipped when already in CI

What languages does CodeRabbit support?

CodeRabbit supports 9+ languages and frameworks, including JavaScript, TypeScript, C, Rust, Go, Java, C#, Kotlin, Python.

What does CodeRabbit integrate with?

CodeRabbit integrates with GitHub, GitHub Enterprise Server, GitLab, GitLab Self-Managed, Bitbucket, Bitbucket Data Center (partial), Azure DevOps for source control, CI systems including GitHub Actions, GitLab CI, CircleCI, Azure DevOps Pipelines, and IDEs including VS Code, Cursor, Windsurf.

What tools are similar to CodeRabbit?

Similar PR Review tools tracked here include CodeAnt AI, Cursor (Bugbot), Greptile, Qodo.

What are CodeRabbit's plans and pricing?

CodeRabbit offers a free tier, with paid plans starting around Free tier available; enterprise pricing is quote-only.