---
title: "Automatic code review"
description: "Review pull requests with a GitHub Action, your model and your MiniRouter key."
canonical_url: "https://minirouter.sh/docs/guides/code-review"
markdown_url: "https://minirouter.sh/docs/guides/code-review.md"
last_updated: "2026-09-26"
---

# Automatic code review

Review pull requests with a GitHub Action, your model and your MiniRouter key.

[Get a key](https://minirouter.sh/key)

## GitHub Action

### 1. Add your key

Create a dedicated [review key](https://minirouter.sh/dashboard/keys) with a [spend cap](https://minirouter.sh/docs/rate-limits), then save it as a repository Actions secret.

```sh
gh secret set MINIROUTER_API_KEY
```

### 2. Add the workflow

No checkout step is needed. The Action reads committed code without executing it. It defaults to three agents, with a maximum of eight.

The $2 budget below stops new calls once reported cost reaches it. Calls already in flight can exceed it; your key's spend cap is the hard limit.

```yaml
name: Code review

on:
  pull_request:
    types: [opened, synchronize, reopened, ready_for_review]

permissions:
  contents: read
  pull-requests: write

concurrency:
  group: code-review-${{ github.event.pull_request.number }}
  cancel-in-progress: true

jobs:
  review:
    runs-on: ubuntu-latest
    timeout-minutes: 20
    steps:
      - uses: minirouter/code-review@v1
        with:
          api-key: ${{ secrets.MINIROUTER_API_KEY }}
          model: minirouter/auto
          budget: '2'
```

### 3. Open a pull request

The Action verifies findings against the source, posts them on changed lines and updates one summary comment. The job summary shows status, reported cost and the models that served the requests.

> **Note:** Fork pull requests are skipped. The Action refuses `pull_request_target` events.

## Choose your model

The default is `minirouter/auto`. Use any [model ID](https://minirouter.sh/models), or a [preset](https://minirouter.sh/docs/presets) to manage the model from your dashboard.

```yaml
with:
  api-key: ${{ secrets.MINIROUTER_API_KEY }}
  model: '@preset/code-review'
```

Edit the preset to change the review model without editing workflows.

## Local agent swarm

Review, swarm and audit commands are in the [Local agent swarm guide](/docs/guides/local-agent-swarm).

## Audit a repository

Set `mode: audit` and grant `issues: write` to review the committed head snapshot. The Action updates one tracking issue, creating it on the first run, and writes SARIF.

### Manual audit workflow

```yaml
name: Repository audit

on:
  workflow_dispatch:

permissions:
  contents: read
  issues: write

concurrency:
  group: code-review-audit
  cancel-in-progress: true

jobs:
  audit:
    runs-on: ubuntu-latest
    timeout-minutes: 20
    steps:
      - uses: minirouter/code-review@v1
        with:
          api-key: ${{ secrets.MINIROUTER_API_KEY }}
          mode: audit
          budget: '2'
```

## Action inputs

### All inputs and defaults

| Input | Default and behavior |
| --- | --- |
| `api-key` | Required. Your MiniRouter key, stored as a secret. |
| `model` | `minirouter/auto`. Any model ID or `@preset/slug`. |
| `agents` | `3`. Choose 3–8 agents in the Action. |
| `budget` | `2` USD. Stops new calls once reported cost reaches this amount. |
| `mode` | `pr`. Set `audit` to review the whole repository. |
| `fail-on` | `none`. Use `P1`, `P2` or `P3` to fail for findings at that priority or higher. |
| `github-token` | `${{ github.token }}`. Needs pull request write permission, or issue write permission for audits. |
| `base-url` | `https://api.minirouter.sh/v1`. Override for local testing. |

The Action writes `review.md`, `review.json` and `review.sarif` under `$GITHUB_WORKSPACE/.minirouter-review`. Outputs: `markdown`, `json`, `sarif`, `status` and `cost-usd`. Upload the files with your usual artifact step to retain them after the job.

## Cost and incomplete reviews

The budget adds up the cost MiniRouter reports. Calls already in flight can finish above the budget, so use a [per-key spend cap](https://minirouter.sh/docs/rate-limits) as the hard limit. See requests in [Activity](https://minirouter.sh/dashboard/activity).

Timeouts, missing cost reports, exhausted credits and unrepaired model responses produce an incomplete review. Reports preserve completed work and explain the stop; an incomplete review is never presented as clean.

The Action fails on incomplete runs even with `fail-on: none`.

### The API returned 402 or 403

402 `insufficient_credits` means the available balance cannot cover the request; [top up](https://minirouter.sh/dashboard/billing). For 403 `spend_limit_exceeded`, check the [key cap](https://minirouter.sh/dashboard/keys).

### The model returned invalid JSON

Each agent gets one repair turn. If it still cannot return a valid response, the review is incomplete. Findings outside changed head-side lines are dropped from pull request reviews.

### The API is slow or rate limited

Calls have individual timeouts and the run has an overall deadline. A 429 response is retried with backoff within those limits.

## Other agents

Already using [Codex](https://minirouter.sh/docs/integrations/codex) or [Claude Code](https://minirouter.sh/docs/integrations/claude-code)? These standalone recipes send a diff through MiniRouter and post the agent's response.

These recipes have their own agent permissions and post a new comment on each run. Use a dedicated capped key and keep the same-repository condition.

### Codex and Claude Code workflows

**Codex**

```yaml
name: Code review

on:
  pull_request:
    types: [opened, synchronize, ready_for_review]

permissions:
  contents: read
  pull-requests: write

jobs:
  review:
    if: github.event.pull_request.head.repo.full_name == github.repository
    runs-on: ubuntu-latest
    timeout-minutes: 15
    steps:
      - uses: actions/checkout@v4
        with:
          persist-credentials: false
      - uses: actions/setup-node@v4
        with:
          node-version: 22
      - run: npm install -g @openai/codex
      - name: Configure Codex
        run: |
          mkdir -p ~/.codex
          cat > ~/.codex/config.toml <<'EOF'
          model = "zai/glm-5.3-flash"
          model_provider = "minirouter"
          web_search = "disabled"
          model_reasoning_summary = "none"

          [model_providers.minirouter]
          name = "MiniRouter"
          base_url = "https://api.minirouter.sh/v1"
          wire_api = "responses"
          auth = { command = "sh", args = ["-c", "echo $MINIROUTER_API_KEY"] }
          EOF
      - name: Fetch diff
        env:
          GH_TOKEN: ${{ github.token }}
          PR: ${{ github.event.pull_request.number }}
        run: gh pr diff "$PR" > pr.diff
      - name: Review
        env:
          MINIROUTER_API_KEY: ${{ secrets.MINIROUTER_API_KEY }}
        run: codex exec --sandbox read-only --ephemeral -o review.md "Review this pull request diff. List bugs, security issues and missing tests with file and line. Be brief." < pr.diff
      - name: Post review
        env:
          GH_TOKEN: ${{ github.token }}
          PR: ${{ github.event.pull_request.number }}
        run: gh pr comment "$PR" --body-file review.md
```

**Claude Code**

```yaml
name: Code review

on:
  pull_request:
    types: [opened, synchronize, ready_for_review]

permissions:
  contents: read
  pull-requests: write

jobs:
  review:
    if: github.event.pull_request.head.repo.full_name == github.repository
    runs-on: ubuntu-latest
    timeout-minutes: 15
    steps:
      - uses: actions/checkout@v4
        with:
          persist-credentials: false
      - uses: actions/setup-node@v4
        with:
          node-version: 22
      - run: npm install -g @anthropic-ai/claude-code
      - name: Fetch diff
        env:
          GH_TOKEN: ${{ github.token }}
          PR: ${{ github.event.pull_request.number }}
        run: gh pr diff "$PR" > pr.diff
      - name: Review
        env:
          ANTHROPIC_BASE_URL: https://api.minirouter.sh
          ANTHROPIC_AUTH_TOKEN: ${{ secrets.MINIROUTER_API_KEY }}
          ANTHROPIC_MODEL: zai/glm-5.3-flash
        run: claude -p "Review this pull request diff. List bugs, security issues and missing tests with file and line. Be brief." < pr.diff > review.md
      - name: Post review
        env:
          GH_TOKEN: ${{ github.token }}
          PR: ${{ github.event.pull_request.number }}
        run: gh pr comment "$PR" --body-file review.md
```

## Related guides

- [Presets](https://minirouter.sh/docs/presets): Change the review model without editing workflows.
- [Spend limits](https://minirouter.sh/docs/rate-limits): Set a hard spending cap for your review key.
