Alibaba Group · Open Code Review: Alibaba's Open-Source AI Code Review Agent CLI
Open Code Review (OCR) is Alibaba's open-source (Apache 2.0) AI code review CLI. It combines deterministic file selection and rule matching with an LLM agent that reads files and searches your codebase, then posts line-level comments on diffs, branches, commits, or whole files. It suits teams that want self-run, model-agnostic code review in the terminal or CI.
Best for
Engineering and platform teams that want an open-source, self-run AI reviewer with precise line-level comments, full control over which model sees their code, and ready-made CI integrations
Not ideal for
Teams that want a hosted review bot with no setup, teams that need a reviewer to catch most issues on its own, and anyone without access to a tool-calling LLM or a supported coding agent
Who it's for
Individual developers, platform teams, and ML researchers who need automated code review they can run on their own infrastructure with any model
Open Code Review is a focused reviewer rather than a general coding agent, and its main idea is sound: let code, not the model, decide which files get reviewed and where comments land, then use the model for judgment. That addresses real complaints about agent-based review, such as skipped files and comments on the wrong lines, and it keeps token use down. The catch is coverage. By Alibaba's own numbers, even the top-ranked setup finds only about a fifth of the issues human experts flagged, so it works best as a low-noise first pass that saves reviewers time, not as a safety net. Because it is Apache 2.0 and model-agnostic, trying it in CI costs little beyond tokens.
Who should use it
Teams that want automated pull request review without sending code to a new SaaS vendor, platform teams standardizing review across GitHub, GitLab, or Gerrit, and developers who already pay for Claude Code or Codex and want structured review through Delegation Mode.
Who should skip it
Teams that want a fully hosted review bot, teams expecting an AI reviewer to replace human review, and environments where no tool-calling model or approved LLM endpoint is available.
Open source
Free
Note: Open Code Review itself is free. Costs come from the LLM provider you configure, which scale with the effort level, the number of review rounds, and the size of the diff. In Delegation Mode the host coding agent's own plan or API usage covers the review.
Pull request review in CI
The provided GitHub Actions and GitLab CI recipes run OCR on each pull or merge request and post inline comments, with file-level findings folded into a summary.
Review without a new API key
Delegation Mode lets a coding agent you already pay for, such as Claude Code or Codex, do the review while OCR decides which files matter and which rules apply.
Auditing unfamiliar code
`ocr scan` reviews whole files or directories when there is no useful diff, such as when inheriting a legacy module.
Open Code Review vs. OpenAI Codex
Codex includes a code review command and automatic GitHub code review tied to ChatGPT plans. Open Code Review is a dedicated, open-source review CLI that works with any tool-calling model and can also delegate the review to Codex itself.
Open Code Review vs. Factory Droid
Factory offers pull request code review as one automation in a broader commercial agent platform. Open Code Review does only code review, is free and Apache 2.0, and runs wherever you install the CLI.
Open Code Review vs. Kilo Code
Kilo Code is an open-source coding agent whose platform includes a paid cloud Code Review option billed by compute time. Open Code Review is a standalone review tool you run in your own terminal or CI with your own model.
Open Code Review vs. Claude Code
Claude Code is a general-purpose coding agent that can review code through prompts, skills, or its GitHub Actions and GitLab CI integration. Open Code Review adds deterministic file selection, rule routing, and line positioning around the model, and Alibaba reports higher precision with fewer tokens than Claude Code on its benchmark.
What is Open Code Review?
Open Code Review (OCR) is an AI code review CLI from Alibaba Group. It reads Git diffs or whole files, runs an LLM agent that can read files and search the codebase, and returns structured review comments tied to exact lines.
Is Open Code Review free and open source?
Yes. The code is on GitHub at alibaba/open-code-review under the Apache 2.0 license. You only pay for the LLM you connect, or nothing extra if you use Delegation Mode with a coding agent subscription you already have.
Which models does Open Code Review support?
Any model reachable through the Anthropic Messages API, OpenAI Chat Completions API, or OpenAI Responses API. More than 20 providers have presets, including Anthropic, Amazon Bedrock, OpenAI, OpenRouter, Gemini, DashScope, DeepSeek, Kimi, and Z.AI. Custom or local endpoints such as Ollama also work, as long as the model supports native tool calling.
Can Open Code Review comment on GitHub pull requests?
Yes. The repository ships a GitHub Actions workflow that runs OCR on pull requests (or on a `/open-code-review` comment) and posts findings as inline review comments. There are also recipes for GitLab CI, Bitbucket Pipelines, GitFlic CI, and Gerrit, and SARIF output for GitHub Code Scanning.
Does Open Code Review work with Claude Code or Codex?
Yes. There are plugins for Claude Code, Codex, Cursor, Kimi Code, and OpenCode. In Delegation Mode, OCR handles file selection and rules while the host agent performs the review with its own model, so no separate OCR API key is needed.
How accurate is Open Code Review?
On Alibaba's AACR-Bench (200 real pull requests, 1,505 expert-annotated issues), the top-ranked setup, OCR with Claude 4.6 Opus, scored 33.9% precision, 20.0% recall, and 25.1% F1. Claude Code with the same model scored 7.2% precision and 28.9% recall while using far more tokens. These are self-reported results, so OCR is best treated as a low-noise first pass, not a complete review.
Does Open Code Review send my code anywhere?
It sends diffs and any file snippets the agent reads to the LLM endpoint you configure. The docs say nothing else leaves your machine, and session logs and rule files stay local.

OpenAI
Developers and teams already paying for ChatGPT Plus, Pro, Business, or Enterprise who want one coding agent across the terminal, IDE, and parallel cloud tasks
FreemiumFactory
Engineering organizations that want one model-agnostic agent platform across local coding, CI automation, code review, and long-running missions, with enterprise deployment and governance options
PaidKilo (Anaconda)
Developers and teams who want an open-source coding agent across VS Code, JetBrains, and the terminal with free choice of models and pay-as-you-go pricing
FreemiumAnthropic
Developers and teams who want deep codebase reasoning, multi-file changes, and persistent project instructions in a terminal-friendly or IDE-native workflow
PaidOpen Code Review started as Alibaba Group's internal AI code review assistant, which the project says served tens of thousands of developers over two years before it was open-sourced in 2026. It is a Go CLI, `ocr`, installed through npm, Homebrew, an install script, or release binaries for macOS, Linux, and Windows, and it needs Git 2.41 or newer. The design splits the work. Deterministic code decides which files need review, bundles related files into groups that each run as a sub-agent with isolated context, matches review rules to each file, and places comments on exact lines. The LLM agent handles the judgment calls, using tools such as `file_read` and `code_search` to pull in context beyond the diff, and a separate reflection step tries to filter hallucinated comments. You can review workspace changes, a branch range, a single commit, or run `ocr scan` over whole files. An effort setting (low, medium, or high) controls how many review rounds each group gets. OCR is model-agnostic: it speaks the Anthropic Messages, OpenAI Chat Completions, and OpenAI Responses APIs, ships more than 20 built-in provider presets (including Anthropic, Amazon Bedrock, OpenAI, OpenRouter, Gemini, DashScope, DeepSeek, Kimi, and Z.AI), and accepts custom or local endpoints such as Ollama, as long as the model supports native tool calling. Delegation Mode lets a coding agent such as Claude Code, Codex, or Cursor do the review with its own subscription while OCR supplies file lists and rules. Plugins cover Claude Code, Codex, Cursor, Kimi Code, and OpenCode, and CI recipes cover GitHub Actions (including a reusable action), GitLab CI, Bitbucket Pipelines, GitFlic CI, and Gerrit, with JSON and SARIF output. On its own AACR-Bench benchmark (200 pull requests from 50 open-source repositories), Alibaba reports higher precision and F1 than Claude Code with the same model at about a ninth of the tokens, but recall is lower by design: the top-ranked configuration finds about 20% of the 1,505 annotated issues. Treat it as a precise first reviewer, not a replacement for human review.
Alibaba shipped v1.12.11 of the open-source Open Code Review CLI with Jinja template support for allowlists and fixes to the Session Viewer and Windows builds. It follows v1.12.10 (September 28), which added OpenRouter as a built-in provider and an `ocr session rm` command.
Are you the founder? Claim this listing →