LaunchedEditorial Listing

Open Code Review

Alibaba Group · Open Code Review: Alibaba's Open-Source AI Code Review Agent CLI

Open Open Code Review

Open Code Review (OCR) is Alibaba's open-source (Apache 2.0) AI code review CLI. It combines deterministic file selection and rule matching with an LLM agent that reads files and searches your codebase, then posts line-level comments on diffs, branches, commits, or whole files. It suits teams that want self-run, model-agnostic code review in the terminal or CI.

PricingFree
Setupmedium
Runs onSelf-hosted
APINo
Open sourceYes
DocsYes
CategoryCoding
Code ReviewOpen SourceCLICI/CDPull RequestsMulti-ModelSecurityMCP

Best for

Engineering and platform teams that want an open-source, self-run AI reviewer with precise line-level comments, full control over which model sees their code, and ready-made CI integrations

Not ideal for

Teams that want a hosted review bot with no setup, teams that need a reviewer to catch most issues on its own, and anyone without access to a tool-calling LLM or a supported coding agent

Who it's for

Individual developers, platform teams, and ML researchers who need automated code review they can run on their own infrastructure with any model

Capabilities

  • Reviews workspace changes, a branch range, a single commit, or whole files (`ocr scan`) and returns line-level comments
  • Hybrid design: deterministic file filtering, file bundling, rule routing, and line positioning, with an LLM agent for risk detection and context exploration
  • Agent tools such as `file_read` and `code_search` let the reviewer read full files and search the repository beyond the diff
  • Separate comment-positioning and reflection modules aimed at accurate line numbers and fewer hallucinated comments
  • Effort levels (low, medium, high) set how many review rounds each file group gets
  • Built-in review rules for 40+ languages and file types, with checks for null-pointer errors, thread safety, XSS, and SQL injection, plus custom project rules
  • Works with the Anthropic Messages, OpenAI Chat Completions, and OpenAI Responses APIs, with 20+ provider presets (Anthropic, Amazon Bedrock, OpenAI, OpenRouter, Gemini, DashScope, DeepSeek, Kimi, Z.AI, and more) plus custom endpoints
  • Delegation Mode lets Claude Code, Codex, Cursor, or another host agent run the review with its own model while OCR supplies files and rules
  • Plugins and skills for Claude Code, Codex, Cursor, Kimi Code, OpenCode, and skill-compatible agents
  • CI/CD recipes for GitHub Actions, GitLab CI, Bitbucket Pipelines, GitFlic CI, and Gerrit, with JSON and SARIF output for GitHub Code Scanning
  • Acts as an MCP client so external MCP servers can give the reviewer tools such as ticket or docs lookup
  • Resumable sessions and a local Session Viewer to replay reviews and mark comments fixed or ignored

Limitations

  • You bring your own LLM endpoint and pay its token costs, unless you use Delegation Mode with a host agent's subscription
  • The model must support native tool calling. Models that only describe tool calls in text, such as deepseek-r1, do not work
  • Recall is deliberately lower than general-purpose agents. On Alibaba's own benchmark the top-ranked configuration finds about 20% of annotated issues
  • The published benchmark comes from Alibaba. An independent 10-PR test cited by InfoQ measured about 12% precision, which the maintainer attributed to a since-fixed tool-call bug, and no independent re-test has been published
  • Diffs and any file snippets the agent reads are sent to whichever LLM endpoint you configure, and there is no built-in secret redaction
  • Very large diffs can exceed the prompt budget, in which case that file group is skipped
  • It is a CLI and CI tool, not a hosted service. PR comments require wiring up the provided CI workflows and tokens
  • Requires Git 2.41 or newer

Use cases

  • Reviewing staged and unstaged changes locally with `ocr review` before committing
  • Adding a GitHub Actions or GitLab CI job that posts inline review comments on every pull or merge request
  • Scanning an unfamiliar directory or legacy module with `ocr scan` when there is no meaningful diff
  • Letting Claude Code or Codex run the review through Delegation Mode without a separate API key
  • Uploading findings as SARIF so they appear in GitHub Code Scanning
  • Using OCR as a code-quality verifier that supplies reward signals in reinforcement learning pipelines for code generation models

Our take

Open Code Review is a focused reviewer rather than a general coding agent, and its main idea is sound: let code, not the model, decide which files get reviewed and where comments land, then use the model for judgment. That addresses real complaints about agent-based review, such as skipped files and comments on the wrong lines, and it keeps token use down. The catch is coverage. By Alibaba's own numbers, even the top-ranked setup finds only about a fifth of the issues human experts flagged, so it works best as a low-noise first pass that saves reviewers time, not as a safety net. Because it is Apache 2.0 and model-agnostic, trying it in CI costs little beyond tokens.

Who should use it

Teams that want automated pull request review without sending code to a new SaaS vendor, platform teams standardizing review across GitHub, GitLab, or Gerrit, and developers who already pay for Claude Code or Codex and want structured review through Delegation Mode.

Who should skip it

Teams that want a fully hosted review bot, teams expecting an AI reviewer to replace human review, and environments where no tool-calling model or approved LLM endpoint is available.

Strengths

  • Apache 2.0 and free, with no vendor account beyond your chosen LLM provider
  • Works with Anthropic, OpenAI-compatible, and local endpoints, or with a coding agent's subscription via Delegation Mode
  • Deterministic file selection and positioning address missed files and drifting line numbers
  • Ready-made GitHub Actions, GitLab CI, and Gerrit integrations with JSON and SARIF output
  • Token-efficient by design, according to Alibaba's benchmark

Weaknesses

  • Low recall means many real issues still go unflagged
  • Benchmark results are self-reported
  • Needs a tool-calling model and some CI configuration
  • No built-in secret redaction before code is sent to the model

Open Code Review pricing

Open source

Free

  • Apache 2.0 CLI for macOS, Linux, and Windows
  • Bring your own LLM endpoint, or use Delegation Mode with a coding agent

Note: Open Code Review itself is free. Costs come from the LLM provider you configure, which scale with the effort level, the number of review rounds, and the size of the diff. In Delegation Mode the host coding agent's own plan or API usage covers the review.

Technical specs

Where Open Code Review excels

Pull request review in CI

The provided GitHub Actions and GitLab CI recipes run OCR on each pull or merge request and post inline comments, with file-level findings folded into a summary.

Review without a new API key

Delegation Mode lets a coding agent you already pay for, such as Claude Code or Codex, do the review while OCR decides which files matter and which rules apply.

Auditing unfamiliar code

`ocr scan` reviews whole files or directories when there is no useful diff, such as when inheriting a legacy module.

Open Code Review vs. competitors

Open Code Review vs. OpenAI Codex

Codex includes a code review command and automatic GitHub code review tied to ChatGPT plans. Open Code Review is a dedicated, open-source review CLI that works with any tool-calling model and can also delegate the review to Codex itself.

Open Code Review vs. Factory Droid

Factory offers pull request code review as one automation in a broader commercial agent platform. Open Code Review does only code review, is free and Apache 2.0, and runs wherever you install the CLI.

Open Code Review vs. Kilo Code

Kilo Code is an open-source coding agent whose platform includes a paid cloud Code Review option billed by compute time. Open Code Review is a standalone review tool you run in your own terminal or CI with your own model.

Open Code Review vs. Claude Code

Claude Code is a general-purpose coding agent that can review code through prompts, skills, or its GitHub Actions and GitLab CI integration. Open Code Review adds deterministic file selection, rule routing, and line positioning around the model, and Alibaba reports higher precision with fewer tokens than Claude Code on its benchmark.

Frequently asked questions

What is Open Code Review?

Open Code Review (OCR) is an AI code review CLI from Alibaba Group. It reads Git diffs or whole files, runs an LLM agent that can read files and search the codebase, and returns structured review comments tied to exact lines.

Is Open Code Review free and open source?

Yes. The code is on GitHub at alibaba/open-code-review under the Apache 2.0 license. You only pay for the LLM you connect, or nothing extra if you use Delegation Mode with a coding agent subscription you already have.

Which models does Open Code Review support?

Any model reachable through the Anthropic Messages API, OpenAI Chat Completions API, or OpenAI Responses API. More than 20 providers have presets, including Anthropic, Amazon Bedrock, OpenAI, OpenRouter, Gemini, DashScope, DeepSeek, Kimi, and Z.AI. Custom or local endpoints such as Ollama also work, as long as the model supports native tool calling.

Can Open Code Review comment on GitHub pull requests?

Yes. The repository ships a GitHub Actions workflow that runs OCR on pull requests (or on a `/open-code-review` comment) and posts findings as inline review comments. There are also recipes for GitLab CI, Bitbucket Pipelines, GitFlic CI, and Gerrit, and SARIF output for GitHub Code Scanning.

Does Open Code Review work with Claude Code or Codex?

Yes. There are plugins for Claude Code, Codex, Cursor, Kimi Code, and OpenCode. In Delegation Mode, OCR handles file selection and rules while the host agent performs the review with its own model, so no separate OCR API key is needed.

How accurate is Open Code Review?

On Alibaba's AACR-Bench (200 real pull requests, 1,505 expert-annotated issues), the top-ranked setup, OCR with Claude 4.6 Opus, scored 33.9% precision, 20.0% recall, and 25.1% F1. Claude Code with the same model scored 7.2% precision and 28.9% recall while using far more tokens. These are self-reported results, so OCR is best treated as a low-noise first pass, not a complete review.

Does Open Code Review send my code anywhere?

It sends diffs and any file snippets the agent reads to the LLM endpoint you configure. The docs say nothing else leaves your machine, and session logs and rule files stay local.

Integrations & fit

GitHub ActionsGitLab CIBitbucket PipelinesGitFlic CIGerritGitHub Code Scanning (SARIF)Claude CodeCodexCursorKimi CodeOpenCodeAnthropic APIAmazon BedrockOpenAI APIOpenRouterGemini APIDashScopeDeepSeekZ.AIOllamaMCP serversOpenTelemetry
Good fit forSolo / individual, Startup / small team, Enterprise
Pricing modelFree· No cost to start
See pricing on Open Code Review →

Alternatives to consider

About Open Code Review

Open Code Review started as Alibaba Group's internal AI code review assistant, which the project says served tens of thousands of developers over two years before it was open-sourced in 2026. It is a Go CLI, `ocr`, installed through npm, Homebrew, an install script, or release binaries for macOS, Linux, and Windows, and it needs Git 2.41 or newer. The design splits the work. Deterministic code decides which files need review, bundles related files into groups that each run as a sub-agent with isolated context, matches review rules to each file, and places comments on exact lines. The LLM agent handles the judgment calls, using tools such as `file_read` and `code_search` to pull in context beyond the diff, and a separate reflection step tries to filter hallucinated comments. You can review workspace changes, a branch range, a single commit, or run `ocr scan` over whole files. An effort setting (low, medium, or high) controls how many review rounds each group gets. OCR is model-agnostic: it speaks the Anthropic Messages, OpenAI Chat Completions, and OpenAI Responses APIs, ships more than 20 built-in provider presets (including Anthropic, Amazon Bedrock, OpenAI, OpenRouter, Gemini, DashScope, DeepSeek, Kimi, and Z.AI), and accepts custom or local endpoints such as Ollama, as long as the model supports native tool calling. Delegation Mode lets a coding agent such as Claude Code, Codex, or Cursor do the review with its own subscription while OCR supplies file lists and rules. Plugins cover Claude Code, Codex, Cursor, Kimi Code, and OpenCode, and CI recipes cover GitHub Actions (including a reusable action), GitLab CI, Bitbucket Pipelines, GitFlic CI, and Gerrit, with JSON and SARIF output. On its own AACR-Bench benchmark (200 pull requests from 50 open-source repositories), Alibaba reports higher precision and F1 than Claude Code with the same model at about a ninth of the tokens, but recall is lower by design: the top-ranked configuration finds about 20% of the 1,505 annotated issues. Treat it as a precise first reviewer, not a replacement for human review.

Updates from Open Code Review

New FeatureOpen Code Review v1.12.11 released

Alibaba shipped v1.12.11 of the open-source Open Code Review CLI with Jinja template support for allowlists and fixes to the Session Viewer and Windows builds. It follows v1.12.10 (September 28), which added OpenRouter as a built-in provider and an `ocr session rm` command.

Are you the founder? Claim this listing →