Review local changes
The CodeRabbit CLI analyzes local Git changes using the same pattern recognition that powers our PR reviews. By default, it reviews tracked changes: committed changes, staged changes (including new files added withgit add), and unstaged edits to tracked files. Use --uncommitted to review only staged and tracked local edits. Files not added to Git are skipped unless you pass --include-untracked.
Key features
Review local changes
Catch bugs before they reach your repository. CodeRabbit scans committed and uncommitted Git changes for race conditions, null pointer exceptions, and logic errors.
Turn findings into fixes
CodeRabbit reports each issue with fix guidance. Apply the change in your editor, or pass structured findings to your AI coding agent to implement it.
Context-aware reviews
Paid plans unlock reviews powered by your team’s codebase history: error handling conventions, architectural patterns, and coding preferences applied automatically to every review.
Install agent skills
Run
coderabbit skills to preview and install or update verified CodeRabbit skills for supported coding agents.Getting started
1
Install CLI
Install the CLI using your preferred method:If
- Install script
- Homebrew
- Windows
coderabbit is not available immediately after installation, start a new shell, or run the exact shell-specific reload command printed under Next steps. If the install script offers browser sign-in without first asking for a region, EU users should skip it and authenticate later with an explicit --region eu.2
Authenticate
Link your CodeRabbit account to enable personalized reviews based on your team’s patterns.A browser window opens automatically. Sign in to CodeRabbit and the authentication completes in the browser.When no region is specified or saved, login uses the US region. The CLI saves the selected region for future commands, and API-key authentication uses the key’s organization and is also the recommended flow for headless or bot-driven environments. Reviews use the assigned user’s plan allowance first, then usage credits only for eligible over-limit reviews when usage-based reviews are enabled.
cr auth status displays it. Use --region us during login to switch back to US. Self-hosted authentication uses --self-hosted instead of a SaaS region.For browser logins without SSO, choose your default organization during sign-in if your account has access to multiple CodeRabbit organizations. CLI reviews still resolve the current repository first. You can change the default later with cr auth org. SSO logins use workspace billing instead of organization selection.If browser sign-in is blocked or unavailable, authenticate with an Agentic API key instead:3
Review your code
Analyze your Git repository for issues using the CodeRabbit CLI.If your main branch is not CodeRabbit scans the selected Git changes and provides specific feedback with suggested fixes.
Local reviews require a Git repository: Run the CLI from anywhere inside an initialized Git worktree. The
--dir flag can target a Git worktree or a subdirectory within one. To review without a checkout, use a remote review.main, specify your base branch:4
Verify local setup
If setup, authentication, or review startup fails, run the local diagnostics command:The command checks installation, local storage, authentication, Git repository state, and CodeRabbit service connectivity.
5
Apply suggestions
Review findings in your terminal and either apply quick fixes or send complex issues to your AI coding agent.
Local review
New files are included once staged with
git add. To review them before staging, use --include-untracked. You can combine it with --uncommitted, but not with --committed. Contradictory scope flags, such as --committed with --uncommitted, are rejected before a review starts.--committed reads reviewed file content and automatically discovered configuration from the selected Git snapshot. Explicit --config files are read from the filesystem.
Saved context for incremental reviews is reset when the comparison base changes. On upgrade to CLI 0.7.7, checkpoints from earlier versions reset once; the next review establishes a new checkpoint.
PR reviews and CLI reviews will differ, even if run on the same code. CLI reviews optimize for immediate feedback during active development, while PR reviews provide comprehensive team collaboration context and broader repository analysis.
Review without a local checkout
With CLI 0.7.7 or later, review an installed GitHub repository from any directory:--remote accepts owner/repo or a GitHub HTTPS repository URL. Both --base and --source-branch are required. The source must be a branch name or a full 40-character commit SHA; source tags are unsupported. The server compares the source with the merge base and reads repository content at the resolved source commit, without uploading local files. Add --agent for structured output.
Remote reviews require GitHub Cloud, a repository installed in the active CodeRabbit organization, and browser-based CodeRabbit SaaS authentication or an Agentic API key. Private repositories also require the authenticated user’s repository read access. GitHub Enterprise, self-hosted CodeRabbit, and other providers are unsupported.
Comparisons with 300 or more changed files are rejected because the provider response may be incomplete. Narrow the branch comparison before retrying. Remote reviews cannot be combined with local selectors such as --dir, --committed, --uncommitted, --include-untracked, or --base-commit, or with --show-prompts.
The server reads configuration from the reviewed repository; local --config files are ignored. Remote findings appear in the existing plain or agent output stream, without locally generated diff snippets or local findings history. For agent output, review_context includes remote, currentBranch, and baseBranch and omits workingDirectory. See agent mode output.
Configure your repository
With CLI 0.7.7 or later, run guided setup in an interactive terminal inside your Git repository:--detailed, lets you configure review style and path instructions. The command creates .coderabbit.yaml at the repository root, or updates an existing .coderabbit.yaml or .coderabbit.yml. It validates against the current official schema, previews the changes, and asks before saving. Existing settings are preserved unless you choose to change them. Commit and push the configuration through your normal workflow to use it for pull request reviews.
If both YAML filenames exist, resolve the duplicate before setup. Guided setup also refuses to replace a symbolic link, override a TypeScript-only configuration with YAML, or edit a file that delegates through remote_config; update the existing configuration source instead. To check a YAML file in your browser, use the interactive YAML validator.
Agent-guided setup
Use structured output to inspect configuration or prepare a Standard proposal without writing files:--agent returns the active configuration, whether it can be edited, and its content hash as baseHash. Adding --generate returns a validated proposal with before and after YAML. Supported profiles are chill, quiet, assertive, and default; default removes the explicit profile setting. These commands do not save the proposal.
Configuration discovery during local reviews
Without explicit--config files, local reviews look for .coderabbit.yaml, .coderabbit.yml, coderabbit.yaml, coderabbit.yml, then .coderabbit.config.ts, in that order. For each filename, the CLI checks the review directory before the Git repository root and uses the first readable match. YAML therefore takes precedence over TypeScript.
TypeScript discovery requires CLI 0.7.7 or later. Guided YAML setup does not evaluate or edit .coderabbit.config.ts. See the configuration overview for repository settings.
Continue local work in the cloud
Usecr code to start and follow cloud Coding Agent tasks from your terminal, hand off a local agent session to a new task, and upload local skills. See continue a local session in the cloud, import local skills, and Run Coding Agent tasks from the CLI.
Organization selection
For browser logins without SSO, the active CodeRabbit organization is the login/default org. It is used when the current repository resolves to that org, but it is not a silent billing fallback for unrelated local repositories. For SSO, see SSO workspace logins. During a local review, CodeRabbit resolves the current repository first:- If the repository matches the selected org, the review uses that org.
- If the repository matches a different org you can access, CodeRabbit switches attribution to that org.
- If the repository matches an installed public repo but you do not have access to the owning org, the review uses OSS behavior.
- If the repository cannot be matched to an installed accessible repo, the CLI falls back to limited/free review behavior until CodeRabbit is installed for that repo or org.
cr auth org requires an active browser-based login. If your local session is missing or expired, run cr auth login first, then run cr auth org again. Organization switching is not available for workspace-based SSO, self-hosted mode, or API key authentication.
SSO workspace logins
Starting with CLI 0.8.0, signing in through SSO binds review billing to your SSO workspace. You do not select a default organization, even if your account belongs to several organizations. Repository access and review configuration still depend on the repository being reviewed.cr auth org reports that reviews are billed to the SSO workspace and there is no organization to select. This is expected; no organization switch is needed.
cr auth status shows Billing: workspace ... (SSO) and Default: workspace/<username>. This output omits the Plan and Seat lines, so it does not confirm or deny a seat or mean that you are on the Free plan. Check seat assignment in the dashboard. Provider: GitHub names the Git provider and can appear after either SSO or GitHub OAuth login.
Older SSO login output
CLI versions before 0.8.0 can show an organization, plan, and seat after a genuine SSO login. That output alone does not mean you chose GitHub OAuth. To use workspace-based SSO, update the CLI and sign in again:brew upgrade coderabbit instead of cr update. For an EU-hosted account, use cr auth login --region eu. Choose your organization’s SSO option in the browser. After signing in, check for the workspace billing line in cr auth status.
Review modes
The CLI uses plain-text, human-readable output by default, with agent output and an optional deeper review also available:--deep is available in CLI 0.8.0 or later with a compatible CodeRabbit server. It uses the same review capability policy as GitHub Pull Request Reviews and keeps your existing CLI limits and billing. Repository settings, plan access, and available context still apply. It does not attach your changes to an existing pull request or fetch its description and discussions, so findings can differ. Self-hosted installations must update the server before using this flag. You can combine --deep with --agent.
The default plain-text mode displays a finding count and severity summary at the end of each run. No output flag is required. If the CLI detects a known agent environment, it suggests re-running with --agent for NDJSON output, which writes one JSON object per line.
Usage-based reviews and consent
When an organization sets usage-based reviews to the On demand continuation mode and the included review limit is reached, CodeRabbit shows the number of billable files and the maximum review price before starting paid work. See usage-based review pricing for rates. Only developers with an assigned seat can authorize them. This self-serve launch excludes Enterprise organizations. In an interactive terminal, confirm the price prompt to run that one review with usage credits. You can also give explicit consent when starting the review:coderabbit review command never creates a charge in on_demand mode without this confirmation.
In headless or agent mode, CodeRabbit never waits for or assumes confirmation. Instead, it returns a structured action_required result with status: "awaiting_confirmation", the billable file count, maximum price, confirmationHeadCommitId content identity, and the explicit coderabbit review --use-credits command. Automation can inspect that result and decide whether to start a new authorized review.
Diagnostics
Runcr doctor at any time to verify your local setup. The command checks:
- CLI runtime and version
- Local CodeRabbit storage directory
- Authentication state and auth environment
- Current Git repository and branch metadata
- Auto-update policy
- CodeRabbit backend reachability
- CodeRabbit WebSocket reachability
cr doctor exits with status code 1 when any check fails. Warnings appear in the report but do not cause a non-zero exit code.
Review statistics
Usecr stats to inspect your review statistics from local review history:
Check your usage
Runcr usage inside a repository to show available included reviews, the rolling quota window, and when capacity returns if the quota is exhausted. The report also shows your review count, usage-billing status, and, when available, spend and the reset date for the current billing period. cr review --usage and cr --usage are aliases that show the same report instead of starting a review.
Add --agent to any of these forms for structured output. Availability is a snapshot, not a reservation. If quota cannot be verified, the report marks it unavailable while retaining any successful billing result.
The usage command requires authentication and is not available for self-hosted logins.
Working with review results
CodeRabbit analyzes your code and surfaces specific issues with actionable suggestions. Each finding includes the problem location, explanation, and recommended fix. Example findings include:- Race condition detected: “This goroutine accesses shared state without proper locking”
- Memory leak potential: “Stream not closed in error path - consider using defer”
- Security vulnerability: “SQL query uses string concatenation - switch to parameterized queries”
- Logic error: “Function returns nil without checking error condition first”
Browse and apply suggestions
In plain mode, read each finding in the terminal output and apply the suggested change in your editor or coding agent. For simple issues like missing imports, syntax errors, or formatting problems, use the suggested fix directly. For larger changes, usecr review --agent so your coding agent can consume structured findings.
Use AI coding agents
For AI agent integration, see the AI agent integration section for detailed workflow guidance and integration guides.Replay stored findings
Runcr review findings to read results from the most recent local review that produced findings, without re-running the analysis. The command shows the most recent local session that contains findings for the current review directory, branch, and base branch. An empty review can still show a reminder about earlier findings; that reminder does not mean the latest review found new issues. Up to ten sessions are retained per scope, with no time-based expiry. Remote reviews do not store findings locally.
Clear stored findings
Clearing stored findings requires CLI 0.7.7 or later. Run
cr update to update.--clear dismisses findings from every retained session in the selected scope. Other repositories, branches, base branches, and review directories are unchanged. A review run with --dir src has a separate scope from a whole-repository review.
The command runs without a confirmation prompt and prints the review directory, current branch, and base branch it affected. Findings are dismissed, not deleted; incremental review state is preserved. Cleared findings stop appearing in both cr review findings and the zero-finding reminder. Repeating the command is safe, and future reviews can report new findings normally.
If some findings cannot be updated, the command reports the affected scope and counts, then exits with code 1. Successfully dismissed findings remain dismissed; retry after correcting the local storage permissions.
Inspect AI prompts
Runcr review --show-prompts to print the AI prompts saved from the most recent local review without triggering a new review. Useful for tuning --config instructions or understanding why the model flagged a particular finding. --show-prompts cannot be combined with --agent.
AI agent integration
CodeRabbit detects the problems, then your AI coding agent implements the fixes.Claude Code users: Claude Code now supports CodeRabbit through a native plugin. See the Claude Code integration guide for the recommended plugin-based setup using
/coderabbit:coderabbit-review instead of the CLI commands shown below.Integration guides
See detailed workflows for AI coding agents and workflows:CodeRabbit Skills
Run
coderabbit skills to install agent-native Skills and trigger reviews with an explicit request such as “Run a CodeRabbit review.”Claude Code integration
Automated workflow with background execution and task-based fixes
Codex integration
Integrated code review and fix implementation with Codex CLI
Cursor integration
Install the CodeRabbit plugin so Cursor Agent routes review requests to CodeRabbit
Headless CLI integration
Authenticate CodeRabbit non-interactively in GitHub Actions and other bot-driven automation
--agent output and the exit codes your agent should check, see agent mode output and exit codes.
Example prompt for your AI agent
Here’s a complete prompt you can use with Cursor, Codex, or other AI coding agents:Sample prompt
Components of a good prompt
Breaking down what makes an effective CodeRabbit + AI agent workflow:1. Run CodeRabbit CLI
1. Run CodeRabbit CLI
Tell your AI agent to run CodeRabbit with the You can also specify a review scope or base branch:
--agent flag:2. Run in the background
2. Run in the background
CodeRabbit reviews can take 7-30+ minutes depending on the scope of changes. Instruct your AI agent to run CodeRabbit in the background and set up a timer to check periodically:
Prompt
3. Evaluate and implement fixes
3. Evaluate and implement fixes
Once CodeRabbit completes, have your AI agent evaluate the findings and prioritize:This keeps your agent focused on meaningful improvements rather than minor style issues. If the
Prompt
complete event has status: "review_skipped", there were no file changes in scope.4. Verify with a second pass
4. Verify with a second pass
Run CodeRabbit one more time to ensure fixes didn’t introduce new issues:
Prompt
5. Set loop limits
5. Set loop limits
Prevent infinite iteration by setting clear completion criteria:This ensures your AI agent completes the task efficiently and provides a clear report.
Prompt
Pricing and capabilities
See the rate limits table on the Plans and pricing page for current per-plan limits. To increase the limits, consider upgrading your plan or using usage-based reviews.Free tier
Basic static analysis with limited daily usage. Catches syntax errors, logic issues, and security vulnerabilities. Eligible Free users may see an Advanced trial prompt after sign-in or when a CLI review reaches the rate limit.
Paid plans
Enhanced reviews powered by learnings from your CodeRabbit organization plus higher rate limits and more files per review. Paid users reviewing repositories connected to that organization get:
- Learnings-powered reviews: Remembers your team’s preferred patterns for error handling, state management, and architecture
- Full contextual analysis: Understands your imports, dependencies, and project structure
- Team standards enforcement: Applies your documented coding guidelines automatically
- Advanced issue detection: Spots subtle race conditions, performance bottlenecks, and security vulnerabilities
Usage-based reviews (pay-as-you-go)
Continues eligible CodeRabbit CLI reviews after rate limits
- Assigned-seat users use their plan allowance first
- Usage is billed only for eligible over-limit reviews
- Full control over usage and spending caps through the dashboard
- Usage-based billing — each over-limit file is added to your monthly invoice
CLI with usage-based reviews
Usage-based reviews let eligible CodeRabbit CLI reviews continue after the applicable review limit is reached. Authenticated CLI and agentic API-key reviews use the assigned user’s plan allowance first. Usage is billed only when a review continues over that limit. See usage-based review pricing for per-file rates. Usage is added to your monthly invoice. Enable pay-as-you-go and set a spending cap from the Subscription and Billing dashboard for US or EU. This self-serve launch excludes Enterprise organizations.1
Enable the add-on
Go to Subscription and Billing for US or EU, then open the Usage-based add-on tab to turn on pay-as-you-go and set a spending cap.For full setup details, see Manage your subscription.
2
3
Authenticate with your API key
You can pass For GitHub Actions and other non-interactive environments, see Headless CLI integration.
--api-key KEY to a review directly, but if you plan to make multiple calls, it is more convenient to authenticate once with your CodeRabbit API key:4
Run a CodeRabbit review
After logging in, prompt your agent to run a CodeRabbit CLI review without passing the API key again:If plan allowance is available, no usage is billed. If the review is rate-limited, usage-based reviews can continue the review only when pay-as-you-go is enabled, remaining spending capacity is available, and the review is attributed to an assigned-seat user.
Update the CLI
Runcr update for an installation made with the install script. For Homebrew installations, run brew upgrade coderabbit. See Windows updates for the native Windows installer.
On Linux, the install script and CLI 0.9.0 or later verify a signed release manifest before installing a stable release. A failed check leaves the installed CLI unchanged. Updating an older CLI to 0.9.0 uses that older updater; signed-manifest verification starts with subsequent updates.
The Linux install script requires openssl and a release with a signed manifest, available from 0.9.0. Set CODERABBIT_VERSION to a plain X.Y.Z version without a leading v. A mirror configured through CODERABBIT_DOWNLOAD_URL must also serve SHA256SUMS.sig and VERSION alongside the archives and checksums.
CLI 0.9.0 fixes access-token refresh for GitLab, Bitbucket, and Azure DevOps. If authentication errors continue after updating, run cr auth login again.
Shell completion
With CLI 0.9.0 or later,cr completion <shell> prints a completion script for bash, zsh, fish, or powershell. The script completes commands and options for both coderabbit and cr. It also completes the IDs of the tasks that this computer listed or opened with cr code, and file names for options and arguments that take a path. A Tab press makes no network call.
To turn on completion, add the line for your shell to its startup file:
bash-completion package, and it works with Bash 3.2.
Command reference
See the CLI Command Reference for command and option details, and agent mode output and exit codes for machine-readable output.Uninstall
Remove CodeRabbit CLI based on how you installed it.If installed using install script
If installed using Homebrew