Qodo
Also known as: CodiumAI, PR-Agent
AI code review and governance platform, formerly CodiumAI: parallel specialist review agents with a judge agent, a Context Engine that indexes the codebase and PR history, Rule Miner that turns accepted review patterns into rules, and an Agentic Toolbox that brings Qodo's skills into Claude Code, Codex and Kiro.
Qodo, formerly CodiumAI, is an AI code review and governance platform. It sits outside the code generation loop and checks changes whichever assistant wrote them, reviewing pull requests on GitHub, GitLab, Bitbucket and Azure DevOps and reviewing changes before a pull request through IDE and pre-PR skills.
Review is split across specialist agents for logic and bugs, standards, architecture and risk that run in parallel, and a judge agent consolidates their findings, removes duplicates and filters by confidence. A finding recommendation agent ranks each issue against how the team handled similar findings before, so feedback the team usually ignores is marked as such.
The Context Engine is the knowledge layer behind every agent: it indexes the codebase to reason across modules and services, and PR history indexing, in beta for GitHub and GitLab, keeps a running record of past review decisions. Rule Miner mines accepted review patterns into rules scoped to an organization, repository or path, which activate directly or wait for an admin to approve, and fade when their suggestions keep being dismissed.
The Agentic Toolbox packages Qodo's skills (Get Rules, Reviewer, Review Resolver, Manage Standards, Codebase Wisdom) for other coding agents, with plugins for Claude Code, Codex and Kiro and connections over MCP or APIs. Deployment runs from multi-tenant and single-tenant SaaS to on-premises and air-gapped, with SOC 2 listed on the trust center and SSO, audit logs and bring your own key on Enterprise. The original PR-Agent project continues as open source under community governance, separate from the commercial platform.
Vendor details
Canonical URL
https://www.qodo.ai/
Category
Coding agent
Funding status
Independent. Founded 2022 as CodiumAI, rebranded to Qodo. Early investors include TLV Partners. Built its reputation on the open source PR-Agent, which it donated to community governance under Apache 2.0 in early 2026, now maintained independently as a legacy project distinct from the commercial platform.
Company status
independent
Use cases & customers
Target customers
Deployment options
Integrations
Git platform integrations cover GitHub, GitLab, Bitbucket and Azure DevOps for automated pull request review, with the open source PR-Agent extending to CodeCommit and Gitea. IDE plugins for VS Code and JetBrains add code generation, chat, test generation via /test and shift-left pre-commit local audits. Qodo Command installs as @qodo/command, exposing agents as scriptable CLI and HTTP workflows for pre-commit hooks and CI gates. Slash commands including /describe and /add_docs invoke capabilities from PR comments, and Enterprise bring-your-own-key supports OpenAI, Anthropic, Azure OpenAI or self-hosted models.
In practice
Your team writes more code with Copilot and Claude Code than anyone can review. Qodo reviews every pull request with parallel specialist agents and a judge that filters to the findings worth acting on, independent of whichever tool wrote the code.
Review comments keep repeating the same conventions. Rule Miner turns the patterns your team keeps accepting into rules scoped to the repository or path, so they are enforced on the next review without anyone writing them down.
You're in a regulated industry and code can't leave your network. Qodo deploys single-tenant, on-premises or air-gapped, with bring your own key on Enterprise.
Sources & related URLs
Related / legacy domains
Agentic Index coverage score
12.0 / 14 capabilities · 86%
| Integrations & Tool Calling | Full |
|---|---|
|
Git platform integrations cover GitHub, GitLab, Bitbucket and Azure DevOps, with the open source PR-Agent adding CodeCommit and Gitea, IDE plugins for VS Code and JetBrains, and a CLI installable as @qodo/command exposing agents as scriptable CLI and HTTP workflows for pre commit hooks and CI pipelines; slash commands including /describe, /add_docs and /test invoke capabilities from PR comments. Sourceqodo.ai and docs.pr-agent.airead 2026-08-30 |
|
| Workflow Orchestration | Full |
|
Review is split across specialist agents for logic and bugs, standards, architecture and risk that run in parallel with dedicated context, and a judge agent consolidates their findings, removes duplicates, resolves conflicts and filters by confidence; a finding recommendation agent then ranks each issue against PR history. Custom agentic quality workflows are available on Enterprise. Sourcedocs.qodo.ai/core-concepts/qodo-platform-core-capabilities and qodo.ai/pricingread 2026-09-29 |
|
| Knowledge Grounding & RAG | Full |
|
The Context Engine is the platform's knowledge layer and indexes and reasons over the customer's codebases, detecting cross-module issues and dependencies across services. PR history indexing, in beta for GitHub and GitLab, indexes each connected repository's pull request history in the background and keeps it current incrementally as pull requests merge, so every finding is classified against how similar issues were handled before. Both are maintained retrieval structures over the customer's knowledge. Sourcedocs.qodo.ai/core-concepts/context-engine, /core-concepts/pr-history and /core-concepts/qodo-platform-core-capabilitiesread 2026-09-29 |
|
| Human Oversight & Guardrails | Partial |
|
Output is advisory: reviews land as prioritized findings and suggested changes on a pull request that a human accepts or rejects, and the vendor's stated position is that sitting outside the generation loop lets it check code independently rather than approving its own work. A Review Standards system and PR linting templates let teams encode the rules agents apply, and Enterprise adds governance analytics; no per action approval gate or runtime guardrail is documented, since the agent does not act autonomously on the codebase. Sourceqodo.ai and qodo.ai/solutions/enterpriseread 2026-08-30 |
|
| Security, Identity & Governance | Full |
|
trust.qodo.ai lists SOC 2 under Certifications, without stating Type I or Type II, and the enterprise page says Qodo is SOC 2 compliant and encrypts all data in transit. The access surface is documented: SSO and SAML, roles and permissions, invite-only access, restricting reviews to registered users, API key management and scoped context access, with audit logs on Enterprise. Sourcetrust.qodo.ai, docs.qodo.ai/account-management and qodo.ai/solutions/enterpriseread 2026-09-29 |
|
| Observability & Auditability | Partial |
|
Each finding lands on the pull request with an explanation, the relevant snippet, quality labels, evidence and reasoning and suggested remediation, resolved findings can be tracked, and Enterprise lists audit logs and governance analytics on the pricing page; the enterprise page claims full auditability. None of these is a documented per step or per tool call record of what the review agents did: the findings are the output, and the audit log is named without saying what it records. Sourcedocs.qodo.ai/core-concepts/qodo-platform-core-capabilities, qodo.ai/pricing and qodo.ai/solutions/enterpriseread 2026-09-29 |
|
| Memory & State Persistence | Full |
|
Rule Miner mines the organization's pull request history for recurring accepted review patterns and writes rules from them, scoped to the organization, repository or the paths they govern. Generated rules either activate directly or wait in a Pending rules tab for an admin to accept; rules can be edited, activated or removed afterwards; and once a rule is active, dismissed suggestions it generates reduce its signal over time so noise fades on its own. These rules persist because the system retained what it learned, not because a person wrote them, which is what separates them from instructions. Sourcedocs.qodo.ai/governance/rule-enforcement/rule-minerread 2026-09-29 |
|
| Deployment & Data Residency | Full |
|
Deployment spans SaaS, single tenant SaaS, VPC, on premises and fully air gapped environments so code never leaves the customer's infrastructure, with zero data retention where code is analyzed and discarded, no training on customer code, and 48 hour data deletion across storage systems for Teams and Enterprise; PR-Agent can be self hosted with the team's own model keys. Sourceqodo.ai and qodo.ai/solutions/enterpriseread 2026-08-30 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Ready-made capability ships in two named sets: the specialist review agents (logic and bugs, standards, architecture, risk, a judge agent and a finding recommendation agent) run out of the box, and the Agentic Toolbox packages ready-made skills (Get Rules, Reviewer, Review Resolver, Manage Standards, Codebase Wisdom) that install into Claude Code, Codex and Kiro as plugins or connect over MCP. Sourcedocs.qodo.ai/agentic-toolbox/agentic-toolbox-overview and /core-concepts/qodo-platform-core-capabilitiesread 2026-09-29 |
|
| Triggers & Channel Coverage | Full |
|
Reviews fire automatically on pull request events across GitHub, GitLab, Bitbucket and Azure DevOps, with the open source PR-Agent extending coverage to CodeCommit and Gitea; slash commands including /describe, /add_docs and /test are invoked from PR comments, the IDE plugin for VS Code and JetBrains runs shift left pre commit local audits on uncommitted changes, and the CLI runs in pre commit hooks and CI gates. Sourceqodo.ai and docs.pr-agent.airead 2026-08-30 |
|
| Model Flexibility & Routing | Full |
|
Bring your own key is an Enterprise feature on the pricing page, so the customer supplies its own model provider. The current pages name BYOK but not the providers it covers; earlier vendor pages listed BYOK across OpenAI, Anthropic, Azure OpenAI or self-hosted models, and premium model choices such as Claude Opus and Grok on credit tiers. Sourceqodo.ai/pricingread 2026-09-29 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
Other systems call Qodo through the Agentic Toolbox, which connects coding agents, CI/CD pipelines, internal tools and custom applications over MCP or APIs, installs from a CLI, and ships as plugins for Claude Code, Codex and Kiro; API keys are managed in the account settings, and repository behavior is configurable through a.pr_agent.toml file. PR-Agent remains open source under community governance, separate from the commercial platform. Sourcedocs.qodo.ai/agentic-toolbox/mcp, /agentic-toolbox/cli and /account-management/manage-api-keysread 2026-09-29 |
|
| Testing, Debugging & Optimization | Full |
|
Reviewing the customer's change is the product the buyer purchases: Qodo describes itself as an AI code review and governance platform, runs specialist review agents on every pull request and before it through pre-PR review skills, and classifies each finding against the repository's history. A review product that measures the customer's own changes is Full here. Test generation and Qodo Cover do not appear on the current pages. Sourcedocs.qodo.ai/core-concepts/qodo-platform-core-capabilities and qodo.ai/pricingread 2026-09-29 |
|
| Browser & Computer Use | Not documented |
|
The platform operates on repositories, pull requests and the IDE through git platform APIs and plugins; no browser control or capability to operate software lacking a programmatic interface is documented on any first party page. Sourceqodo.airead 2026-08-30 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Qodo 3.0 added PR Triage in research preview, one queue that pulls open pull requests from GitHub, GitLab, Bitbucket and Azure DevOps and orders them by policies for deadlines, priority, blast radius and inactivity. Each pull request shows its next action and how it relates to others across repositories.
Bears on: Workflow orchestration
View sourceQodo launched an Advanced Configurations release that allows engineering teams to control how AI-generated code review findings are grouped, ordered, labeled, and routed into pull requests.
Bears on: Workflow orchestration
View sourceQodo 2.4 removed most of its repo-wide RAG indexing layer for code review, replacing it with an agent-driven fetch-on-demand loop plus long-term memory over PR history. The agent now rediscovers code context itself via git and grep, while retrieval is reserved for team-specific review decisions, repeated feedback, and conventions that cannot be recovered from the working tree. Qodo reports the leaner architecture leads on its review benchmarks with a fraction of the indexing infrastructure.
Bears on: Memory / state
View sourcePricing
14-day free trial; Pro Team is credit based at $0.012 a credit pooled across the team, in packs of 2,500 (about 18 reviews a month), 5,000 or 20,000 credits, up to 30 users, no annual commitment; Enterprise custom
hybrid
Included quota
Developer (free): 30 PR reviews/mo (org pool, reduced from 75) + 250 IDE/CLI credits/mo, IDE plugin, CLI, community support. Teams ($30/user/mo annual): 2,500 IDE/CLI credits/user/mo (10x free), agentic PR review (20 PRs/user/mo standard - currently unlimited as a limited-time promo), Living Rules System, Git + IDE integrations, governance dashboard, standard support, up to ~30 users. Enterprise (custom): SSO/SAML, audit logs, governance analytics, BYOK, single-tenant SaaS or on-prem/air-gapped, multi-repo Context Engine, priority support + SLA.
What is public
The pricing page lists a 14-day free trial with unlimited reviews and credits; Pro Team priced at $0.012 a credit pooled across the team, in packs of 2,500 credits (about 18 reviews a month), 5,000 (about 36) and 20,000 (about 144), for up to 30 users with unlimited repositories, no rate limits and no annual commitment; and a custom Enterprise tier adding SSO and SAML, audit logs, governance analytics, advanced self-learning, BYOK, single-tenant SaaS or on-prem and priority support. The free Developer tier and the per-seat Teams price are no longer listed.
Billing mechanics
Credit based: reviews and IDE or CLI use draw on a credit pool shared across the team at $0.012 a credit, bought in monthly packs that can be switched at any time. Enterprise is contracted.
Cost watchouts
Credits are pooled and review size drives consumption, so the reviews-per-pack figures are estimates; Pro Team caps at 30 users.
Variable cost rationale
Hybrid - a fixed per-seat base plus usage that scales with credit consumption (model choice matters: Opus 5x a standard request) and PR-review volume; the spending cap bounds overage, and PR-Agent self-host removes per-credit cost for teams with DevOps capacity
Additional watchouts
Cost now scales with review volume rather than seats: a 2,500 credit pack is about 18 reviews a month for the whole team, so busy repositories need the larger packs. Audit logs, BYOK and single-tenant or on-prem deployment are Enterprise only.
Overage / add-ons
When base credits are depleted, reviews/usage keep running and you enter overage at the SAME per-credit rate as your plan (no premium, no penalty), accruing against a monthly spending cap you set and can change anytime; you're notified before hitting the cap. Credits reset monthly with no rollover; PR-review pools are per-plan.
Sales call required
Mixed (some tiers require a call)
Free / trial
14-day free trial, no credit card, unlimited reviews and credits
Lowest paid plan
Pro Team, 2,500 credits at $0.012 a credit
Commercial notes
Formerly CodiumAI. Now positioned as an AI code review and governance platform; pricing moved from per seat with a free Developer tier to a trial plus pooled credits.
Key ambiguities
Credits per review vary with the size of the change, so the cost per review (about 18 reviews a month on a 2,500-credit pack) is an estimate, and Enterprise pricing is custom.
Cancellation / refund
Free Developer plan (no card, free forever with limits); 14-day trial unlocks unlimited reviews + credits; Teams self-serve monthly or annual (annual 21% cheaper); Enterprise custom (annual contract); switch/upgrade/downgrade credit packs from the dashboard (effective next cycle); qualified OSS projects free via Qodo for Open Source
Support SLA / resale
Community support (Developer); standard support on Teams (docs, in-product help, ticket); Enterprise adds priority response, dedicated SLA, and an assigned Qodo account contact; BYOK on Enterprise; single-tenant SaaS or on-prem/air-gapped deployment; PR-Agent OSS self-host (Docker, your own LLM keys); no training on your code
Missing data
Credits per review vary with the change, so the per-review cost is an estimate; Enterprise pricing is custom.
Related vendors
- Cognition — Maker of Devin, an autonomous AI software engineer
- 10Web — Agentic website platform whose specialized AI agents build, host,…
- AgentUI — Managed AI app builder for operations teams that generates and hosts…
- Aider — Open source, model agnostic terminal coding agent that edits your…
- Anthropic Claude Code — Anthropic's agentic coding system across terminal, desktop, IDE, web…
- AppFactor — Agentic platform that runs persistent agents across an enterprise…
Alternatives to Qodo
The closest documented capability profiles to Qodo among coding agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Greptile11.0 / 14A lighter documented profile than QodoQodo vs Greptile →
- Potpie AI10.5 / 14A lighter documented profile than Qodo
- Sonar10.5 / 14A lighter documented profile than QodoQodo vs Sonar →
- Augment Code12.0 / 14Fuller documented coverage on Human Oversight & Guardrails and Observability & Auditability
- CodeRabbit11.0 / 14Fuller documented coverage on Human Oversight & GuardrailsQodo vs CodeRabbit →
- Kilo Code13.0 / 14Adds documented Browser & Computer Use
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded