Codna
Understand. Fix. Evolve.
Agents read your code. Codna understands it.
Codna maps a repository before it spends a token. It then reviews pull requests, fixes bugs and
proves which scanner findings are reachable. The same codna command runs on your machine, in the
GitHub Action and behind the GitHub App.
Runs on your machine or your cloud. Your code never leaves without your key.
Install
pip install codna # or: pipx install codna · uv tool install codna
codna --version
Python 3.12–3.13. Wheels for macOS on Apple silicon and Linux x86_64. git on your PATH.
Nothing else to install: no Node, Bun, Docker or server. The agent runtime ships inside the wheel.
Local commands need no Codna key. fix and review use your own model provider key, stored in
the OS keychain and never printed:
codna key set anthropic # also: openai, gemini, google, groq, mistral, openrouter, xai, cursor
Commands
codna triage . --issue "checkout total is wrong" # suspect files. Deterministic. 0 LLM tokens.
codna review . --pr 123 --post # findings with a verdict on the pull request
codna fix . --tests --apply --max-iterations 3 # patch, re-run your tests, re-fix until green
codna fix <git url> --ref <sha> --issue "…" --open-pr # push a branch and open a pull request
codna secure . --from-sarif results.sarif # which scanner findings are reachable. 0 LLM tokens.
codna fix prints the root cause, the impacted symbols, the blast radius, its confidence and a
regression risk. --open-pr needs a git URL and a GitHub write token. codna review posts one
inline comment per finding with severity, category and a suggestion block, and an Approve when the
diff is clean at medium and high. codna secure reads SARIF 2.1.0 from CodeQL, Semgrep, Snyk,
Trivy or any other scanner.
Other commands: init, status, doctor, login, key, impact, memory export, report.
Full reference: docs.codna.ai/reference/cli.
MCP server
Run Codna as a Model Context Protocol server over stdio — the same engine the CLI uses, inside Cursor, Claude Desktop, or your own agent:
pipx install "codna[mcp]" # or: pip install "codna[mcp]"
codna mcp # serve over stdio
codna mcp install --client cursor # optional: write the client config for you (or --client claude)
Five tools, each returning JSON; a failure comes back as codna_<tool> error: … text and never
crashes the server:
| Tool | What it does | Key needed |
|---|---|---|
codna_triage |
Understand a repo and locate the code relevant to an issue. Deterministic, 0 LLM tokens. | none |
codna_secure |
Prove which SARIF scanner findings (CodeQL, Semgrep, Snyk, Trivy) are reachable. Read-only, 0 LLM tokens. | none |
codna_recall |
Recall code from local on-device memory — semantic + lexical search, fully offline. | none |
codna_fix |
Root-cause and plan a fix (read-only by default); with open_pr=true pushes a branch and opens a real PR. |
provider key (+ GITHUB_TOKEN for open_pr=true) |
codna_report_bug |
File a bug, feature, or question to thyn-ai/feedback. | GITHUB_TOKEN (else returns a pre-filled URL) |
3 of 5 tools need no key at all — codna_triage, codna_secure and codna_recall run with
zero credentials and zero network calls. Full reference:
docs.codna.ai/guides/mcp.
Code memory
Code memory and recall run on your machine with no login and no extra install. The optional
codna[memory] extra adds the on-device semantic reranker; without it, recall ranks lexically.
What leaves your machine
- Repository mapping, triage, recall and
impactrun offline. No model is involved. fixandreviewsend one issue-specific evidence bundle to the provider you chose, under your key. Not the repository.- Secret redaction is always on and cannot be turned off.
privacy.egress: fail-closedincodna.yamlrefuses to run tests without network denial and skips registry lookups during review.- Source distributions exclude runtime binaries, keys,
.envfiles and logs.
Links
- Homepage: https://codna.ai
- Documentation: https://docs.codna.ai
- Source: https://github.com/thyn-ai/codna
- Security: https://codna.ai/security
Release files for codna 0.2.83
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| codna-0.2.83.tar.gz | 3.9 MB | Details |
Built distributions (wheels)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| codna-0.2.83-py3-none-manylinux_2_28_x86_64.whl | Python 3 | none | Linux glibc 2.28+ x86-64 | Details |
| codna-0.2.83-py3-none-macosx_14_0_arm64.whl | Python 3 | none | macOS 14.0+ ARM64 | Details |
Total release size: 97.8 MB
Release files / codna-0.2.83.tar.gz
| Download URL | codna-0.2.83.tar.gz |
|---|---|
| Size | 3.9 MB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
eee031a2273b1bb5315bdd1d4ecd5178f0dfbce316724aeba384e9dbdafab0ff
|
|
BLAKE2b-256 checksum How to use checksums |
d54b583db1ddcf80a55e31cb360a6b231b2c71233f817e77a4825378a36a9318
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.7
|
Release files / codna-0.2.83-py3-none-manylinux_2_28_x86_64.whl
| Download URL | codna-0.2.83-py3-none-manylinux_2_28_x86_64.whl |
|---|---|
| Size | 64.2 MB |
| Tags | Linux glibc 2.28+ x86-64 Python 3 |
|
SHA-256 checksum How to use checksums |
debe3fb996d47bd4c04c854c84bf4f68a17daa2dfc236c811fb7317ae319d5ab
|
|
BLAKE2b-256 checksum How to use checksums |
2a9bd9b83948018c495cbbe3aef12fcc64fc3aa8d0785583d83b6b14e7c6e35b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.7
|
Release files / codna-0.2.83-py3-none-macosx_14_0_arm64.whl
| Download URL | codna-0.2.83-py3-none-macosx_14_0_arm64.whl |
|---|---|
| Size | 29.7 MB |
| Tags | Python 3 macOS 14.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
f45defce4eadb1f4312f1251a5b24e3051febf4f4151f662f08b6aef98d3c3ed
|
|
BLAKE2b-256 checksum How to use checksums |
7a44d35277f3ace0a0caa55df7217e76beec13fa45c83abda19dd77d6381ddaa
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.7
|