Skip to main content

prxref

Fast automated AI code review for Bitbucket, GitLab, and GitHub.

prxref inspects pull and merge requests across the three major code hosting forges in sub-minute review cycles. It parses unified diffs, partitions changes into risk-ranked chunks, fans out parallel single-shot LLM reviews across a cheap-first model fallback chain, filters findings through deterministic quality gates, and publishes inline comments alongside an executive summary.

                  ┌──────────────────────┐
                  │    Pull / MR URL     │
                  └──────────┬───────────┘
                             │
                             ▼
                  ┌──────────────────────┐
                  │     detect_forge     │
                  └──────────┬───────────┘
                             │
                             ▼
                  ┌──────────────────────┐
                  │    Forge Adapter     │
                  │ (BB / GitHub / GL)   │
                  └──────────┬───────────┘
                             │
                             ▼
                  ┌──────────────────────┐
                  │     Unified Diff     │
                  └──────────┬───────────┘
                             │
                             ▼
                  ┌──────────────────────┐
                  │ Risk-Ranked Chunking │
                  └──────────┬───────────┘
                             │
                             ▼
                  ┌──────────────────────┐
                  │ Parallel LLM Workers │
                  │  (Fallback Chain)    │
                  └──────────┬───────────┘
                             │
                             ▼
                  ┌──────────────────────┐
                  │     Quality Gate     │
                  │ Line Align / Dedup   │
                  └──────────┬───────────┘
                             │
                             ▼
                  ┌──────────────────────┐
                  │ Post Inline Comments │
                  │     + Summary        │
                  └──────────────────────┘

Quickstart

Run reviews instantly without local installation using uvx, or install the CLI globally:

# Run one-shot review via uvx
uvx prxref review --pr-url https://github.com/org/repo/pull/123

# Or install tool globally
uv tool install prxref
prxref review --pr-url https://github.com/org/repo/pull/123

# Or install straight from source (works before the first PyPI release)
uv tool install git+https://github.com/sblattj/prxref

Review Any Forge

Pass any PR or MR URL directly. Forge type, repository namespace, and pull request ID are detected automatically:

# Bitbucket Cloud
prxref review --pr-url https://bitbucket.org/workspace/repo/pull-requests/42

# GitHub & GitHub Enterprise
prxref review --pr-url https://github.com/owner/repository/pull/108

# GitLab & Self-Hosted GitLab (including nested subgroups)
prxref review --pr-url https://gitlab.com/group/subgroup/project/-/merge_requests/15

Supported hosts. GitHub Enterprise Server and self-hosted GitLab are supported on any host — their self-hosted products speak the same REST API as their SaaS ones. Bitbucket is Cloud only: a Bitbucket Server / Data Center URL is rejected on the host check inside parse_pr_url, before any credential is read, so a wrong token is never the explanation. Server exposes a different API (/rest/api/1.0) from Cloud's v2, which makes this a missing adapter rather than a base-URL setting. See docs/forges.md.

LLM Configuration

prxref operates without direct cloud provider SDK keys (no Anthropic API keys). It ships with no default endpoint and no default model chain: point it at any OpenAI-compatible /chat/completions server (OpenRouter, Together, Groq, vLLM, Ollama, a self-hosted gateway), or install the optional litellm extra. PRXREF_LLM_BASE_URL and PRXREF_LLM_MODELS are required — leaving either unset exits 2 with an error naming the variable.

# Default backend: plain HTTP to any OpenAI-compatible endpoint
export PRXREF_LLM_BACKEND=openai-compat        # aliases: ferry, http
export PRXREF_LLM_BASE_URL="https://openrouter.ai/api/v1"
export PRXREF_LLM_API_KEY="$OPENROUTER_API_KEY"
export PRXREF_LLM_MODELS="z-ai/glm-5.3-flash"
export PRXREF_LLM_REASONING_EFFORT=low
export PRXREF_LLM_MAX_TOKENS=4096              # raise this if you raise the effort

# Optional: in-process litellm extra
# pip install 'prxref[litellm]'
export PRXREF_LLM_BACKEND=litellm
export PRXREF_LLM_MODELS="openrouter/meta-llama/llama-3.3-70b-instruct,bedrock/anthropic.claude-3-7-sonnet-20250219-v1:0"

On a reasoning model the hidden reasoning trace draws from the same completion budget as the answer, so turning PRXREF_LLM_REASONING_EFFORT up makes truncation more likely. A truncated chunk is counted as failed and the posted summary names the reason and the variable to raise; see Reasoning models and the token budget.

See docs/llm.md for architecture, failover behavior, and backend setup, and docs/env-vars.md for tuning the confidence floor and finding caps to your team.

Forge Authentication

Configure the authentication token matching your forge:

Forge Environment Variable Notes
Bitbucket PRXREF_BITBUCKET_TOKEN Bearer token (workspace or repo access token)
Bitbucket (Basic) PRXREF_BITBUCKET_USER + PRXREF_BITBUCKET_APP_PASSWORD App password fallback
GitHub PRXREF_GITHUB_TOKEN Personal Access Token (PAT) or GitHub App token
GitHub Enterprise PRXREF_GITHUB_ENTERPRISE_TOKEN Used when host is not github.com (falls back to PRXREF_GITHUB_TOKEN)
GitLab PRXREF_GITLAB_TOKEN Personal, project, or group access token (PRIVATE-TOKEN)

See docs/env-vars.md for the full configuration reference and docs/forges.md for forge specifics.

Webhook Server

Run prxref as a persistent daemon to handle webhook events from GitHub, Bitbucket, and GitLab:

prxref serve --port 8080 --host 0.0.0.0

The service exposes:

  • POST /webhook — verifies HMAC or token signatures per forge, enqueues incoming PR events, and responds immediately with 202 Accepted. A background worker processes reviews serially.
  • GET /health — liveness probe returning {"ok": true}.

CLI Flags

  • --pr-url URL — full web URL of the PR or MR (required for review).
  • --no-post — dry run; run review analysis and quality passes without writing comments to the forge.
  • --max-chunks N — override maximum diff chunks evaluated (default 8).
  • -v, --verbose — output run timing, token counts, and finding breakdowns to stdout.

Exit Codes

prxref is an advisor, never a gate. Its exit code says whether prxref was configured correctly, not whether your code is good.

Code Meaning
0 The run finished — including every review error: an empty diff, a network failure, an LLM timeout, bad forge credentials, an unrecognized URL, or a review in which every chunk failed. Diagnostics go to stderr; the pipeline step stays green.
2 Usage or configuration error — no subcommand, invalid command-line arguments, or a required value missing, malformed, or outside its valid range. The message names the source that supplied it: the environment variable, or the CLI flag when a flag is what you typed.
$ prxref review --pr-url https://github.com/org/repo/pull/1 --max-chunks 0
configuration error: --max-chunks: must be a finite number greater than 0, got 0

There is deliberately no PRXREF_FAIL_ON. Failing a build on a finding would turn a probabilistic reviewer into a merge gate, and the first false positive teaches a team to bypass the gate. Read the verdict from the posted summary, which also carries a partial-review banner when some chunks did not make it. Do not build a security control on the exit code.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

prxref-0.3.0.tar.gz (120.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

prxref-0.3.0-py3-none-any.whl (60.2 kB view details)

Uploaded Python 3

File details

Details for the file prxref-0.3.0.tar.gz.

File metadata

  • Download URL: prxref-0.3.0.tar.gz
  • Upload date:
  • Size: 120.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for prxref-0.3.0.tar.gz
Algorithm Hash digest
SHA256 59eeeb860742b18f2cb5357caf8968be4f1c61fe738cbfe89a4738ba3a982078
MD5 17ad024d3954141929bfa9e713de2e6c
BLAKE2b-256 382c2cf933dec57080a5589876ae676bcaeb143ff3eb265321fc9150f96dc9ec

See more details on using hashes here.

Provenance

The following attestation bundles were made for prxref-0.3.0.tar.gz:

Publisher: release.yml on sblattj/prxref

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file prxref-0.3.0-py3-none-any.whl.

File metadata

  • Download URL: prxref-0.3.0-py3-none-any.whl
  • Upload date:
  • Size: 60.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for prxref-0.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 9890d48a2e7939ad0bb9d455765f0c00a17b170a270ee36d71bf7be23eee0b4f
MD5 b2008ad2d0c5a74a97236372fa861676
BLAKE2b-256 ea56093ba7b76eaada6bcff9be398b7f77002a34abdfec5f3040a623b9955126

See more details on using hashes here.

Provenance

The following attestation bundles were made for prxref-0.3.0-py3-none-any.whl:

Publisher: release.yml on sblattj/prxref

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.12.1

2 files

0.12.0

2 files

0.11.1

2 files

0.11.0

2 files

0.10.1

2 files

0.10.0

2 files

0.9.1

2 files

0.9.0

2 files

0.8.0

2 files

0.7.0

2 files

0.6.0

2 files

0.5.0

2 files

0.4.0

2 files

This release

0.3.0 This release

2 files

0.2.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page