Guide

Claude Code in GitHub Actions and pull request review: setup, @claude, and cost

Three ways to get Claude reviewing pull requests: the free GitHub Action, Anthropic's managed Code Review, and /code-review from your terminal. Setup, cost and the security catch.

To use Claude Code in GitHub, run /install-github-app inside Claude Code in your repository: it installs the Claude GitHub App, saves your API key (or a Claude subscription token) as a repository secret, and opens a pull request with a workflow file. Once that's merged, anyone with write access can mention @claude in an issue or pull request and Claude answers, reviews or pushes a fix to a branch. The action, anthropics/claude-code-action@v1, is free; you pay for the tokens on your Anthropic key and the GitHub Actions minutes. Team and Enterprise organizations can instead switch on Anthropic's managed Code Review, which averages $15 to $25 a review.

Key takeaways

  • Setup: /install-github-app needs repository admin and the gh CLI; manual setup is three steps.
  • Two modes: answer @claude in comments, or run a fixed prompt on any event, such as every pull request or a nightly schedule.
  • Cost: API tokens (or your Claude plan's usage with an OAuth token) plus Actions minutes.
  • Managed Code Review: a fleet of agents on Anthropic's machines; Team and Enterprise, research preview since March 2026, billed as usage credits.
  • From the terminal: /code-review reviews a branch or pull request, and /code-review ultra runs a verified multi-agent review in the cloud.
Ways to get Claude reviewing GitHub pull requests, from Anthropic's docs, October 7, 2026.
Claude Code GitHub ActionManaged Code Review/code-review ultra
Runs onYour GitHub Actions runnersAnthropic's infrastructureAnthropic's cloud sandbox
PlansAny API key, or Pro and up with a tokenTeam and EnterpriseClaude accounts (not API keys)
Triggered by@claude, or any workflow eventPR opened, every push, or @claude reviewYou, from Claude Code
CostAPI tokens or plan usage, plus Actions minutesAbout $15 to $25 a review, usage credits3 free runs, then about $5 to $25
Can push fixesYes, to a branchNo; comments onlyNo; findings, with an option to post

How do you set up Claude Code GitHub Actions?

Quick setup (Anthropic): open Claude Code in the repository and run /install-github-app. You need admin rights on the repository and the GitHub CLI signed in. It:

  1. Installs the Claude GitHub App.
  2. Saves ANTHROPIC_API_KEY, or CLAUDE_CODE_OAUTH_TOKEN if you choose to use your Claude subscription, as a repository secret.
  3. Opens a pull request adding claude.yml and, if you want automatic reviews, claude-code-review.yml. Merge it and @claude works.

Manual setup: install the app from github.com/apps/claude, add the secret (a Console API key, or a token from claude setup-token on Pro, Max, Team or Enterprise), and copy the example workflow from the action's repository. For an organization, Anthropic recommends an API key over a personal subscription token. Bedrock, Google Cloud and Microsoft Foundry work through OIDC.

What does the workflow look like?

A minimal .github/workflows/claude.yml, from Anthropic's docs:

on:
  issue_comment:
    types: [created]
  pull_request_review_comment:
    types: [created]
jobs:
  claude:
    if: contains(github.event.comment.body, '@claude')
    runs-on: ubuntu-latest
    permissions:
      contents: write
      pull-requests: write
      issues: write
      id-token: write
      actions: read
    steps:
      - uses: actions/checkout@v6
      - uses: anthropics/claude-code-action@v1
        with:
          anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}

With no prompt, Claude waits for @claude in issue and pull request comments and replies in a comment it updates as it works. Add a prompt (plain text or a skill) to run on its own, for example a review on every pull request. Other useful inputs: claude_args passes any CLI flag, such as --max-turns; trigger_phrase changes @claude; track_progress shows a progress comment (action inputs). By default Claude pushes to a branch and gives you a link to open the pull request, rather than opening it itself.

How much does Claude Code in GitHub Actions cost?

Two meters, according to Anthropic:

  • GitHub Actions minutes: the job runs on GitHub-hosted runners, "which consume your GitHub Actions minutes."
  • Tokens: billed to your Anthropic API key at API rates. "If you authenticate with an OAuth token, runs use your Claude subscription instead of API billing."

To keep it down: write specific @claude requests, keep CLAUDE.md short (it's read on every run), set --max-turns in claude_args, add a workflow timeout, and use GitHub's concurrency controls to stop duplicate runs.

What is Claude Code Review?

Anthropic's managed reviewer, in research preview since March 9, 2026 for Team and Enterprise (Anthropic). An owner switches it on in Claude Code's admin settings, installs the GitHub App and picks repositories. Then:

  • When it runs: once when a pull request opens, after every push, or only when someone comments @claude review (@claude review always subscribes the pull request to later pushes).
  • What it does: several agents look for logic errors, security bugs, edge cases and regressions on Anthropic's infrastructure; a verification pass filters them; findings arrive as inline comments marked Important, Nit or Pre-existing. It reads CLAUDE.md and REVIEW.md, takes about 20 minutes, and never blocks a merge.
  • Cost: "Each review averages $15-25 in cost," billed as usage credits separate from plan usage, with monthly caps an admin sets.

It isn't available to organizations with zero data retention or HIPAA settings. How it compares with CodeRabbit, Bugbot and Copilot is in AI code review tools.

How do you review a pull request from Claude Code?

  • /code-review reviews your current changes, a branch or a pull request number, at a level from low to max; low and medium report only high-confidence findings. --fix applies them, and --comment posts them as inline comments on the pull request. /review is now an alias (Anthropic).
  • /code-review ultra (or /ultrareview) runs a multi-agent review in a cloud sandbox where each finding is reproduced, in about 5 to 10 minutes. Pro and Max get three free runs per account; after that it costs about $5 to $25 a review in usage credits (Anthropic). --post puts the findings on the pull request as one comment from your account.
  • /security-review checks your branch's changes for injection, authentication and data-exposure risks.

Is it safe to run Claude on pull requests?

Pull requests and comments can carry prompt injection, text written to steer the agent. The action's security guide (Anthropic) says it strips hidden markdown, but "new bypass techniques may emerge." Its defaults help: only people with write access can trigger it, bots are refused unless listed, and on pull requests it restores .claude/, CLAUDE.md and .mcp.json from the base branch. On a public repository, limit which commenters it listens to, give the workflow only the permissions it needs, and keep full output off, because Actions logs are public. Anthropic's separate security-review action says outright that it is "not hardened against prompt injection attacks."

Does it work with GitLab, or with Codex?

  • GitLab: a beta GitLab CI/CD integration, maintained by GitLab, answers @claude in issues and merge requests (Anthropic). Managed Code Review is GitHub-only.
  • Codex: comment @codex review on a pull request or turn on automatic reviews in Codex settings; it reads guidelines from AGENTS.md. For your own workflows there's openai/codex-action (GitHub). More in How to use Codex.

Reviewing changes before they're a pull request

GitHub review comes after the agent has written the code. Poly (usepoly.co) moves the review earlier: a team works with one Claude Code or Codex agent in a shared browser room, sees each step live, and any member can approve or stop a change before it happens. Free to start. What is Poly?

Common questions

How do I set up Claude Code GitHub Actions?

Run /install-github-app inside Claude Code in the repository. It installs the Claude GitHub App, saves your API key or subscription token as a secret, and opens a pull request with the workflow. Merge it and mention @claude in an issue or pull request.

Is the Claude Code GitHub Action free?

The action itself is free and open source. You pay for tokens on your Anthropic API key, or use your Claude plan with an OAuth token, plus the GitHub Actions minutes the runner uses.

How much does Claude Code Review cost?

Anthropic's managed Code Review, for Team and Enterprise, averages $15 to $25 a review, billed as usage credits separate from plan usage. Admins can set a monthly cap.

What is /code-review ultra in Claude Code?

A multi-agent review that runs in Anthropic's cloud and reproduces each finding before reporting it. Pro and Max accounts get three free runs; after that it costs about $5 to $25 a review in usage credits.

Can Claude Code review pull requests in GitLab?

Yes, through a beta GitLab CI/CD integration maintained by GitLab that answers @claude in issues and merge requests. Anthropic's managed Code Review works only with GitHub.