# Claude Code in GitHub Actions and pull request review: setup, @claude, and cost

Three ways to get Claude reviewing pull requests: the free GitHub Action, Anthropic's managed Code Review, and /code-review from your terminal. Setup, cost and the security catch.

Published 2026-10-07 by Richard Kaminsky and Mitchell Lipyansky, the co-founders of Poly. Canonical: https://usepoly.co/claude-code-github-actions
Poly is a multiplayer AI coding workspace: a shared room where your team works with one AI agent, together. Free to start: https://usepoly.co/

**To use Claude Code in GitHub, run /install-github-app inside Claude Code in your repository: it installs the Claude GitHub App, saves your API key (or a Claude subscription token) as a repository secret, and opens a pull request with a workflow file. Once that's merged, anyone with write access can mention @claude in an issue or pull request and Claude answers, reviews or pushes a fix to a branch. The action, anthropics/claude-code-action@v1, is free; you pay for the tokens on your Anthropic key and the GitHub Actions minutes. Team and Enterprise organizations can instead switch on Anthropic's managed Code Review, which averages $15 to $25 a review.**

## Key takeaways

- **Setup:** `/install-github-app` needs repository admin and the `gh` CLI; manual setup is three steps.
- **Two modes:** answer `@claude` in comments, or run a fixed `prompt` on any event, such as every pull request or a nightly schedule.
- **Cost:** API tokens (or your Claude plan's usage with an OAuth token) plus Actions minutes.
- **Managed Code Review:** a fleet of agents on Anthropic's machines; Team and Enterprise, research preview since March 2026, billed as usage credits.
- **From the terminal:** `/code-review` reviews a branch or pull request, and `/code-review ultra` runs a verified multi-agent review in the cloud.

*Ways to get Claude reviewing GitHub pull requests, from Anthropic's docs, October 7, 2026.*

|  | Claude Code GitHub Action | Managed Code Review | /code-review ultra |
| --- | --- | --- | --- |
| Runs on | Your GitHub Actions runners | Anthropic's infrastructure | Anthropic's cloud sandbox |
| Plans | Any API key, or Pro and up with a token | Team and Enterprise | Claude accounts (not API keys) |
| Triggered by | @claude, or any workflow event | PR opened, every push, or @claude review | You, from Claude Code |
| Cost | API tokens or plan usage, plus Actions minutes | About $15 to $25 a review, usage credits | 3 free runs, then about $5 to $25 |
| Can push fixes | Yes, to a branch | No; comments only | No; findings, with an option to post |

## How do you set up Claude Code GitHub Actions?

**Quick setup** ([Anthropic](https://code.claude.com/docs/en/github-actions)): open Claude Code in the repository and run `/install-github-app`. You need admin rights on the repository and the GitHub CLI signed in. It:

1. Installs the Claude GitHub App.
2. Saves `ANTHROPIC_API_KEY`, or `CLAUDE_CODE_OAUTH_TOKEN` if you choose to use your Claude subscription, as a repository secret.
3. Opens a pull request adding `claude.yml` and, if you want automatic reviews, `claude-code-review.yml`. Merge it and `@claude` works.

**Manual setup:** install the app from [github.com/apps/claude](https://github.com/apps/claude), add the secret (a Console API key, or a token from `claude setup-token` on Pro, Max, Team or Enterprise), and copy the example workflow from the action's repository. For an organization, Anthropic recommends an API key over a personal subscription token. Bedrock, Google Cloud and Microsoft Foundry work through OIDC.

## What does the workflow look like?

A minimal `.github/workflows/claude.yml`, from Anthropic's docs:

```
on:
  issue_comment:
    types: [created]
  pull_request_review_comment:
    types: [created]
jobs:
  claude:
    if: contains(github.event.comment.body, '@claude')
    runs-on: ubuntu-latest
    permissions:
      contents: write
      pull-requests: write
      issues: write
      id-token: write
      actions: read
    steps:
      - uses: actions/checkout@v6
      - uses: anthropics/claude-code-action@v1
        with:
          anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
```

With no `prompt`, Claude waits for `@claude` in issue and pull request comments and replies in a comment it updates as it works. Add a `prompt` (plain text or a skill) to run on its own, for example a review on every pull request. Other useful inputs: `claude_args` passes any CLI flag, such as `--max-turns`; `trigger_phrase` changes `@claude`; `track_progress` shows a progress comment ([action inputs](https://github.com/anthropics/claude-code-action/blob/main/docs/usage.md#inputs)). By default Claude pushes to a branch and gives you a link to open the pull request, rather than opening it itself.

## How much does Claude Code in GitHub Actions cost?

Two meters, according to Anthropic:

- **GitHub Actions minutes:** the job runs on GitHub-hosted runners, "which consume your GitHub Actions minutes."
- **Tokens:** billed to your Anthropic API key at API rates. "If you authenticate with an OAuth token, runs use your Claude subscription instead of API billing."

To keep it down: write specific `@claude` requests, keep CLAUDE.md short (it's read on every run), set `--max-turns` in `claude_args`, add a workflow timeout, and use GitHub's concurrency controls to stop duplicate runs.

## What is Claude Code Review?

Anthropic's managed reviewer, in research preview since March 9, 2026 for Team and Enterprise ([Anthropic](https://code.claude.com/docs/en/code-review)). An owner switches it on in Claude Code's admin settings, installs the GitHub App and picks repositories. Then:

- **When it runs:** once when a pull request opens, after every push, or only when someone comments `@claude review` (`@claude review always` subscribes the pull request to later pushes).
- **What it does:** several agents look for logic errors, security bugs, edge cases and regressions on Anthropic's infrastructure; a verification pass filters them; findings arrive as inline comments marked Important, Nit or Pre-existing. It reads CLAUDE.md and REVIEW.md, takes about 20 minutes, and never blocks a merge.
- **Cost:** "Each review averages $15-25 in cost," billed as usage credits separate from plan usage, with monthly caps an admin sets.

It isn't available to organizations with zero data retention or HIPAA settings. How it compares with CodeRabbit, Bugbot and Copilot is in [AI code review tools](/ai-code-review-tools).

## How do you review a pull request from Claude Code?

- **`/code-review`** reviews your current changes, a branch or a pull request number, at a level from `low` to `max`; low and medium report only high-confidence findings. `--fix` applies them, and `--comment` posts them as inline comments on the pull request. `/review` is now an alias ([Anthropic](https://code.claude.com/docs/en/commands)).
- **`/code-review ultra`** (or `/ultrareview`) runs a multi-agent review in a cloud sandbox where each finding is reproduced, in about 5 to 10 minutes. Pro and Max get three free runs per account; after that it costs about $5 to $25 a review in usage credits ([Anthropic](https://code.claude.com/docs/en/ultrareview)). `--post` puts the findings on the pull request as one comment from your account.
- **`/security-review`** checks your branch's changes for injection, authentication and data-exposure risks.

## Is it safe to run Claude on pull requests?

Pull requests and comments can carry prompt injection, text written to steer the agent. The action's security guide ([Anthropic](https://github.com/anthropics/claude-code-action/blob/main/docs/security.md)) says it strips hidden markdown, but "new bypass techniques may emerge." Its defaults help: only people with write access can trigger it, bots are refused unless listed, and on pull requests it restores `.claude/`, CLAUDE.md and `.mcp.json` from the base branch. On a public repository, limit which commenters it listens to, give the workflow only the permissions it needs, and keep full output off, because Actions logs are public. Anthropic's separate security-review action says outright that it is "not hardened against prompt injection attacks."

## Does it work with GitLab, or with Codex?

- **GitLab:** a beta GitLab CI/CD integration, maintained by GitLab, answers `@claude` in issues and merge requests ([Anthropic](https://code.claude.com/docs/en/gitlab-ci-cd)). Managed Code Review is GitHub-only.
- **Codex:** comment `@codex review` on a pull request or turn on automatic reviews in Codex settings; it reads guidelines from AGENTS.md. For your own workflows there's `openai/codex-action` ([GitHub](https://github.com/openai/codex-action)). More in [How to use Codex](/how-to-use-codex).

## Reviewing changes before they're a pull request

GitHub review comes after the agent has written the code. Poly (usepoly.co) moves the review earlier: a team works with one Claude Code or Codex agent in a shared browser room, sees each step live, and any member can approve or stop a change before it happens. Free to start. [What is Poly?](/what-is-poly)

## Common questions

**How do I set up Claude Code GitHub Actions?**

Run /install-github-app inside Claude Code in the repository. It installs the Claude GitHub App, saves your API key or subscription token as a secret, and opens a pull request with the workflow. Merge it and mention @claude in an issue or pull request.

**Is the Claude Code GitHub Action free?**

The action itself is free and open source. You pay for tokens on your Anthropic API key, or use your Claude plan with an OAuth token, plus the GitHub Actions minutes the runner uses.

**How much does Claude Code Review cost?**

Anthropic's managed Code Review, for Team and Enterprise, averages $15 to $25 a review, billed as usage credits separate from plan usage. Admins can set a monthly cap.

**What is /code-review ultra in Claude Code?**

A multi-agent review that runs in Anthropic's cloud and reproduces each finding before reporting it. Pro and Max accounts get three free runs; after that it costs about $5 to $25 a review in usage credits.

**Can Claude Code review pull requests in GitLab?**

Yes, through a beta GitLab CI/CD integration maintained by GitLab that answers @claude in issues and merge requests. Anthropic's managed Code Review works only with GitHub.

More guides: https://usepoly.co/guides · Security: https://usepoly.co/security · Pricing: https://usepoly.co/pricing
