Model or dataset
kodustech/kodus-ai avatar
kodustech/kodus-ai

kodustech/kodus-ai: self-hosted AI code review with your own model keys

AI Code Review with Full Control Over Model Choice and Costs.

1,437 stars165 forksTypeScriptNOASSERTION

At a glance

What is it?
Kodus AI runs AI reviews inside GitHub, GitLab, Bitbucket and Azure Repos pull requests, or from a CLI, and lets you point it at your own model provider. The trade-off is that self-hosting means operating the deployment yourself.
Who is it for?
Adopt Kodus AI if you already pay a model provider directly and want review rules expressed in plain language across GitHub, GitLab, Bitbucket or Azure Repos, and you are willing to run the deployment yourself. Do not adopt it if you want a hosted product with no infrastructure work, or if you need a documented rollback path, because the README does not cover one.
Can I use it commercially?
Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
Is it still maintained?
Yes. The repository received new commits within the last day.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The problem Kodus AI targets: review cost and model lock-in

Most AI review tools bundle the model into the price. You get a monthly number per seat or per pull request, and the provider's margin is invisible inside it. Kodus AI takes the opposite position. The README states you connect your own provider credentials and choose the models behind reviews, listing OpenAI, Anthropic, Google Gemini, Vertex AI, Novita, or any OpenAI-compatible endpoint. The project calls this "Zero Markup on LLM Costs": you pay model providers directly.

The second problem is context. Generic reviewers repeat the same feedback because they do not know your conventions. Kody Rules, described in the README, let teams define review instructions in plain language and apply them across organizations, repositories, paths, or specific review scopes. Rules are supplied to the model as context during review.

Who this is for: platform or DevEx engineers at teams that already have provider accounts and want review behaviour they can edit as text rather than as a prompt hidden behind a vendor UI. It is a heavier choice than a hosted reviewer, and the repository layout reflects that, with apps/, libs/, docker-compose files for dev, prod, preview, test, sim and bench, plus a pnpm workspace.

How Kody reviews a pull request, and where the rules live

The README's review example is concrete. Kody detects a critical IDOR risk where an organizationId query parameter could bypass tenant protection when passed as an array, then suggests an explicit runtime validation before the code is merged. That is the shape of the output: a severity-tagged finding attached to the pull request, not a diff summary.

Kody Issues extends the loop past the merge. The README says unimplemented suggestions from closed pull requests are tracked automatically, managed by status, severity, category and repository, and resolved by Kody when the fix appears in a future pull request. That is a stateful component: it needs somewhere to persist findings and a way to match a later diff against an earlier suggestion.

The repository layout supports the claim that this is a full application rather than a script. There is a NestJS backend (nest-cli.json, package.json name "kodus-orchestrator"), a web app under apps/, shared code under libs/, and a default-kodus-config.yml plus kodus-config.yml at the root. Cockpit, described in the README, measures review effectiveness, Kody Rule health, repository health and delivery metrics. Token usage tracking is listed as a separate feature, which is what makes the bring-your-own-key model workable in practice: you can see consumption per review instead of discovering it on the provider invoice.

Installing Kodus AI: Docker Compose and the CLI

The README points self-hosters at a generic VM installation guide on docs.kodus.io rather than reproducing steps inline, and it offers a Cloud signup for teams that do not want to manage infrastructure. For local contribution the repository ships docker-compose.dev.yml, docker-compose.prod.yml and a setup script wired into package.json.

The package manager is pinned, and the preinstall script enforces it. Running npm install fails with a message telling you to use pnpm. The declared packageManager field is [email protected].

bash
pnpm install
pnpm run setup

The setup script is ./scripts/dev/setup.sh. After configuration, environment drift is checkable before you start services, which matters because the .env.example file is auto-generated from .env.schema and warns against editing it by hand.

bash
pnpm run env:doctor
pnpm run env:generate --apply

For a first real use without deploying anything, the CLI is the shortest path. The README gives these forms against a working tree, a staged diff, a branch or a commit.

bash
kodus review
kodus review --staged
kodus review --prompt-only

kodus review --prompt-only is the one to try first if you want to judge output quality before wiring anything into CI. The CLI documentation is at docs.kodus.io/how_to_use/en/cli/overview, with a command reference and a CI/CD page linked from the README.

Self-hosting constraints the environment file makes explicit

The .env.example carries unusually direct warnings, and they describe real failure modes rather than preferences. API_NODE_ENV defaults to development in the dev tree, but the file states the installer ships production for self-hosted, because with development the SSO handoff cookie is emitted without a Domain attribute and without the Secure flag. The file cites auth.controller.ts:287,292 and derive-sso-cookie-domain.ts:33. The consequence is stated plainly: the browser stores the cookie host-only on the API origin, and a front-end on a different subdomain cannot read it. Any self-hosted deployment using SSO on a separate subdomain needs production mode.

The SSL default is the other trap. API_DATABASE_DISABLE_SSL defaults to true because local docker dev and self-hosted both run a Postgres container without SSL. The comment notes that this covers all data sources, and that an earlier narrower setting only flipped the primary connection, which is why the API still crashed on the analytics connection when db_postgres was non-loopback. Cloud environments must set it to false explicitly. If you self-host against a managed Postgres that requires SSL, the default will not work for you.

Telemetry is opt-out and scoped. The README states self-hosted instances send one anonymous heartbeat per day with aggregated counters only, no code, names or identifiers, and that KODUS_TELEMETRY_DISABLED=true turns it off.

Where Kodus AI is the wrong tool

The licence is the first boundary. The README badge says AGPLv3 and links to license.md, but the repository also contains license_ee.md, and package.json declares "license": "UNLICENSED". The repository metadata reports the licence as NOASSERTION. That combination means you should read license.md and license_ee.md yourself before deciding how the code can be used, particularly if you plan to modify it and expose it as a network service. This article is not legal advice.

The second boundary is operational. The README does not document rollback or upgrade procedure for a self-hosted instance. There is a docker-compose.prod.yml and a release stream (2.2.2 and web-1.2.2 on 2026-09-08, 2.2.1 on 2026-09-04), but the README does not describe how to move between them safely or how database migrations are handled. Teams without anyone who can own a Postgres-backed deployment should use the Cloud option instead.

Third, this is not a linter. It does not replace deterministic static analysis. A model-backed reviewer produces findings that need judgement, and the README's own example is a security finding that a human still has to accept or reject. If your requirement is a blocking gate with reproducible output on every commit, a rule-based analyser is the better fit.

Finally, the model-agnostic claim has a limit. The README lists specific providers and adds any OpenAI-compatible endpoint. A provider that does not expose an OpenAI-compatible API is not covered by that statement.

How Kodus AI differs from Qodo, Refact and Reptile AI

The comparison that matters is where the model and the money sit. Qodo and Refact AI appear in the searches people run around this project, and both are established AI review tools. The practical difference is deployment and billing shape: Kodus AI is designed to be self-hosted with your own provider keys, so the review runs on infrastructure you control and the model bill goes to your provider account. Hosted tools in that space generally run the model for you and charge for the result.

That difference has a cost. A hosted reviewer is working the day you sign up. Kodus AI self-hosted means Postgres, environment configuration, and the SSO cookie detail described above. The README's own framing of the Cloud option ("Start reviewing pull requests without managing infrastructure") acknowledges the gap.

The second difference is the rules layer. Kody Rules are plain-language instructions scoped to organizations, repositories, paths or review scopes, held in configuration the repository ships as default-kodus-config.yml and kodus-config.yml. If your team's review standards already exist as written guidance, that mapping is direct. If they exist only as habits in reviewers' heads, you will have to write them down either way.

The third difference is the loop back. Kody Issues tracks unimplemented suggestions from closed pull requests and resolves them when the fix lands. That is closer to a technical-debt tracker attached to review than to a one-shot review bot, and Cockpit's delivery metrics sit alongside it.

Maintenance, releases and upgrade cost

The last push to the default branch was on 2026-09-10, and the most recent releases are 2.2.2 and web-1.2.2 on 2026-09-08, following 2.2.1 on 2026-09-04. The backend and web artefacts are versioned separately, which is worth noting before you plan an upgrade: a release of the orchestrator and a release of the web app are distinct entries in the release list.

The repository is a pnpm monorepo with a pinned packageManager of [email protected] and a preinstall guard. That guard is helpful for consistency and mildly annoying if your CI images assume npm. Environment handling is scripted rather than manual: .env.example is auto-generated from .env.schema, and there are dedicated scripts for generation, drift checking, coverage checking and reconciliation (env:generate, env:check:drift, env:check:coverage, env:reconcile). If you fork or self-host, expect to keep .env.schema as the source of truth rather than editing the example file, which the file itself tells you not to do.

Licence implications, stated as a reading task rather than advice: the README badge says AGPLv3, package.json says UNLICENSED, the repository metadata says NOASSERTION, and license_ee.md sits next to license.md. Resolve that before distributing a modified build.

Editorial conclusion

Adopt Kodus AI if you already pay a model provider directly and want review rules expressed in plain language across GitHub, GitLab, Bitbucket or Azure Repos, and you are willing to run the deployment yourself. Do not adopt it if you want a hosted product with no infrastructure work, or if you need a documented rollback path, because the README does not cover one. Verify first that your provider endpoint is OpenAI-compatible, that API_DATABASE_DISABLE_SSL matches your Postgres setup, and that API_NODE_ENV is set to production on any self-hosted instance using SSO.

Frequently asked questions

Is Kodus AI free?

The README describes a free Cloud account signup and a self-host path, and it states there is zero markup on LLM costs because you pay model providers directly. The repository licence situation is not straightforward: the README badge says AGPLv3, package.json declares UNLICENSED, and license_ee.md is present alongside license.md.

Which AI models can Kodus AI use for code review?

The README lists Claude, GPT-5, Gemini, Llama, GLM and Kimi, and says any OpenAI-compatible endpoint works. Provider credentials are connected by the user, so billing stays on your own provider account.

Does Kodus AI work with GitHub, GitLab, Bitbucket and Azure Repos?

The README states Kodus works directly in pull requests with GitHub, GitLab, Bitbucket and Azure Repos. It also offers a CLI that reviews a working tree, staged diff, branch or commit.

Can I install Kodus AI on my own server?

Yes. The README links a self-host guide at docs.kodus.io/how_to_deploy/en/deploy_kodus/generic_vm and the repository ships docker-compose.prod.yml plus a setup script at ./scripts/dev/setup.sh. Self-hosted instances send one anonymous heartbeat per day unless KODUS_TELEMETRY_DISABLED is set to true.

Official sources

  1. Issues
  2. kodustech/kodus-ai on GitHub
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/kodustech-kodus-ai.svg)](https://hysenlabs.com/projects/kodustech-kodus-ai)