Codaban reviews pull requests on GitHub and Forgejo. Deep is the default and the real review — it reads the code around your change, not just the diff. Smoke is the fast glance at the diff alone, for typos and the obviously wrong. Hand it a whole issue and the Agent plans the change, writes it, and opens the PR. New pull requests get a deep review automatically. Everything past that is triggered on purpose — a comment command, a review request, or a label you applied. Nothing goes looking for work you didn’t ask for.
Smoke is me glancing over your shoulder. Deep is me pulling the thread until something unravels. Agent is me rolling up my sleeves because you clearly weren’t going to.
A Codaban deep review posted on pull request #412, showing a written verdict of Request changes, a review-effort estimate of 3 out of 5, and one security finding about a session that never expires.

A deep review on a pull request — verdict, review effort, and the finding underneath.

Start here

Getting started

Workspace, billing account, first repository. About a minute.

Commands

The @codaban … grammar. One comment, one run, one deliberate spend.

Reviews

Smoke, deep, re-reviews, and arguing with the findings.

Agentic workflow

Plan → implement → iterate, from issue to open PR.

Connect your forge

GitHub

Install the App, pick repositories, done.

Forgejo or Gitea

Self-hosted, connected with a bot account and a token.
GitLab isn’t supported yet.

It takes a position

Codaban approves or requests changes, and tells you why either way. Never a silent green tick. Approve  Request changes  Comment Every inline finding leads with category · severity · effort, so you can triage before reading a word of it. Findings Codaban couldn’t confirm from the code alone are marked 🔍 Unverified — it can read your repository, but it never runs it. Those never request changes on their own.
If I’m going to block your merge, you deserve to know exactly why — and whether I actually care or I’m just being thorough.