GitHub Copilot code review gets an API: how to automate AI review
GitHub now lets teams request Copilot code reviews through REST and GraphQL APIs. Here is how that changes review workflows and where human review still matters.
GitHub has made Copilot code review programmable. Teams can now request a review through REST and GraphQL APIs instead of starting every review manually in GitHub. Each API request can also set a review effort level, turning AI review into a reusable step that can be called from scripts, workflows and internal tools.
What changed
GitHub says Copilot code review API support is generally available for Copilot Pro, Pro+, Max, Business and Enterprise plans. Balanced is now the default review effort level, while API callers can choose an effort level for an individual request.
The important change is orchestration. A team can use its own rules to decide when an AI review should run: after a pull request reaches a certain state, when selected files change, or before a human review stage. Copilot review becomes one callable capability inside a larger process rather than a separate manual action.
A practical automation pattern
- Define which pull requests should receive an automated Copilot review.
- Request the review through the API and select an effort level based on the change.
- Send the findings to the author or existing review queue.
- Keep tests and required human approvals in the workflow.
- Track useful findings, false positives, review time and human corrections before expanding the automation.
Where effort controls fit
Per-request effort allows teams to route different changes differently. A small routine change may not need the same review depth as a large or sensitive change. The useful pattern is to let deterministic workflow rules choose the requested effort while people remain responsible for interpreting ambiguous findings.
A bounded review workflow
| Automate | Keep human-led |
|---|---|
| Starting reviews from predefined workflow conditions | Final decisions on consequential changes |
| Selecting effort from known routing rules | Judgment on ambiguous design trade-offs |
| Routing findings to the right queue | Required approvals and repository policy |
| Logging when reviews run | Evaluation of uncertain findings |
How this differs from Dynamic Workflows
GitHub Dynamic Workflows are a broader orchestration system that can combine coded stages and agents. The code review API is narrower: it exposes one specific Copilot capability as a callable workflow step. A larger workflow could decide that a review is needed, request it through the API and then use the result in later validation or human-review stages.
API access makes review easier to automate, but it does not make every review correct. Review usefulness can vary with repository context and change complexity, so existing tests and review requirements should remain in place where mistakes carry meaningful cost.
A useful first rollout
Start with a repository where the automated review can remain advisory. Trigger Copilot on a clearly defined subset of pull requests, record whether its findings caused a useful change, and compare review time and correction rates with the existing process. Expand the trigger only when the signal is consistently useful.
The Copilot code review API turns AI review into a composable workflow primitive. Automate the trigger, routing and effort selection, while keeping deterministic checks and people around the decisions where context and accountability matter.
Sources & useful resources
- GitHub Changelog— Primary announcement, Oct. 2, 2026