The problem
AI code review is useful only when it is dependable, explainable, and safe to run against real repositories. A synchronous webhook handler cannot absorb model latency or provider failures, while a hosted reviewer can make source code and findings leave the team's infrastructure. PRPilot separates ingestion, queueing, model execution, persistence, and GitHub delivery so every review can be retried, audited, and self-hosted.
Architecture
Interactive system view
See the product from purpose to implementation.
Follow the work, then switch views when you want the practical answer: who it is for and what it is built with.
Step 01 of 05
A GitHub App receives pull-request…
A GitHub App receives pull-request events at a FastAPI webhook receiver. HMAC verification rejects forged payloads before any repository content enters the system, and Redis-backed idempotency prevents duplicate reviews when GitHub retries delivery.
Full system map
The grouped dependency view stays visible so the infrastructure is readable at a glance.
System map
How the pieces connect
Outcome
- Open-source, self-hostable GitHub App with MIT licensing.
- Durable Kafka → Celery processing keeps webhook ingestion independent from model latency.
- Multi-provider review routing through LiteLLM, including local Ollama deployments.
- Dashboard, audit history, Redis idempotency, and PostgreSQL persistence around every review.
Lessons learned
- Webhook ingestion, model execution, and GitHub delivery should be separate failure domains.
- Idempotency belongs at the boundary because retries are normal behaviour, not exceptional behaviour.
- A model gateway is most valuable when it preserves product policy while providers remain replaceable.