AI code review for Azure DevOps pull requests.
Mesrai reviews every pull request in Azure Repos automatically — bugs, security risks, performance problems and architecture issues — and posts its findings as comments in the pull request thread. Connect with a Personal Access Token, choose your repositories, and the next PR gets reviewed.
- Platform
- Azure DevOps · Azure Repos
- Connects with
- Personal Access Token
- Reviews
- Every pull request
57var invoices = db.Invoices.Where(i => i.TenantId == tenantId).ToList();Loads every invoice for the tenant into memory before paging. Large tenants have hundreds of thousands of rows; stream with AsAsyncEnumerable() or page in the query.
- 01
Most AI review tools are built for GitHub first; Azure Repos is often missing or an afterthought.
- 02
Large .NET and enterprise codebases change in ways a diff alone doesn't show — a small change can break a caller three projects away.
- 03
Senior reviewers become the bottleneck, and pull requests wait days for a first look.
- 04
Security and performance problems get through because reviewers are focused on whether the feature works.
Bugs and logic errors
A dedicated bug agent looks for incorrect conditions, null handling, off-by-one errors and broken edge cases in the changed code.
Security risks
The security agent checks for injection, secrets committed to code, missing authorization checks and other common vulnerability patterns.
Performance problems
Unbounded queries, N+1 database calls, work inside loops and other patterns that slow down under real data are flagged with a suggested fix.
Architecture impact
Mesrai builds a graph of your repository from its syntax tree, so it can see when a change affects code outside the diff.
Your team's rules
Mesrai Rules enforce your own conventions in plain English or YAML, alongside the built-in checks.
Linked work items
Business logic validation compares the pull request with the requirements in its linked work item or ticket.
- 01
A webhook tells Mesrai when a pull request is opened or updated.
- 02
Mesrai reads the changes through your Personal Access Token and builds context from the repository graph.
- 03
Specialised agents review the change in parallel: general, bugs, security, performance and Mesrai Rules.
- 04
Findings are posted as comments directly in the Azure DevOps pull request.
- 05
Per-repository settings in mesrai-config.yml override the web settings when you need different behaviour.
Azure DevOps connects with a Personal Access Token (PAT) and a webhook. The setup screen walks you through both.
- 1
Create a Mesrai account and choose Azure DevOps.
- 2
Create a PAT in Azure DevOps (profile → Security → Personal Access Tokens) with the scopes listed below, and paste it into Mesrai.
- 3
Follow the guided webhook setup to send pull request events to Mesrai.
- 4
Select the repositories Mesrai should review, then open a pull request.
- Code
- Read & Write — write is needed to post review comments
- Analytics · Graph · Identities and Groups
- Read
- Project and Team · User Profile
- Read
- PAT owner
- Needs Contribute and Contribute to pull requests on the repositories
- Pricing
- Every feature is free for 14 days with no credit card. After the trial, Pro is ₹499 / $6 per developer per month on your own LLM key (BYOK) — you pay your AI provider directly, with no markup.
If Mesrai is connected but doesn't comment, the cause is almost always a missing Code: Write scope or a PAT owner without pull request permissions. The troubleshooting steps are in the docs.
Why does Mesrai need write access to Code?+
Write access is what lets Mesrai post review comments on your pull requests. With read-only access it can analyse the code, but the review stays invisible because nothing can be posted.
Mesrai is connected but nothing happens on new pull requests. What should I check?+
First, the PAT scopes — Code: Read & Write is the one most often missed, and Azure DevOps won't add scopes to an existing token. Second, the PAT owner's permissions: they need Contribute and Contribute to pull requests on the repository. The docs cover a third, rarer cause: stricter organisation policies.
Can different repositories have different review settings?+
Yes. Add a mesrai-config.yml file to a repository's root to customise review behaviour for that repository. It overrides the settings from the web app automatically.
Which AI model reviews our code?+
You choose. Mesrai is BYOK: connect your own key from OpenAI, Anthropic, Google, AWS Bedrock or any OpenAI-compatible provider, and you pay that provider directly.
Is our code used to train AI models?+
No. Your code is never used to train any model. See the data usage page in the docs for how code is processed during a review.
Try Mesrai on your next pull request.
14-day free trial · every feature unlocked · no credit card required.