Mesrai
All integrations
GitLab · Merge requests

AI code review for GitLab merge requests.

Mesrai reviews every GitLab merge request automatically and posts its findings as comments in the merge request — bugs, security risks, performance problems and architecture impact, checked by specialised agents that understand your whole project, not just the diff.

Platform
GitLab merge requests
Connects with
OAuth or access token
Reviews
Every merge request
GitLabExample
!2093Cache user permissions in sessionperf/session-cache → main
app/services/permission_cache.rb
23Rails.cache.write("perms:#{user.id}", perms)
MesraiSecurity agentMUST_FIX

Cached permissions never expire, so a user who loses a role keeps it until the cache is cleared. Set expires_in and clear this key whenever the user's roles change.

I.Why GitLab teams need more than a diff review
  • 01

    Merge requests pile up while waiting for the one person who knows that part of the codebase.

  • 02

    Reviews focus on the lines that changed, so effects on other modules go unnoticed until production.

  • 03

    Security issues hide in ordinary-looking changes — a cache, a query, a missing check.

  • 04

    Team conventions live in people's heads and get applied inconsistently from one reviewer to the next.

II.What Mesrai reviews on every merge request

Bugs and logic errors

Incorrect conditions, unhandled errors, race conditions and broken edge cases in the changed code.

Security risks

Injection, secrets committed to the repository, missing authorization, unsafe caching and other vulnerability patterns.

Performance problems

N+1 queries, unbounded loads and expensive work in hot paths, each with a suggested fix.

Architecture impact

A repository graph built from the syntax tree shows how the change reaches code outside the diff.

Your team's rules

Mesrai Rules turn your conventions into automatic checks, written in plain English or YAML.

Linked tasks

Business logic validation compares the merge request with the requirements in its linked task or ticket.

III.How Mesrai works with GitLab
  1. 01

    A webhook tells Mesrai when a merge request is opened or updated.

  2. 02

    Mesrai reads the changes and builds context from the project's repository graph.

  3. 03

    Specialised agents review the change in parallel: general, bugs, security, performance and Mesrai Rules.

  4. 04

    Findings are posted as comments directly in the GitLab merge request.

  5. 05

    Per-project settings in mesrai-config.yml override the web settings when a project needs different behaviour.

IV.Set up in a few minutes

GitLab connects with OAuth during setup, plus a webhook for merge request events. A Personal Access Token works too.

  1. 1

    Create a Mesrai account and choose GitLab.

  2. 2

    Authorize Mesrai with OAuth — or create a Personal Access Token with the scopes listed below.

  3. 3

    Follow the guided webhook setup to send merge request events to Mesrai.

  4. 4

    Select the projects Mesrai should review, then open a merge request.

Full GitLab setup guide
Access token scopes
api · read_api
API access to read merge requests and post review comments
read_user
Identify the account Mesrai acts as
read_repository · write_repository
Read the code under review
Token expiry
Choose a long expiry (180 days or more) so reviews don't stop unexpectedly
Pricing
Every feature is free for 14 days with no credit card. After the trial, Pro is ₹499 / $6 per developer per month on your own LLM key (BYOK) — you pay your AI provider directly, with no markup.
V.Mesrai for GitLab — frequently asked
5 questions
  • Does Mesrai comment directly in the merge request?+

    Yes. Findings are posted as comments in the GitLab merge request, so your team reviews them in the same place as human feedback.

  • Should I use OAuth or a Personal Access Token?+

    OAuth is the quickest: you authorize Mesrai during setup. A Personal Access Token is an alternative when you want access tied to a specific account; give it the api, read_api, read_user, read_repository and write_repository scopes and a long expiry.

  • Can each GitLab project have its own review settings?+

    Yes. Add a mesrai-config.yml file to a project's root to customise review behaviour for that project. It overrides the web settings automatically.

  • Which AI model reviews our code?+

    You choose. Mesrai is BYOK: connect your own key from OpenAI, Anthropic, Google, AWS Bedrock or any OpenAI-compatible provider, and you pay that provider directly.

  • Is our code used to train AI models?+

    No. Your code is never used to train any model. See the data usage page in the docs for how code is processed during a review.

Try Mesrai on your next merge request.

14-day free trial · every feature unlocked · no credit card required.

Start free