AI code review for Azure DevOps
Azure DevOps is where enterprise teams live and where AI code review tools mostly aren't. How Pullora connects, what access it needs, and why it stores a token when GitHub doesn't.
Azure DevOps runs a large share of enterprise .NET, Java and internal tooling. It is also close to invisible in the AI code review category — most tools do not support it at all.
The structural reason
Azure DevOps has no app installation model comparable to a GitHub App. There is no flow where an organisation installs your product and your service receives scoped, short-lived tokens per repository.
Instead you authenticate with a Personal Access Token created by a user, carrying whatever scopes that user grants. That is a meaningfully different security posture, and it is why we are explicit about it rather than burying it.
What Pullora asks for
An organisation URL and a PAT with two scopes: Code (Read & write), so reviews can be posted as pull request comments, and Service hooks (Read & write), so new pull requests trigger reviews automatically.
The token is encrypted at rest with AES-256-GCM and never written to logs. It is the one place in Pullora where a long-lived credential is stored — GitHub, GitLab and Bitbucket all use short-lived or refreshable OAuth credentials. We would rather you know that than find out later.
What you get
The same engine as every other provider: inline comments on the pull request with severity, confidence and a suggested fix; a dry-run mode that keeps findings in your dashboard until you choose to post them; incremental reviews that only look at commits since the last reviewed SHA; and review policy committed to the repository as .ai-review.yml.
If your organisation requires SOC 2, SSO/SAML or self-hosting before a tool can touch your repositories, Pullora does not have those yet. That is a real blocker for larger Azure DevOps shops and we would rather say so up front.
See a review before you install anything
Paste any public GitHub pull request URL and read the full review — no app installed, no repository access, nothing posted to the PR.
Review a public PR →