Tools & Products

GitHub Exposes Copilot Code Review via REST and GraphQL APIs: Programmatic PR Audits at Scale

GitHub announced public availability of dedicated REST and GraphQL endpoints for Copilot Code Review, enabling development teams to automate AI reviews across custom deployment pipelines, external forge bridges, and scheduled branch audits.

By FreakVinci · 2026-10-03 · 12 min read

GitHub opened programmatic access to Copilot Code Review through both the REST API and GraphQL API.

The release enables software engineering organizations to incorporate AI-assisted pull request audits directly into automated continuous integration pipelines, scheduled compliance checks, and multi-repository management tools.

Until now, invoking a Copilot code review required an engineer to manually open the GitHub pull request interface, click the Copilot icon in the review dropdown, and await feedback. The new endpoints remove this human bottleneck.


REST API Integration: Triggering a Review

The REST endpoint allows developers to request a review using standard HTTP headers and a fine-grained GitHub token:

curl -X POST \
  -H "Accept: application/vnd.github+json" \
  -H "Authorization: Bearer ghp_yourPersonalAccessToken" \
  -H "X-GitHub-Api-Version: 2022-11-28" \
  https://api.github.com/repos/octocat/my-service/pulls/142/copilot/reviews \
  -d '{
    "severity_filter": "medium",
    "review_scope": "all_changed_files",
    "custom_instructions": "Verify thread-safety and adhere to Google C++ Style Guide."
  }'

The endpoint responds with an HTTP 202 Accepted status code and a review task ID:

{
  "task_id": "rev_task_88921a92",
  "status": "queued",
  "created_at": "2026-10-03T18:42:00Z",
  "estimated_duration_sec": 14
}

GraphQL Mutation Schema

For teams running modern GraphQL orchestration, GitHub exposed the requestCopilotCodeReview mutation:

mutation TriggerCopilotReview($pullRequestId: ID!) {
  requestCopilotCodeReview(input: {
    pullRequestId: $pullRequestId,
    focusAreas: [SECURITY_VULNERABILITIES, PERFORMANCE_BOTTLENECKS],
    maxComments: 5
  }) {
    reviewRequest {
      id
      state
      queuedAt
    }
    clientMutationId
  }
}

Webhook Event Handling

Once the automated review completes, GitHub broadcasts a copilot_code_review webhook event:

{
  "action": "completed",
  "pull_request": {
    "number": 142,
    "title": "Migrate auth service to Argon2id hashing"
  },
  "review": {
    "id": 921004,
    "state": "changes_requested",
    "total_findings": 2,
    "critical_count": 1,
    "medium_count": 1,
    "summary_url": "https://github.com/octocat/my-service/pull/142#pullrequestreview-921004"
  }
}

CI pipelines can listen for this payload and automatically block merges if Copilot detects critical vulnerabilities.


Enterprise Use Cases

  1. Gatekeeping Large-Scale Automated PRs: Dependabot and automated library upgrade tools generate dozens of PRs every week. Calling the Copilot review endpoint ensures non-breaking semantics before auto-merging.
  2. Cross-Forge Code Review: Enterprise companies with source repositories on isolated on-premise GitLab or Bitbucket servers can mirror git diffs to a private GitHub staging repository, invoke the Copilot API, and stream comments back to their primary developer portal.