To run Claude Code reviews manually in GitHub Actions, add a pull-request workflow that calls anthropics/claude-code-action@v1, store its credential as a GitHub secret, and grant only the permissions the review actually needs. Treat the workflow as review assistance—not an automatic merge gate—and decide in advance what should happen with forked pull requests, which do not receive ordinary repository secrets.
What a manual Claude Code review workflow does
Claude Code’s GitHub Action runs inside a repository’s GitHub Actions workflow. A checked-in YAML file can start it for selected pull-request events and provide a review prompt. This differs from Anthropic’s separate automatic Claude Code Review feature and from cloud-hosted Claude Code sessions. Manual setup requires repository administrator access. See Anthropic’s GitHub Actions documentation.
As an Amazon Associate I earn from qualifying purchases.
Anthropic’s documented review example checks out the repository, installs the code-review plugin, and passes a review prompt to the Action. It uses anthropics/claude-code-action@v1 and listens for pull requests that are opened, synchronized with new commits, marked ready for review, or reopened. The example skips draft and closed pull requests, pull requests judged not to need review, and pull requests that already have a Claude comment.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11There are two Action modes: without a prompt, it waits for a trigger phrase (by default, @claude); with a prompt, it runs automatically when a configured workflow event occurs. For a predictable manual PR review, make both the event trigger and review prompt explicit in the workflow file.
#1 Best Overall
Set up the workflow and credential
- Install the GitHub App. Install Anthropic’s Claude GitHub App, or create and install a custom app if your organization needs a narrower installation permission set. You need repository administrator access for manual setup.
- Add an authentication credential. Store an
ANTHROPIC_API_KEYor, where appropriate, aCLAUDE_CODE_OAUTH_TOKENas a GitHub Actions secret. Never put either value directly in the workflow file or commit it to the repository. Anthropic also documents OIDC federation for supported enterprise provider routes. - Add a workflow file. Put the YAML under
.github/workflows/and configure its pull-request events, job permissions, credential input, checkout, plugin installation, and review prompt. Use Anthropic’s current example as the starting point rather than copying an older beta configuration unchanged. - Choose where findings appear. Without explicit comment configuration, findings are available in the workflow run log. Anthropic’s inline-comment example includes
--commentin the prompt and allowsmcp__github_inline_comment__create_inline_commentthroughclaude_args. Confirm the permissions required by the comment integration before enabling it.
Separate App permissions from workflow-token permissions
The Claude GitHub App’s installation permissions and the workflow’s GITHUB_TOKEN permissions are separate controls. Limiting one does not automatically narrow the other.
Anthropic says its standard GitHub App uses a shared permission set for multiple Claude features, which cannot be reduced at installation. It includes read/write access to Actions, Checks, Contents, Discussions, Issues, Pull requests, repository hooks, and Workflows, plus read access to Members, Metadata, and Statuses. For organizations that require a narrower installation, Anthropic documents a custom GitHub App with Contents, Issues, and Pull requests.
Separately, set the workflow or job’s permissions to the minimum the task needs. The documented review example grants read access to contents, pull requests, and issues, plus id-token: write for the Action’s default GitHub App authentication. Do not add write access simply because another example posts comments; check the live requirements for the output method you enable. GitHub explains token scoping in its GITHUB_TOKEN guidance.
Plan for fork pull requests and secret access
GitHub does not pass ordinary repository secrets to workflows triggered by pull requests from forks in public repositories. As a result, a secret-based Claude review workflow will not authenticate for those contributions. GitHub also does not automatically forward secrets to reusable workflows. See GitHub’s secrets guidance.
Choose a deliberate policy for fork contributions, such as having a maintainer trigger a review through a trusted path. Do not expose a privileged credential to untrusted pull-request code merely to make the workflow run for every contributor. OIDC can be an alternative where the cloud or enterprise authentication route supports it; confirm that the provider and workflow are configured for that model.
Limit triggers and prevent unnecessary runs
Keep event filters narrow so the workflow runs only when a review is useful. The Action checks the triggering actor: for issue and pull-request events, the user generally needs repository write access unless exceptions are configured. It rejects bot actors by default to reduce automation loops; any named exceptions require explicit configuration.
If you use mention-driven behavior instead of an automatic prompt, filter for the intended comment phrase. This keeps unrelated comments from starting runs and consuming runner time or model usage. Decide which pull-request states and events matter to your review process instead of enabling a broad trigger by default.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Choose output and keep a human in the merge decision
Workflow logs and PR comments serve different needs. Logs keep findings in the run record; inline comments put them beside relevant code, but require explicit prompt and tool configuration. Make the intended output clear to maintainers so they know where to look.
Best Value
Anthropic advises: “Grant the workflow only the permissions it needs, and review Claude’s changes before merging.” Its documentation does not establish a guaranteed defect-detection rate or independent review-accuracy measure. Treat findings as suggestions to assess alongside your normal human review and branch-protection process.
Keep the Action configuration current
Anthropic’s current examples use anthropics/claude-code-action@v1. For older beta workflows, Anthropic says to replace @beta with @v1, remove the old mode input, replace direct_prompt with prompt, and move CLI settings such as max_turns and model into claude_args.
Action inputs, examples, permissions, and model defaults can change. Recheck the official documentation before upgrading. The documentation does not prescribe a pinned commit SHA; teams with supply-chain requirements should choose and verify their own action-pinning policy.
Account for usage without assuming a fixed price
Each run uses GitHub Actions minutes and model tokens. Consumption varies with the prompt and response length, task complexity, and codebase size, so the documentation does not establish a stable per-review price. Anthropic says OAuth-authenticated runs use the subscription rather than API billing.
For organizations routing inference through other platforms, Anthropic documents Amazon Bedrock, Google Cloud Agent Platform, and Microsoft Foundry integrations using OIDC identity federation. Availability and configuration depend on the applicable provider route.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




