curl --request POST \
--url https://api.ara.so/v3/organizations/{orgId}/pr-reviews \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"repository": "acme/web",
"pr_number": 482,
"provider": "github",
"instructions": "Pay special attention to the new auth middleware."
}
'import requests
url = "https://api.ara.so/v3/organizations/{orgId}/pr-reviews"
payload = {
"repository": "acme/web",
"pr_number": 482,
"provider": "github",
"instructions": "Pay special attention to the new auth middleware."
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
repository: 'acme/web',
pr_number: 482,
provider: 'github',
instructions: 'Pay special attention to the new auth middleware.'
})
};
fetch('https://api.ara.so/v3/organizations/{orgId}/pr-reviews', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.ara.so/v3/organizations/{orgId}/pr-reviews",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'repository' => 'acme/web',
'pr_number' => 482,
'provider' => 'github',
'instructions' => 'Pay special attention to the new auth middleware.'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.ara.so/v3/organizations/{orgId}/pr-reviews"
payload := strings.NewReader("{\n \"repository\": \"acme/web\",\n \"pr_number\": 482,\n \"provider\": \"github\",\n \"instructions\": \"Pay special attention to the new auth middleware.\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.ara.so/v3/organizations/{orgId}/pr-reviews")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"repository\": \"acme/web\",\n \"pr_number\": 482,\n \"provider\": \"github\",\n \"instructions\": \"Pay special attention to the new auth middleware.\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.ara.so/v3/organizations/{orgId}/pr-reviews")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"repository\": \"acme/web\",\n \"pr_number\": 482,\n \"provider\": \"github\",\n \"instructions\": \"Pay special attention to the new auth middleware.\"\n}"
response = http.request(request)
puts response.read_body{
"pr_review_id": "rev_71c2a8",
"status": "queued"
}{
"error": "prompt_required"
}{
"error": "unauthorized"
}Request a change request review
Automated pull-request and merge-request reviews are currently disabled. Valid requests return 409 pr_review_disabled.
reviews:writecurl --request POST \
--url https://api.ara.so/v3/organizations/{orgId}/pr-reviews \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"repository": "acme/web",
"pr_number": 482,
"provider": "github",
"instructions": "Pay special attention to the new auth middleware."
}
'import requests
url = "https://api.ara.so/v3/organizations/{orgId}/pr-reviews"
payload = {
"repository": "acme/web",
"pr_number": 482,
"provider": "github",
"instructions": "Pay special attention to the new auth middleware."
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
repository: 'acme/web',
pr_number: 482,
provider: 'github',
instructions: 'Pay special attention to the new auth middleware.'
})
};
fetch('https://api.ara.so/v3/organizations/{orgId}/pr-reviews', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.ara.so/v3/organizations/{orgId}/pr-reviews",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'repository' => 'acme/web',
'pr_number' => 482,
'provider' => 'github',
'instructions' => 'Pay special attention to the new auth middleware.'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.ara.so/v3/organizations/{orgId}/pr-reviews"
payload := strings.NewReader("{\n \"repository\": \"acme/web\",\n \"pr_number\": 482,\n \"provider\": \"github\",\n \"instructions\": \"Pay special attention to the new auth middleware.\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.ara.so/v3/organizations/{orgId}/pr-reviews")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"repository\": \"acme/web\",\n \"pr_number\": 482,\n \"provider\": \"github\",\n \"instructions\": \"Pay special attention to the new auth middleware.\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.ara.so/v3/organizations/{orgId}/pr-reviews")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"repository\": \"acme/web\",\n \"pr_number\": 482,\n \"provider\": \"github\",\n \"instructions\": \"Pay special attention to the new auth middleware.\"\n}"
response = http.request(request)
puts response.read_body{
"pr_review_id": "rev_71c2a8",
"status": "queued"
}{
"error": "prompt_required"
}{
"error": "unauthorized"
}Authorizations
Your ara_ API key from Settings > Ara API. Keys are capability-scoped: run, mcp:read, mcp:write, secrets:read, secrets:write, sessions:read, sessions:debug, knowledge:read, memory:read, memory:write, skills:read, skills:write, repos:read, repos:write, reviews:read, reviews:write, deployment:read, analytics:read, org:read, org:write, attachments:read, attachments:write, guardrails:read, guardrails:write, automations:read, automations:write, agent_auth:read. mcp:write manages MCP server configuration only; it does not authorize remote MCP-tool execution. sessions:debug is privileged: it expands diagnostic session events only for organization owners/admins.
Path Parameters
Organization id or slug. Resolve it with GET /v3/self.
Body
GitHub repository path.
The pull request number to review.
GitHub pull request URL. Alternative to repository + pr_number.
Source-control provider. GitHub is the only supported provider.
github Optional guidance to focus the review.
Response
Legacy success response retained for client compatibility. The code-disabled service does not emit this response.

