Every public repository, free forever. Private repositories are one flat plan, never per seat.See pricing
[ Console ]
FAQ

Questions, answered plainly

What quellbot does, where it runs, what it costs, and what it will never do. Still stuck? Email support.

What is quellbot?

quellbot is a GitHub App that acts as an AI teammate for the verification half of the development loop. It reviews every pull request with a verdict and committable suggestions, explains why a GitHub Actions run went red, turns a triggered issue into a pull request, and answers @quellbot mentions on any thread. It is a hosted service; there is no self-hosted distribution.

Does quellbot merge my pull requests?

No, and it cannot. Never merging is one of nine invariants enforced in code and covered by tests, not a setting you can turn off. quellbot also never pushes to a default branch and never modifies anything under .github/workflows: the GitHub App is not granted the workflows permission, so GitHub itself refuses those writes. A person approves and merges every change.

Where does the code actually run?

In your own cloud. Every model run happens in an ephemeral machine created in your own Fly.io account, on your own Anthropic or OpenAI credential, with deny-by-default outbound networking, and the machine is destroyed when the run ends, typically within about a minute. quellbot's own servers run no model or CLI compute at all. If no runner is connected, the compute features are simply off; there is no fallback that runs the work somewhere else.

Does quellbot store my source code?

No. Your repository is cloned only into that throwaway machine in your own account, using a short-lived scoped installation token, and it goes away with the machine. quellbot's control plane stores run metadata, account records and settings in PostgreSQL. It never stores repository source.

Which models does quellbot use?

Claude (Anthropic) through Claude Code, or Codex (OpenAI), whichever you connect. You choose the lane and the model per account, with per-repository overrides. No model id is hardcoded, so a new model appears in the picker without waiting for a quellbot release.

Do I have to hand over an API key?

You connect a credential, and it is encrypted at rest with AES-256-GCM and decrypted only to start a run. You can connect an Anthropic or OpenAI API key, or a Claude or ChatGPT subscription instead of a key. The connect CLI mints a subscription credential through the provider's own browser approval, so you never copy a secret by hand: run npx quellbot-connect and approve once.

What does quellbot cost?

Public repositories are free, unlimited, forever. Private repositories are one flat plan for your whole team at $29 a month or $290 a year, with no per-seat pricing. quellbot never marks up model spend: you pay your model provider directly, and you pay Fly.io directly for the seconds your machines run, which is usually a fraction of a cent per run.

Is quellbot free for open source?

Yes. Every public repository is free with no run limit and no feature held back, permanently. The paid plan exists only to unlock private repositories.

What starts a run?

Five things, and only from someone with write, maintain or admin permission on the repository. A new issue whose title or body begins with one of your trigger slugs, which default to quell:, build: and fix:. A /build comment on any issue. A pull request opening, which starts a review, or being pushed to, which re-reviews just the new commits. A GitHub Actions run failing, which starts CI triage on the pull request or on the commit. And an @quellbot mention on any thread, which starts a reply. An issue opened by a stranger starts nothing.

How does quellbot handle prompt injection?

By assuming it. The agent reads issue bodies, pull request comments, CI logs and repository files, all of which are text other people wrote, so everything the agent produces is treated as untrusted data until something deterministic has validated it. Model judgment is never asked whether a change is safe. Every proposed diff passes a fixed policy gate before a branch is pushed: hard-denied paths, secret-shaped strings, size and file-count limits, new symlinks and submodules. A blocked diff is discarded and the issue gets a comment naming the rule.

What stops a run from costing too much?

Two limits. A hard per-run ceiling stops a single run outright, and a monthly cap holds new work of every kind, fixes, reviews, CI triage and replies, once the account crosses it. On a subscription credential, where dollars are not the unit, a runaway guard caps the number of model calls per run instead.

How is this different from a review bot that just leaves comments?

A review has to arrive as a decision, not a wall of text. quellbot posts a verdict of Approve, Request changes or Comment, groups findings by severity, attaches committable suggestion blocks so a fix is one click, and on a new push re-reviews only the delta rather than repeating findings you already addressed. It also reads your repository's own CLAUDE.md conventions before it reads the diff, so it flags what your team actually cares about.

Can I use quellbot without connecting a cloud account?

No. Every model-powered feature needs both a model credential and a connected Fly.io runner, reviews and CI triage and replies included, because quellbot's own servers run no model compute at all. With no runner connected those features are simply off for that account, and there is no fallback that runs the work somewhere else. Connecting each takes one command and one browser approval, and the console walks you through it.

Public repositories are free, forever. Install the GitHub App and open a pull request.

Open the console