Troubleshooting
Symptom-first fixes for reviews that don't trigger, webhook failures, and CLI errors.
Reviews are not triggering
Work through this list in order — it resolves the large majority of cases:
Is the integration connected?
Settings → Integrations should show the provider as connected with a recent sync time. Reconnect if it shows Action required (usually an expired token after a credential rotation).
Is the repository granted?
Only explicitly selected repositories are reviewed. Add the repo, or switch the integration to "all repositories".
Did the webhook arrive?
Integrations → Last deliveries lists recent events. If the list is empty, the provider isn't reaching you — go to Webhook Setup and register manually.
Is the PR eligible?
Draft PRs and PRs labeled scandrix-skip are skipped by default. Check path filters in scandrix.yml — a PR touching only ignored paths produces a Skipped status, not silence.
Check the check run
Open the PR's checks tab. A Failed status with a log link means analysis errored after retries — the log names the failing stage.
Webhook received but no comment
| Symptom | Likely cause | Fix |
|---|---|---|
| Event logged, review never starts | Idempotency collision (re-delivery of same commit) | Push an empty commit or re-run from Reviews → Re-run |
| Review completes, zero comments | Nothing violated active rules | Expected — Approved with no comments |
| Comments appear on old PR only | Processing backlog | Check worker health /readyz; queue depth metric should drain |
| Duplicate comments | Two delivery paths (webhook + CI job) | Remove one, or keep both — dedupe needs the same commit SHA |
CLI errors
401 unauthorized
Team key missing, malformed, or revoked. Echo it (never print it in shared terminals): echo ${#SCANDRIX_TEAM_KEY} should be > 20. Rotate/regenerate in Settings → API Keys if needed.
429 too many requests
Rate limit per key — wait for the Retry-After window or use a different team key for parallel CI shards.
config validate fails
Line-anchored YAML error. Common: tabs (use spaces), quoting on/off values as booleans, or a rule ID not in the catalog — scandrix rules list shows valid IDs.
No findings but CI should fail
Blocking severity is configured above your findings' severity. Check Settings → Merge Policies, or pass --fail-on warning in CI.
Provider-side errors
- GitHub 403 on comments — app missing from the repo, or branch protection blocking bot pushes to the check; reinstall the app (GitHub App Setup).
- GitLab 401 — project access token expired or missing
apiscope. - Azure 401 — PAT expired or missing PR-threads write scope.
Still failing?
Email hello@scandrix.dev with the inquiryId/review ID shown in the dashboard — it carries enough context for us to trace the event through the queue without you sharing source code.