SonarQubevf.sr
listing.by · home.legend.verified
Check code quality and security issues, quality gates and code snippets with SonarQube Server or SonarQube Cloud from your AI assistant.
listing.install
listing.local.explain
listing.local.needs listing.local.note
SONARQUBE_TOKENlisting.env.secret Your SonarQube USER tokenSONARQUBE_ORGlisting.env.secret listing.env.optional Your SonarQube Cloud organization key (if using SonarQube Cloud)SONARQUBE_URLlisting.env.secret listing.env.optional Your SonarQube Server URL (if using SonarQube Server)
listing.share.h
listing.share.p_local
mcp.tc/i/sonarqubelisting.about
Connects an AI assistant to SonarQube Server or SonarQube Cloud for code quality and security data. It can read issues and quality gate results from your projects, and it can analyze code snippets directly in the agent context.
It runs locally as a Docker container (sonarsource/sonarqube-mcp) over stdio. A SonarQube user token is required in SONARQUBE_TOKEN. Set SONARQUBE_ORG for SonarQube Cloud, or SONARQUBE_URL for SonarQube Server. SonarQube Cloud also offers a hosted endpoint with a smaller, fixed set of tools.
listing.can
- Look up code quality and security issues in SonarQube projects
- Check quality gate status
- Analyze code snippets inside the agent context
- Work with SonarQube Server or SonarQube Cloud
- Run as a local Docker container
listing.tools
listing.notools.key
listing.prompts
List the open security issues in my SonarQube project
Does my project pass its SonarQube quality gate?
Analyze this code snippet for quality and security problems
Show the highest severity issues on the main branch
listing.setup.h
listing.setup.local
Claude Code
- Run this in a terminal, in your project folder:
claude mcp add --transport stdio sonarqube --env "SONARQUBE_TOKEN=<YOUR_SONARQUBE_TOKEN>" --env "SONARQUBE_ORG=<YOUR_SONARQUBE_ORG>" --env "SONARQUBE_URL=<YOUR_SONARQUBE_URL>" -- docker run --init --pull=always -i --rm -e SONARQUBE_TOKEN -e SONARQUBE_ORG sonarsource/sonarqube-mcp- Start Claude Code and type
/mcp. sonarqube should show as connected.
Add --scope user to make it available in every project. Replace the placeholders with your own values.
Claude Desktop
- Open Settings → Developer → Edit Config. It opens
claude_desktop_config.json. Add:
{
"mcpServers": {
"sonarqube": {
"command": "docker",
"args": [
"run",
"-e",
"SONARQUBE_TOKEN",
"-e",
"SONARQUBE_ORG",
"-e",
"SONARQUBE_URL",
"--init",
"--pull=always",
"-i",
"--rm",
"-e",
"SONARQUBE_TOKEN",
"-e",
"SONARQUBE_ORG",
"sonarsource/sonarqube-mcp"
],
"env": {
"SONARQUBE_TOKEN": "<YOUR_SONARQUBE_TOKEN>",
"SONARQUBE_ORG": "<YOUR_SONARQUBE_ORG>",
"SONARQUBE_URL": "<YOUR_SONARQUBE_URL>"
}
}
}
}- Save the file and restart Claude Desktop. Replace the placeholders with your own values.
Needs Docker on your computer. The file lives in ~/Library/Application Support/Claude/ on macOS and %APPDATA%\Claude\ on Windows.
Cursor
Or add it by hand to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (this project):
{
"mcpServers": {
"sonarqube": {
"command": "docker",
"args": [
"run",
"-e",
"SONARQUBE_TOKEN",
"-e",
"SONARQUBE_ORG",
"-e",
"SONARQUBE_URL",
"--init",
"--pull=always",
"-i",
"--rm",
"-e",
"SONARQUBE_TOKEN",
"-e",
"SONARQUBE_ORG",
"sonarsource/sonarqube-mcp"
],
"env": {
"SONARQUBE_TOKEN": "<YOUR_SONARQUBE_TOKEN>",
"SONARQUBE_ORG": "<YOUR_SONARQUBE_ORG>",
"SONARQUBE_URL": "<YOUR_SONARQUBE_URL>"
}
}
}
}Needs Docker on your computer. Replace the placeholders with your own values.
VS Code
Add it to .vscode/mcp.json. VS Code asks for the secret the first time and stores it securely:
{
"servers": {
"sonarqube": {
"type": "stdio",
"command": "docker",
"args": [
"run",
"-e",
"SONARQUBE_TOKEN",
"-e",
"SONARQUBE_ORG",
"-e",
"SONARQUBE_URL",
"--init",
"--pull=always",
"-i",
"--rm",
"-e",
"SONARQUBE_TOKEN",
"-e",
"SONARQUBE_ORG",
"sonarsource/sonarqube-mcp"
],
"env": {
"SONARQUBE_TOKEN": "${input:sonarqube-token}",
"SONARQUBE_ORG": "${input:sonarqube-org}",
"SONARQUBE_URL": "${input:sonarqube-url}"
}
}
},
"inputs": [
{
"type": "promptString",
"id": "sonarqube-token",
"description": "SONARQUBE_TOKEN",
"password": true
},
{
"type": "promptString",
"id": "sonarqube-org",
"description": "SONARQUBE_ORG",
"password": true
},
{
"type": "promptString",
"id": "sonarqube-url",
"description": "SONARQUBE_URL",
"password": true
}
]
}Needs Docker on your computer.
Devin Desktop
- Add it to
~/.config/devin/mcp_config.json(macOS and Linux) or%APPDATA%\devin\mcp_config.json(Windows):
{
"mcpServers": {
"sonarqube": {
"command": "docker",
"args": [
"run",
"-e",
"SONARQUBE_TOKEN",
"-e",
"SONARQUBE_ORG",
"-e",
"SONARQUBE_URL",
"--init",
"--pull=always",
"-i",
"--rm",
"-e",
"SONARQUBE_TOKEN",
"-e",
"SONARQUBE_ORG",
"sonarsource/sonarqube-mcp"
],
"env": {
"SONARQUBE_TOKEN": "<YOUR_SONARQUBE_TOKEN>",
"SONARQUBE_ORG": "<YOUR_SONARQUBE_ORG>",
"SONARQUBE_URL": "<YOUR_SONARQUBE_URL>"
}
}
}
}- Refresh the MCP server list in Cascade. Replace the placeholders with your own values.
Devin Desktop is the new name for Windsurf.
Codex
codex mcp add sonarqube --env "SONARQUBE_TOKEN=<YOUR_SONARQUBE_TOKEN>" --env "SONARQUBE_ORG=<YOUR_SONARQUBE_ORG>" --env "SONARQUBE_URL=<YOUR_SONARQUBE_URL>" -- docker run --init --pull=always -i --rm -e SONARQUBE_TOKEN -e SONARQUBE_ORG sonarsource/sonarqube-mcpOr edit ~/.codex/config.toml directly:
[mcp_servers.sonarqube]
command = "docker"
args = ["run", "--init", "--pull=always", "-i", "--rm", "-e", "SONARQUBE_TOKEN", "-e", "SONARQUBE_ORG", "sonarsource/sonarqube-mcp"]
env = { SONARQUBE_TOKEN = "<YOUR_SONARQUBE_TOKEN>", SONARQUBE_ORG = "<YOUR_SONARQUBE_ORG>", SONARQUBE_URL = "<YOUR_SONARQUBE_URL>" }Needs Docker on your computer. Replace the placeholders with your own values.
Gemini CLI
gemini mcp add -e "SONARQUBE_TOKEN=<YOUR_SONARQUBE_TOKEN>" -e "SONARQUBE_ORG=<YOUR_SONARQUBE_ORG>" -e "SONARQUBE_URL=<YOUR_SONARQUBE_URL>" sonarqube docker -- run --init --pull=always -i --rm -e SONARQUBE_TOKEN -e SONARQUBE_ORG sonarsource/sonarqube-mcpThis adds it to the current project. Add -s user to use it everywhere.
Any client
Most clients that start local servers accept this shape:
{
"mcpServers": {
"sonarqube": {
"command": "docker",
"args": [
"run",
"-e",
"SONARQUBE_TOKEN",
"-e",
"SONARQUBE_ORG",
"-e",
"SONARQUBE_URL",
"--init",
"--pull=always",
"-i",
"--rm",
"-e",
"SONARQUBE_TOKEN",
"-e",
"SONARQUBE_ORG",
"sonarsource/sonarqube-mcp"
],
"env": {
"SONARQUBE_TOKEN": "<YOUR_SONARQUBE_TOKEN>",
"SONARQUBE_ORG": "<YOUR_SONARQUBE_ORG>",
"SONARQUBE_URL": "<YOUR_SONARQUBE_URL>"
}
}
}
}Zed puts servers under context_servers in its settings, with the same command, args and env fields.
Needs Docker on your computer. Replace the placeholders with your own values.
listing.faq
Can I paste mcp.tc/i/sonarqube into my MCP client?
No. SonarQube runs on your own computer, started by your client, so it has no web address to connect to. The quick link is the page to share; the install command is docker run --init --pull=always -i --rm -e SONARQUBE_TOKEN -e SONARQUBE_ORG sonarsource/sonarqube-mcp.
Does SonarQube need an API key?
Yes. It reads SONARQUBE_TOKEN, SONARQUBE_ORG and SONARQUBE_URL from its environment, and SONARQUBE_TOKEN, SONARQUBE_ORG and SONARQUBE_URL are secrets. Put the value in your client's config on your own machine, never in a shared file.
Is SonarQube a remote or a local server?
Local. Your client starts it as a process on your computer with docker run --init --pull=always -i --rm -e SONARQUBE_TOKEN -e SONARQUBE_ORG sonarsource/sonarqube-mcp, which needs Docker.
What can SonarQube do?
You can look up code quality and security issues in SonarQube projects, check quality gate status and analyze code snippets inside the agent context.
Which clients can use it?
Any client that starts local servers: Claude Code, Claude Desktop, Cursor, VS Code, Devin Desktop, Codex, Gemini CLI, Zed and others. claude.ai and ChatGPT only connect to remote servers.
Who wrote this page?
mcp.tc's robot read SonarQube's public metadata (its package and repository pages), and an AI model drafted the text from it. A person reviews anything the checks can't confirm. The text can still be wrong, so if you spot a mistake, use Report this listing on this page.
listing.em.h
listing.em.lead_local listing.em.how
listing.em.badge
[](https://mcp.tc/i/sonarqube)<a href="https://mcp.tc/i/sonarqube"><img src="https://mcp.tc/i/sonarqube/badge.svg" alt="SonarQube on mcp.tc" height="20"></a>listing.em.badge_note
listing.em.widget
<script src="https://mcp.tc/w/sonarqube.js" async></script>listing.em.widget_note
iframe
<iframe src="https://mcp.tc/embed/sonarqube" title="SonarQube on mcp.tc" width="420" height="200" loading="lazy" allow="clipboard-write" style="border:0;border-radius:8px;max-width:100%"></iframe>listing.em.iframe_note
listing.disclaimer_checked