SonarQube Cloudvf.sr

listing.by · home.legend.verified

Query code quality and security issues, quality gates, hotspots and metrics from SonarQube Cloud in your AI assistant.

state.key.long (state.key.title)Streamable HTTP

listing.connect

listing.explain.api_key

https://api.sonarcloud.io/mcp

listing.note.key_header listing.note.key_where

listing.share.h

listing.share.p

mcp.tc/i/sonarqube-cloud

listing.about

Connects an AI assistant to the SonarQube MCP Server embedded in SonarQube Cloud. It exposes a fixed subset of tools grouped into toolsets: analysis, coverage, dependency-risks, duplications, quality-gates, issues, measures, projects, rules and security-hotspots.

It runs as a hosted streamable HTTP endpoint at https://api.sonarcloud.io/mcp, with https://api.sonarqube.us/mcp for the US region. Requests need an Authorization header with a user token and a SONARQUBE_ORG header with the organization. SONARQUBE_READ_ONLY defaults to true, and SONARQUBE_TOOLSETS limits which toolsets load. SonarQube Server users run the sonarsource/sonarqube-mcp Docker image instead.

listing.can

  • Browse projects and code quality measures in SonarQube Cloud
  • Look up code issues and security hotspots
  • Check quality gate status for a project
  • Review test coverage and code duplications
  • Inspect dependency risks and rule details
  • Limit loaded toolsets and keep read-only mode on by default

listing.tools

listing.notools.key

listing.prompts

  • List the open security hotspots in my payments-service project.

  • Does the main branch of my web-app project pass its quality gate?

  • Show the highest severity issues in my SonarQube Cloud project.

  • What is the test coverage and duplication rate for my api project?

listing.setup.h

listing.setup.remote

Claude Code

  1. Run this in a terminal, in your project folder:
claude mcp add --transport http sonarqube-cloud https://api.sonarcloud.io/mcp --header "Authorization: Bearer <YOUR_API_KEY>"
  1. Replace the placeholder with your key before you run it, then check it with /mcp inside Claude Code.

Add --scope user to make it available in every project, not just this one.

Claude Desktop

  1. Custom connectors can't send this server's key header, so use the mcp-remote bridge. Open Settings → Developer → Edit Config and add:
claude_desktop_config.json
{
  "mcpServers": {
    "sonarqube-cloud": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://api.sonarcloud.io/mcp",
        "--header",
        "Authorization: Bearer <YOUR_API_KEY>"
      ]
    }
  }
}
  1. Replace the placeholder with your key and restart Claude Desktop.

The bridge needs Node.js on your computer.

Cursor

Or add it by hand to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (this project):

mcp.json
{
  "mcpServers": {
    "sonarqube-cloud": {
      "url": "https://api.sonarcloud.io/mcp",
      "headers": {
        "Authorization": "Bearer <YOUR_API_KEY>"
      }
    }
  }
}

VS Code

Add it to .vscode/mcp.json. VS Code asks for the key the first time and stores it securely:

.vscode/mcp.json
{
  "servers": {
    "sonarqube-cloud": {
      "type": "http",
      "url": "https://api.sonarcloud.io/mcp",
      "headers": {
        "Authorization": "Bearer ${input:api-key}"
      }
    }
  },
  "inputs": [
    {
      "type": "promptString",
      "id": "api-key",
      "description": "API key",
      "password": true
    }
  ]
}

Devin Desktop

  1. Add it to ~/.config/devin/mcp_config.json (macOS and Linux) or %APPDATA%\devin\mcp_config.json (Windows):
mcp_config.json
{
  "mcpServers": {
    "sonarqube-cloud": {
      "serverUrl": "https://api.sonarcloud.io/mcp",
      "headers": {
        "Authorization": "Bearer <YOUR_API_KEY>"
      }
    }
  }
}
  1. Refresh the MCP server list in Cascade.

Devin Desktop is the new name for Windsurf. It reads serverUrl (or url) for remote servers.

Codex

codex mcp add sonarqube-cloud --url https://api.sonarcloud.io/mcp --bearer-token-env-var SONARQUBE_CLOUD_API_KEY

Or edit ~/.codex/config.toml directly:

config.toml
[mcp_servers.sonarqube-cloud]
url = "https://api.sonarcloud.io/mcp"
bearer_token_env_var = "SONARQUBE_CLOUD_API_KEY"

Set SONARQUBE_CLOUD_API_KEY to your key in the shell that runs Codex.

Gemini CLI

gemini mcp add --transport http --header "Authorization: Bearer <YOUR_API_KEY>" sonarqube-cloud https://api.sonarcloud.io/mcp

This adds it to the current project. Add -s user to use it everywhere.

Any client

Most clients accept this shape. Some name the URL field differently: serverUrl in Devin Desktop, httpUrl in Gemini CLI's settings file.

{
  "mcpServers": {
    "sonarqube-cloud": {
      "type": "http",
      "url": "https://api.sonarcloud.io/mcp",
      "headers": {
        "Authorization": "Bearer <YOUR_API_KEY>"
      }
    }
  }
}

Zed puts servers under context_servers in its settings. Cline needs "type": "streamableHttp", or it assumes SSE.

Client only starts local servers? Bridge it with npx -y mcp-remote https://api.sonarcloud.io/mcp.

listing.faq

Can I paste mcp.tc/i/sonarqube-cloud into my MCP client?

No. mcp.tc links are pages, not server addresses. Connect with https://api.sonarcloud.io/mcp, so your client talks to SonarQube Cloud directly. Your key goes there too, never to mcp.tc. The quick link is for sharing: it opens this page, with setup steps for every client.

Does SonarQube Cloud need an API key or a sign-in?

Yes. SonarQube Cloud needs an API key, sent as the Authorization header. Get one from SonarSource and keep it in your client's config, never in a shared file.

Is SonarQube Cloud a remote or a local server?

Remote. SonarSource hosts it at https://api.sonarcloud.io/mcp, and it speaks Streamable HTTP. There's nothing to install.

What can SonarQube Cloud do?

You can browse projects and code quality measures in SonarQube Cloud, look up code issues and security hotspots and check quality gate status for a project.

Which clients can use it?

Any client that supports remote MCP servers and can send your key: Claude Code, Cursor, VS Code, Devin Desktop, Codex, Gemini CLI, Zed and others, and Claude Desktop through the mcp-remote bridge. claude.ai and ChatGPT can't send a key, so they can't use it.

Who wrote this page?

mcp.tc's robot read SonarQube Cloud's own metadata (its MCP handshake, tool list and public pages), and an AI model drafted the text from it. A person reviews anything the checks can't confirm. The text can still be wrong, so if you spot a mistake, use Report this listing on this page.

listing.em.h

listing.em.lead listing.em.how

listing.em.badge

em.prev_lightem.prev_dark
Markdown
[![SonarQube Cloud on mcp.tc](https://mcp.tc/i/sonarqube-cloud/badge.svg)](https://mcp.tc/i/sonarqube-cloud)
HTML
<a href="https://mcp.tc/i/sonarqube-cloud"><img src="https://mcp.tc/i/sonarqube-cloud/badge.svg" alt="SonarQube Cloud on mcp.tc" height="20"></a>

listing.em.badge_note

listing.em.widget

HTML
<script src="https://mcp.tc/w/sonarqube-cloud.js" async></script>

listing.em.widget_note

iframe

HTML
<iframe src="https://mcp.tc/embed/sonarqube-cloud" title="SonarQube Cloud on mcp.tc" width="420" height="200" loading="lazy" allow="clipboard-write" style="border:0;border-radius:8px;max-width:100%"></iframe>

listing.em.iframe_note

JSON

listing.em.json

https://mcp.tc/i/sonarqube-cloud.json

listing.em.fields

listing.disclaimer_checked