# SonarQube Cloud MCP server

> Query code quality and security issues, quality gates, hotspots and metrics from SonarQube Cloud in your AI assistant.

- Listing: https://mcp.tc/i/sonarqube-cloud
- Connect: use the server's own URL `https://api.sonarcloud.io/mcp` (with your API key); clients connect to it directly. The listing link is a page, not an MCP endpoint.
- Type: remote (Streamable HTTP)
- Auth: API key
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: SonarSource
- Verified: yes, mcp.tc checked that this is the official server (https://mcp.tc/verify). It says who runs the server, not that it is safe.
- Homepage: <https://docs.sonarsource.com/sonarqube-mcp-server/setup/sonarqube-cloud-hosted>

## About

Connects an AI assistant to the SonarQube MCP Server embedded in SonarQube Cloud. It exposes a fixed subset of tools grouped into toolsets: analysis, coverage, dependency-risks, duplications, quality-gates, issues, measures, projects, rules and security-hotspots.

It runs as a hosted streamable HTTP endpoint at https://api.sonarcloud.io/mcp, with https://api.sonarqube.us/mcp for the US region. Requests need an Authorization header with a user token and a SONARQUBE\_ORG header with the organization. SONARQUBE\_READ\_ONLY defaults to true, and SONARQUBE\_TOOLSETS limits which toolsets load. SonarQube Server users run the sonarsource/sonarqube-mcp Docker image instead.

## What it can do

- Browse projects and code quality measures in SonarQube Cloud
- Look up code issues and security hotspots
- Check quality gate status for a project
- Review test coverage and code duplications
- Inspect dependency risks and rule details
- Limit loaded toolsets and keep read-only mode on by default

## Example prompts

- "List the open security hotspots in my payments-service project."
- "Does the main branch of my web-app project pass its quality gate?"
- "Show the highest severity issues in my SonarQube Cloud project."
- "What is the test coverage and duplication rate for my api project?"

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport http sonarqube-cloud https://api.sonarcloud.io/mcp --header "Authorization: Bearer <YOUR_API_KEY>"
```

2. Replace the placeholder with your key before you run it, then check it with `/mcp` inside Claude Code.

Add `--scope user` to make it available in every project, not just this one.

### Claude Desktop

1. Custom connectors can’t send this server’s key header, so use the `mcp-remote` bridge. Open **Settings → Developer → Edit Config** and add:

`claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "sonarqube-cloud": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://api.sonarcloud.io/mcp",
        "--header",
        "Authorization: Bearer <YOUR_API_KEY>"
      ]
    }
  }
}
```

2. Replace the placeholder with your key and restart Claude Desktop.

The bridge needs Node.js on your computer.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=sonarqube-cloud&config=eyJ1cmwiOiJodHRwczovL2FwaS5zb25hcmNsb3VkLmlvL21jcCIsImhlYWRlcnMiOnsiQXV0aG9yaXphdGlvbiI6IkJlYXJlciA8WU9VUl9BUElfS0VZPiJ9fQ%3D%3D>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "sonarqube-cloud": {
      "url": "https://api.sonarcloud.io/mcp",
      "headers": {
        "Authorization": "Bearer <YOUR_API_KEY>"
      }
    }
  }
}
```

### VS Code

Add it to `.vscode/mcp.json`. VS Code asks for the key the first time and stores it securely:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "sonarqube-cloud": {
      "type": "http",
      "url": "https://api.sonarcloud.io/mcp",
      "headers": {
        "Authorization": "Bearer ${input:api-key}"
      }
    }
  },
  "inputs": [
    {
      "type": "promptString",
      "id": "api-key",
      "description": "API key",
      "password": true
    }
  ]
}
```

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "sonarqube-cloud": {
      "serverUrl": "https://api.sonarcloud.io/mcp",
      "headers": {
        "Authorization": "Bearer <YOUR_API_KEY>"
      }
    }
  }
}
```

2. Refresh the MCP server list in Cascade.

Devin Desktop is the new name for Windsurf. It reads `serverUrl` (or `url`) for remote servers.

### Codex

```bash
codex mcp add sonarqube-cloud --url https://api.sonarcloud.io/mcp --bearer-token-env-var SONARQUBE_CLOUD_API_KEY
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.sonarqube-cloud]
url = "https://api.sonarcloud.io/mcp"
bearer_token_env_var = "SONARQUBE_CLOUD_API_KEY"
```

Set `SONARQUBE_CLOUD_API_KEY` to your key in the shell that runs Codex.

### Gemini CLI

```bash
gemini mcp add --transport http --header "Authorization: Bearer <YOUR_API_KEY>" sonarqube-cloud https://api.sonarcloud.io/mcp
```

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients accept this shape. Some name the URL field differently: `serverUrl` in Devin Desktop, `httpUrl` in Gemini CLI’s settings file.

```json
{
  "mcpServers": {
    "sonarqube-cloud": {
      "type": "http",
      "url": "https://api.sonarcloud.io/mcp",
      "headers": {
        "Authorization": "Bearer <YOUR_API_KEY>"
      }
    }
  }
}
```

Zed puts servers under `context_servers` in its settings. Cline needs `"type": "streamableHttp"`, or it assumes SSE.

Client only starts local servers? Bridge it with `npx -y mcp-remote https://api.sonarcloud.io/mcp`.

## Details

- Last checked: 2026-10-03 (reachable, asks for credentials)
- Listed: 2026-10-03
- Updated: 2026-10-04

---
Source: https://mcp.tc/i/sonarqube-cloud (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
