# SonarQube MCP server

> Check code quality and security issues, quality gates and code snippets with SonarQube Server or SonarQube Cloud from your AI assistant.

- Listing: https://mcp.tc/i/sonarqube
- Connect: this is a local (stdio) server; install it on your machine (see Install). The listing link is a page, not an MCP endpoint.
- Type: local (stdio)
- Auth: API key
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: SonarSource
- Verified: yes, mcp.tc checked that this is the official server (https://mcp.tc/verify). It says who runs the server, not that it is safe.
- Homepage: <https://docs.sonarsource.com/sonarqube-mcp-server>
- Repository: <https://github.com/SonarSource/sonarqube-mcp-server>
- Package: oci `docker.io/sonarsource/sonarqube-mcp`

## About

Connects an AI assistant to SonarQube Server or SonarQube Cloud for code quality and security data. It can read issues and quality gate results from your projects, and it can analyze code snippets directly in the agent context.

It runs locally as a Docker container (sonarsource/sonarqube-mcp) over stdio. A SonarQube user token is required in SONARQUBE\_TOKEN. Set SONARQUBE\_ORG for SonarQube Cloud, or SONARQUBE\_URL for SonarQube Server. SonarQube Cloud also offers a hosted endpoint with a smaller, fixed set of tools.

## What it can do

- Look up code quality and security issues in SonarQube projects
- Check quality gate status
- Analyze code snippets inside the agent context
- Work with SonarQube Server or SonarQube Cloud
- Run as a local Docker container

## Example prompts

- "List the open security issues in my SonarQube project"
- "Does my project pass its SonarQube quality gate?"
- "Analyze this code snippet for quality and security problems"
- "Show the highest severity issues on the main branch"

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport stdio sonarqube --env "SONARQUBE_TOKEN=<YOUR_SONARQUBE_TOKEN>" --env "SONARQUBE_ORG=<YOUR_SONARQUBE_ORG>" --env "SONARQUBE_URL=<YOUR_SONARQUBE_URL>" -- docker run --init --pull=always -i --rm -e SONARQUBE_TOKEN -e SONARQUBE_ORG sonarsource/sonarqube-mcp
```

2. Start Claude Code and type `/mcp`. **sonarqube** should show as connected.

Add `--scope user` to make it available in every project. Replace the placeholders with your own values.

### Claude Desktop

1. Open **Settings → Developer → Edit Config**. It opens `claude_desktop_config.json`. Add:

`claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "sonarqube": {
      "command": "docker",
      "args": [
        "run",
        "-e",
        "SONARQUBE_TOKEN",
        "-e",
        "SONARQUBE_ORG",
        "-e",
        "SONARQUBE_URL",
        "--init",
        "--pull=always",
        "-i",
        "--rm",
        "-e",
        "SONARQUBE_TOKEN",
        "-e",
        "SONARQUBE_ORG",
        "sonarsource/sonarqube-mcp"
      ],
      "env": {
        "SONARQUBE_TOKEN": "<YOUR_SONARQUBE_TOKEN>",
        "SONARQUBE_ORG": "<YOUR_SONARQUBE_ORG>",
        "SONARQUBE_URL": "<YOUR_SONARQUBE_URL>"
      }
    }
  }
}
```

2. Save the file and restart Claude Desktop. Replace the placeholders with your own values.

Needs Docker on your computer. The file lives in `~/Library/Application Support/Claude/` on macOS and `%APPDATA%\Claude\` on Windows.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=sonarqube&config=eyJjb21tYW5kIjoiZG9ja2VyIiwiYXJncyI6WyJydW4iLCItZSIsIlNPTkFSUVVCRV9UT0tFTiIsIi1lIiwiU09OQVJRVUJFX09SRyIsIi1lIiwiU09OQVJRVUJFX1VSTCIsIi0taW5pdCIsIi0tcHVsbD1hbHdheXMiLCItaSIsIi0tcm0iLCItZSIsIlNPTkFSUVVCRV9UT0tFTiIsIi1lIiwiU09OQVJRVUJFX09SRyIsInNvbmFyc291cmNlL3NvbmFycXViZS1tY3AiXSwiZW52Ijp7IlNPTkFSUVVCRV9UT0tFTiI6IjxZT1VSX1NPTkFSUVVCRV9UT0tFTj4iLCJTT05BUlFVQkVfT1JHIjoiPFlPVVJfU09OQVJRVUJFX09SRz4iLCJTT05BUlFVQkVfVVJMIjoiPFlPVVJfU09OQVJRVUJFX1VSTD4ifX0%3D>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "sonarqube": {
      "command": "docker",
      "args": [
        "run",
        "-e",
        "SONARQUBE_TOKEN",
        "-e",
        "SONARQUBE_ORG",
        "-e",
        "SONARQUBE_URL",
        "--init",
        "--pull=always",
        "-i",
        "--rm",
        "-e",
        "SONARQUBE_TOKEN",
        "-e",
        "SONARQUBE_ORG",
        "sonarsource/sonarqube-mcp"
      ],
      "env": {
        "SONARQUBE_TOKEN": "<YOUR_SONARQUBE_TOKEN>",
        "SONARQUBE_ORG": "<YOUR_SONARQUBE_ORG>",
        "SONARQUBE_URL": "<YOUR_SONARQUBE_URL>"
      }
    }
  }
}
```

Needs Docker on your computer. Replace the placeholders with your own values.

### VS Code

Add it to `.vscode/mcp.json`. VS Code asks for the secret the first time and stores it securely:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "sonarqube": {
      "type": "stdio",
      "command": "docker",
      "args": [
        "run",
        "-e",
        "SONARQUBE_TOKEN",
        "-e",
        "SONARQUBE_ORG",
        "-e",
        "SONARQUBE_URL",
        "--init",
        "--pull=always",
        "-i",
        "--rm",
        "-e",
        "SONARQUBE_TOKEN",
        "-e",
        "SONARQUBE_ORG",
        "sonarsource/sonarqube-mcp"
      ],
      "env": {
        "SONARQUBE_TOKEN": "${input:sonarqube-token}",
        "SONARQUBE_ORG": "${input:sonarqube-org}",
        "SONARQUBE_URL": "${input:sonarqube-url}"
      }
    }
  },
  "inputs": [
    {
      "type": "promptString",
      "id": "sonarqube-token",
      "description": "SONARQUBE_TOKEN",
      "password": true
    },
    {
      "type": "promptString",
      "id": "sonarqube-org",
      "description": "SONARQUBE_ORG",
      "password": true
    },
    {
      "type": "promptString",
      "id": "sonarqube-url",
      "description": "SONARQUBE_URL",
      "password": true
    }
  ]
}
```

Needs Docker on your computer.

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "sonarqube": {
      "command": "docker",
      "args": [
        "run",
        "-e",
        "SONARQUBE_TOKEN",
        "-e",
        "SONARQUBE_ORG",
        "-e",
        "SONARQUBE_URL",
        "--init",
        "--pull=always",
        "-i",
        "--rm",
        "-e",
        "SONARQUBE_TOKEN",
        "-e",
        "SONARQUBE_ORG",
        "sonarsource/sonarqube-mcp"
      ],
      "env": {
        "SONARQUBE_TOKEN": "<YOUR_SONARQUBE_TOKEN>",
        "SONARQUBE_ORG": "<YOUR_SONARQUBE_ORG>",
        "SONARQUBE_URL": "<YOUR_SONARQUBE_URL>"
      }
    }
  }
}
```

2. Refresh the MCP server list in Cascade. Replace the placeholders with your own values.

Devin Desktop is the new name for Windsurf.

### Codex

```bash
codex mcp add sonarqube --env "SONARQUBE_TOKEN=<YOUR_SONARQUBE_TOKEN>" --env "SONARQUBE_ORG=<YOUR_SONARQUBE_ORG>" --env "SONARQUBE_URL=<YOUR_SONARQUBE_URL>" -- docker run --init --pull=always -i --rm -e SONARQUBE_TOKEN -e SONARQUBE_ORG sonarsource/sonarqube-mcp
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.sonarqube]
command = "docker"
args = ["run", "--init", "--pull=always", "-i", "--rm", "-e", "SONARQUBE_TOKEN", "-e", "SONARQUBE_ORG", "sonarsource/sonarqube-mcp"]
env = { SONARQUBE_TOKEN = "<YOUR_SONARQUBE_TOKEN>", SONARQUBE_ORG = "<YOUR_SONARQUBE_ORG>", SONARQUBE_URL = "<YOUR_SONARQUBE_URL>" }
```

Needs Docker on your computer. Replace the placeholders with your own values.

### Gemini CLI

```bash
gemini mcp add -e "SONARQUBE_TOKEN=<YOUR_SONARQUBE_TOKEN>" -e "SONARQUBE_ORG=<YOUR_SONARQUBE_ORG>" -e "SONARQUBE_URL=<YOUR_SONARQUBE_URL>" sonarqube docker -- run --init --pull=always -i --rm -e SONARQUBE_TOKEN -e SONARQUBE_ORG sonarsource/sonarqube-mcp
```

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients that start local servers accept this shape:

```json
{
  "mcpServers": {
    "sonarqube": {
      "command": "docker",
      "args": [
        "run",
        "-e",
        "SONARQUBE_TOKEN",
        "-e",
        "SONARQUBE_ORG",
        "-e",
        "SONARQUBE_URL",
        "--init",
        "--pull=always",
        "-i",
        "--rm",
        "-e",
        "SONARQUBE_TOKEN",
        "-e",
        "SONARQUBE_ORG",
        "sonarsource/sonarqube-mcp"
      ],
      "env": {
        "SONARQUBE_TOKEN": "<YOUR_SONARQUBE_TOKEN>",
        "SONARQUBE_ORG": "<YOUR_SONARQUBE_ORG>",
        "SONARQUBE_URL": "<YOUR_SONARQUBE_URL>"
      }
    }
  }
}
```

Zed puts servers under `context_servers` in its settings, with the same `command`, `args` and `env` fields.

Needs Docker on your computer. Replace the placeholders with your own values.

## Details

- Server version: 1.21.0
- Last checked: 2026-10-03
- Listed: 2026-10-03
- Updated: 2026-10-04

---
Source: https://mcp.tc/i/sonarqube (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
