Sonatype Guide
listing.by
Look up open-source component versions, vulnerabilities and Trust Score upgrade recommendations from Sonatype.
listing.connect
listing.explain.api_key
listing.note.key_header listing.note.key_where
listing.share.h
listing.share.p
mcp.tc/i/sonatypelisting.about
Connects an AI coding assistant to Sonatype's dependency intelligence. It helps pick component versions, check open-source packages for known vulnerabilities and license issues, review dependency health, and get Trust Score based recommendations before adding or upgrading a dependency.
Runs as a hosted remote server over streamable HTTP at https://mcp.guide.sonatype.com/mcp. A Sonatype Guide account and a personal API token are required, sent as a Bearer token in the Authorization header. Clients that only support stdio can use mcp-remote.
listing.can
- Choose a suitable version of an open-source component
- Check dependencies for known security vulnerabilities
- Check dependencies against license compliance policies
- Review dependency health and maintenance status
- Get Trust Score based upgrade and remediation recommendations
listing.tools
listing.notools.key
listing.prompts
Which version of lodash should I upgrade to, and are there known vulnerabilities?
Check the dependencies I'm about to add for security and license problems.
Recommend a safer version of log4j-core for this project.
How healthy and well maintained is the requests package?
listing.setup.h
listing.setup.remote
Claude Code
- Run this in a terminal, in your project folder:
claude mcp add --transport http sonatype https://mcp.guide.sonatype.com/mcp --header "Authorization: Bearer <YOUR_API_KEY>"- Replace the placeholder with your key before you run it, then check it with
/mcpinside Claude Code.
Add --scope user to make it available in every project, not just this one.
Claude Desktop
- Custom connectors can't send this server's key header, so use the
mcp-remotebridge. Open Settings → Developer → Edit Config and add:
{
"mcpServers": {
"sonatype": {
"command": "npx",
"args": [
"-y",
"mcp-remote",
"https://mcp.guide.sonatype.com/mcp",
"--header",
"Authorization: Bearer <YOUR_API_KEY>"
]
}
}
}- Replace the placeholder with your key and restart Claude Desktop.
The bridge needs Node.js on your computer.
Cursor
Or add it by hand to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (this project):
{
"mcpServers": {
"sonatype": {
"url": "https://mcp.guide.sonatype.com/mcp",
"headers": {
"Authorization": "Bearer <YOUR_API_KEY>"
}
}
}
}VS Code
Add it to .vscode/mcp.json. VS Code asks for the key the first time and stores it securely:
{
"servers": {
"sonatype": {
"type": "http",
"url": "https://mcp.guide.sonatype.com/mcp",
"headers": {
"Authorization": "Bearer ${input:api-key}"
}
}
},
"inputs": [
{
"type": "promptString",
"id": "api-key",
"description": "API key",
"password": true
}
]
}Devin Desktop
- Add it to
~/.config/devin/mcp_config.json(macOS and Linux) or%APPDATA%\devin\mcp_config.json(Windows):
{
"mcpServers": {
"sonatype": {
"serverUrl": "https://mcp.guide.sonatype.com/mcp",
"headers": {
"Authorization": "Bearer <YOUR_API_KEY>"
}
}
}
}- Refresh the MCP server list in Cascade.
Devin Desktop is the new name for Windsurf. It reads serverUrl (or url) for remote servers.
Codex
codex mcp add sonatype --url https://mcp.guide.sonatype.com/mcp --bearer-token-env-var SONATYPE_API_KEYOr edit ~/.codex/config.toml directly:
[mcp_servers.sonatype]
url = "https://mcp.guide.sonatype.com/mcp"
bearer_token_env_var = "SONATYPE_API_KEY"Set SONATYPE_API_KEY to your key in the shell that runs Codex.
Gemini CLI
gemini mcp add --transport http --header "Authorization: Bearer <YOUR_API_KEY>" sonatype https://mcp.guide.sonatype.com/mcpThis adds it to the current project. Add -s user to use it everywhere.
Any client
Most clients accept this shape. Some name the URL field differently: serverUrl in Devin Desktop, httpUrl in Gemini CLI's settings file.
{
"mcpServers": {
"sonatype": {
"type": "http",
"url": "https://mcp.guide.sonatype.com/mcp",
"headers": {
"Authorization": "Bearer <YOUR_API_KEY>"
}
}
}
}Zed puts servers under context_servers in its settings. Cline needs "type": "streamableHttp", or it assumes SSE.
Client only starts local servers? Bridge it with npx -y mcp-remote https://mcp.guide.sonatype.com/mcp.
listing.faq
Can I paste mcp.tc/i/sonatype into my MCP client?
No. mcp.tc links are pages, not server addresses. Connect with https://mcp.guide.sonatype.com/mcp, so your client talks to Sonatype Guide directly. Your key goes there too, never to mcp.tc. The quick link is for sharing: it opens this page, with setup steps for every client.
Does Sonatype Guide need an API key or a sign-in?
Yes. Sonatype Guide needs an API key, sent as the Authorization header. Get one from Sonatype and keep it in your client's config, never in a shared file.
Is Sonatype Guide a remote or a local server?
Remote. Sonatype hosts it at https://mcp.guide.sonatype.com/mcp, and it speaks Streamable HTTP. There's nothing to install.
What can Sonatype Guide do?
You can choose a suitable version of an open-source component, check dependencies for known security vulnerabilities and check dependencies against license compliance policies.
Which clients can use it?
Any client that supports remote MCP servers and can send your key: Claude Code, Cursor, VS Code, Devin Desktop, Codex, Gemini CLI, Zed and others, and Claude Desktop through the mcp-remote bridge. claude.ai and ChatGPT can't send a key, so they can't use it.
Who wrote this page?
mcp.tc's robot read Sonatype Guide's own metadata (its MCP handshake, tool list and public pages), and an AI model drafted the text from it. A person reviews anything the checks can't confirm. The text can still be wrong, so if you spot a mistake, use Report this listing on this page.
listing.em.h
listing.em.lead listing.em.how
listing.em.badge
[](https://mcp.tc/i/sonatype)<a href="https://mcp.tc/i/sonatype"><img src="https://mcp.tc/i/sonatype/badge.svg" alt="Sonatype Guide on mcp.tc" height="20"></a>listing.em.badge_note
listing.em.widget
<script src="https://mcp.tc/w/sonatype.js" async></script>listing.em.widget_note
iframe
<iframe src="https://mcp.tc/embed/sonatype" title="Sonatype Guide on mcp.tc" width="420" height="200" loading="lazy" allow="clipboard-write" style="border:0;border-radius:8px;max-width:100%"></iframe>listing.em.iframe_note
listing.disclaimer_checked