Sonatype Guide

listing.by

Look up open-source component versions, vulnerabilities and Trust Score upgrade recommendations from Sonatype.

state.key.long (state.key.title)Streamable HTTP

listing.connect

listing.explain.api_key

https://mcp.guide.sonatype.com/mcp

listing.note.key_header listing.note.key_where

listing.share.h

listing.share.p

mcp.tc/i/sonatype

listing.about

Connects an AI coding assistant to Sonatype's dependency intelligence. It helps pick component versions, check open-source packages for known vulnerabilities and license issues, review dependency health, and get Trust Score based recommendations before adding or upgrading a dependency.

Runs as a hosted remote server over streamable HTTP at https://mcp.guide.sonatype.com/mcp. A Sonatype Guide account and a personal API token are required, sent as a Bearer token in the Authorization header. Clients that only support stdio can use mcp-remote.

listing.can

  • Choose a suitable version of an open-source component
  • Check dependencies for known security vulnerabilities
  • Check dependencies against license compliance policies
  • Review dependency health and maintenance status
  • Get Trust Score based upgrade and remediation recommendations

listing.tools

listing.notools.key

listing.prompts

  • Which version of lodash should I upgrade to, and are there known vulnerabilities?

  • Check the dependencies I'm about to add for security and license problems.

  • Recommend a safer version of log4j-core for this project.

  • How healthy and well maintained is the requests package?

listing.setup.h

listing.setup.remote

Claude Code

  1. Run this in a terminal, in your project folder:
claude mcp add --transport http sonatype https://mcp.guide.sonatype.com/mcp --header "Authorization: Bearer <YOUR_API_KEY>"
  1. Replace the placeholder with your key before you run it, then check it with /mcp inside Claude Code.

Add --scope user to make it available in every project, not just this one.

Claude Desktop

  1. Custom connectors can't send this server's key header, so use the mcp-remote bridge. Open Settings → Developer → Edit Config and add:
claude_desktop_config.json
{
  "mcpServers": {
    "sonatype": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://mcp.guide.sonatype.com/mcp",
        "--header",
        "Authorization: Bearer <YOUR_API_KEY>"
      ]
    }
  }
}
  1. Replace the placeholder with your key and restart Claude Desktop.

The bridge needs Node.js on your computer.

Cursor

Or add it by hand to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (this project):

mcp.json
{
  "mcpServers": {
    "sonatype": {
      "url": "https://mcp.guide.sonatype.com/mcp",
      "headers": {
        "Authorization": "Bearer <YOUR_API_KEY>"
      }
    }
  }
}

VS Code

Add it to .vscode/mcp.json. VS Code asks for the key the first time and stores it securely:

.vscode/mcp.json
{
  "servers": {
    "sonatype": {
      "type": "http",
      "url": "https://mcp.guide.sonatype.com/mcp",
      "headers": {
        "Authorization": "Bearer ${input:api-key}"
      }
    }
  },
  "inputs": [
    {
      "type": "promptString",
      "id": "api-key",
      "description": "API key",
      "password": true
    }
  ]
}

Devin Desktop

  1. Add it to ~/.config/devin/mcp_config.json (macOS and Linux) or %APPDATA%\devin\mcp_config.json (Windows):
mcp_config.json
{
  "mcpServers": {
    "sonatype": {
      "serverUrl": "https://mcp.guide.sonatype.com/mcp",
      "headers": {
        "Authorization": "Bearer <YOUR_API_KEY>"
      }
    }
  }
}
  1. Refresh the MCP server list in Cascade.

Devin Desktop is the new name for Windsurf. It reads serverUrl (or url) for remote servers.

Codex

codex mcp add sonatype --url https://mcp.guide.sonatype.com/mcp --bearer-token-env-var SONATYPE_API_KEY

Or edit ~/.codex/config.toml directly:

config.toml
[mcp_servers.sonatype]
url = "https://mcp.guide.sonatype.com/mcp"
bearer_token_env_var = "SONATYPE_API_KEY"

Set SONATYPE_API_KEY to your key in the shell that runs Codex.

Gemini CLI

gemini mcp add --transport http --header "Authorization: Bearer <YOUR_API_KEY>" sonatype https://mcp.guide.sonatype.com/mcp

This adds it to the current project. Add -s user to use it everywhere.

Any client

Most clients accept this shape. Some name the URL field differently: serverUrl in Devin Desktop, httpUrl in Gemini CLI's settings file.

{
  "mcpServers": {
    "sonatype": {
      "type": "http",
      "url": "https://mcp.guide.sonatype.com/mcp",
      "headers": {
        "Authorization": "Bearer <YOUR_API_KEY>"
      }
    }
  }
}

Zed puts servers under context_servers in its settings. Cline needs "type": "streamableHttp", or it assumes SSE.

Client only starts local servers? Bridge it with npx -y mcp-remote https://mcp.guide.sonatype.com/mcp.

listing.faq

Can I paste mcp.tc/i/sonatype into my MCP client?

No. mcp.tc links are pages, not server addresses. Connect with https://mcp.guide.sonatype.com/mcp, so your client talks to Sonatype Guide directly. Your key goes there too, never to mcp.tc. The quick link is for sharing: it opens this page, with setup steps for every client.

Does Sonatype Guide need an API key or a sign-in?

Yes. Sonatype Guide needs an API key, sent as the Authorization header. Get one from Sonatype and keep it in your client's config, never in a shared file.

Is Sonatype Guide a remote or a local server?

Remote. Sonatype hosts it at https://mcp.guide.sonatype.com/mcp, and it speaks Streamable HTTP. There's nothing to install.

What can Sonatype Guide do?

You can choose a suitable version of an open-source component, check dependencies for known security vulnerabilities and check dependencies against license compliance policies.

Which clients can use it?

Any client that supports remote MCP servers and can send your key: Claude Code, Cursor, VS Code, Devin Desktop, Codex, Gemini CLI, Zed and others, and Claude Desktop through the mcp-remote bridge. claude.ai and ChatGPT can't send a key, so they can't use it.

Who wrote this page?

mcp.tc's robot read Sonatype Guide's own metadata (its MCP handshake, tool list and public pages), and an AI model drafted the text from it. A person reviews anything the checks can't confirm. The text can still be wrong, so if you spot a mistake, use Report this listing on this page.

listing.em.h

listing.em.lead listing.em.how

listing.em.badge

em.prev_lightem.prev_dark
Markdown
[![Sonatype Guide on mcp.tc](https://mcp.tc/i/sonatype/badge.svg)](https://mcp.tc/i/sonatype)
HTML
<a href="https://mcp.tc/i/sonatype"><img src="https://mcp.tc/i/sonatype/badge.svg" alt="Sonatype Guide on mcp.tc" height="20"></a>

listing.em.badge_note

listing.em.widget

HTML
<script src="https://mcp.tc/w/sonatype.js" async></script>

listing.em.widget_note

iframe

HTML
<iframe src="https://mcp.tc/embed/sonatype" title="Sonatype Guide on mcp.tc" width="420" height="200" loading="lazy" allow="clipboard-write" style="border:0;border-radius:8px;max-width:100%"></iframe>

listing.em.iframe_note

JSON

listing.em.json

https://mcp.tc/i/sonatype.json

listing.em.fields

listing.disclaimer_checked