# Sonatype Guide MCP server

> Look up open-source component versions, vulnerabilities and Trust Score upgrade recommendations from Sonatype.

- Listing: https://mcp.tc/i/sonatype
- Connect: use the server's own URL `https://mcp.guide.sonatype.com/mcp` (with your API key); clients connect to it directly. The listing link is a page, not an MCP endpoint.
- Type: remote (Streamable HTTP)
- Auth: API key
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: Sonatype
- Homepage: <https://guide.sonatype.com/>
- Repository: <https://github.com/sonatype/dependency-management-mcp-server>

## About

Connects an AI coding assistant to Sonatype's dependency intelligence. It helps pick component versions, check open-source packages for known vulnerabilities and license issues, review dependency health, and get Trust Score based recommendations before adding or upgrading a dependency.

Runs as a hosted remote server over streamable HTTP at https://mcp.guide.sonatype.com/mcp. A Sonatype Guide account and a personal API token are required, sent as a Bearer token in the Authorization header. Clients that only support stdio can use mcp-remote.

## What it can do

- Choose a suitable version of an open-source component
- Check dependencies for known security vulnerabilities
- Check dependencies against license compliance policies
- Review dependency health and maintenance status
- Get Trust Score based upgrade and remediation recommendations

## Example prompts

- "Which version of lodash should I upgrade to, and are there known vulnerabilities?"
- "Check the dependencies I'm about to add for security and license problems."
- "Recommend a safer version of log4j-core for this project."
- "How healthy and well maintained is the requests package?"

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport http sonatype https://mcp.guide.sonatype.com/mcp --header "Authorization: Bearer <YOUR_API_KEY>"
```

2. Replace the placeholder with your key before you run it, then check it with `/mcp` inside Claude Code.

Add `--scope user` to make it available in every project, not just this one.

### Claude Desktop

1. Custom connectors can’t send this server’s key header, so use the `mcp-remote` bridge. Open **Settings → Developer → Edit Config** and add:

`claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "sonatype": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://mcp.guide.sonatype.com/mcp",
        "--header",
        "Authorization: Bearer <YOUR_API_KEY>"
      ]
    }
  }
}
```

2. Replace the placeholder with your key and restart Claude Desktop.

The bridge needs Node.js on your computer.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=sonatype&config=eyJ1cmwiOiJodHRwczovL21jcC5ndWlkZS5zb25hdHlwZS5jb20vbWNwIiwiaGVhZGVycyI6eyJBdXRob3JpemF0aW9uIjoiQmVhcmVyIDxZT1VSX0FQSV9LRVk%2BIn19>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "sonatype": {
      "url": "https://mcp.guide.sonatype.com/mcp",
      "headers": {
        "Authorization": "Bearer <YOUR_API_KEY>"
      }
    }
  }
}
```

### VS Code

Add it to `.vscode/mcp.json`. VS Code asks for the key the first time and stores it securely:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "sonatype": {
      "type": "http",
      "url": "https://mcp.guide.sonatype.com/mcp",
      "headers": {
        "Authorization": "Bearer ${input:api-key}"
      }
    }
  },
  "inputs": [
    {
      "type": "promptString",
      "id": "api-key",
      "description": "API key",
      "password": true
    }
  ]
}
```

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "sonatype": {
      "serverUrl": "https://mcp.guide.sonatype.com/mcp",
      "headers": {
        "Authorization": "Bearer <YOUR_API_KEY>"
      }
    }
  }
}
```

2. Refresh the MCP server list in Cascade.

Devin Desktop is the new name for Windsurf. It reads `serverUrl` (or `url`) for remote servers.

### Codex

```bash
codex mcp add sonatype --url https://mcp.guide.sonatype.com/mcp --bearer-token-env-var SONATYPE_API_KEY
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.sonatype]
url = "https://mcp.guide.sonatype.com/mcp"
bearer_token_env_var = "SONATYPE_API_KEY"
```

Set `SONATYPE_API_KEY` to your key in the shell that runs Codex.

### Gemini CLI

```bash
gemini mcp add --transport http --header "Authorization: Bearer <YOUR_API_KEY>" sonatype https://mcp.guide.sonatype.com/mcp
```

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients accept this shape. Some name the URL field differently: `serverUrl` in Devin Desktop, `httpUrl` in Gemini CLI’s settings file.

```json
{
  "mcpServers": {
    "sonatype": {
      "type": "http",
      "url": "https://mcp.guide.sonatype.com/mcp",
      "headers": {
        "Authorization": "Bearer <YOUR_API_KEY>"
      }
    }
  }
}
```

Zed puts servers under `context_servers` in its settings. Cline needs `"type": "streamableHttp"`, or it assumes SSE.

Client only starts local servers? Bridge it with `npx -y mcp-remote https://mcp.guide.sonatype.com/mcp`.

## Details

- Server version: 1.0.2
- Last checked: 2026-10-03 (reachable, asks for credentials)
- Listed: 2026-10-03
- Updated: 2026-10-03

---
Source: https://mcp.tc/i/sonatype (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
