SonarQube MCP Server

By thumbsupordown

The official SonarQube MCP server, surfacing code quality and security analysis to AI agents. Pull issues, hotspots and quality-gate status for a project so an agent can act on findings instead of re-deriving them.

Install SonarQube

Published by
Official (vendor)
Transport
Remote (HTTP)
Authentication
API key

Claude Desktop, Claude Code and Cursor

Add this to the mcpServers object in your client's config file, then restart the client.

{
  "mcpServers": {
    "sonarqube": {
      "type": "http",
      "url": "https://api.sonarcloud.io/mcp",
      "headers": {
        "Authorization": "Bearer ${SONARQUBE_USER_TOKEN}",
        "SONARQUBE_ORG": "${SONARQUBE_ORG}"
      }
    }
  }
}
VS Code uses a different key — show that config

Identical entry, filed under servers rather than mcpServers. Put it in .vscode/mcp.json for one workspace.

{
  "servers": {
    "sonarqube": {
      "type": "http",
      "url": "https://api.sonarcloud.io/mcp",
      "headers": {
        "Authorization": "Bearer ${SONARQUBE_USER_TOKEN}",
        "SONARQUBE_ORG": "${SONARQUBE_ORG}"
      }
    }
  }
}

Before it will answer

It has to be a SonarQube USER token. Project tokens, global tokens and scoped organization tokens all authenticate but leave the binding broken, which is the failure people spend an afternoon on. US-region SonarQube Cloud organizations use https://api.sonarqube.us/mcp instead of the URL shown. Self-hosted SonarQube Server can install the MCP server as an extension and proxy it at <YourSonarQubeURL>/mcp; there is also a sonarsource/sonarqube-mcp container and a standalone JAR needing Java 21+.

Documentation ↗ Source ↗ Config checked against vendor docs August 25, 2026 · how we verify

Want to create your own MCP server?

Create an account to add and manage your own MCP servers.