SonarQube MCP Server
The official SonarQube MCP server, surfacing code quality and security analysis to AI agents. Pull issues, hotspots and quality-gate status for a project so an agent can act on findings instead of re-deriving them.
Install SonarQube
- Published by
- Official (vendor)
- Transport
- Remote (HTTP)
- Authentication
- API key
Claude Desktop, Claude Code and Cursor
Add this to the mcpServers object in your client's
config file, then restart the client.
{
"mcpServers": {
"sonarqube": {
"type": "http",
"url": "https://api.sonarcloud.io/mcp",
"headers": {
"Authorization": "Bearer ${SONARQUBE_USER_TOKEN}",
"SONARQUBE_ORG": "${SONARQUBE_ORG}"
}
}
}
}
VS Code uses a different key — show that config
Identical entry, filed under servers rather than
mcpServers. Put it in
.vscode/mcp.json for one workspace.
{
"servers": {
"sonarqube": {
"type": "http",
"url": "https://api.sonarcloud.io/mcp",
"headers": {
"Authorization": "Bearer ${SONARQUBE_USER_TOKEN}",
"SONARQUBE_ORG": "${SONARQUBE_ORG}"
}
}
}
}
Before it will answer
It has to be a SonarQube USER token. Project tokens, global tokens and scoped organization tokens all authenticate but leave the binding broken, which is the failure people spend an afternoon on. US-region SonarQube Cloud organizations use https://api.sonarqube.us/mcp instead of the URL shown. Self-hosted SonarQube Server can install the MCP server as an extension and proxy it at <YourSonarQubeURL>/mcp; there is also a sonarsource/sonarqube-mcp container and a standalone JAR needing Java 21+.