Skip to content

SonarQube MCP Server

Integration with SonarQube for static code analysis, quality gates, and security vulnerability detection.

Capabilities
Code Quality Security Scanning Quality Gates Reports
Maintained by
SonarSource
Hosting
Runs locally on your machine
Authentication
API key or credentials (environment variables)
Last checked

Config shown is for SonarQube Cloud; for SonarQube Server pass SONARQUBE_URL instead of SONARQUBE_ORG.

How to connect the SonarQube MCP server

Pick your AI client and paste the snippet. Swap the YOUR_… placeholders for your own values. New to this? Our guide to how MCP clients and servers fit together explains what each piece does.

Claude Code

Terminal
claude mcp add --env SONARQUBE_TOKEN=YOUR_TOKEN --env SONARQUBE_ORG=YOUR_ORG --transport stdio sonarqube \
  -- docker run --init --pull=always -i --rm -e SONARQUBE_TOKEN -e SONARQUBE_ORG sonarsource/sonarqube-mcp
Full Claude Code setup guide →

Claude Desktop

claude_desktop_config.json (Settings → Developer → Edit Config)
{
  "mcpServers": {
    "sonarqube": {
      "command": "docker",
      "args": [
        "run",
        "--init",
        "--pull=always",
        "-i",
        "--rm",
        "-e",
        "SONARQUBE_TOKEN",
        "-e",
        "SONARQUBE_ORG",
        "sonarsource/sonarqube-mcp"
      ],
      "env": {
        "SONARQUBE_TOKEN": "YOUR_TOKEN",
        "SONARQUBE_ORG": "YOUR_ORG"
      }
    }
  }
}

Fully quit and reopen Claude Desktop after saving.

Full Claude Desktop setup guide →

Cursor

~/.cursor/mcp.json (or .cursor/mcp.json in a project)
{
  "mcpServers": {
    "sonarqube": {
      "command": "docker",
      "args": [
        "run",
        "--init",
        "--pull=always",
        "-i",
        "--rm",
        "-e",
        "SONARQUBE_TOKEN",
        "-e",
        "SONARQUBE_ORG",
        "sonarsource/sonarqube-mcp"
      ],
      "env": {
        "SONARQUBE_TOKEN": "YOUR_TOKEN",
        "SONARQUBE_ORG": "YOUR_ORG"
      }
    }
  }
}
Full Cursor setup guide →

VS Code

.vscode/mcp.json
{
  "servers": {
    "sonarqube": {
      "type": "stdio",
      "command": "docker",
      "args": [
        "run",
        "--init",
        "--pull=always",
        "-i",
        "--rm",
        "-e",
        "SONARQUBE_TOKEN",
        "-e",
        "SONARQUBE_ORG",
        "sonarsource/sonarqube-mcp"
      ],
      "env": {
        "SONARQUBE_TOKEN": "YOUR_TOKEN",
        "SONARQUBE_ORG": "YOUR_ORG"
      }
    }
  }
}
Full VS Code setup guide →

Frequently asked questions

What is the SonarQube MCP server?

It is a Model Context Protocol (MCP) server — a small piece of software that gives AI assistants like Claude a secure, governed connection to SonarQube. Integration with SonarQube for static code analysis, quality gates, and security vulnerability detection.

Is there an official SonarQube MCP server?

Yes. The SonarQube MCP server is an official integration, maintained by the vendor or the Model Context Protocol project, which makes it the safest default for business use. It is maintained by SonarSource.

Is the SonarQube MCP server hosted, or do I run it myself?

It runs locally. Your AI client starts it on your own machine with docker, and it talks to the client over standard input and output rather than the network.

Do I need an API key for the SonarQube MCP server?

Yes. The local server reads SONARQUBE_TOKEN, SONARQUBE_ORG from its environment, so you create those credentials first and add them to your client's config.

What can an AI assistant actually do with SonarQube?

Through this server an assistant can work with code quality, security scanning, quality gates, reports — reading from and acting on SonarQube directly instead of you copy-pasting between windows. What you allow it to do is controlled by the permissions you grant.

How do I set this up for my business?

The setup section above has copy-paste config for Claude Code, Claude Desktop, Cursor and VS Code. If you want it rolled out across a team with permissions, governance and support handled, that is what Crox's Build engagement covers.

New to MCP? Start with our plain-English guide to the Model Context Protocol or see how to connect AI to your business tools without writing code .

Done-for-you integration

Want this connected to your business — with governance handled?

Crox maps your processes, connects AI to the tools you already use, and keeps it working as models change. Start with a readiness assessment or talk to us about a build.