BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

SonarQube MCP Server

Connector Security Usable
Works inClaude Code Claude Cowork Claude Chat
Usable Reviewed

Bridges existing SonarQube investments into AI workflows. Enterprise-grade code quality data accessible via natural language.

SonarSource-official MCP server bringing code quality and security analysis into Claude workflows. Query issues, metrics, and findings.

623 starsFreeNo code needed
Usable rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

Bridges existing SonarQube investments into AI workflows. Enterprise-grade code quality data accessible via natural language.

Teams with existing SonarQube Server or Cloud subscriptions. DevSecOps workflows.

Claude Code Claude Cowork Claude Chat

https://github.com/SonarSource/sonarqube-mcp-server

By SonarSource

How to Get It

Option 1: Claude Desktop AppOpen the Customize panel in the sidebar → browse connectors → search and add. Works in Claude Code, Claude Cowork, and Claude Chat.
Option 2: Paste into Claude CodeCopy the command below and paste it into a Claude Code conversation. Claude will run it for you.
Command
claude mcp add sonarqube --env SONARQUBE_TOKEN=$SONAR_TOKEN --env SONARQUBE_ORG=$SONAR_ORG -- docker run --init --pull=always -i --rm -e SONARQUBE_TOKEN -e SONARQUBE_ORG sonarsource/sonarqube-mcp

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

First thing to try

Once it’s connected, paste this into Claude:

Help me check code quality scores and outstanding issue counts
PrerequisitesDocker or any OCI-compatible container runtime; a SonarQube user token; organization key (SonarQube Cloud) or server URL (SonarQube Server)CostFree

Trust Signals Reviewed

Stars623Contributors29Last updated2026-08-14Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-08-16 · scanner v1

Data & Access

Data processingPrompts sent to Anthropic API. Enterprise/Team plans exclude training.

Community Pulse Growing

Discussed on Reddit

3 mentions across 1 sources

Reviewer notes

Reviewed review. These are observations, not a security certification.

453 stars, SonarSource-official. Docker-first deployment. Requires SonarQube subscription.

Official vendor. Docker isolation. Read-only access to SonarQube data. No file system writes.

Things to check

  • Requires a running SonarQube Server or Cloud instance and a user token. Not read-only by default: it ships write tools (e.g., change issue status, review security hotspots); set SONARQUBE_READ_ONLY=true to disable write operations. Latency depends on instance performance and project size.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
3/5
Versatility
3/5
Reliability
4/5
Security
4/5
Overall score3.40 / 5.00 UsableEvaluatedApr 2026
453 stars, SonarSource-official. Docker-first deployment. Requires SonarQube subscription.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →