Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. Sonar MCP Server
S
Health: Not checked yetWe have not completed a health check for this listing yet.No health check has run yet.

Sonar MCP Server

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View RepositoryVisit Website

Read-only SonarQube Community Build access for AI agents: issues, hotspots, rules, code snippets

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet β€” we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself β€” its README, its docs, or a verified owner. We haven’t found those for Sonar MCP Server, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Directory Badge Claim listing AlternativesπŸ”’ More in Security

Documentation Overview

Sonar MCP Server

CI Release License Java 25 MCP Glama score Listed on mcpservers.org

A local MCP server providing read-only access to a SonarQube Community Build (26.4+) instance via its web-api. It lets AI agents (Claude Code, Cursor, VS Code Copilot, etc.) fetch a project's issue list, the files and locations where they occur, rule descriptions, source-code snippets around issues, and Security Hotspots.

Typical scenario: "find and fix Sonar issues in such-and-such project" β€” the LLM calls listIssues, optionally getRule and getIssueSnippets, and edits files locally.

Why this server

There is an official SonarSource MCP server, but it targets SonarQube 10+ (and SonarCloud) and assumes a cloud-style deployment. This server is built for self-hosted SonarQube Community Build 26.4+ installations that expose the classic /api/ web-api. It supports both Standard Experience and MQR mode, handling per-software-quality impacts when the instance runs in MQR mode.

It is also intentionally narrower in scope:

  • Read-only by design. The server never creates, updates, or deletes anything in SonarQube β€” no marking issues as false-positive, no editing comments, no admin endpoints. The token's write permissions in SonarQube are irrelevant because the server never calls those endpoints.
  • Curated tool set. Instead of mirroring the SonarQube API surface, the server exposes a small, focused set of tools (13 in total) chosen for a single workflow: let an AI agent read Sonar's findings and fix the code based on them. Listing components, issues and hotspots, drilling into a single finding, fetching the rule explanation, and pulling the source-code snippet around the location β€” and that's it. Anything outside this "diagnose -> fix the code locally" loop is deliberately left out to keep the tool list small and the agent's choices unambiguous.

In short: a focused, read-only bridge from a self-hosted SonarQube Community Build to an AI coding agent.

Quick start

  1. Install JDK 25+.
  2. Download sonar-mcp-server.jar from the latest release, or build it yourself: ./gradlew bootJar (see Build). A Docker image is published as well.
  3. Get your SonarQube URL and user token (see Configuration).
  4. Add the JAR to your client's MCP configuration (see Connecting to an AI client).

For Claude Code that is one command:

Terminal
claude mcp add --scope user -e SONAR_URL=https://sonar.example.com -e SONAR_TOKEN=your_token -- sonar java -jar /path/to/sonar-mcp-server.jar

Architecture

The server only supports the stdio transport.

Code
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”     stdio      β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”    web-api     β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  AI agent   β”‚ <------------> β”‚  sonar-mcp-      β”‚ -------------> β”‚ SonarQubeβ”‚
β”‚ (Claude Codeβ”‚   stdin/stdout β”‚  server (Java)   β”‚  HTTP + Bearer  β”‚  CB 26.4+β”‚
β”‚  Cursor...) β”‚                β”‚                  β”‚  auth (token)   β”‚          β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜                β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜                β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

The AI client spawns the server as a child process; communication uses the MCP protocol over stdin/stdout. The server does not open any HTTP port and accepts no incoming connections.

Tools

The server exports 13 read-only MCP tools.

Projects

ToolDescription
listProjectsList of SonarQube projects. Parameters: query (name substring), limit, offset. Returns key, name, qualifier.
listComponentsSearch/browse components inside a project using Sonar's component tree. Parameters: projectKey, query, qualifiers, branch / pullRequest, limit, offset. Returns opaque component key values plus path, qualifier, name, language, and project. Use returned key values unchanged as listIssues.componentKeys; do not pass Java package names directly as component keys.
getProjectProject overview: header info (name, qualifier, visibility, description, version, last analysis date), quality gate status with failed conditions, and curated metrics (ncloc, bugs, vulnerabilities, security hotspots, code smells, coverage, duplicated lines density, technical debt in minutes, alert status). Parameters: projectKey, branch (opt.), pullRequest (opt.).
listProjectBranchesList of branches analysed for the project. Each entry: name, isMain, type (LONG/SHORT/BRANCH), excludedFromPurge, analysisDate, qualityGateStatus, plus bugs/vulnerabilities/codeSmells counts. No pagination β€” Sonar returns all branches at once.
listProjectPullRequestsList of PR analyses for the project. Each entry: PR key (use as pullRequest= elsewhere), title, branch (head), base, url, analysisDate, qualityGateStatus, plus bugs/vulnerabilities/codeSmells counts. Empty list if the Sonar install has no DevOps integration.

Issues

ToolDescription
listIssuesFlat list of issues for a project. Parameters: projectKey (required unless defaulted), componentPathPrefix (opt.) β€” a single subtree-or-file filter relative to the Sonar project root (e.g. bc-doc/src/main/java/ru/foo or bc-doc/src/main/java/ru/foo/Bar.java); convert Java/Kotlin package dots to slashes; honours directory boundaries (bc-doc/src does not match bc-doc/srcExtra). Plus severities, types, statuses, rules, branch / pullRequest (mutually exclusive), resolved, limit, offset. By default returns only open issues (resolved=false, statuses OPEN/CONFIRMED/REOPENED). Each item contains the rule, severity, type, status, file path, line, primary textRange, and secondary flows for cross-file rules. When componentPathPrefix is used, the server scans the project and filters client-side; the scan is capped (default 10000 issues) β€” if the cap is hit, pathPrefixTruncated=true in the response.
getIssueDetails of a single issue by key plus its change history (changelog). Accepts optional branch / pullRequest.
getIssueSnippetsSource-code snippets around all issue locations (primary plus flows for cross-file rules). For each location: componentPath, language, and an array of source lines with SCM info. Useful when the repository isn't available locally or you need to see exactly the file version Sonar analyzed. Accepts optional branch / pullRequest β€” important when the issue lives on a non-main ref whose files differ from main.
getProjectIssuesSummaryAggregated summary of open issues in a project: total plus breakdowns by severity, type, status, rule, tag, and SCM author. Parameters mirror listIssues (incl. componentPathPrefix) except pagination.
getProjectIssuesBreakdownMulti-module aggregation of issues by logical module and rule. Module is derived from the first componentPath segment. Parameters mirror getProjectIssuesSummary.

Rules

ToolDescription
getRuleDetails of a Sonar rule by key (e.g. java:S1234): title, severity, type, language, tags, description sections (introduction, root cause, how to fix, resources). Backed by an in-memory cache β€” repeated calls are free.

Security Hotspots

ToolDescription
listHotspotsList of Security Hotspots for a project. Hotspots are a separate category from issues, marking spots that require manual security review. By default Sonar returns hotspots in status TO_REVIEW. Parameters: projectKey, componentPathPrefix (opt.) β€” same prefix semantics as on listIssues, status (opt.), branch / pullRequest (opt., mutually exclusive), limit, offset. Subject to the same client-side scan cap (pathPrefixTruncated flag in the response).
getHotspotSecurity Hotspot details: full rule description (risk, vulnerability, fix recommendations), primary textRange, secondary flows, changelog. Hotspot keys are globally unique, so no branch/pullRequest parameter is needed.

All tools are read-only β€” no data in SonarQube is modified.

Working with branches and pull requests

Sonar analyses a branch and a pull request as two distinct, mutually exclusive scopes. The Sonar web-api accepts either branch= or pullRequest= on a single request, never both.

  • branch β€” long-lived branches (main, develop, feature/...). Resolved as: explicit branch argument β†’ SONAR_DEFAULT_BRANCH β†’ none (Sonar uses the project's main branch).
  • pullRequest β€” the Sonar PR key, usually the PR/MR number. Independent from branch analyses; PR analyses often contain the most relevant findings for in-flight work. Pull request keys never fall back to a server-level default β€” pass them explicitly.

Passing both branch and pullRequest to the same tool call is an error. Use listProjectBranches / listProjectPullRequests to discover available refs.

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Security View all alternatives
  • I
    Ida Pro MCP

    MCP server for IDA Pro, allowing you to perform binary analysis with AI assistants. This plugin implement decompilation, disassembly and allows you to generate malware analysis reports automatically.

    πŸ”’ Security4 views
    Compare vs Ida Pro MCP β†’
  • A
    Agent Security Scanner MCP

    Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.

    πŸ”’ Security1 views
    Compare vs Agent Security Scanner MCP β†’
  • C
    CrowdStrike Falcon MCP Server

    Connects AI agents with CrowdStrike Falcon for security analysis and automation.

    πŸ”’ Security1 views
    Compare vs CrowdStrike Falcon MCP Server β†’
  • U
    Ui Ux Suite

    UI/UX design-audit MCP server: scores a project on 12 dimensions vs WCAG 2.2 + APCA.

    πŸ”’ Security1 views
    Compare vs Ui Ux Suite β†’

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Sonar MCP Server

We don't have a confirmed install command for Sonar MCP Server yet, so we don't publish a generated one β€” a guessed package name would point at the wrong package or none at all. Follow the project's own README or setup instructions (https://github.com/igorolv/sonar-mcp-server) for the current steps.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewSonar MCP Server AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/sonar-mcp-server?style=directory)](https://allmcps.com/mcp/sonar-mcp-server)
HTML Embed
<a href="https://allmcps.com/mcp/sonar-mcp-server"><img src="https://allmcps.com/api/badge/sonar-mcp-server?style=directory" alt="Sonar MCP Server on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
More technical detailsExpand β–Ύ
Last updatedSep 28, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
27Quality signal: Emerging Β· 27/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership8/20
Documentation & tools11/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to Sonar MCP Server β†’Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients