Read-only SonarQube Community Build access for AI agents: issues, hotspots, rules, code snippets
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
A local MCP server providing read-only access to a SonarQube Community Build (26.4+) instance via its web-api. It lets AI agents (Claude Code, Cursor, VS Code Copilot, etc.) fetch a project's issue list, the files and locations where they occur, rule descriptions, source-code snippets around issues, and Security Hotspots.
Typical scenario: "find and fix Sonar issues in such-and-such project" β the LLM calls listIssues, optionally getRule and getIssueSnippets, and edits files locally.
There is an official SonarSource MCP server, but it targets SonarQube 10+ (and SonarCloud) and assumes a cloud-style deployment. This server is built for self-hosted SonarQube Community Build 26.4+ installations that expose the classic /api/ web-api. It supports both Standard Experience and MQR mode, handling per-software-quality impacts when the instance runs in MQR mode.
It is also intentionally narrower in scope:
In short: a focused, read-only bridge from a self-hosted SonarQube Community Build to an AI coding agent.
sonar-mcp-server.jar from the latest release,
or build it yourself: ./gradlew bootJar (see Build). A Docker image is
published as well.For Claude Code that is one command:
The server only supports the stdio transport.
The AI client spawns the server as a child process; communication uses the MCP protocol over stdin/stdout. The server does not open any HTTP port and accepts no incoming connections.
The server exports 13 read-only MCP tools.
| Tool | Description |
|---|---|
listProjects | List of SonarQube projects. Parameters: query (name substring), limit, offset. Returns key, name, qualifier. |
listComponents | Search/browse components inside a project using Sonar's component tree. Parameters: projectKey, query, qualifiers, branch / pullRequest, limit, offset. Returns opaque component key values plus path, qualifier, name, language, and project. Use returned key values unchanged as listIssues.componentKeys; do not pass Java package names directly as component keys. |
getProject | Project overview: header info (name, qualifier, visibility, description, version, last analysis date), quality gate status with failed conditions, and curated metrics (ncloc, bugs, vulnerabilities, security hotspots, code smells, coverage, duplicated lines density, technical debt in minutes, alert status). Parameters: projectKey, branch (opt.), pullRequest (opt.). |
listProjectBranches | List of branches analysed for the project. Each entry: name, isMain, type (LONG/SHORT/BRANCH), excludedFromPurge, analysisDate, qualityGateStatus, plus bugs/vulnerabilities/codeSmells counts. No pagination β Sonar returns all branches at once. |
listProjectPullRequests | List of PR analyses for the project. Each entry: PR key (use as pullRequest= elsewhere), title, branch (head), base, url, analysisDate, qualityGateStatus, plus bugs/vulnerabilities/codeSmells counts. Empty list if the Sonar install has no DevOps integration. |
| Tool | Description |
|---|---|
listIssues | Flat list of issues for a project. Parameters: projectKey (required unless defaulted), componentPathPrefix (opt.) β a single subtree-or-file filter relative to the Sonar project root (e.g. bc-doc/src/main/java/ru/foo or bc-doc/src/main/java/ru/foo/Bar.java); convert Java/Kotlin package dots to slashes; honours directory boundaries (bc-doc/src does not match bc-doc/srcExtra). Plus severities, types, statuses, rules, branch / pullRequest (mutually exclusive), resolved, limit, offset. By default returns only open issues (resolved=false, statuses OPEN/CONFIRMED/REOPENED). Each item contains the rule, severity, type, status, file path, line, primary textRange, and secondary flows for cross-file rules. When componentPathPrefix is used, the server scans the project and filters client-side; the scan is capped (default 10000 issues) β if the cap is hit, pathPrefixTruncated=true in the response. |
getIssue | Details of a single issue by key plus its change history (changelog). Accepts optional branch / pullRequest. |
getIssueSnippets | Source-code snippets around all issue locations (primary plus flows for cross-file rules). For each location: componentPath, language, and an array of source lines with SCM info. Useful when the repository isn't available locally or you need to see exactly the file version Sonar analyzed. Accepts optional branch / pullRequest β important when the issue lives on a non-main ref whose files differ from main. |
getProjectIssuesSummary | Aggregated summary of open issues in a project: total plus breakdowns by severity, type, status, rule, tag, and SCM author. Parameters mirror listIssues (incl. componentPathPrefix) except pagination. |
getProjectIssuesBreakdown | Multi-module aggregation of issues by logical module and rule. Module is derived from the first componentPath segment. Parameters mirror getProjectIssuesSummary. |
| Tool | Description |
|---|---|
getRule | Details of a Sonar rule by key (e.g. java:S1234): title, severity, type, language, tags, description sections (introduction, root cause, how to fix, resources). Backed by an in-memory cache β repeated calls are free. |
| Tool | Description |
|---|---|
listHotspots | List of Security Hotspots for a project. Hotspots are a separate category from issues, marking spots that require manual security review. By default Sonar returns hotspots in status TO_REVIEW. Parameters: projectKey, componentPathPrefix (opt.) β same prefix semantics as on listIssues, status (opt.), branch / pullRequest (opt., mutually exclusive), limit, offset. Subject to the same client-side scan cap (pathPrefixTruncated flag in the response). |
getHotspot | Security Hotspot details: full rule description (risk, vulnerability, fix recommendations), primary textRange, secondary flows, changelog. Hotspot keys are globally unique, so no branch/pullRequest parameter is needed. |
All tools are read-only β no data in SonarQube is modified.
Sonar analyses a branch and a pull request as two distinct, mutually exclusive scopes. The Sonar web-api accepts either branch= or pullRequest= on a single request, never both.
branch β long-lived branches (main, develop, feature/...). Resolved as: explicit branch argument β SONAR_DEFAULT_BRANCH β none (Sonar uses the project's main branch).pullRequest β the Sonar PR key, usually the PR/MR number. Independent from branch analyses; PR analyses often contain the most relevant findings for in-flight work. Pull request keys never fall back to a server-level default β pass them explicitly.Passing both branch and pullRequest to the same tool call is an error. Use listProjectBranches / listProjectPullRequests to discover available refs.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/sonar-mcp-server)<a href="https://allmcps.com/mcp/sonar-mcp-server"><img src="https://allmcps.com/api/badge/sonar-mcp-server?style=directory" alt="Sonar MCP Server on AllMCPs" /></a>