Sonar MCP Server
by igorolvio.github.igorolv/sonar-mcp-serverv0.1.0
Read-only access to self-hosted SonarQube Community Build: issues, security hotspots, rules and code snippets so an agent can fix findings locally.
context tax
queued
security
queued
cold start
queued
freshness
Active21d ago
Install Sonar MCP server
Install in Claude Code
claude mcp add sonar -e SONAR_URL='<sonar-url>' -e SONAR_TOKEN='<sonar-token>' -- docker run -i --rm -e SONAR_URL -e SONAR_TOKEN ghcr.io/igorolv/sonar-mcp-server:0.1.0Install in Cursor
{
"mcpServers": {
"sonar": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"SONAR_URL",
"-e",
"SONAR_TOKEN",
"ghcr.io/igorolv/sonar-mcp-server:0.1.0"
],
"env": {
"SONAR_URL": "<sonar-url>",
"SONAR_TOKEN": "<sonar-token>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"sonar": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"SONAR_URL",
"-e",
"SONAR_TOKEN",
"ghcr.io/igorolv/sonar-mcp-server:0.1.0"
],
"env": {
"SONAR_URL": "<sonar-url>",
"SONAR_TOKEN": "<sonar-token>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"sonar": {
"type": "stdio",
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"SONAR_URL",
"-e",
"SONAR_TOKEN",
"ghcr.io/igorolv/sonar-mcp-server:0.1.0"
],
"env": {
"SONAR_URL": "<sonar-url>",
"SONAR_TOKEN": "<sonar-token>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"sonar": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"SONAR_URL",
"-e",
"SONAR_TOKEN",
"ghcr.io/igorolv/sonar-mcp-server:0.1.0"
],
"env": {
"SONAR_URL": "<sonar-url>",
"SONAR_TOKEN": "<sonar-token>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| SONAR_URL | yes | — | Base URL of the SonarQube instance, e.g. https://sonar.example.com |
| SONAR_TOKEN | yes | yes | SonarQube user token (My Account -> Security -> Generate Tokens) |
| SONAR_DEFAULT_PROJECT_KEY | — | — | Project key used when a tool call does not name one |
Freshness
Active — last maintenance signal 21d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-09-18 · 21d ago · GitHub
Latest release
2026-09-17 · 22d ago · GitHub · v0.1.0
Package published
no data · npm/PyPI
Registry entry updated
2026-09-17 · 22d ago · official registry · v0.1.0
FAQ
›How do I install the Sonar MCP server in Claude Code?
Run: claude mcp add sonar -e SONAR_URL='<sonar-url>' -e SONAR_TOKEN='<sonar-token>' -- docker run -i --rm -e SONAR_URL -e SONAR_TOKEN ghcr.io/igorolv/sonar-mcp-server:0.1.0. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Sonar require an API key?
Yes. It expects SONAR_URL, SONAR_TOKEN, of which 1 is a secret.
›Can I use Sonar as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Sonar in the official MCP registry?
Yes, as io.github.igorolv/sonar-mcp-server.
Alternatives to Sonar
Other devops & ci/cd MCP servers.