Developer · Local MCP server

SonarQube MCP Server

Analyze code quality and security with SonarQube Server or Cloud directly in AI assistants.

What the MCP Registry states

The entry as published to the official MCP Registry (read 2026-10-04), latest version.

Registry name
io.github.SonarSource/sonarqube-mcp-server
Version
1.21.0
Status
Active
Category
developer
Transport
stdio (local process)
Package
OCI image (Docker)
Published
2026-06-25
Updated
2026-06-25
Publisher
SonarSource (GitHub)
Repository
github.com/SonarSource/sonarqube-mcp-server
Source
Registry API entry

Packages

RegistryPackageVersionTransportEnvironment variables
OCI image (Docker)docker.io/sonarsource/sonarqube-mcp—stdioSONARQUBE_TOKEN (required, secret), SONARQUBE_ORG (secret), SONARQUBE_URL (secret)

How to connect SonarQube MCP Server

SonarQube MCP Server runs locally from a container image in an OCI registry such as Docker Hub or GitHub Container Registry: docker.io/sonarsource/sonarqube-mcp. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Docker or another OCI container runtime; started with docker run — the usual command is docker run -i --rm -e SONARQUBE_TOKEN -e SONARQUBE_ORG -e SONARQUBE_URL docker.io/sonarsource/sonarqube-mcp. It reads these environment variables: SONARQUBE_TOKEN (required, secret), SONARQUBE_ORG (secret) and SONARQUBE_URL (secret); set them in the client's configuration for this server.

In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):

{
  "mcpServers": {
    "sonarqube-mcp-server": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "-e",
        "SONARQUBE_TOKEN",
        "-e",
        "SONARQUBE_ORG",
        "-e",
        "SONARQUBE_URL",
        "docker.io/sonarsource/sonarqube-mcp"
      ],
      "env": {
        "SONARQUBE_TOKEN": "<secret>",
        "SONARQUBE_ORG": "<secret>",
        "SONARQUBE_URL": "<secret>"
      }
    }
  }
}

Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect

More developer servers

All 6,250 →
ServerRunsEndpoint or package
Solvicus FinOps - GCP Committed Use Discount (CUD) OptimizationFinOps for Google Cloud: size 1- and 3-year CUD commitments to known demand. Also solves LP/MIP.Remote · HTTPmcp.solvicus.com
SomaRMCP runtime for provider-backed agents with CLI, REST, HTTP MCP, plugins, and scaffold support.Local · stdioOCI image (Docker): ghcr.io/dinglebear-ai/soma:0.10.0
SomaExecution-verified code generation and verification with signed, offline-checkable certificates.Local · stdionpm: soma-verify-mcp
Sonar MCP ServerRead-only SonarQube Community Build access for AI agents: issues, hotspots, rules, code snippets.Local · stdioOCI image (Docker): ghcr.io/igorolv/sonar-mcp-server:0.1.0
SondeLocal code graph for TypeScript, Python and Swift: who calls this, what breaks if I change it.Local · stdionpm: @cheppulabs/sonde
SooverynAI personas with a lasting, encrypted memory per project, for Claude Code. Hosted in France.Remote · HTTPmcp.sooveryn.com
SophonHonest token economics for MCP agents. 68% tokens saved, zero-ML Rust binary.Local · stdionpm: mcp-sophon
Sophos Central MCPMCP server for Sophos Central — endpoint security, XDR/MDR, and MSSP multi-tenant ops.Local · stdionpm: @rijul170/sophos-mcp