A TypeScript-based Model Context Protocol (MCP) server that provides AI assistants with seamless access to SonarCloud data. Query code quality metrics, issues, pull requests, and project information directly from your AI tools.
- No Docker Required: Unlike SonarSource's official Docker-based MCP server, this is a lightweight TypeScript solution
- AI-Optimized: Returns JSON data structured for optimal AI consumption and analysis
- Comprehensive API Coverage: 12 tools covering all major SonarCloud endpoints
- Flexible Authentication: Multiple auth methods including environment variables, CLI args, and config files
- Claude Code Integration: Perfect for use with Anthropic's Claude Code and other MCP-compatible AI tools
npm install -g community-sonarcloud-mcp-serverOr run directly with npx:
npx community-sonarcloud-mcp-serverCheck version:
npx community-sonarcloud-mcp-server --versionexport SONARCLOUD_TOKEN="your_token_here"
export SONARCLOUD_ORGANIZATION="your_org_here"
export SONARCLOUD_URL="https://sonarcloud.io" # Optional, defaults to sonarcloud.ionpx community-sonarcloud-mcp-server --token "your_token" --org "your_org" --url "https://sonarcloud.io"Create a config file and use:
npx community-sonarcloud-mcp-server --config ./sonarcloud-config.jsonConfig file format:
{
"token": "your_sonarcloud_token",
"organization": "your_organization_key",
"url": "https://sonarcloud.io"
}Priority order: CLI args > Environment vars > Config file
This server provides 12 comprehensive tools for SonarCloud integration:
list_projects- List all projects in your organizationsearch_issues- Search and filter issues by project, severity, type, status, and Clean Code impact qualitiesget_pull_requests- List pull requests for a specific projectchange_issue_status- Mark issues as confirmed, false positive, won't fix, or reopen
get_measures- Get detailed metrics (coverage, bugs, vulnerabilities, code smells, technical debt)search_metrics- Discover available metrics and their descriptionsget_quality_gate_status- Check if projects pass quality gateslist_quality_gates- List all available quality gate configurations
show_rule- Get detailed information about specific coding ruleslist_rule_repositories- Browse rule repositories by languagelist_languages- See all supported programming languages
get_raw_source- Retrieve raw source code for any file in your projects
Each tool returns structured JSON data optimized for AI analysis and decision-making.
claude mcp add -s user -e SONARCLOUD_TOKEN=your-token-here -e SONARCLOUD_ORGANIZATION=your-org-key sonarcloud -- npx community-sonarcloud-mcp-serverVerify the connection with:
claude mcp listAdd this server to your MCP configuration file (.mcp.json for Claude Code):
{
"mcpServers": {
"community-sonarcloud-mcp": {
"command": "npx",
"args": ["community-sonarcloud-mcp-server"],
"env": {
"SONARCLOUD_TOKEN": "your_token_here",
"SONARCLOUD_ORGANIZATION": "your_org_here"
}
}
}
}npm install -g community-sonarcloud-mcp-serverThen reference the global installation:
{
"mcpServers": {
"community-sonarcloud-mcp": {
"command": "community-sonarcloud-mcp",
"env": {
"SONARCLOUD_TOKEN": "your_token_here",
"SONARCLOUD_ORGANIZATION": "your_org_here"
}
}
}
}- Go to SonarCloud Security Settings
- Click Generate Tokens
- Give your token a name (e.g., "Claude Code MCP")
- Set token permissions:
- Browse: Required for viewing projects and issues
- Execute Analysis: Optional (only needed for CI/CD integration)
- Generate the token and copy it immediately (you won't see it again)
- Add the token to your configuration
Your organization key is found in the URL when viewing your SonarCloud organization:
- URL format:
https://sonarcloud.io/organizations/{your-org-key} - Example: For URL
https://sonarcloud.io/organizations/my-company, the key ismy-company
- Ensure your token is properly set in environment variables or config
- Check that the token hasn't been revoked or expired in SonarCloud
- Verify the token has the correct permissions (Browse is minimum required)
- Verify the organization name matches exactly (case-sensitive)
- Check that your organization key is correct (found in SonarCloud URL)
- Ensure the token has access to the specified organization
- Try running the server directly:
SONARCLOUD_TOKEN="your_token" SONARCLOUD_ORGANIZATION="your_org" npx community-sonarcloud-mcp-server
- Verify your token has Browse permissions for the organization
- Check that projects exist in the specified organization
- Ensure your user account has access to the organization's projects
- Check that Node.js version is compatible (18+)
- Verify npm/npx is working correctly
- Try installing globally first:
npm install -g community-sonarcloud-mcp-server
Once configured, you can ask your AI assistant questions like:
- "What projects do I have in SonarCloud?"
- "Show me all bugs in my main project"
- "What's the test coverage for my latest pull request?"
- "List all critical security vulnerabilities"
- "Show me the quality gate status for project X"
- "What coding rules are failing in this project?"
The server will automatically query SonarCloud and return structured data for analysis.
git clone https://github.com/langtind/community-sonarcloud-mcp-server.git
cd community-sonarcloud-mcp-server
npm install
npm run devnpm run build
npm start# Test the server directly
SONARCLOUD_TOKEN="your_token" SONARCLOUD_ORGANIZATION="your_org" npm start- Fork the repository
- Create a feature branch
- Make your changes
- Add tests if applicable
- Submit a pull request
MIT License - see LICENSE file for details.
- Model Context Protocol - The protocol this server implements
- SonarCloud - The service this server integrates with
- Claude Code - AI coding assistant that works great with this server