Ext Ops Panel
Open dashboard

What it can do: SonarQube MCP Server

MCP server · SonarSource

What SonarQube MCP Server declares, asks for and runs, according to the marketplaces we read. Runs on your machine, in a container started from this image: docker.io/sonarsource/sonarqube-mcp. Tools it declares: 25. Environment variables it asks for: 3, secrets among them: 3. As of our marketplace pass on 2026-10-11.

This is not a security audit. We list what the marketplaces publish about this plugin: what it declares, what it asks for and what it runs. We do not run or inspect its code, and a verified mark is the marketplace's statement, not ours.

Where it runs

  • Runs on your machine, in a container started from this image: docker.io/sonarsource/sonarqube-mcpAs declared on: Official MCP Registry.
  • Runs on your machine, in a container started from this image: mcp/sonarqubeAs declared on: Docker MCP Catalog.

What it declares

Tools it declares: 25. As declared on: Docker MCP Catalog.

  • analyze_code_snippet
  • analyze_file_list
  • change_sonar_issue_status
  • create_webhook
  • get_component_measures
  • get_project_quality_gate_status
  • get_raw_source
  • get_scm_info
  • get_system_health
  • get_system_info
  • get_system_logs
  • get_system_status
Show the remaining 13
  • list_enterprises
  • list_languages
  • list_portfolios
  • list_quality_gates
  • list_rule_repositories
  • list_webhooks
  • ping_system
  • search_dependency_risks
  • search_metrics
  • search_my_sonarqube_projects
  • search_sonar_issues_in_projects
  • show_rule
  • toggle_automatic_analysis

Prompts and resources: the marketplaces we read do not publish them.

What it asks for

Environment variables it asks for: 3, secrets among them: 3. As declared on: Official MCP Registry.

  • SONARQUBE_ORG secret
  • SONARQUBE_TOKEN secret required
  • SONARQUBE_URL secret

Environment variables it asks for: 3, secrets among them: 1. As declared on: Docker MCP Catalog.

  • SONARQUBE_ORG
  • SONARQUBE_TOKEN secret required
  • SONARQUBE_URL

Names only: we keep no values, examples or descriptions of these variables. OAuth scopes and install-time settings are not published by the marketplaces we read.

What it runs besides MCP

None of the marketplaces we read lists hooks, commands, agents or language servers for it.

Who answers for it

SonarSource

  • No marketplace we read marks it or its publisher as verified.
  • License: NOASSERTION.
  • The repository github.com/sonarsource/sonarqube-mcp-server belongs to the account the publisher is listed under on Official MCP Registry.

How it has changed

Its tools, settings, hooks and composition have not changed since we started watching it.

In context

  • Median number of secrets an MCP server asks for on the marketplaces we read: 0.0. This one asks for: 3.
  • Share of MCP servers that run on a remote server: 63%.

Where it is published and how its figures have moved

Data comes from the Official MCP Registry (registry.modelcontextprotocol.io), CC0 1.0. Data comes from the Docker MCP Catalog (desktop.docker.com/mcp/catalog) and Docker Hub. Figures come from our own regular passes over the marketplaces, last read on . We publish no contact details for plugin publishers.

Where the data comes from: how the catalog is built