SonarSource · Codex
Add the SonarQube MCP server to Codex
Check code quality and security issues with SonarQube Server or Cloud.
Official serverLocalSecurity & code quality
1. Add the server
Run in your terminal
# ~/.codex/config.toml [mcp_servers.sonarqube] command = "docker" args = ["run", "-i", "--rm", "-e", "SONARQUBE_TOKEN", "docker.io/sonarsource/sonarqube-mcp"] [mcp_servers.sonarqube.env] SONARQUBE_TOKEN = "<your SONARQUBE_TOKEN>"
2. Sign in
Run codex mcp login <name> to complete OAuth for a remote server. SonarQube runs locally and needs SONARQUBE_TOKEN. Replace the placeholder values above with your own before starting Codex.
3. Try it
Ask Codex for something SonarQube can do. Check code quality and security issues with SonarQube Server or Cloud. Approve the first tool call and check the result before allowing write actions automatically.
- · Each server is a [mcp_servers.<name>] table in config.toml.
- · Use enabled_tools or disabled_tools to keep the tool list short.
FAQ
- How do I add the SonarQube MCP server to Codex?
- Run: # ~/.codex/config.toml …. Run codex mcp login <name> to complete OAuth for a remote server.
- Is this the official SonarQube MCP server?
- Yes. It is published by SonarSource as io.github.SonarSource/sonarqube-mcp-server in the official MCP registry.
- Does the SonarQube MCP server need an API key?
- Yes. It runs locally and requires SONARQUBE_TOKEN.
Links
SonarQube in other clients
More security & code quality for Codex
Work at SonarSource?
Feature SonarQube across the directory and its category from $49/month.
Reviewed Oct 5, 2026. Command generated from the registry record and checked against Codex's documented syntax.