SonarSource · Cursor
Add the SonarQube MCP server to Cursor
Check code quality and security issues with SonarQube Server or Cloud.
1. Add the server
Paste into .cursor/mcp.json (project) or ~/.cursor/mcp.json (global)
{
"mcpServers": {
"sonarqube": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"SONARQUBE_TOKEN",
"docker.io/sonarsource/sonarqube-mcp"
],
"env": {
"SONARQUBE_TOKEN": "<your SONARQUBE_TOKEN>"
}
}
}
}2. Sign in
Cursor prompts you to sign in the first time a remote OAuth server is used. SonarQube runs locally and needs SONARQUBE_TOKEN. Replace the placeholder values above with your own before starting Cursor.
3. Try it
Ask Cursor for something SonarQube can do. Check code quality and security issues with SonarQube Server or Cloud. Approve the first tool call and check the result before allowing write actions automatically.
- · Remote servers take a url; local servers take command and args.
- · Values can reference ${env:NAME} so secrets stay out of the file.
FAQ
- How do I add the SonarQube MCP server to Cursor?
- Run: { …. Cursor prompts you to sign in the first time a remote OAuth server is used.
- Is this the official SonarQube MCP server?
- Yes. It is published by SonarSource as io.github.SonarSource/sonarqube-mcp-server in the official MCP registry.
- Does the SonarQube MCP server need an API key?
- Yes. It runs locally and requires SONARQUBE_TOKEN.
Links
SonarQube in other clients
More security & code quality for Cursor
Work at SonarSource?
Feature SonarQube across the directory and its category from $49/month.
Reviewed Oct 5, 2026. Command generated from the registry record and checked against Cursor's documented syntax.