SonarSource · VS Code (GitHub Copilot)
Add the SonarQube MCP server to VS Code (GitHub Copilot)
Check code quality and security issues with SonarQube Server or Cloud.
1. Add the server
Run in your terminal
code --add-mcp '{"name":"sonarqube","command":"docker","args":["run","-i","--rm","-e","SONARQUBE_TOKEN","docker.io/sonarsource/sonarqube-mcp"],"env":{"SONARQUBE_TOKEN":"<your SONARQUBE_TOKEN>"}}'2. Sign in
VS Code opens the sign-in flow when Copilot first calls a remote OAuth server. SonarQube runs locally and needs SONARQUBE_TOKEN. Replace the placeholder values above with your own before starting VS Code (GitHub Copilot).
3. Try it
Ask VS Code (GitHub Copilot) for something SonarQube can do. Check code quality and security issues with SonarQube Server or Cloud. Approve the first tool call and check the result before allowing write actions automatically.
- · mcp.json uses a top-level servers key, not mcpServers.
- · code --add-mcp installs a server into your user profile from the terminal.
FAQ
- How do I add the SonarQube MCP server to VS Code (GitHub Copilot)?
- Run: code --add-mcp '{"name":"sonarqube","command":"docker","args":["run","-i","--rm","-e","SONARQUBE_TOKEN","docker.io/sonarsource/sonarqube-mcp"],"env":{"SONARQUBE_TOKEN":"<your SONARQUBE_TOKEN>"}}'. VS Code opens the sign-in flow when Copilot first calls a remote OAuth server.
- Is this the official SonarQube MCP server?
- Yes. It is published by SonarSource as io.github.SonarSource/sonarqube-mcp-server in the official MCP registry.
- Does the SonarQube MCP server need an API key?
- Yes. It runs locally and requires SONARQUBE_TOKEN.
Links
SonarQube in other clients
More security & code quality for VS Code (GitHub Copilot)
Work at SonarSource?
Feature SonarQube across the directory and its category from $49/month.
Reviewed Oct 5, 2026. Command generated from the registry record and checked against VS Code (GitHub Copilot)'s documented syntax.