Connect Sonarqube to AI agents

Connect Sonarqube to Claude, Codex, Cursor, or other AI agents for your entire team. Metorial security, governance, observability, and gives your team a unified Magic MCP url to connect.

Supported Tools

get_system_status

Get SonarQube System Status

Get state information about SonarQube Server. Returns status (STARTING, UP, DOWN, RESTARTING, DB_MIGRATION_NEEDED, DB_MIGRATION_RUNNING), version, and id.

list_languages

List SonarQube Supported Languages

List all programming languages supported in this instance

list_quality_gates

List SonarQube Quality Gates

List all quality gates.

get_scm_info

Get SonarQube SCM Information

Get SCM information of source files. Requires See Source Code permission on file's project

get_duplications

Get SonarQube Code Duplications

Get duplications for a file. Requires Browse permission on file's project

search_duplicated_files

Search SonarQube Files With Duplications

Search for files with code duplications in a project. By default, automatically fetches all duplicated files across all pages (up to 10,000 files max).

search_files_by_coverage

Search SonarQube Files by Coverage

Search for files in a project sorted by coverage (ascending - worst coverage first). This tool helps identify files that need test coverage improvements.

get_project_quality_gate_status

Get SonarQube Project Quality Gate Status

Get the Quality Gate Status for a project. Either 'analysisId', 'projectId' or 'projectKey' must be provided.

search_dependency_risks

Search SonarQube Dependency Risks

Search for software composition analysis issues (dependency risks) of a project, paired with releases that appear in the analyzed project, application, or portfolio.

run_advanced_code_analysis

SonarQube Advanced Code Analysis

Run advanced code analysis on a single file using SonarQube Cloud's server-side engine. Identifies code quality and security issues, leveraging the project's full analysis context for deeper cross-file detection. Always specify the file scope (MAIN or TEST) for more accurate results.

get_raw_source

Get SonarQube Raw Source Code

Get source code as raw text. Requires 'See Source Code' permission on file. Source text is returned as a Slate text attachment, not inline output.

get_file_coverage_details

Get SonarQube File Coverage Details

Get complete line-by-line coverage information for a file, including which exact lines are uncovered and which have partially covered branches. This tool helps identify precisely where to add test coverage. Use after identifying files with low coverage via search_files_by_coverage.

change_sonar_issue_status

Change SonarQube Issue Status

Change the status of an issue. This tool can be used to change the status of an issue to "accept", "falsepositive" or to "reopen" an issue.

change_security_hotspot_status

Change SonarQube Security Hotspot Status

Change the status of a Security Hotspot to review it. When marking as REVIEWED, you must specify a resolution.

get_component_measures

Get SonarQube Project Measures

Get SonarQube measures for a project, such as ncloc, complexity, violations, coverage, etc.

search_security_hotspots

Search SonarQube Security Hotspots

Search for Security Hotspots in a project.

list_pull_requests

List SonarQube Pull Requests

List all pull requests for a project. Use this tool to discover available pull requests and their corresponding branch names before analyzing their coverage, issues, or quality. Returns the pull request key/ID and source branch for each PR, which can be used with other tools that accept a pullRequest parameter. For long-lived branches (main, develop), use list_branches instead.

search_sonar_issues_in_projects

Search SonarQube Issues

Search for issues (bugs, vulnerabilities, code smells) in my SonarQube projects. Filter by severities=['HIGH','BLOCKER'] for critical issues, impactSoftwareQualities=['SECURITY'] for security, issueStatuses=['OPEN'] to exclude resolved.

search_my_sonarqube_projects

Search My SonarQube Projects

Find SonarQube projects in your organization or instance. Supports searching by project name or key. Use this first when projectKey is unknown - most other tools require the project key from this response.

search_metrics

Search SonarQube Metrics

Search for available metrics

show_security_hotspot

Show SonarQube Security Hotspot Details

Get detailed information about a specific Security Hotspot, including rule details, code context, flows, and comments.

list_branches

List SonarQube Branches

List analyzed branches for a SonarQube project. Returns long-lived branches such as main and develop plus short-lived SonarQube Cloud branches analyzed without a pull request. Use returned branch names as the branch parameter on other tools (e.g. get_project_quality_gate_status, get_component_measures). Use branchTypes to narrow Cloud results, or list_pull_requests for pull request analysis.

show_rule

Show SonarQube Rule Details

Shows detailed information about a SonarQube rule.

ping_system

Ping SonarQube Server System

Ping the SonarQube Server system to check whether it is reachable. Returns the server's plain-text response.

More integrations teams use with Sonarqube

GitHub

Manage repositories, issues, and pull requests. Create and configure branches, star repositories, review code, and merge changes. Automate CI/CD workflows with GitHub Actions, manage workflow runs, secrets, and artifacts. Track issues with labels, milestones, and assignees. Search across code, repositories, issues, and users. Manage organizations, teams, and memberships. Create and manage projects, gists, packages, deployments, and environments. Access security alerts including code scanning, secret scanning, and Dependabot alerts. Read and write file contents in repositories. Manage webhooks, notifications, and codespaces.

Salesforce

Manage CRM data including Accounts, Contacts, Leads, Opportunities, Cases, and custom objects. Create, read, update, and delete records. Query data using SOQL and search across objects using SOSL. Perform bulk data operations for large-scale imports, exports, and migrations. Execute composite requests to batch multiple operations in a single API call. Access analytics, reports, and dashboards. Manage files and attachments associated with records. Interact with Chatter feeds, posts, and groups for social collaboration. Subscribe to real-time change events via Change Data Capture and Platform Events. Manage org metadata including custom objects, fields, layouts, and workflows. Query data using GraphQL for precise data retrieval across related objects.

Sharepoint

Manage SharePoint sites, document libraries, lists, and files. Create, read, update, and delete lists and list items with custom columns. Resolve site users to numeric Person/Group LookupId values. Upload, download, move, copy, and version files in document libraries. Search across sites, files, folders, lists, and list items using Microsoft Search. Manage permissions at site, list, and item levels with granular access control. Define and manage content types and site columns. Subscribe to webhooks for list and library change notifications. Retrieve site properties and search for sites across Microsoft 365.

Airtable

Create, read, update, and delete records in Airtable bases and tables. Manage base schemas including creating tables and fields. Filter records using formulas, sort by fields, and scope queries to specific views. Upsert records to find, create, or update in a single call. Upload attachments to records, read and write record comments, list accessible bases, and receive real-time base change events through webhooks.

Sentry

Track, manage, and resolve application errors and performance issues. List, query, and bulk-update issues and error events with filters like status, assignment, and tags. Create and manage releases, associate commits, and upload source maps. Configure issue alert rules and metric alert rules with notification actions. Set up cron monitors to detect missed or failed scheduled jobs. Build custom dashboards with configurable widgets. Run ad-hoc Discover queries across errors and transactions for performance analysis. Manage organizations, teams, projects, and members. Provision users via SCIM. Access session replay data. Receive webhooks for issues, errors, alerts, comments, and installation events.

Bitbucket

Manage Git repositories, pull requests, and CI/CD pipelines on Bitbucket Cloud. Create, fork, and configure repositories within workspaces and projects. Create, review, approve, merge, and decline pull requests with inline code comments. Browse source code, list commits, and manage branches and tags. Trigger, monitor, and manage Bitbucket Pipelines. List workspace members, configure repository default reviewers and branch restrictions, create and manage repository webhooks, and search code across repositories.

Technical notes for Sonarqube

Connect to SonarQube Server or SonarQube Cloud to inspect project quality, issues, branches, pull requests, measures, quality gate status, dependency risks, and advanced code analysis.

Connect Sonarqube to production AI agents

See how Metorial gives Sonarqube access the governance, tracing, and security controls teams need.

Frequently asked questions

Common questions about connecting Sonarqube to AI agents with Metorial.

  1. Can Metorial connect Sonarqube to AI agents?
    Yes. Metorial connects AI agents to Sonarqube through a governed integration layer, so teams can use the provider while keeping access controlled and observable.
  2. Metorial is MCP compatible and lets teams expose approved provider tools to MCP-capable agents and clients through a controlled access layer.
  3. Metorial applies policies across users, groups, providers, agents, and individual tools, then records the context around every agent interaction.
  4. Yes. Metorial records provider activity so teams can inspect tool calls, troubleshoot integrations, and give security teams the visibility they need.