Claude Code
Install the SonarQube plugin in Claude Code to enable code analysis, issue management, and secrets detection skills directly from your AI coding sessions.
The SonarQube plugin for Claude Code connects your AI coding agent to SonarQube's code quality and security features. The plugin works with SonarQube Cloud or SonarQube Server.
Features
Through the SonarQube CLI integration set up by /sonarqube:sonar-integrate, the plugin adds:
Secrets detection: hooks that run before the agent executes a tool or receives a prompt, keeping credentials out of the files the agent reads and out of prompts sent to Claude Code.
Vortex analysis (project-level installs with a Vortex subscription: SonarQube Cloud Team or Enterprise plan, or SonarQube Server 2026.5 Enterprise and Data Center editions): hooks that run
sonar verify --stagedafter Claude Code edits files.Vortex context (project-level installs with a Vortex subscription: SonarQube Cloud Team or Enterprise plan, or SonarQube Server 2026.5 Enterprise and Data Center editions): a skill that tells Claude Code to pull project guidelines before editing code, check dependencies before changing a manifest, and use SonarQube's architecture and semantic-navigation context as it works.
It also adds SonarQube skills that you can invoke as slash commands in Claude Code. See the Usage article for more details.
The plugin also gives Claude Code's agent access to the full set of Tools exposed by the SonarQube MCP Server, including:
Code analysis: analyze code snippets and files in the agent context.
Issues: search, review, and update code issues.
Quality gates: check the quality gate status for a project.
Security hotspots: search and review security hotspots.
Coverage: find under-covered files and review line-by-line coverage.
Dependencies: check third-party dependencies for SCA issues.
Prerequisites
A SonarQube Cloud organization or SonarQube Server instance.
Node.js, required to run the hook that checks the integration when a session starts.
A container runtime (Docker, Podman, or nerdctl) to run the SonarQube MCP Server image.
Install
Install the SonarQube plugin from the claude-plugins-official marketplace:
From your shell, run
claude plugin install sonarqube@claude-plugins-official.Or inside Claude Code, run
/plugin install sonarqube@claude-plugins-official.
Then reload SonarQube's skills and hooks in Claude Code:
Either restart Claude Code, or
Run
/reload-pluginsif your version supports it.
Configuration
After installing the plugin, finish setup by running the guided integration skill:
The skill does the following:
Install the SonarQube CLI if not already present, or update it with
sonar self-update.Authenticate with SonarQube Cloud or your SonarQube Server instance via
sonar auth login. Your browser opens to complete login; the token is stored in your system keychain.Run
sonar integrate claudeto register the SonarQube MCP Server and install the secrets-detection hooks. On a project install with a Vortex subscription, it also sets up the Vortex analysis hook and the Vortex context skill.
Sonar Vortex: analysis and context features
When you run sonar integrate claude, the command configures Claude to use the What is Sonar Vortex? features. They run through the SonarQube CLI:
Vortex analysis: a hook runs after Claude edits files and feeds findings back into the session, so Claude can fix new issues before ending the turn.
Vortex context: gives Claude your project's coding guidelines, dependency health, architecture, and semantic-navigation context as it works.
Both features are project-scoped and skipped on a global install. Run sonar integrate claude --project <YourProjectKey> from a project directory to install them, or pass --skip-context to opt out of Vortex context.
Verify that it works
Test the secrets hook
Create a file with a fake-looking but secret-shaped value:
Ask Claude to read it: "Read secrets.js."
Claude Code should block the read and explain that the file contains a secret.
Once you've confirmed the hook is active, delete the test file.
Test the MCP server
In Claude Code, ask: "Use the SonarQube MCP server to list my open projects." Claude should call SonarQube and return your project list. If it doesn't, run sonar auth status to confirm the underlying token is healthy and restart Claude.
Test Sonar Vortex
Vortex adds Vortex analysis and Vortex context. To confirm both are working, see Checking that Vortex works properly.
Non-interactive install
For provisioning scripts and onboarding automation, skip the interactive skill and run the SonarQube CLI directly:
In non-interactive mode, the CLI doesn't prompt for confirmation or token repair. Run sonar auth status afterward to confirm the integration is wired up. See Claude Code in the SonarQube CLI docs for full details.
Usage
After setup, invoke SonarQube skills in Claude Code using explicit slash commands or natural language. Both options are shown for each skill.
List projects
Or in natural language:
"List my SonarQube projects."
"Search for projects with
authin the name."
List issues
Or in natural language:
"List the issues in
my-project.""Show me critical issues in
my-project.""Search issues in
my-projecton branchmain."
Fix an issue
Or in natural language:
"Fix the issue
java:S1481insrc/main/java/MyClass.java.""Help me fix
python:S2077on line 34 ofsrc/auth/login.py."
Quality gate
Or in natural language:
"Check the quality gate status for
my-project.""Show me the quality gate for
my-projecton pull request 42."
Analyze a file
Or in natural language:
"Analyze
src/auth/login.pyfor code quality and security issues.""Run analysis on the current file."
Coverage
Or in natural language:
"What files in
my-projecthave less than 50% coverage?""Show me line-by-line coverage for
src/auth/login.py."
Duplication
Or in natural language:
"Find duplicated files in
my-project.""Show duplications in
my-projecton pull request 42."
Dependency risks
Dependency risks require SonarQube Advanced Security.
Or in natural language:
"List dependency risks in
my-project.""Show me SCA issues on pull request 42."
Security hotspots
Access security hotspots through the same sonar-list-issues skill:
Or in natural language:
"Search security hotspots in
my-project.""Show hotspots in
my-projectthat are still to review."
Uninstall
To remove the SonarQube plugin from Claude Code:
From your shell, run
claude plugin uninstall sonarqube.Or inside Claude Code, run
/pluginto open the Manage plugins window and remove the SonarQube plugin.
Uninstalling the plugin removes the SonarQube skills and hooks the plugin registered. To also remove the underlying CLI integration files written by /sonarqube:sonar-integrate (the SonarQube MCP server entry, secrets-detection hook configuration, state record), see Uninstall on the SonarQube CLI integration page.
Related pages
Set up the SonarQube MCP Server in Claude Code
Last updated
Was this helpful?

