Subscription plans

SonarQube Cloud offers three subscription-based plans: Free, Team, and Enterprise, each with varying features and suitable for different team sizes.

The SonarQube Cloud’s pricing modelarrow-up-right is subscription-based: each organization is assigned a subscription plan. Four different plans are available:

  • Free plan, for small teams. Only basic analysis features are available.

  • Team plan, if you want to benefit from advanced analysis features.

  • Enterprise plan, for larger organizations and teams, and if you want to benefit from the enterprise-level hierarchy and from even more features.

  • OSS plan, a free plan for open source organizations that offers unlimited access to branch analysis and pull request analysis.

circle-exclamation

For information about the billing model, see the Billing model page.

Comparison table (Free, Team, and Enterprise)

The table below shows a comparison between the SonarQube Cloud's Free, Team, and Enterprise.

Feature
Free
Team
Enterprise
Note

General

Analysis of public projects: unlimited number of projects

Checkmark icon

Checkmark icon

Checkmark icon

Analysis of private projects

Up to 50k LOC

Up to 1.9M LOC

Unlimited (ideal from 5M LOC for the whole enterprise)

The maximum number of lines of code (LOC) in a plan restricts the analysis of private projects in your organization or enterprise. See LOC-based pricing below.

Organization onboarding from multiple DevOps platforms (except Bitbucket)

Checkmark icon

As an enterprise member, you can import a DevOps organization using any of your DevOps accounts or SSO account (except for a Bitbucket workspace which can only be imported using a Bitbucket account).

Maximum number of organization members

5

Unlimited

Unlimited

Enterprise-level hierarchy

Checkmark icon

You can group several organizations into an enterprise.

Code analysis

Branch analysis

Only main branch analysis

Unlimited

Unlimited

Pull request analysis

Only if the target branch is the main branch

Unlimited

Unlimited

Custom quality profiles

Checkmark icon

Checkmark icon

Custom quality gates

Checkmark icon

Checkmark icon

Report of security alerts in GitHub

Checkmark icon

SonarQube Cloud automatically provides feedback about security vulnerabilities inside the GitHub interface itself. See GitHub code scanning alertsarrow-up-right.

AI code analysis

AI Code Assurance

Checkmark icon

Checkmark icon

Checkmark icon

Autodetected AI code (on GitHub only)

Checkmark icon

Checkmark icon

Checkmark icon

Advanced security analysis

Software Composition Analysis (SCA)

Add-on1

Advanced SAST (Static Application Security Testing)

Add-on1

AI-powered code remediation

AI CodeFix

Checkmark icon

Checkmark icon

Remediation Agent (on GitHub only)

Checkmark icon

Management reporting

Portfolios

Checkmark icon

Project PDF reports

Checkmark icon

Integrations

JFrog Evidence Collection

Checkmark icon

Webhooks

Checkmark icon

Checkmark icon

SonarQube Cloud supports the configuration of webhooks, allowing you to send automatic notifications to external services of analysis activity. See Webhooks.

User authentication and provisioning

GitHub member synchronization

Checkmark icon

Checkmark icon

SonarQube Cloud synchronizes automatically organization members with GitHub. See GitHub member synchronization in Default authentication through DevOps platform

DevOps platform authentication

Checkmark icon

Checkmark icon

Checkmark icon

SSO authentication

Checkmark icon

Enterprise security

Scoped Organization Token (SOT)

Checkmark icon

Checkmark icon

Audit logs

Checkmark icon

IP allow list restriction

Checkmark icon

Administration

Groups

Checkmark icon

Checkmark icon

As an organization admin, you can manage custom groups and change the permissions of any group. See User group concept

Permission templates

Checkmark icon

Checkmark icon

As an organization admin, you can use permissions templates to manage the default permissions applying to new projects. See Using permission templates

Organization-wide project configurations

Checkmark icon

As an organization admin, you can define the long-lived branch name pattern, the analysis scope adjustment, and the automatic analysis disabling for new projects at the organization level. See Introduction to Performing global analysis setup.

Projects Management page

Checkmark icon

As an organization admin, you can manage the projects of your organization on a centralized page: the Projects Management page. See Using Projects Management page

Delegation of the quality profile management permission

Checkmark icon

With the Administer Quality Profiles permission, you can authorize users or groups to manage a specific custom quality profile. See Granting permissions to users

1) Enterprise's add-ons require a separate subscription to your Enterprise license.

circle-info

ABAP, APEX, COBOL, JCL, PL/I, and RPG languages are only supported with the Enterprise plan. See Supported languages for more information.

OSS plan (SonarQube for OSS)

If you are part of an open source organization, you may be interested in the OSS plan. This plan is a free plan that allows you to analyze an unlimited number of public repositories but no private project, and to benefit from advanced features as described below. Note that all legacy free organizations have been moved to the OSS plan.

Feature
Description

Maximum number of organization members

Unlimited.

Code analysis

Languages

All languages supported in the Team plan. See Supported languages.

Branch analysis

Unlimited. For more information about the feature, see Branch analysis.

Pull request analysis

Unlimited.

For more information about the feature, see Pull request analysis.

Custom quality profiles

Custom quality gates

Advanced SAST (Static Application Security Testing)

Integrations

Webhooks

SonarQube Cloud supports the configuration of webhooks, allowing you to send automatic notifications to external services of analysis activity. See Webhooks.

User administration

Projects Management page

As an organization admin, you can manage the projects of your organization on a centralized page: the Projects Management page. See Using Projects Management page.

GitHub member synchronization

SonarQube Cloud synchronizes automatically organization members with GitHub. See GitHub member synchronization.

DevOps platform authentication

Groups

As an organization admin, you can manage custom groups and change the permissions of any group. See User group concept.

Permission templates

As an organization admin, you can use permissions templates to manage the default permissions applying to new projects. See Using permission templates.

LOC-based pricing

Your subscription plan determines the maximum number of private Lines of Code (LOC) you are permitted to analyze, in your organization (for a Free or Team plan) or in your enterprise (for an Enterprise plan):

  • Free: You can analyze up to 50k LOC in your organization.

  • Team: You can choose a LOC between 100k and 1.9M for your organization.

  • Enterprise: You can choose any LOC you want for your entire enterprise (ideal from 5M LOC). By default, the enterprise LOC is shared by all organizations in the enterprise (Shared LOC). You can also allocate an individual LOC limit to one or more organizations within the enterprise (Allocated LOC). The other organizations will share the remaining LOC limit. For more information, see About the enterprise lines of code limit (Shared LOC and Allocated LOC).

circle-exclamation

LOC limit management

You cannot exceed your LOC limit in SonarQube Cloud. Once you are near your LOC limit, you will receive a notification informing you of this and advising you to upgrade your current subscription plan to a higher LOC limit or to reduce the number of LOC in your projects. This notification is currently not supported for the enterprise LOC limit.

You can analyze the same code as often as you like. However, if you try to analyze more LOC than is allowed under your current subscription, SonarQube Cloud will not perform the analysis, and you will also receive an error message clearly explaining the reason for this.

chevron-rightLOC limit application examplehashtag

Your organization has a 20,000 LOC license.

When you analyze a project that contains 10,000 lines of code (LOC) once, you have used 10,000 LOC from your organization’s license. If you analyze the same project 20 more times, you will still have only used 10,000 LOC from the license.

However, if you then try to analyze a different project that has 15,000 LOC, you will exceed the 20,000 LOC limit of your organization’s license and receive an error message.

Used LOC calculation

The LOC used by an organization is calculated by adding up the LOC of each private project analyzed for your organization. The calculation is a measure of the sum of the LOC of the largest long-lived branches for all your projects. It is not a measure of the new code analyzed in a given billing cycle. During calculation, the following are excluded from your LOC count:

  • Test code.

  • Files excluded from analysis.

  • Code in unsupported languages.

  • Comments or blank lines.

chevron-rightOrganization LOC calculation examplehashtag

Your organization has two private projects:

  • Project-1 has 500 lines of code on its main branch and 400 on a secondary long-lived branch: its LOC is 500.

  • Project-2 has 0 lines of code on its main branch (provisioned but never analyzed) and 200 on a secondary long-lived branch: its LOC is 200.

  • The total LOC for your organization is 500 + 200 = 700.

Last updated

Was this helpful?