> For the complete documentation index, see [llms.txt](https://docs.sonarsource.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sonarsource.com/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/remediation-agent.md).

# Remediation Agent

The SonarQube Remediation Agent helps you fix and manage code issues found by SonarQube Cloud and SonarQube Server.

The Remediation Agent requires a separate subscription:

* SonarQube Cloud: part of Sonar Agent Essentials, on top of your Team (annual) or Enterprise plan.
* SonarQube Server: on version 2026.5 or newer, available on the Enterprise or Data Center edition with a separate subscription alongside your SonarQube Server license. See the [Sonar product subscriptions](https://docs.sonarsource.com/sonarqube-server/instance-administration/license-management/product-subscriptions) page for activation details.

## Overview

The SonarQube Remediation Agent runs an independent review and analysis to help you fix reliability, maintainability, and security issues found in your latest code. It focuses on issues in your backlog (discovered in your main branch analysis) and on issues found in your latest pull request (PR). On SonarQube Cloud, it can also remediate dependency vulnerabilities found by Software Composition Analysis (SCA). See [SCA basic remediation](#sca-basic-remediation).

DevOps platform support depends on your SonarQube product and the remediation type:

* SonarQube Cloud: automated and manual backlog remediation are available for projects bound to GitHub or Azure DevOps. Pull request remediation is available for GitHub-bound projects only.
* SonarQube Server: backlog and pull request remediation are both available for projects bound to GitHub, GitLab, or Azure DevOps. You can only trigger pull request remediation from the SonarQube Server UI, not from the DevOps platform.

The agent generates fix suggestions in the background and checks that the new code does not introduce new issues before offering the suggestion.

* On SonarQube Cloud, using the agent requires your own LLM provider API key, added at the organization level. See [Configure your LLM provider key](https://docs.sonarsource.com/sonarqube-cloud/administering-sonarcloud/ai-features/administer-remediation-agent#configure-your-llm-provider-key) for more information.
* On SonarQube Server, an instance administrator configures an LLM provider for the whole instance. See [LLM providers](https://docs.sonarsource.com/sonarqube-server/instance-administration/ai-features/llm-providers) for more information.

After issues from your analysis are assigned, the agent proposes fixes and creates new PRs for your review. Enable it per project, then review and approve code suggestions for each issue.

The SonarQube Remediation Agent can suggest fixes in three ways:

* **Automated backlog remediation**: The agent runs on a schedule you set, automatically proposing fixes for eligible issues in your main branch without manual assignment, then opens pull requests grouped by rule key and file type, the same way it does for manual backlog remediation. You set the frequency (daily or weekly), time, and timezone.
  * SonarQube Cloud: an organization administrator enables the scheduler org-wide, or a project administrator enables it for their own project.
  * SonarQube Server: an instance administrator enables the scheduler instance-wide, or a project administrator enables it for their own project.
* **Manual backlog remediation**: The agent fixes issues you select from your backlog and assign with the **Fix with Agent** button on the **Issues** page.
* **Pull request remediation**: The agent is triggered from a pull request analysis when your quality gate fails.

## Supported languages

The Remediation Agent works with your most common languages (C#, Java, JavaScript/TypeScript, and Python) by providing feedback on maintainability, reliability, and select security issues. Both products also offer fix suggestions for Secrets.

* SonarQube Cloud: can also remediate dependency vulnerabilities found by Software Composition Analysis (SCA); see [SCA basic remediation](#sca-basic-remediation) below. See [Requirements and limitations](https://docs.sonarsource.com/sonarqube-cloud/administering-sonarcloud/ai-features/administer-remediation-agent#requirements-and-limitations) for complete details.
* SonarQube Server: see the Remediation Agent's [Prerequisites](https://docs.sonarsource.com/sonarqube-server/instance-administration/ai-features/remediation-agent#prerequisites) for complete details.

## Sharing your code with Sonar <a href="#sharing-your-code-with-sonar" id="sharing-your-code-with-sonar"></a>

If you use the SonarQube Remediation Agent, the affected code is processed by Sonar to generate and verify a fix suggestion. Sonar's remediation service sends the affected code snippet to your provider's LLM to generate the suggestion, then verifies the generated code, even when SonarQube Server runs on your own infrastructure.

Because you bring your own provider, the request is made under your own provider account, so your provider's usage agreement governs how your data is handled:

* SonarQube Cloud: a BYOK (bring your own key) API key.
* SonarQube Server: a BYOP (bring your own provider) instance-level provider.

For Sonar terms and conditions, see [Early Access terms](https://www.sonarsource.com/legal/early-access/) in our [Legal documentation](https://www.sonarsource.com/legal/).

## Setup

Find instructions for enabling and installing the agent in the following product documentation:

* SonarQube Cloud: [Administer the Remediation Agent](https://docs.sonarsource.com/sonarqube-cloud/administering-sonarcloud/ai-features/administer-remediation-agent).
* SonarQube Server: [Remediation Agent](https://docs.sonarsource.com/sonarqube-server/instance-administration/ai-features/remediation-agent).

## Using the agent

To understand the agent's behavior and learn how to engage with it, see the following product documentation:

* SonarQube Cloud: [Pull request fix suggestions](https://docs.sonarsource.com/sonarqube-cloud/administering-sonarcloud/ai-features/administer-remediation-agent) and [Backlog fix suggestions](https://docs.sonarsource.com/sonarqube-cloud/administering-sonarcloud/ai-features/administer-remediation-agent).
* SonarQube Server: [Remediation Agent](https://docs.sonarsource.com/sonarqube-server/instance-administration/ai-features/remediation-agent) and [Backlog fix suggestions](https://docs.sonarsource.com/sonarqube-server/user-guide/issues/with-ai-features/backlog-fix-suggestions).

## SCA basic remediation

This feature is available on SonarQube Cloud only.

The Remediation Agent can fix Software Composition Analysis (SCA) vulnerabilities by bumping the dependency version suggested by the SCA analysis. Triggered by a SonarQube Cloud [Dependency risks](https://docs.sonarsource.com/sonarqube-cloud/advanced-security/reviewing-and-fixing-dependency-risks) analysis, the agent generates a PR for your review.

The following package managers are supported:

* **NPM** — covers npm and yarn
* **PyPI** — covers pip
* **Maven** — covers Maven and Gradle

## FAQ

#### What does the Remediation Agent do?

The Remediation Agent resolves SonarQube issues and returns each fix as a reviewable pull request. It's a purpose-built remediation workflow for Sonar issues, not a general-purpose coding assistant: SonarQube triggers it rather than a prompt, it works from your issue and full repository context, and Sonar's own analysis engine verifies every fix before you see it.

#### How does the Remediation Agent relate to Sonar's other AI capabilities?

They operate at different points in the development cycle and are designed to be used together.

|                   | When it runs                                                                        | What it does                                       | Setup                  |
| ----------------- | ----------------------------------------------------------------------------------- | -------------------------------------------------- | ---------------------- |
| Vortex analysis   | While you code (inner loop). Also used by the Remediation Agent on SonarQube Server | Verifies what your coding agent produces           | Your prompts and tools |
| Remediation Agent | Pull request review and backlog (outer loop)                                        | Generates and verifies fixes for Sonar issues      | Native, no prompting   |
| AI Code Fix       | In-product, per issue                                                               | Suggests a fix for a single issue for you to apply | Enabled per project    |
| Sonar MCP server  | While you code                                                                      | Exposes Sonar data to the LLM of your choice       | You configure          |

The Remediation Agent differs from using the MCP server with your own LLM in two ways: it requires no prompting or configuration, and every fix passes through closed-loop verification before it reaches you.

#### How does the agent make sure its fixes are correct?

Every fix goes through closed-loop verification. The agent generates a candidate fix, then re-runs Sonar's analysis engine against the modified code. Only fixes confirmed to resolve the original issue without introducing new ones are surfaced as pull requests. Fixes that fail verification are not shown to you.

Because the agent works from full repository context rather than only the pull request diff, it can account for code outside the changed files when generating a fix.

#### Who reviews and merges the agent's pull requests?

Your developers do. The agent prepares reviewable output; it does not merge. Your existing controls apply unchanged: branch protection rules, required reviewers and review rules, and merge controls and status checks. Each pull request includes the rule that was violated, an explanation, and the diff, so reviewers can assess the change in context.

#### What happens when the agent cannot fix an issue?

* SonarQube Cloud: for pull request remediation, the issue appears in the Remediation Agent Summary under Issues requiring manual fix. Review the issue details and fix it manually.
* SonarQube Server: an explanation of the error is available on your project's Remediation Agent activity page. For more detail, download the logs from the **Project > Agentic tasks** page.

#### What languages, issue types, and platforms are supported?

**Languages**: Java, JavaScript and TypeScript, Python, and C#. Both products also offer fix suggestions for Secrets.

**Issue types**: Reliability, Maintainability, and selected Security rules.

**Platforms**:

* SonarQube Cloud: automated and manual backlog remediation work with GitHub- and Azure DevOps-bound projects. Pull request remediation works with GitHub-bound projects only.
* SonarQube Server: backlog and pull request remediation both work with projects bound to GitHub, GitLab, or Azure DevOps. You can only trigger pull request remediation from the SonarQube Server UI, not from the DevOps platform.

#### Is the Remediation Agent available on SonarQube Server?

Yes. The Remediation Agent is available on SonarQube Server 2026.5 or newer, in the Enterprise and Data Center editions, with a separate subscription.

#### What are the prerequisites for running the agent on SonarQube Server?

* **SonarQube Server version**: 2026.5 LTA or newer.
* **LLM provider**: an instance administrator configures an LLM provider and model for the whole instance. See [LLM providers](https://docs.sonarsource.com/sonarqube-server/instance-administration/ai-features/llm-providers).
* **Network access**: the agent needs outbound access to your LLM provider, your DevOps platform, shared storage, and more. See [Network access](https://docs.sonarsource.com/sonarqube-server/server-installation/ai-agents/before-you-start#network-access).
* **Proxy**: the Agent Orchestrator supports an authenticated HTTP/HTTPS proxy. See [Outbound proxy](https://docs.sonarsource.com/sonarqube-server/server-installation/ai-agents/configuration-reference#outbound-proxy).
* **DevOps platform configuration**: a configured connection to a supported DevOps platform, with write permissions, bound to the repositories you want the agent to work on.

If your network routes outbound traffic through an authenticated proxy, confirm the proxy configuration before starting a trial. Unresolved proxy settings are the most common cause of a failed setup.

#### Does our code leave our network when the agent runs?

Yes, on both SonarQube Cloud and SonarQube Server. The Remediation Agent sends code and issue context to the model provider for processing, even when you run SonarQube Server on your own infrastructure. Running SonarQube Server on your own infrastructure does not keep code within your network when you use the agent.

Data is processed by the LLM provider and region you configure, and that provider's data-handling terms (training, retention) apply.

#### Can I run the agent without internet access to Sonar?

* SonarQube Cloud: not applicable. SonarQube Cloud is a hosted service.
* SonarQube Server: you can run the AI agents without internet access to Sonar, but you must supply the sandbox runtime yourself. Sonar does not mirror it or provide a side-loading package, so obtaining and installing it on your hosts or nodes is your responsibility.

#### Which LLM does the agent use? Can we use our own?

The Remediation Agent supports the following models: Claude Opus 4.6, Claude Opus 4.7, Claude Opus 4.8, Claude Opus 5, GPT-5.3 Codex, GPT-5.5, and GPT-5.6 Sol. We recommend Claude Opus 4.6 or GPT-5.5.

* SonarQube Cloud: an organization administrator adds your own OpenAI or Anthropic API key at the organization level.
* SonarQube Server: an instance administrator configures an LLM provider for the whole instance, using the Azure AI Foundry or AWS Bedrock provider types, or the Custom provider type for any OpenAI-compatible endpoint (including OpenAI, Anthropic, OpenRouter, or Portkey).

#### How do we control where the agent runs?

The agent is enabled per project. It uses the application and repository binding model of your DevOps platform, so it can only access repositories you've explicitly bound.

You control:

* The projects the agent is enabled for
* The repositories it can act on, through your DevOps platform binding
* The issues it works on; you assign them or configure a schedule

We recommend enabling the agent on one or two repositories first, then expanding once your team is comfortable with the output.

#### Which plans and editions include the Remediation Agent?

* SonarQube Cloud: part of Sonar Agent Essentials, a separate subscription to your Team (annual) or Enterprise plan.
* SonarQube Server: available on version 2026.5 or newer, in the Enterprise and Data Center editions, with a separate subscription.

#### Are there usage limits?

* SonarQube Cloud: see [Viewing billing or usage information](https://docs.sonarsource.com/sonarqube-cloud/administering-sonarcloud/managing-subscription/viewing-billing-and-usage) for your consumption, and [Subscription plans](https://docs.sonarsource.com/sonarqube-cloud/administering-sonarcloud/managing-subscription/subscription-plans) for overage.
* SonarQube Server: see the [Sonar product subscriptions](https://docs.sonarsource.com/sonarqube-server/instance-administration/license-management/product-subscriptions) page for your consumption, and the [Overage activation](https://docs.sonarsource.com/sonarqube-server/instance-administration/license-management/overage-activation) page for overage.

#### What is the simplest way to try the Remediation Agent?

Pilot it on a small scope rather than rolling it out broadly:

1. Choose one or two repositories.
2. Enable the agent for that limited scope.
3. Try it on a pull request that has failed its quality gate, and on a handful of backlog issues.
4. Review the resulting pull requests through your normal process.

A short session is usually enough to judge fit. No broad rollout is needed to evaluate it.

#### How do we enable it?

* SonarQube Cloud: [Administer the Remediation Agent](https://docs.sonarsource.com/sonarqube-cloud/administering-sonarcloud/ai-features/administer-remediation-agent).
* SonarQube Server: [Remediation Agent](https://docs.sonarsource.com/sonarqube-server/instance-administration/ai-features/remediation-agent).

## Related products

For AI-powered pull request review automation, see [Gitar](https://docs.gitar.ai), a separate Sonar product.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.sonarsource.com/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/remediation-agent.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
