> For the complete documentation index, see [llms.txt](https://docs.sonarsource.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sonarsource.com/sonarqube-server/instance-administration/ai-features/hunter-agent.md).

# Hunter Agent

Set up the SonarQube Hunter Agent on SonarQube Server, from deploying the agent to enabling it for your projects.

SonarQube Hunter Agent runs a deep AI-powered analysis of your projects to find vulnerabilities that require human-like understanding of the code, such as broken access control and business-logic flaws, then raises them as issues you triage like any other.

To learn how the agent works, see [Hunter Agent](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/hunter-agent.md) in the Agent Centric Development Cycle documentation. For subscription and consumption details, see [#subscription-and-consumption](#subscription-and-consumption "mention").

## Subscription and consumption <a href="#subscription-and-consumption" id="subscription-and-consumption"></a>

### Subscription requirements <a href="#subscription-requirements" id="subscription-requirements"></a>

The Hunter Agent is sold as a separate product alongside your SonarQube Server Enterprise or Data Center edition. Once purchased, it's added to your license as an additional feature. See the [Sonar product subscriptions](/sonarqube-server/instance-administration/license-management/product-subscriptions.md) page for details about adding a subscription. Your SonarQube Server license must be activated through LicenseSpring, either online or offline; the Hunter Agent is not available with a server ID-based license.

Your Hunter Agent subscription supports overage, letting you keep running scans past your base allowance for an extra cap you set yourself, which resets at the end of your contract term. See the [Overage activation](/sonarqube-server/instance-administration/license-management/overage-activation.md) page to activate it. Overage requires online license connectivity and is not available on a server ID-based license. Your base allowance and overage cap are both measured in scan units.

### What counts as a scan unit <a href="#what-counts-as-a-scan-unit" id="what-counts-as-a-scan-unit"></a>

A scan unit is the unit the Hunter Agent consumes to analyze a codebase. Scan units are drawn from your base allowance first and, if overage is active, from your overage cap. Each time the agent analyzes a project, it consumes scan units based on the project's size in [Lines of Code](/sonarqube-server/server-update-and-maintenance/monitoring/lines-of-code.md#calculating-lines-of-code). Sonar groups codebases into size ranges rather than calculating scan units per line: scanning a larger codebase generally consumes more scan units.

| Codebase size | Lines of code (LOC)   |
| ------------- | --------------------- |
| XS            | Up to 1,000           |
| S             | 1,001–10,000          |
| M             | 10,001–100,000        |
| L             | 100,001–500,000       |
| XL            | 500,001–1.5 million   |
| XXL           | More than 1.5 million |

The exact number of scan units each tier consumes depends on your subscription and whether you bring your own LLM provider key.

See the [Sonar product subscriptions](/sonarqube-server/instance-administration/license-management/product-subscriptions.md) page to manage your scan unit usage.

## Setup overview <a href="#setup-overview" id="setup-overview"></a>

Setup spans several roles. Complete the steps in order.

| Step | Task                                                                                                                                                                                          | Who does it            | Where                                                                                                                                                                                            |
| ---- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| 1    | Add the Hunter Agent to your license                                                                                                                                                          | Instance administrator | [License management](/sonarqube-server/instance-administration/license-management.md)                                                                                                            |
| 2    | Deploy the agent                                                                                                                                                                              | System administrator   | [Deploying AI agents](/sonarqube-server/server-installation/ai-agents.md)                                                                                                                        |
| 3    | Add an LLM provider, then choose Opus 4.8 as the agent's primary model. The agent also uses Sonnet 4.6 as a secondary model, so make sure both models are available to your provider and key. | Instance administrator | **AI Capabilities** > **LLM Providers** (see [LLM providers](/sonarqube-server/instance-administration/ai-features/llm-providers.md)), then [#enabling-the-agent](#enabling-the-agent "mention") |
| 4    | Enable the agent                                                                                                                                                                              | Instance administrator | [#enabling-the-agent](#enabling-the-agent "mention")                                                                                                                                             |
| 5    | Set up scheduled scans for a project                                                                                                                                                          | Project administrator  | [Hunter Agent](/sonarqube-server/project-administration/ai-features/hunter-agent.md)                                                                                                             |

Steps 1 to 4 are all required. Step 5 is optional.

Before you start, check what the agent needs from your projects in [#prerequisites](#prerequisites "mention").

## Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* The Hunter Agent is deployed, and an LLM provider and a model are configured. The provider can vary, but the agent requires two Anthropic Claude models: Opus 4.8 (`claude-opus-4-8`) as the primary model and Sonnet 4.6 (`claude-sonnet-4-6`) as the secondary model. Select the provider-specific identifier or deployment for each model when you configure a provider for the agent. For these steps and who does each one, see [#setup-overview](#setup-overview "mention"). Until you save a provider and a model, you cannot enable the Hunter Agent.
* Each project you want to scan is bound to a repository on a supported DevOps platform. The agent supports GitHub, GitLab, and Azure DevOps. See [DevOps platform integration](/sonarqube-server/instance-administration/devops-platforms.md) for details.
* You've analyzed the project, so the agent has code to scan.

## Enabling the agent <a href="#enabling-the-agent" id="enabling-the-agent"></a>

The Hunter Agent is enabled once for the whole instance. There's no per-project enable setting: once you turn it on, every bound project can use it, and project administrators set up scheduled scans for their own project.

With a provider and a model configured, enable the agent:

1. Go to **Administration** > **Configuration** > **AI capabilities** > **Hunter Agent**.
2. Turn on the Hunter Agent.

Once enabled, project administrators can run analyses and set up scheduled scans from their project's **Hunter Agent** page. See [Hunter Agent](/sonarqube-server/project-administration/ai-features/hunter-agent.md).

The agent raises its findings as issues in each scanned project. See [Hunter Agent findings](/sonarqube-server/user-guide/issues/with-ai-features/hunter-agent-findings.md).

To understand what counts as one scan unit, see [#what-counts-as-a-scan-unit](#what-counts-as-a-scan-unit "mention").

## Related pages <a href="#related-pages" id="related-pages"></a>

* AC/DC: [Hunter Agent](/agent-centric-development-cycle/in-your-long-living-branches-the-code-maintenance-loop/hunter-agent.md)
* Project admin: [Hunter Agent](/sonarqube-server/project-administration/ai-features/hunter-agent.md)
* [Hunter Agent findings](/sonarqube-server/user-guide/issues/with-ai-features/hunter-agent-findings.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.sonarsource.com/sonarqube-server/instance-administration/ai-features/hunter-agent.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
