# SonarQube Cloud MCP connector

The SonarQube Cloud connector lets Claude, ChatGPT, Cursor and other AI clients look up the users, groups, notification settings and account details in your SonarQube Cloud organization, with every request running as the person who signed in and recorded in an audit log.

Source: https://elaichi.ai/connectors/sonarqubecloud/

## Facts

| | |
| --- | --- |
| Application | SonarQube Cloud |
| Category | Application Development |
| AI tools | 4 |
| Authentication | Connects with an API key |
| Needs your own OAuth app | No |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | Yes |

## What you can ask once SonarQube Cloud is connected

- List every SonarQube Cloud group and its member count.
- Which users have notifications turned on this week?
- Show SonarQube Cloud users added since last Monday.

## Connect SonarQube Cloud in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick SonarQube Cloud.
2. Optionally set Share with, then press Connect.
3. Paste a SonarQube Cloud API key. One person generates a token in SonarQube Cloud and pastes it once. Everyone else works through Share with, and never sees it.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which SonarQube Cloud tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Connect SonarQube Cloud to Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Connect SonarQube Cloud to ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Connect SonarQube Cloud to Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect SonarQube Cloud to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a SonarQube Cloud tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with SonarQube Cloud through Elaichi

### See who has a SonarQube Cloud seat

Engineering management. Ask for the full list of people in your SonarQube Cloud organization before a renewal or a headcount review, and get names and accounts back in one answer instead of paging through the members screen.

### Check group membership during offboarding

IT. When someone leaves, ask which SonarQube Cloud groups still include them and which groups exist at all, so nothing is missed when their access is removed.

### Review groups before an access audit

Security. Pull the list of SonarQube Cloud groups and the users behind them into a document your auditor can read, without anyone exporting spreadsheets by hand.

### Find out which alerts you are subscribed to

DevOps. Ask what notifications your SonarQube Cloud account currently sends you, so you know why an alert about a failed quality gate or a new issue did or did not arrive.

### Confirm your own account details

Engineering. Check the login, name and email SonarQube Cloud has on file for you when a colleague cannot find you in a group or a mention is going to the wrong person.

### Answer who can see code quality results

Compliance. Produce a plain-language summary of the users and groups in SonarQube Cloud for a quarterly access review, drawn from the live organization rather than a stale export.

## Frequently asked questions

### How do I connect SonarQube Cloud to Claude?

Two steps. First, connect SonarQube Cloud in Elaichi by pasting an API key from your SonarQube Cloud account; there is no OAuth application to register and no client ID or secret to generate. Then in Claude open Customize, then Connectors, then Add, and paste the endpoint https://api.elaichi.ai/mcp. Claude will ask you to sign in to Elaichi, and from then on it can look up SonarQube Cloud users, groups and notifications for you.

### Does SonarQube Cloud work with ChatGPT and Cursor as well as Claude?

Yes. Once SonarQube Cloud is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect SonarQube Cloud once and every client you use picks it up.

### What can an AI agent actually do with my SonarQube Cloud data?

With this connector an agent can list the users in your SonarQube Cloud organization, list the groups and who belongs to them, show the notifications your account is subscribed to, and show your own account details. That covers questions like who has a seat, which groups a departing colleague is in, and why a quality gate alert did or did not reach you. It reads this information; it does not change anything in SonarQube Cloud.

### Does connecting SonarQube Cloud give the AI access to my whole organization?

No. Every request runs with the SonarQube Cloud permissions of the person who signed in, so an agent sees exactly the users, groups and notifications that person can already see, and nothing more. Elaichi can narrow that further with restrictions, but it can never widen access beyond what SonarQube Cloud itself allows that person.

### Can my team share one SonarQube Cloud connection?

Yes. One person connects SonarQube Cloud in Elaichi and shares the connection with a team, and nobody else ever handles the API key. Each teammate still signs in to Elaichi as themselves, so the audit log names the actual person who asked for a list of SonarQube Cloud users or groups, not the account owner.

### Can I stop an agent from deleting or changing things in SonarQube Cloud?

This SonarQube Cloud connector only reads: it lists users, groups, notifications and your own account, and it has no way to create, edit or delete anything. Even so, Elaichi lets you restrict each action individually, and any action you block is never shown to Claude, ChatGPT or Cursor at all, so no prompt can reach it.

### What happens to a SonarQube Cloud connection when someone leaves?

Offboarding a person in Elaichi ends their access to SonarQube Cloud through every AI client at once. If they had shared a SonarQube Cloud connection with a team, that connection keeps working for everyone else. If you want it gone entirely, disconnecting SonarQube Cloud once in Elaichi removes it from Claude, ChatGPT, Cursor and every other client in one step.

## All 4 SonarQube Cloud tools

Every tool below is callable through https://api.elaichi.ai/mcp once SonarQube Cloud is connected, subject to the toolbox it is in and the restrictions on the caller.

- **List all SonarQube Cloud users** (List). Use this endpoint to retrieve users from your SonarQube Cloud account.
- **List all SonarQube Cloud groups** (List). Use this endpoint to retrieve groups from an organization in your SonarQube Cloud account. Use the organization query parameter to specify the organization for which you want to retrieve groups.
- **List all SonarQube Cloud notifications** (List). Use this endpoint to list all notifications associated with the authenticated user. The response includes major details such as the organizations the notifications belong to and the channels through which these notifications are delivered.
- **List all SonarQube Cloud me** (List). Use this endpoint to retrieve the currently authenticated user information for your SonarQube Cloud account.
