# SonarSource

**Canonical:** https://apis.io/providers/sonarsource/  
**Website:** https://www.sonarsource.com/  
**APIs profiled:** 33

SonarSource (Sonar) builds the industry-standard tooling for code quality and code security, trusted by large engineering organizations to keep code Clean. Its product line spans SonarQube Cloud (formerly SonarCloud, the hosted SaaS analysis service), SonarQube Server (self-managed), SonarQube for IDE (formerly SonarLint), and the SonarQube Community Build. SonarQube Cloud exposes a REST Web API for programmatically managing projects, issues, quality gates, quality profiles, rules, measures, hotspots, permissions, webhooks, and user tokens, plus a family of first-party scanners (npm, PyPI, Maven, Gradle, .NET, and Docker) for wiring analysis into CI/CD pipelines.

## Kin Score — 54.7 / 100 (developing)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 54.7).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 63.7 |
| Governance | 11.5 |
| Operational Transparency | 50.0 |
| Developer Ergonomics | 69.0 |
| Commercial Clarity | 44.7 |

## Agent readiness — 44.8 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| MCP Server | derived |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | verified |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | yes |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (33)

- **SonarSource authentication API** — Handle authentication.
- **SonarSource ce API** — Get information on Compute Engine tasks.
- **SonarSource components API** — Get information about a component (file, directory, project, ...) and its ancestors or descendants. Update a project or module key.
- **SonarSource duplications API** — Get duplication information for a project.
- **SonarSource favorites API** — Manage user favorites
- **SonarSource favourites API** — Removed since 6.3, please use api/favorites instead
- **SonarSource hotspots API** — Read and update Security Hotspots. Hotspots are deprecated and replaced by security issues (software quality) and vulnerabilities (type). Please use the API of security issues /...
- **SonarSource issues API** — Read and update issues.
- **SonarSource languages API** — Get the list of programming languages supported in this instance.
- **SonarSource measures API** — Get components or children with specified measures.
- **SonarSource metrics API** — Get information on automatic metrics, and manage custom metrics. See also api/custom_measures.
- **SonarSource notifications API** — Manage notifications of the authenticated user
- **SonarSource permissions API** — Manage permission templates, and the granting and revoking of permissions at the global and project levels.
- **SonarSource project_analyses API** — Manage project analyses.
- **SonarSource project_badges API** — Generate badges based on quality gates or measures
- **SonarSource project_branches API** — Manage branch (only available when the Branch plugin is installed)
- **SonarSource project_links API** — Manage projects links.
- **SonarSource project_pull_requests API** — Manage pull request (only available when the Branch plugin is installed)
- **SonarSource project_tags API** — Manage project tags
- **SonarSource projects API** — Manage project existence.
- **SonarSource properties API** — This web service is deprecated, please use api/settings instead.
- **SonarSource qualitygates API** — Manage quality gates, including conditions and project association.
- **SonarSource qualityprofiles API** — Manage quality profiles.
- **SonarSource rules API** — Get and update some details of automatic rules, and manage custom rules.
- **SonarSource settings API** — Manage settings.
- **SonarSource sources API** — Get details on source files. See also api/tests.
- **SonarSource timemachine API** — Removed since 6.3, please use api/measures/search_history instead
- **SonarSource user_groups API** — Manage user groups.
- **SonarSource user_properties API** — Removed since 6.3, please use api/favorites and api/notifications instead
- **SonarSource user_tokens API** — List, create, and delete a user's access tokens.
- **SonarSource users API** — Manage users.
- **SonarSource webhooks API** — Webhooks allow to notify external services when a project analysis is done
- **SonarSource webservices API** — Get information on the web api supported on this instance.

## MCP servers (1)

- **sonarsource-mcp.yml**

## Agentic access (1)

- **Sonarsource Agentic Access** — 156 operations · 87 acting · 2 human-in-the-loop

## Security (2)

- **Sonarsource Authentication** — http · 2 schemes
- **Sonarsource Domain Security** — TLSv1.3 · HSTS · DMARC

## Tags

Company, Code Quality, Static Analysis, Code Security, SAST, Developer Tools, DevOps, Code Review, SonarQube

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/sonarsource/). Scores are computed from the provider's own public artifacts under a published rubric.
