Sonatype MCP Server

Sonatype MCP Server

The Sonatype MCP Server extends Sonatype Guide’s automation capabilities by connecting AI coding assistants and IDEs to Sonatype’s trusted open-source intelligence.

With the MCP Server configured, you get real-time security scanning, version guidance, and compliance checks directly in your AI chat. As you write code or ask about dependencies, your AI assistant checks components instantly and recommends secure, policy-aligned versions and safe upgrade options.

What Can You Do with Sonatype MCP Server?

Sonatype MCP Server provides three powerful tools for AI assistants:

With these tools, you can use Sonatype MCP Server and your preferred AI assistant to do the following:

Getting Started

To use the Sonatype MCP Server, follow these steps:

  1. Generate an MCP API token
    Create a personal token from your Sonatype Guide account. Your AI assistant uses this token to connect securely. For detailed instructions on creating and managing tokens, see Manage Guide User Tokens.

Important
Keep this token secure and avoid committing it to version control or sharing it in project files.

  1. Configure the MCP server connection
    Add the Sonatype MCP Server URL and your token to your IDE or AI assistant settings. For detailed instructions on configuring the MCP Server, see

  2. Set up your IDE or AI assistant
    Complete the tool-specific configuration so your assistant can use the MCP tools.

Data Access and Privacy

The Sonatype MCP Server connects your AI assistant to Sonatype’s open-source intelligence. It does not access or retrieve your application source code.

When you use the MCP Server:

This is similar to how Sonatype can see that a customer called a policy evaluation API, but does not have access to the customer’s application source code. The MCP Server operates in the same way. It processes specific dependency information provided in the request, without visibility into your codebase.

The MCP Server does not access your repositories, scan your codebase, read local files, or collect your intellectual property. It only processes the specific dependency information included in a tool request.

You maintain control of your source code and development environment at all times.