Skip to main content

SonarCloud

SonarCloud (SonarQube Cloud) is a cloud-based code quality and security service that continuously analyzes projects for bugs, vulnerabilities, security hotspots, and code smells. Its Web API exposes projects, issues, metrics, measures, quality gates, rules, and organization data, letting you pull analysis results into Nexla or push administrative changes back to SonarCloud.

SonarCloud icon

Power end-to-end data operations for your SonarCloud API with Nexla. Our bi-directional SonarCloud connector is purpose-built for SonarCloud, making it simple to ingest data, sync it across systems, and deliver it anywhere — all with no coding required. Nexla turns API-sourced data into ready-to-use, reusable data products and makes it easy to send data to SonarCloud or any other destination. With comprehensive monitoring, lineage tracking, and access controls, Nexla keeps your SonarCloud workflows fast, secure, and fully governed.

Features

Type: API

SourceDestination

  • Seamless API Integration: Connect to any endpoint as source or destination without coding, with automatic data product creation
  • Visual Composition & Chaining: Build complex integrations using visual templates, chain API calls, and compose workflows with data validation and filtering
  • API Proxy: Expose curated slices of your data securely with a secure and customizable API proxy that validates and transforms data on the fly
  • Request optimization with intelligent batching, retry, and caching to minimize API calls and costs

Prerequisites

SonarCloud authenticates Web API requests with a personal access token, which is sent as a bearer token in the Authorization header. Before creating a SonarCloud credential in Nexla, generate a token from your SonarCloud account.

To obtain a SonarCloud API token, follow these steps:

  1. Sign in to SonarCloud with your account.

  2. Click your account avatar in the top-right corner, and select My Account.

  3. Open the Security tab (also labeled Access Tokens).

  4. Enter a name for the token, and select an expiration period.

  5. Click Generate Token, then copy the token value immediately. SonarCloud displays the token only once — if you leave or refresh the page, the value can no longer be retrieved.

  6. Store the token securely. You will paste it into the Nexla credential in the next section.

The token inherits the permissions of the user who generated it, so ensure that user has access to the organizations and projects you intend to read from or write to. If a token is lost or compromised, revoke it from the same Security screen and generate a new one. For more detail, see the SonarQube Cloud token documentation and the SonarCloud Web API reference.

Authenticate

Credentials required

Authenticate to Sonar Cloud.

FieldRequiredSecretDescription
API KeyYesYesAPI key.

Create a credential in Nexla

  1. After selecting the data source/destination type, click the Add Credential tile to open the Add New Credential overlay.

  2. Enter a name for the credential in the Credential Name field and a short, meaningful description in the Credential Description field.

  3. Enter your SonarCloud personal access token in the API Key field. Nexla sends this value as a bearer token in the Authorization header on every API request.

    Treat the API Key as a secret. The token grants access to your SonarCloud organizations and projects based on the permissions of the user who generated it. If it is compromised, revoke it in your SonarCloud account under My Account > Security and generate a new one.

    For detailed information about tokens and available endpoints, see the SonarQube Cloud token documentation and the SonarCloud Web API reference.

  4. Click the Save button at the bottom of the overlay. The newly added credential will now appear in a tile on the Authenticate screen during data source/destination creation.

Use as a data source

To create a new data flow, navigate to the Integrate section, and click the New Data Flow button. Select the SonarCloud connector tile, then select the credential that will be used to connect to SonarCloud, and click Next; or, create a new SonarCloud credential for use in this flow.

Endpoint templates

Nexla provides pre-built templates that can be used to rapidly configure data sources to ingest data from common SonarCloud endpoints. Select the endpoint from which this source will fetch data from the Endpoint pulldown menu. Available endpoint templates are listed in the expandable boxes below.

[Rest API] List Metrics

Retrieve metrics.

  • Returns the catalog of metrics available in SonarCloud, such as coverage, bugs, code smells, and duplications, that can be used when querying measures and measure history.

[Rest API] List Components

Retrieve components.

  • Returns components (projects, directories, and files) known to SonarCloud, useful for building an inventory of analyzed code.

[Rest API] List Issues

Retrieve issues.

  • Returns issues (bugs, vulnerabilities, and code smells) detected during analysis. You can scope results by component key to focus on a specific project.

[Rest API] List Projects

Retrieve projects visible to the authenticated user in an organization.

  • Returns the projects the authenticated user can access within an organization, useful for cataloging projects before querying their issues, measures, or analyses.

[Rest API] List Quality Gates

Retrieve all quality gates defined for the organization.

  • Returns the quality gates configured for the organization, including their names and default status.

[Rest API] List Rules

Search coding rules with optional filters.

  • Returns the coding rules used during analysis. Optional filters let you narrow the results by language, repository, severity, and other rule attributes.

[Rest API] List Organizations

Find organizations with optional query.

  • Returns SonarCloud organizations, optionally filtered by a search query, useful for discovering the organization keys needed by other endpoints.

[Rest API] List Users

Locate user accounts with optional criteria.

  • Returns user accounts, optionally filtered by search criteria, for building a directory of the people associated with your organization.

[Rest API] List Branches

Enumerate branches with statistics for a given project.

  • Returns the branches analyzed for a project, along with their status statistics. Provide the target project key in the required Project field when configuring this endpoint.

[Rest API] List Pull Requests

Display pull requests analyzed for a project.

  • Returns the pull requests analyzed for a project. Provide the target project key in the required Project field when configuring this endpoint.

[Rest API] List Project Analyses

Find project analyses and associated events.

  • Returns the analysis history for a project, including associated events such as version changes and quality gate status. Provide the target project key in the required Project field when configuring this endpoint.

[Rest API] Get Measure History

Retrieve historical measure data for a component's metrics.

  • Returns the historical values of one or more metrics for a component over time. Provide the target component key in the required Component field and a comma-separated list of metric keys in the required Metrics field when configuring this endpoint.

Once the selected endpoint template has been configured, click the Test button to the right of the endpoint selection menu to retrieve a sample of the data that will be fetched. Sample data will be displayed in the Endpoint Test Result panel on the right, allowing you to verify that the source is configured correctly before saving.

Manual configuration

SonarCloud data sources can also be manually configured to ingest data from any valid SonarCloud Web API endpoint, including endpoints not covered by the pre-built templates, chained API calls, or custom request parameters. Select the Advanced tab at the top of the configuration screen, and follow the instructions in Connect to Any API to configure the API method, endpoint URL, date/time and lookup macros, path to data, metadata, and request headers.

Once all of the relevant settings have been configured, click the Create button in the upper right corner of the screen to save and create the new SonarCloud data source. Nexla will now begin ingesting data from the configured endpoint and will organize any data that it finds into one or more Nexsets.

Use as a destination

Click the + icon on the Nexset that will be sent to the SonarCloud destination, and select the Send to Destination option from the menu. Select the SonarCloud connector from the list of available destination connectors, then select the credential that will be used to connect to SonarCloud, and click Next; or, create a new SonarCloud credential for use in this flow.

Endpoint templates

Nexla provides pre-built templates that can be used to rapidly configure destinations to send data to common SonarCloud endpoints. Select the endpoint to which data will be sent from the Endpoint pulldown menu. Then, click on the template in the list below to expand it, and follow the instructions to configure additional endpoint settings.

[Rest API] Create Project

Create a new project in a SonarCloud organization.

  • Each record from your Nexset is sent as a JSON request body to create a new project. Include the fields required by SonarCloud, such as the organization key, project key, and project name.

[Rest API] Generate User Token

Generate a new authentication token for a SonarCloud user.

  • Each record from your Nexset is sent as a JSON request body to generate a new authentication token. Include the fields required by SonarCloud, such as the token name and target user login.

[Rest API] Revoke User Token

Revoke an existing authentication token for a SonarCloud user.

  • Each record from your Nexset is sent as a JSON request body to revoke an existing authentication token. Include the fields required by SonarCloud, such as the token name and target user login.

[Rest API] Delete Project

Delete a project from a SonarCloud organization.

  • Each record from your Nexset is sent as a JSON request body to delete a project. Include the project key that identifies the project to remove.

[Rest API] Create Quality Gate

Establish a new quality gate for a SonarCloud organization.

  • Each record from your Nexset is sent as a JSON request body to create a new quality gate. Include the fields required by SonarCloud, such as the organization key and quality gate name.

[Rest API] Set Project Tags

Apply tags to a project.

  • Each record from your Nexset is sent as a JSON request body to set the tags on a project. Include the project key and the tags to apply.

[Rest API] Create Webhook

Register a new webhook to be notified when analyses complete.

  • Each record from your Nexset is sent as a JSON request body to register a webhook. Include the fields required by SonarCloud, such as the webhook name and callback URL.

[Rest API] Add User Permission

Grant a permission to a user, optionally scoped to a project.

  • Each record from your Nexset is sent as a JSON request body to grant a permission to a user. Include the target user login and permission, and optionally a project key to scope the permission to a single project.

Manual configuration

SonarCloud destinations can also be manually configured to send data to any valid SonarCloud Web API endpoint. Select the Advanced tab at the top of the configuration screen, and follow the instructions in Connect to Any API to configure the API method, data format, endpoint URL, request headers, attribute exclusions, record batching, and response webhooks.

Save & activate

Once all endpoint settings have been configured, click the Done button in the upper right corner of the screen to save and create the destination. To send the data to the configured SonarCloud endpoint, open the destination resource menu, and select Activate.

The Nexset data will not be sent to the SonarCloud endpoint until the destination is activated. Destinations can be activated immediately or at a later time, providing full control over data movement.