Ellipse Gradient for Header

SonarQube Cloud Integration Guide

Connect SonarQube Cloud analysis results, quality gates, issues, and project metrics with enterprise workflows through REST APIs, webhooks, and CI/CD orchestration.

SonarQube Cloud integration options at a glance

SonarQube Cloud provides a REST-style Web API for organizations, projects, issues, measures, quality gates, analyses, branches, and pull requests. It also supports webhook notifications for selected analysis-related events, while CI/CD tools can run analysis asynchronously and publish results for later retrieval. Martini can authenticate with SonarQube Cloud using bearer tokens stored in secrets, receive webhook calls through an API or HTTP workflow trigger, query authoritative analysis data, paginate large collections, and route mapped results to delivery, work-management, reporting, or governance systems. For changes not covered by webhooks, scheduled REST API synchronization provides a controlled alternative.

Integration pointSupported by SonarQube Cloud?Common use casesHow Martini supports it
REST APIsYesRetrieve organizations, projects, issues, measures, quality gates, analyses, branches, pull requests, and supported administration data.Martini can consume the SonarQube Cloud Web API, map JSON responses, apply business rules, and write or expose the resulting data.
Webhooks / outbound callbacksLimitedNotify external endpoints about selected analysis-related events, including analysis completion and quality-gate context.Martini can expose an API or use an HTTP workflow trigger, validate notifications, enforce idempotency, and retrieve authoritative details through REST.
AuthenticationYesAuthenticate API requests with a SonarQube Cloud token sent as a bearer token.Martini stores tokens in secrets or environment configuration and applies least-privilege access by environment and workflow.
Bulk / async / batch APIsLimitedAnalysis processing is asynchronous, and collection reads such as issues and projects use pagination; no general-purpose bulk write API was confirmed.Martini can poll for completion, paginate responses, filter collections, and use scheduled or asynchronous workflows for larger reads.
CI/CD integrationYesSonarScanner or supported build integrations publish analysis results from CI systems for later quality-gate and measure retrieval.Martini can receive CI callbacks, correlate project and branch context, poll SonarQube Cloud, and route final results to delivery systems.
Scheduled synchronizationYesPoll projects, issues, measures, branches, pull requests, and quality-gate data when no suitable webhook exists.Martini schedulers can run controlled workflows with filters, pagination, synchronization watermarks, retries, and downstream mappings.
File / attachment APIsNot confirmedNo general-purpose source-file or attachment API was confirmed; source analysis is normally performed by SonarScanner or CI tooling.Martini should process structured REST API data rather than assume that source files or attachments can be uploaded or downloaded through SonarQube Cloud.
Database accessNoDirect database or analytics access to the managed SonarQube Cloud service is not a documented integration method.Martini should use the SonarQube Cloud Web API or an approved reporting export instead of direct database connectivity.

How SonarQube Cloud exposes data and business events

SonarQube Cloud REST APIs

SonarQube Cloud exposes REST-style Web API endpoints for organizations, projects, issues, measures, quality gates, analyses, branches, pull requests, and supported administration functions. Responses are generally JSON, and collection endpoints may require pagination.

Martini implementation pattern

Martini implementation pattern: Martini authenticates with a bearer token stored in secrets, calls the required endpoint, preserves filters across pages, maps the JSON response to a canonical model, applies business rules, and writes the result to a target system or exposes it through a Martini API.

Implementation sequence

Authenticate with a least-privilege SonarQube Cloud token
Call the required REST endpoint with project or analysis filters
Retrieve all pages while preserving the request filters
Map the JSON response to the target model
Apply quality, severity, and lifecycle business rules
Write the result and store the synchronization watermark

SonarQube Cloud Webhooks

SonarQube Cloud supports webhook notifications for selected analysis-related events, including analysis completion and quality-gate context. These notifications are not a universal event stream for every issue, measure, project, or administration change.

Martini implementation pattern

Martini implementation pattern: a Martini API or HTTP workflow trigger receives the notification, validates the request, records the project and analysis identifiers, checks idempotency, and then retrieves authoritative analysis details through the REST API. Longer processing can continue asynchronously after an acknowledgement.

Implementation sequence

Receive the SonarQube Cloud webhook notification
Validate the request and identify the project and analysis
Check the analysis identifier against the idempotency store
Retrieve the current analysis and quality-gate details
Retry or defer processing if analysis data is incomplete
Route the normalized result to the downstream workflow

SonarQube Cloud CI/CD Integration

SonarQube Cloud analysis commonly runs asynchronously inside CI/CD pipelines using SonarScanner or supported build integrations. The pipeline can be followed by a callback or API lookup for analysis and quality-gate status.

Martini implementation pattern

Martini implementation pattern: Martini receives a CI callback or starts a follow-up workflow, correlates the project, branch, or pull-request context, polls SonarQube Cloud until processing is complete, and publishes a release, approval, ticket, or reporting outcome.

Implementation sequence

Receive the CI callback or start the follow-up workflow
Correlate the project, branch, or pull-request context
Poll SonarQube Cloud until the analysis reaches a final state
Retrieve measures, issues, and quality-gate results
Apply release or remediation rules
Publish the outcome and record the analysis identifier

Common SonarQube Cloud integration patterns

Pattern 1: Gate releases on analysis quality

When to use this pattern

Use this pattern when a CI/CD pipeline must make a release or approval decision from the final SonarQube Cloud quality gate. The workflow should tolerate asynchronous analysis completion and distinguish passing, failing, and unavailable results.

Integration direction
CI/CD Platform
SonarQube Cloud
Martini
Release Management System
Example Mapping
SonarQube Cloud FieldCanonical FieldTarget Field
projectKeyquality.projectKeyproject
analysisIdquality.analysisIdanalysis_reference
qualityGate.statusquality.decisionrelease_decision
branch.namequality.branchsource_branch
Martini implementation pattern

Martini receives a CI callback or SonarQube Cloud webhook, correlates the analysis, polls until the result is final, and retrieves the authoritative quality-gate status. Business rules route passes to approval, failures to remediation, and incomplete results to retry. The analysis identifier prevents duplicate release actions.

Martini capabilities used
  • workflows
  • API consumption
  • business rules
  • asynchronous execution
  • error handling
  • data mapping

Pattern 2: Synchronize SonarQube Cloud issues to Jira

When to use this pattern

Use this pattern to create or update Jira work items for selected vulnerabilities, bugs, or quality findings across controlled projects. Stable issue identifiers should drive reconciliation rather than source-line positions alone.

Integration direction
SonarQube Cloud
Martini
Jira
Example Mapping
SonarQube Cloud FieldCanonical FieldTarget Field
issue.keyfinding.externalIdexternal_reference
issue.typefinding.typeissue_type
issue.severityfinding.severitypriority
issue.componentfinding.componentcomponent
Martini implementation pattern

A scheduled Martini workflow retrieves filtered and paginated Issues, maps each stable issue key to Jira, and applies rules for creation, update, resolution, and priority. It records synchronization state, retries transient failures, and prevents duplicate Jira items through an external identifier.

Martini capabilities used
  • scheduled workflows
  • API consumption
  • pagination
  • data mapping
  • business rules
  • idempotency
  • retry handling

Pattern 3: Publish project quality metrics

When to use this pattern

Use this pattern when engineering leadership or governance teams need recurring Measures, project status, and quality-gate results in a reporting store or dashboard.

Integration direction
SonarQube Cloud
Martini
Data Warehouse
Example Mapping
SonarQube Cloud FieldCanonical FieldTarget Field
project.keyproject.externalIdproject_key
measure.coveragequality.coveragecoverage_percent
measure.vulnerabilitiesquality.vulnerabilityCountvulnerability_count
analysis.datequality.observedAtobserved_at
Martini implementation pattern

A Martini scheduler selects projects and analysis contexts, retrieves paginated Measures and related analysis results, normalizes metric names and types, and writes an append-or-update record to the warehouse. Filters and an analysis watermark reduce repeated reads, while validation isolates malformed or incomplete responses.

Martini capabilities used
  • scheduler trigger
  • API consumption
  • pagination
  • mapping and transformation
  • validation
  • database or API delivery

Pattern 4: Notify teams about quality-gate failures

When to use this pattern

Use this pattern for event-driven notifications when an analysis or quality gate requires engineering attention. It is appropriate for selected analysis events, not for assuming that every SonarQube Cloud object change generates a webhook.

Integration direction
SonarQube Cloud
Martini
Microsoft Teams
Example Mapping
SonarQube Cloud FieldCanonical FieldTarget Field
project.namenotification.projectmessage_title
qualityGate.statusnotification.severitymessage_emphasis
analysis.branchnotification.branchmessage_context
analysisIdnotification.deduplicationKeyexternal_event_id
Martini implementation pattern

Martini receives the webhook, validates and deduplicates it, retrieves current quality-gate and issue details, and applies notification thresholds before sending a concise Teams message. If analysis data is still processing, the workflow schedules a follow-up lookup rather than publishing a partial result.

Martini capabilities used
  • API endpoints
  • webhook reception
  • workflow orchestration
  • business rules
  • idempotency
  • asynchronous execution
  • error handling

Applications commonly integrated with SonarQube Cloud

SonarQube Cloud is commonly used alongside source-control, CI/CD, work-management, and collaboration products. Martini can coordinate these systems by consuming SonarQube Cloud APIs, receiving selected notifications, applying quality and routing rules, and exposing reusable APIs for downstream consumers.

Application Scenario Direction Martini Pattern
GitHub Connect repository and pull-request analysis with code-review status, quality-gate decisions, and engineering reporting. GitHub → SonarQube Cloud → Martini → GitHub Martini receives a SonarQube Cloud webhook or CI callback, retrieves the authoritative analysis and quality-gate result, then maps the outcome to a GitHub status or review workflow with idempotent processing.
GitLab Use GitLab CI analysis results and quality gates in merge-request and build governance. GitLab → SonarQube Cloud → Martini → GitLab A Martini workflow correlates the project and merge-request context, polls when analysis is asynchronous, retrieves issues and measures, and publishes a normalized result back to the GitLab delivery process.
Bitbucket Relate repository and pull-request activity to SonarQube Cloud analysis outcomes and quality decisions. Bitbucket → SonarQube Cloud → Martini → Bitbucket Martini orchestrates the CI callback and SonarQube Cloud REST lookup, applies branch and quality-gate rules, and sends a concise status update to the relevant Bitbucket workflow.
Azure DevOps Use SonarQube Cloud quality gates and analysis findings in Azure Pipelines and pull-request governance. Azure DevOps → SonarQube Cloud → Martini → Azure DevOps Martini correlates the pipeline, project, branch, or pull-request identifiers, retrieves final measures and gate status, and routes approval or remediation outcomes to Azure DevOps.
Jenkins Coordinate Jenkins analysis stages with quality-gate completion, release decisions, and operational notifications. Jenkins → SonarQube Cloud → Martini → Jenkins After Jenkins starts or completes analysis, Martini waits for the relevant SonarQube Cloud analysis, evaluates the quality gate, and returns a normalized decision with retry and duplicate-event handling.
Jira Create or update development work items for selected SonarQube Cloud vulnerabilities, bugs, or quality failures. SonarQube Cloud → Martini → Jira A scheduled Martini workflow retrieves filtered issues, maps stable issue keys and severity data to Jira fields, applies creation and update rules, and reconciles resolved issues without relying only on source-line positions.
ServiceNow Route significant vulnerabilities, quality-gate failures, or governance exceptions into enterprise workflows. SonarQube Cloud → Martini → ServiceNow Martini receives a notification or runs a scheduled synchronization, enriches the finding with project and analysis context, and creates or updates ServiceNow work items using stable SonarQube Cloud identifiers.
Microsoft Teams Notify engineering and release teams about failed quality gates, critical vulnerabilities, or completed analyses. SonarQube Cloud → Martini → Microsoft Teams Martini validates the event, retrieves current quality and issue details, applies notification thresholds, and sends a deduplicated summary to the appropriate Teams destination.

How to build a SonarQube Cloud integration in Martini

Objective

Establish controlled access to SonarQube Cloud and downstream systems without embedding credentials in workflows.

Instructions in Martini

  • Create a SonarQube Cloud token with only the required organization and project permissions.
  • Store the bearer token in Martini secrets or protected environment configuration.
  • Configure separate credentials and endpoints for development, test, and production.
  • Do not log Authorization headers or complete sensitive webhook payloads.

Objective

Select an event-driven or scheduled entry point based on the SonarQube Cloud capability required.

Instructions in Martini

  • Use a Martini API or HTTP start trigger for selected SonarQube Cloud webhook notifications.
  • Use a scheduler for issues, measures, project changes, or other data without a suitable webhook.
  • Use a CI callback or follow-up workflow when coordinating asynchronous analysis completion.

Objective

Obtain authoritative SonarQube Cloud data and handle asynchronous processing and collection pagination.

Instructions in Martini

  • Identify the project, branch, pull request, or analysis context.
  • Call the SonarQube Cloud REST API with the required filters.
  • Continue through all result pages while preserving filters.
  • Poll or defer processing when an analysis is not yet complete.

Objective

Coordinate validation, correlation, routing, and downstream processing in a maintainable Martini workflow.

Instructions in Martini

  • Validate inbound webhook or callback content before processing.
  • Use the analysis identifier or a compound project and analysis key for idempotency.
  • Route passing, failing, pending, and authorization-error outcomes separately.
  • Keep longer processing asynchronous when a prompt webhook response is required.

Objective

Convert SonarQube Cloud JSON objects into canonical and target-specific structures.

Instructions in Martini

  • Map Projects, Issues, Measures, Quality Gates, and Analyses to the target data model.
  • Normalize severity, status, quality-gate, branch, and pull-request values.
  • Preserve stable SonarQube Cloud identifiers for reconciliation.
  • Validate required fields before writing downstream records.

Objective

Apply enterprise policies to quality results, findings, notifications, and lifecycle updates.

Instructions in Martini

  • Define thresholds for quality-gate failures, vulnerabilities, bugs, and notification priority.
  • Determine whether a finding creates, updates, or resolves a downstream work item.
  • Use filters and synchronization watermarks to limit repeated processing.
  • Treat unsupported or incomplete API results as recoverable workflow outcomes.

Common SonarQube Cloud data objects used in integrations

ObjectTypical UseCommon target systemsMartini handling
OrganizationsRepresent top-level SonarQube Cloud containers and access boundaries for projects and users.Identity, governance, reporting, and configuration storesMartini retrieves organization context through REST, validates authorization scope, and maps it to governance or reporting models.
ProjectsIdentify repositories or codebases analyzed by SonarQube Cloud.CI/CD platforms, data warehouses, Jira, ServiceNow, and reporting systemsMartini synchronizes project keys and metadata, uses project filters for targeted reads, and preserves project identifiers for correlation.
IssuesRepresent code-quality or security findings, including severity, status, resolution, rule, component, and source location.Jira, ServiceNow, work-management systems, and security reporting storesMartini retrieves paginated issue collections, maps stable issue keys, applies severity and lifecycle rules, and reconciles updates.
MeasuresProvide metrics such as bugs, vulnerabilities, code smells, coverage, duplication, and quality ratings.Data warehouses, dashboards, governance systems, and release reportsMartini retrieves measures for selected projects, branches, or pull requests and transforms them into normalized reporting structures.
Quality GatesDefine conditions that determine whether analysis results meet required quality thresholds.CI/CD pipelines, release approvals, notification systems, and governance workflowsMartini evaluates the gate status after retrieving current analysis data and routes pass, fail, or pending outcomes.
AnalysesRepresent individual analysis executions with status, revision, branch or pull-request context, and quality-gate results.CI/CD platforms, release-management systems, audit stores, and reporting applicationsMartini uses analysis identifiers for correlation and idempotency, polls asynchronous processing, and stores final outcomes.

Authentication and security considerations

Token-based authentication

SonarQube Cloud API requests can use a bearer token in the HTTP Authorization header. Tokens should be stored in Martini secrets or protected environment configuration, not in workflow definitions, mappings, or logs.

Least-privilege access

Access depends on the token owner's organization, project, branch, issue, and administration permissions. Use separate tokens for environments and grant only the permissions required by each workflow.

Webhook protection

Validate inbound SonarQube Cloud webhook requests according to current SonarSource guidance. Record only the identifiers and fields needed for correlation, and avoid logging sensitive repository or analysis information.

  • Restrict outbound access to approved SonarQube Cloud endpoints where network policy allows.
  • Keep CI/CD secrets separate from Martini's API credentials where appropriate.
  • Do not expose Authorization headers in errors, traces, or downstream payloads.

Operational considerations for SonarQube Cloud integrations

Rate limits and pagination

Use narrow project and issue filters, preserve filters across pages, and avoid polling every project at short intervals. Prefer a webhook followed by a targeted REST lookup for analysis completion.

Asynchronous processing

A webhook or CI callback may arrive before all analysis details are available. Check status, retry or schedule a follow-up lookup, and publish results only after the required data is final.

Idempotency and reconciliation

Use an analysis identifier, a compound project-and-analysis key, or a stable Issue key to prevent duplicate actions. Do not rely solely on source-line positions because code changes can move issue locations.

Change management and testing

  • Keep API paths, parameters, and response mappings configurable because API versions and parameters can vary.
  • Validate required fields and handle unknown response fields conservatively.
  • Test webhook acknowledgement, replay, partial responses, authorization failures, and downstream retries.
  • Monitor response codes, workflow logs, processing latency, and synchronization watermarks.

Why use Martini instead of scripts or point-to-point integrations?

Reusable orchestration

Martini separates SonarQube Cloud API access, webhook reception, mapping, business rules, and downstream delivery into reusable workflows and APIs rather than embedding the entire process in a script.

Reliable synchronization

Pagination, scheduled execution, asynchronous polling, idempotency, validation, and retry handling provide a structured approach to quality, issue, and metric synchronization.

Controlled integration surface

Martini can expose a normalized API façade for downstream consumers while keeping SonarQube Cloud tokens, endpoint details, and provider-specific transformations behind a governed integration layer.

  • Support event-driven, scheduled, and CI/CD-led patterns in one platform.
  • Apply consistent mappings and quality-gate rules across target systems.
  • Centralize monitoring, troubleshooting, and environment-specific configuration.

Frequently asked questions

How can SonarQube Cloud be integrated with enterprise systems?

SonarQube Cloud can integrate through its REST-style Web API, selected analysis-related webhooks, and CI/CD workflows. Enterprise workflows can retrieve Projects, Issues, Measures, Quality Gates, Analyses, branches, and pull-request data, then route mapped results to delivery, work-management, reporting, or governance systems.

Can Martini integrate with SonarQube Cloud?

Yes. Martini can consume the SonarQube Cloud REST Web API, receive selected SonarQube Cloud webhook notifications through an API or workflow trigger, poll for asynchronous analysis completion, transform JSON data, and orchestrate downstream actions. No native Martini SonarQube Cloud connector is confirmed in the supplied documentation.

Do I need a connector to integrate SonarQube Cloud with Martini?

No. A dedicated SonarQube Cloud connector is not required. Martini can use SonarQube Cloud's confirmed native REST APIs, webhook notifications, CI/CD callbacks, bearer-token authentication, and scheduled synchronization mechanisms.

Is there any extra Lonti cost to integrate SonarQube Cloud with Martini?

Lonti does not charge an additional per-connector or per-vendor fee to integrate SonarQube Cloud. The integration is subject to the provisioned capacity of the Martini environment. Separate costs may apply from SonarSource, cloud infrastructure, or other third-party systems depending on subscription, usage, and deployment model.

Which SonarQube Cloud integration methods should architects use?

Use the REST Web API as the primary integration method. Use webhooks for selected analysis-related notifications, followed by an authoritative REST lookup. Use scheduled, paginated synchronization for Issues, Measures, Projects, or other changes without a suitable webhook. No official SonarQube Cloud GraphQL or SOAP API was confirmed.

Are SonarQube Cloud events or webhooks available?

SonarQube Cloud supports webhook-style notifications for selected analysis-related events, including analysis completion and quality-gate context. They are not a universal event feed for every object or change, so Martini should use scheduled REST polling where no relevant notification exists.

How does Martini synchronize and transform SonarQube Cloud data?

Martini can retrieve paginated JSON responses, apply project, branch, pull-request, issue, status, or analysis filters, and map the results to canonical and target-specific models. Synchronization can use an analysis identifier or watermark, while stable issue keys support reconciliation with work-management systems.

How does Martini handle SonarQube Cloud errors, retries, and duplicate events?

Martini can distinguish transient HTTP failures from authentication or authorization errors, retry recoverable requests with backoff, and defer processing while asynchronous analysis completes. Durable idempotency keys such as an analysis identifier or project-plus-analysis combination prevent duplicate downstream actions. Martini can also expose an API façade that presents a controlled, normalized interface to downstream consumers.