> ## Documentation Index
> Fetch the complete documentation index at: https://docs.oleria.com/llms.txt
> Use this file to discover all available pages before exploring further.

# SonarQube

> Connect your SonarQube instance to Oleria to continuously discover user and group access across your code quality platform.

SonarQube is a code quality and security analysis platform. Connect your SonarQube instance to Oleria to bring user and group access into your identity and access graph, without a dedicated SonarQube-specific integration.

## What Oleria discovers

* User accounts and profile attributes synced from SonarQube's directory.
* Groups and their memberships.

Oleria uses this data for dormant account detection and access reviews, refreshed on SonarQube's standard sync schedule.

## Prerequisites

* Admin access in SonarQube with permission to create a service account and generate a user token.
* Admin access on the Oleria platform to add a new integration.

<Note>
  The exact location of these settings can change over time. If the steps below don't match what you see, refer to SonarQube's own API documentation.
</Note>

## Get your SCIM credentials from SonarQube

<Steps>
  <Step title="Create a service account in SonarQube">
    Sign in to SonarQube as an admin, go to **Administration** → **Security** → **Users**, and create a service account with browse permissions.
  </Step>

  <Step title="Copy your SCIM Base URL and Authentication token">
    Generate a user token for the service account, then copy both values before you leave the page - you'll paste them into Oleria in the next section:

    * **SCIM Base URL** - the HTTPS API endpoint for your SonarQube instance.
    * **Authentication token** - the user token you generated.

    <Note>
      Copy the token now. Many applications display it only once. Store it securely and rotate it per your organization's security policy.
    </Note>
  </Step>
</Steps>

## Connect SonarQube to Oleria

<Steps>
  <Step title="Open the integration">
    Go to your Oleria workspace, select **Integrations**, then select the **SonarQube** tile.
  </Step>

  <Step title="Complete the connection form">
    Select **Continue** and fill in the connection form:

    | Field                | Notes                                                                                    |
    | :------------------- | :--------------------------------------------------------------------------------------- |
    | Instance name        | Optional. Short, recognizable label for this connection (for example, `sonarqube-prod`). |
    | SCIM Base URL        | Required. The HTTPS API endpoint copied from SonarQube.                                  |
    | Authentication token | Required. The user token issued by SonarQube.                                            |
  </Step>

  <Step title="Save the integration">
    Select **Connect** to validate the credentials and save the integration.
  </Step>
</Steps>

## Verify the integration

Confirm the new instance appears in your Oleria workspace under **Connected Integrations** with a status of **Healthy**. Oleria syncs users and groups from SonarQube on the standard SCIM provisioning schedule once the initial sync completes.

<Note>
  If SonarQube rotates your user token, update the Authentication token in Oleria by editing the integration.
</Note>

## Governance actions

Oleria can also invoke lifecycle actions in SonarQube when the token you provide has write access:

* Enable or disable a user account
* Add or remove a user from a group
* Create a new user or group

<Note>
  Many teams start with a read-only token for visibility, then grant write access once they're ready to automate remediation in SonarQube.
</Note>

## Contact us

For questions about this integration, contact us at [support@oleria.com](mailto:support@oleria.com).
