SonarQube Server is SonarSource’s self-managed code analysis server. It is sold in three commercial editions, Developer, Enterprise and Data Center, and each is “licensed per instance per year based on Lines of Code (LOC)”. The customer pays “for a LOC capacity at the instance level”.[3] The SonarQube Server Supplemental Terms of 2026-10-01 grant a licence “to analyze up to the maximum number of Lines of Code specified in the Order”. The same grant also allows additional copies solely for testing, staging and disaster recovery.[1] The free SonarQube Community Build is a separate product under open-source terms. It is described in SonarQube Community Build and IDE licences.
Editions
SonarSource publishes no list prices for SonarQube Server. Its pricing page says that all three editions “are priced per instance per year and based on your lines of code (LOC)”, and that an instance “is an installation of SonarQube Server”.[2]
| Edition | Positioning | Notable entitlements | Catalog row |
|---|---|---|---|
| Developer | Small teams or business units on a single instance; recommended for 100K+ LOC[2] | Branch and pull request analysis; C, C++, Obj-C, Swift, ABAP, T-SQL, PL/SQL on top of Community languages; AI CodeFix; SAML SSO[3] | Developer Edition |
| Enterprise | Larger organizations with many teams; recommended for 1M+ LOC[2] | Adds Apex, COBOL, JCL, PL/I, RPG, VB6; portfolios; compliance, PDF and regulatory reports; SCIM; audit logs; monorepos; multiple DevOps platform instances; product subscriptions[3] | Enterprise Edition |
| Data Center | Very large or mission-critical deployments needing high availability and horizontal scale[3] | Enterprise features plus clustering, redundancy and autoscaling in Kubernetes; all customers entitled to commercial support[14] | Data Center Edition |
Running SonarQube Server requires “a license that corresponds to the plan you purchased, including the SonarQube Server edition, Lines of Code (LOC), staging licenses, commercial support, and additional features such as Advanced Security”.[5] A change of edition therefore means a new licence key as well as a different distribution. The licence page shows the edition, the licence type (“production, test and evaluation”), start and expiry dates, whether support is included, and the activation method.[5]
Metrics
- Lines of Code. The Supplemental Terms define it as “the number of lines of code analyzed by SonarQube Server”. A project’s LOC is counted on the largest branch analysed and is “not cumulative when the same project is re-analyzed”.[1]
- Instance. One installation of SonarQube Server, with its own licence key and LOC capacity.[2]
- LOC overage. The highest monthly LOC peak above the purchased limit, billed monthly where overage is active.[7]
- Agent units. A tool call for Sonar Vortex[9], a suggestion for the Remediation Agent[10] and a scan unit for the Hunter Agent.[11]
Counting / floors
Calculation (documentation, retrieved 2026-10-07). The instance’s LOC is “calculated by adding up the LOC of each project analyzed”. In Data Center Edition, the LOC of each project in each cluster node is summed.[4] For each project, SonarQube Server takes the most recent analysis of the largest branch or pull request. It excludes test code, files excluded from analysis, code in unsupported languages, and comments or blank lines.[4] The documentation gives a worked example: a project with 500 LOC on its main branch and 400 on another long-lived branch counts as 500. A second project with nothing on main and 200 on a branch counts as 200, so the total is 700.[4] Reanalysing the same code does not use up the licence, and Applications do not count again.[4] The measure is exposed as ncloc through the Web API, which is the practical source for an effective license position. Catalog proof: Project LOC is the largest branch, not cumulative across re-analyses; Test code, excluded files, unsupported languages, comments and blank lines are not counted.
Enforcement. Administrators can set a notification threshold, and SonarQube Server emails a warning when remaining LOC falls below it, repeating every 30 days.[4] At the limit, the instance “will reject any analysis whose total lines of code exceed the limit defined by your license”. Browsing and configuration remain available, and analyses that stay within the limit still run.[4] A practical consequence is that a growing codebase stops being analysed before it becomes non-compliant. Branches with unusually large generated code can move a project’s count because only the largest branch counts. Catalog proof: Analyses exceeding the licensed LOC are rejected; the instance stays usable; SonarQube Server is licensed to analyse up to the LOC on the Order.
No contractual minimums. The pricing page recommends Developer Edition from 100K and Enterprise Edition from 1M LOC, but neither the Supplemental Terms nor the documentation states a minimum purchase.[1][2]
LOC overage
Enterprise and Data Center instances can activate LOC overage to keep analysing above the purchased limit. It requires online licence activation, daily pings to LicenseSpring and continuous connectivity. It is not offered on server ID-based keys or for codebases of 100 million LOC or more.[7] Overage is invoiced monthly, “based on the highest LOC peak recorded above your Purchased LOC limit during that month, not on your average or total usage”. The peak resets each calendar month, and brief spikes are not smoothed.[7] The customer sets a monthly hard cap. When it is reached, new analyses are blocked until the cap is raised or resets. Overage is billed at a higher rate than the base subscription, and SonarSource advises customers who use it consistently to resize the core subscription.[7] The contractual basis is the usage-based fees clause of the Primary Customer Agreement, under which unused allowance does not roll over and SonarSource’s measurement is conclusive absent manifest error.[16] Catalog proof: LOC overage is billed monthly on the highest peak above Purchased LOC; Overage requires Enterprise or Data Center edition with online activation; Usage Allowance does not roll over; overage billed in arrears; measurement conclusive.
Licence keys and instances
SonarQube Server uses two kinds of licence key. A LicenseSpring-managed key, in the format XXXX-XXXX-XXXX-XXXX, is activated online or offline and managed in the License user portal. A server ID-based key is tied to the instance’s server ID.[5] The server ID is specific to the database.[6] Several routine operations change it and invalidate the activation: moving or renaming the database server, changing the schema name, restoring another instance’s database, reinstalling on an empty database, and copying with DBCopy or MySQL Migrator.[5] For server ID keys, a one-time seven-day grace period can be activated through the API.[6] To reuse a licence elsewhere, it must first be unset. An offline activation must also be deactivated on SonarSource’s offline licence site, or “the license server will still consider it activated”.[5] Catalog proof: Database host, name or schema changes invalidate the licence activation; A licence must be unset before reuse on another instance.
Virtualization & partitioning
There is no processor, core or host metric, so hypervisor and partitioning rules do not affect the count. What matters is the number of instances and the LOC each one analyses. A Data Center Edition cluster is one instance for licensing, and its LOC is summed across nodes.[4] Additional copies for testing, staging and disaster recovery are permitted by the Supplemental Terms.[1] Activating a non-production copy still needs a key. A staging license “is available in Enterprise and Data Center editions, or in editions with commercial support”, and may include several activations.[5] A break glass license is provided for cases where the production licence cannot be activated. It expires seven days after activation.[5] Developer Edition customers without commercial support therefore have no documented staging key. Catalog proof: Staging licences only in Enterprise and Data Center or with commercial support; Break glass licence expires 7 days after activation.
Cloud / BYOL
SonarQube Server may run in any infrastructure the customer controls, including its own public cloud accounts; the licence is the same. SonarSource publishes no cloud-specific rules. Online activation and overage need outbound HTTPS access to api.prod.sonarsource.licensespring.com.[5]
Product subscriptions
Enterprise and Data Center editions support four add-on subscriptions: Advanced Security, Sonar Vortex, the Remediation Agent and the Hunter Agent.[8]
| Product | Consumption unit | Resets | Overage |
|---|---|---|---|
| Advanced Security | Full access | Not applicable | None[7] |
| Sonar Vortex | Tool call | Monthly | Monthly, in arrears |
| Remediation Agent | Suggestion | Monthly | Monthly, in arrears |
| Hunter Agent | Scan unit, by codebase size band | At licence renewal | Billed monthly |
Source: Sonar product subscriptions and Overage activation documentation.[8][7]
A Remediation Agent fix counts as one suggestion when delivered in a pull request, whether or not the pull request is merged.[10] Hunter Agent scan units depend on project size, in bands from XS (up to 1,000 LOC) to XXL (more than 1.5 million LOC).[11] The three agent subscriptions need a LicenseSpring-managed key and are not available on server ID-based licences.[6] Advanced Security is conditioned on “continuous payment of fees for the underlying SonarQube Server or SonarQube Cloud subscription”.[13] Catalog proof: Vortex, Remediation Agent and Hunter Agent need a LicenseSpring-managed licence; Advanced Security requires continuous payment of the underlying subscription.
Programs
- Support. Standard commercial support is included in Enterprise and Data Center editions from 30M LOC and otherwise costs extra.[2] Support Tiers are linked to edition and LOC. An upgrade that crosses a tier’s eligibility upgrades Support automatically at a prorated fee, and Support cannot be downgraded during a Term.[15] Catalog proof: Support Tier rises automatically with edition or LOC; no mid-term downgrade; Standard support included from 30M LOC (Server) and 5M LOC (Cloud Enterprise).
- LTA patch policy. SonarQube Server releases every two months, and two releases a year are Long-Term Active. For LTA releases from 2026.5, all editions get 12 months of patches. Enterprise and Data Center customers with Enterprise Support get 18 months.[12] Catalog proof: LTA patches for 12 months, or 18 months with Enterprise Support.
- Legacy termination right. For Orders dated before 2026-06-01, customers may terminate without cause on three months’ written notice, without a refund.[1] Catalog proof: Pre-2026-06-01 SonarQube Server Orders keep a 3-month termination-for-convenience right.
- Termination. On termination, all copies of self-managed software and licence keys must be uninstalled and deleted.[16]
Out of scope
- SonarQube Cloud, covered in SonarQube Cloud plans and billing.
- Prices, which SonarSource quotes per customer.
- Licences of third-party or community plugins installed on an instance.
- Versions 10.x and earlier, which used the
MAJOR.MINOR.PATCHscheme and earlier licence administration pages.[12]