SonarSource licensing is the set of terms under which SonarSource Sàrl, a Swiss company, licenses its SonarQube code quality and code security products.[1] The commercial portfolio has two delivery models: SonarQube Server, which customers install and run on their own infrastructure, and SonarQube Cloud, a hosted service operated by SonarSource. Add-on products include SonarQube Advanced Security and the AI agents Sonar Vortex, the Remediation Agent and the Hunter Agent. SonarSource also distributes two free products, SonarQube Community Build and SonarQube for IDE, under open-source and source-available licences rather than under its commercial agreement.[1][9]
The common unit across both commercial platforms is the line of code analysed. SonarQube Server is “licensed per instance per year, with a LOC (Lines of Code) capacity per instance”, while SonarQube Cloud is a “subscription per organization, billed monthly or yearly, based on private LOC”.[19] Neither platform counts users, developers or processor cores for its base entitlement. Some newer add-ons are metered in their own units, such as tool calls, suggestions and scan units, under usage-based terms in the Primary Customer Agreement.[1][12]
Editions
SonarSource publishes list prices only for the self-service SonarQube Cloud Team plan. SonarQube Server and the Cloud Enterprise plan are quoted by sales.[3][7]
| Product | Editions or plans | Licensed as | Deeper article |
|---|---|---|---|
| SonarQube Server | Developer, Enterprise, Data Center[4] | Per instance per year, LOC capacity per instance[3] | SonarQube Server editions and lines of code |
| SonarQube Cloud | Free, Team, Enterprise, OSS[6] | Per organization (Free, Team) or per enterprise (Enterprise), private LOC limit[6] | SonarQube Cloud plans and billing |
| SonarQube Advanced Security | Add-on to SonarQube Server or SonarQube Cloud[14] | Separate subscription, full access without usage limits[12] | SonarQube Server editions and lines of code |
| Sonar Vortex, Remediation Agent, Hunter Agent | Add-ons; Enterprise and Data Center editions on Server[13] | Base usage allowance plus optional overage[12] | same |
| SonarQube Community Build, SonarQube for IDE | Free downloads[1] | LGPLv3; bundled analyzers under SSALv1[9] | SonarQube Community Build and IDE licences |
The SonarQube Server editions differ mainly in features and scale. Developer Edition adds branch and pull request analysis and more languages to the Community Build. Enterprise Edition adds portfolios, compliance and regulatory reports, SCIM provisioning, audit logs and the product subscriptions. Data Center Edition adds high availability, clustering and autoscaling.[4] SonarSource’s pricing page recommends Developer Edition for 100K or more lines of code and Enterprise Edition for 1M or more, but these are recommendations rather than contractual floors.[3]
Metrics
| Unit | Catalog row | Where it applies |
|---|---|---|
| Lines of Code analysed by an instance | Lines of Code (SonarQube Server) | SonarQube Server, all editions |
| Installation of SonarQube Server | Instance (SonarQube Server) | SonarQube Server, all editions |
| Private Lines of Code per organization or enterprise | Lines of Code (SonarQube Cloud private LOC), Shared LOC and Allocated LOC | SonarQube Cloud |
| Monthly LOC peak above the licence | LOC overage (SonarQube Server) | Server Enterprise and Data Center |
| Generic metered unit | Billable Unit | Usage-based Products |
| Agent consumption units | Tool call, Suggestion, Scan unit | Sonar Vortex, Remediation Agent, Hunter Agent |
The SonarQube Server Supplemental Terms define Lines of Code as “the number of lines of code analyzed by SonarQube Server”, counted on the largest branch analysed for each project and “not cumulative when the same project is re-analyzed”.[2] SonarQube Cloud counts in the same way, but only for private projects. Public projects do not count toward the limit.[6]
Counting / floors
What counts (SonarQube Server Supplemental Terms, 2026-10-01; documentation). An instance’s LOC is the sum of the LOC of each analysed project. Each project is measured on the most recent analysis of its largest branch or pull request. Test code, files excluded from analysis, code in unsupported languages, and comments or blank lines are excluded.[5] Applications, which group projects, do not count a second time.[5] Catalog proof: Project LOC is the largest branch, not cumulative across re-analyses; Test code, excluded files, unsupported languages, comments and blank lines are not counted.
Hard caps, not true-ups. Both platforms enforce the licensed LOC technically. A SonarQube Server instance at its limit “will reject any analysis whose total lines of code exceed the limit defined by your license”, while browsing and configuration keep working.[5] SonarQube Cloud states: “You cannot exceed your LOC limit in SonarQube Cloud.”[6] The main exception is LOC overage. Enterprise and Data Center instances with online licence activation can opt in to overage, which is billed monthly on the highest LOC peak above the purchased limit, at a higher rate than the base subscription.[12] Catalog proof: Analyses exceeding the licensed LOC are rejected; the instance stays usable; SonarQube Cloud LOC limits per plan cannot be exceeded; LOC overage is billed monthly on the highest peak above Purchased LOC.
Plan floors on SonarQube Cloud. The Free plan covers up to 50k private LOC and five organization members. Team plans range from 100k to 1.9M LOC per organization. The Enterprise plan accepts any LOC for the whole enterprise and is described as ideal from 5M LOC.[6] The pricing page shows the Team plan “Starts at $34 monthly” for up to 100k LOC; a FAQ on the same page still quotes $32, so the price on the order form should be checked.[7]
Virtualization & partitioning
SonarSource does not count hosts, processors or cores, so the usual virtualization and partitioning rules do not apply. The licence key is tied to the instance. A LicenseSpring-managed key is activated against the instance’s server ID, which is derived from its database. Moving the database to another host, changing its name or schema, or reinstalling on an empty database changes the server ID and invalidates the activation.[13] In Data Center Edition, a cluster is licensed as one instance whose LOC is summed across nodes.[5] The Supplemental Terms permit additional copies “solely for testing, staging, and disaster recovery”.[2] Catalog proof: SonarQube Server is licensed to analyse up to the LOC on the Order; Database host, name or schema changes invalidate the licence activation.
Cloud / BYOL
SonarQube Server can run on premises or in the customer’s own cloud account under the same per-instance licence; the documentation describes it as self-managed “on-prem or in your own cloud”.[19] No public-cloud mapping rules are published. SonarQube Cloud is a separate subscription, and a SonarQube Server licence does not convert into SonarQube Cloud capacity or the reverse. Overage and the AI agents need outbound connectivity from a Server instance to SonarSource’s licence service, and an instance activated offline “is never eligible for overage”.[13] Catalog proof: Overage requires Enterprise or Data Center edition with online activation.
Programs
- Primary Customer Agreement. Since 2026 SonarSource uses one agreement for all commercial Products, with Supplemental Terms for SonarQube Server, SonarQube Cloud, Advanced Security and other products listed in Exhibit A.[1] See SonarSource Primary Customer Agreement.
- Usage-Based Fees and Overages. Base fees buy a Usage Allowance per Measurement Period. Unused Billable Units “do not roll over”, and Overage Charges are billed in arrears.[1][15]
- Sonar Support tiers. Base, Core, Standard and Enterprise tiers, linked to edition and LOC, with no downgrade during a Term.[11] Standard support is included in Server Enterprise and Data Center editions from 30M LOC, and in the Cloud Enterprise plan from 5M LOC.[3][7]
- Staging license and Break glass license. Non-production and emergency keys for SonarQube Server.[13]
- SonarQube Server LTA patch policy. Long-Term Active versions get 12 months of patches, or 18 months for Enterprise and Data Center customers with Enterprise Support.[16]
- Complimentary Access, SonarQube Cloud coupon and SonarQube for OSS. Trials, prepaid annual Cloud subscriptions, and the free offer for open source organizations.[7][8]
Free and open-source software
SonarQube Community Build and SonarQube for IDE are “not Products covered by this Agreement”.[1] They were originally distributed under the GNU LGPLv3. Since 29 November 2024 their binaries remain LGPLv3, but the bundled analyzers are licensed under the Sonar Source-Available License Version 1.0 (SSALv1).[9] The SSAL grants rights only for a “Non-competitive Purpose”. It excludes competing with SonarQube and using outside AI technology to ingest or train on data the Program provides.[10] Commercial Support does not cover Community instances, even inside a licensed organization.[11] Catalog proof: Community Build and SonarQube for IDE: LGPLv3 binaries, analyzers under SSALv1 from 2024-11-29; SSAL rights are limited to Non-competitive Purposes; Support covers only products in the Order, not Community instances or trials.
Contract terms that matter for compliance
The grant covers the Customer and its Affiliates. It is non-transferable and limited to “internal development purposes”.[1] The Acceptable Use Policy forbids making the Products available to anyone other than authorized Users, reselling them, circumventing “technical limitations, recurring fees, or usage limits”, and publishing benchmarks without consent.[17] Users may include employees, consultants, contractors and agents, so outsourced developers can be given access without changing the licence metric.[1] Payments are non-refundable, including for downgrades. On termination, self-managed copies and licence keys must be uninstalled and deleted.[1] The Free and Team plans of SonarQube Cloud carry weaker terms. They have no SLA and no IP indemnity, and SonarSource may use Customer Data on these plans to “train, tune, and improve” its models.[18] Catalog proof: Products and Alerts may be used only for internal development purposes; Self-Managed Products must be uninstalled and keys deleted on termination; Free and Team plan Customer Data may be used to train SonarSource models.
The agreement contains no audit clause of the kind described in software license audit. Compliance is enforced in the product: LOC caps block analysis, and metered usage is measured by SonarSource, whose records are “conclusive absent manifest error”.[1]
Out of scope
- Negotiated Orders, reseller terms and archived versions of SonarSource terms, which differ by date and customer.
- SonarQube Server list prices, which SonarSource does not publish.[3]
- Gitar AI code review, SonarSweep and the SonarQube MCP Server, beyond their listing on SonarSource’s pricing and legal pages.
- Licences of third-party plugins installed on SonarQube Server.