
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@sonarapp/mcp
Advanced tools
Sonar MCP server — App Store Optimization tools for AI agents (Claude, Cursor, Cline)
The official Sonar MCP server — App Store Optimization tools for AI agents.
Lets Claude Desktop, Claude Code, Cursor, Cline, and any Model Context Protocol-compatible client look up apps, research keywords, audit ASO, mine reviews, and estimate revenue across the iOS App Store and Google Play. Powered by Sonar.
| Tool | What it does |
|---|---|
sonar_app_lookup | Look up app metadata by store ID |
sonar_app_search | Search apps by keyword (returns store ranking order) |
sonar_app_aso_score | ASO audit score (0-100) with itemized checks |
sonar_app_extract_keywords | Extract target keywords from an app's listing |
sonar_app_reviews | Fetch reviews with rating filters and sort options |
sonar_app_revenue | Estimate monthly revenue with methodology |
sonar_keyword_search | Keyword research (difficulty, popularity, related terms) |
sonar_keyword_suggestions | Autocomplete suggestions from the store |
All tools are read-only, stateless, and work with both iOS and Android.
You'll need a Sonar API key — get one at trysonar.app/developers.
The cheapest path is the Agent Plan ($9/month), which is API-only with no rate limit and is built specifically for this use case. See pricing.
Add to your config file (~/Library/Application Support/Claude/claude_desktop_config.json on macOS, %APPDATA%\Claude\claude_desktop_config.json on Windows):
{
"mcpServers": {
"sonar": {
"command": "npx",
"args": ["-y", "@sonarapp/mcp"],
"env": {
"SONAR_API_KEY": "aso_your_key_here"
}
}
}
}
Restart Claude Desktop. The 8 sonar_* tools will appear in the tool picker.
claude mcp add sonar -e SONAR_API_KEY=aso_your_key_here -- npx -y @sonarapp/mcp
Add to ~/.cursor/mcp.json (or your project's .cursor/mcp.json):
{
"mcpServers": {
"sonar": {
"command": "npx",
"args": ["-y", "@sonarapp/mcp"],
"env": {
"SONAR_API_KEY": "aso_your_key_here"
}
}
}
}
Most clients use the same command + args + env shape as above. Point the command at npx -y @sonarapp/mcp and pass SONAR_API_KEY in the env.
| Variable | Required | Default | Description |
|---|---|---|---|
SONAR_API_KEY | yes | — | Your Sonar API key (aso_...) |
SONAR_API_URL | no | https://trysonar.app | Override the API base URL (only used for self-hosting / staging) |
"Use Sonar to look up Spotify on iOS in the US store and report its rating, review count, and category."
"Run an ASO audit on
com.duolingoon Android and tell me what to fix."
"Research the keyword 'habit tracker' on iOS — give me difficulty, popularity, and 5 related terms with lower difficulty I should consider."
"Pull the 50 most recent 1- and 2-star reviews of
1517783697on iOS US and group complaints by theme."
"Search 'meditation' on the App Store and estimate monthly revenue for the top 5 results."
The MCP server is a thin client around Sonar's REST API. Your API key is sent as a Bearer token over HTTPS. Tool inputs and the resulting JSON are passed to your AI client; no data is logged by this package itself.
"SONAR_API_KEY is not set" — The MCP client did not pass the env var through. Check the env section of your client's config file. Some clients require an absolute path to npx — try which npx and use that.
"Authentication failed" — Your key is invalid, expired, or your subscription lapsed. Visit trysonar.app/developers to check.
"Access denied. Endpoint may require Full plan" — All 8 MCP tools are available on Agent and Full plans. If you're on a setup or trial-expired plan, reactivate first.
Prefer the terminal? Use @sonarapp/cli (sonar binary) — same data, same API key.
MIT © Peter Sutarik
FAQs
Sonar MCP server — App Store Optimization tools for AI agents (Claude, Cursor, Cline)
The npm package @sonarapp/mcp receives a total of 162 weekly downloads. As such, @sonarapp/mcp popularity was classified as not popular.
We found that @sonarapp/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.