
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@sonarapp/mcp
Advanced tools
Sonar MCP server — App Store Optimization tools for AI agents (Claude, Cursor, Cline)
The official Sonar MCP server — App Store Optimization tools for AI agents.
Lets Claude Desktop, Claude Code, Cursor, Cline, and any Model Context Protocol-compatible client look up apps, research keywords, audit ASO, mine reviews, and estimate revenue across the iOS App Store and Google Play. Powered by Sonar.
| Tool | What it does |
|---|---|
sonar_app_lookup | Look up app metadata by store ID |
sonar_app_search | Search apps by keyword (returns store ranking order) |
sonar_app_aso_score | ASO audit score (0-100) with itemized checks |
sonar_app_extract_keywords | Extract target keywords from an app's listing |
sonar_app_reviews | Fetch reviews with rating filters and sort options |
sonar_app_revenue | Estimate monthly revenue with methodology |
sonar_keyword_search | Keyword research (difficulty, popularity, related terms) |
sonar_keyword_metrics | Difficulty + popularity for specific keywords (single or bulk) |
sonar_keyword_suggestions | Autocomplete suggestions from the store |
sonar_top_charts | Top free/paid/grossing chart with day-over-day movement |
Stateless tools work on any plan with credits, with both iOS and Android.
| Tool | What it does |
|---|---|
sonar_list_apps | List your tracked apps with latest snapshots (rating, reviews, installs) |
sonar_get_app | App detail + up to 90 days of snapshot history |
sonar_app_keywords | Keywords tracked for an app, with difficulty + popularity |
sonar_app_rankings | Daily rank history for an app's tracked keywords |
sonar_app_changes | Detected releases, metadata edits, screenshot/price/category changes |
sonar_keyword_rankings | SERP history for a tracked keyword (who ranked, when) |
sonar_competitor_keywords | Keywords a competitor ranks for + gap analysis vs your app |
sonar_competitor_landscape | Full competitive picture for one of your own apps — gap/winnable/threat/lead stats + latest AI insight |
Workspace reads require an Indie plan (an active trial counts); the default read-scope key is enough.
| Tool | What it does |
|---|---|
sonar_create_product | Create a product in your Sonar workspace and start tracking its app(s) |
sonar_track_app | Link the second-store version (iOS ↔ Android) of an existing product |
sonar_track_competitor | Add a competitor app under a product |
sonar_track_keywords | Start daily rank tracking for keywords on an app (bulk, idempotent) |
sonar_update_keyword_note | Set or clear the note on a tracked keyword |
sonar_scan_competitor | Run a keyword discovery scan on a competitor (read results with sonar_competitor_keywords) |
sonar_analyze_competitors | Generate a fresh AI competitive insight for one of your own apps (7-day cooldown; read it with sonar_competitor_landscape) |
Write tools mutate your workspace and require an Indie plan (an active trial counts) plus either an OAuth sign-in on the hosted endpoint (which carries write access) or an API key created with the write scope. The server enforces both — without them, calls return a 403 explaining what to fix.
Together these close the loop for agents: set up tracking with the write tools, then read back rankings, changes, and gap analyses with the workspace tools.
OAuth-capable MCP clients (Claude Code, claude.ai custom connectors) can skip both the npm install and the API key entirely:
claude mcp add --transport http sonar https://trysonar.app/mcp
The first tool call that needs your account opens a browser sign-in — approve it with your Sonar login and the agent has full access to the workspace you own (read + write). Clients without OAuth support can pass an API key instead: --header "Authorization: Bearer aso_...".
The server runs without a key in free mode: sonar_app_search, sonar_app_lookup, sonar_app_aso_score, sonar_app_extract_keywords, and sonar_keyword_suggestions share a free allowance of 30 requests/day per IP, and sonar_keyword_metrics (keyword difficulty + popularity) gets 5 keywords/day. Just install it with no env block and ask your agent about ASO. When you hit the limit, the error tells you how to sign up.
For everything else (tracking, rankings, competitors, higher limits) you'll need a Sonar API key — get one at trysonar.app/developers.
The cheapest path is prepaid API credits — packs from $10 (1,000 credits), with 50 free credits on signup and no subscription. Built specifically for this use case. See pricing.
Add to your config file (~/Library/Application Support/Claude/claude_desktop_config.json on macOS, %APPDATA%\Claude\claude_desktop_config.json on Windows):
{
"mcpServers": {
"sonar": {
"command": "npx",
"args": ["-y", "@sonarapp/mcp"],
"env": {
"SONAR_API_KEY": "aso_your_key_here"
}
}
}
}
Restart Claude Desktop. The sonar_* tools will appear in the tool picker.
claude mcp add sonar -e SONAR_API_KEY=aso_your_key_here -- npx -y @sonarapp/mcp
Add to ~/.cursor/mcp.json (or your project's .cursor/mcp.json):
{
"mcpServers": {
"sonar": {
"command": "npx",
"args": ["-y", "@sonarapp/mcp"],
"env": {
"SONAR_API_KEY": "aso_your_key_here"
}
}
}
}
Most clients use the same command + args + env shape as above. Point the command at npx -y @sonarapp/mcp and pass SONAR_API_KEY in the env.
| Variable | Required | Default | Description |
|---|---|---|---|
SONAR_API_KEY | no (free mode without it) | — | Your Sonar API key (aso_...) |
SONAR_API_URL | no | https://trysonar.app | Override the API base URL (only used for self-hosting / staging) |
"Use Sonar to look up Spotify on iOS in the US store and report its rating, review count, and category."
"Run an ASO audit on
com.duolingoon Android and tell me what to fix."
"Research the keyword 'habit tracker' on iOS — give me difficulty, popularity, and 5 related terms with lower difficulty I should consider."
"Pull the 50 most recent 1- and 2-star reviews of
1517783697on iOS US and group complaints by theme."
"Search 'meditation' on the App Store and estimate monthly revenue for the top 5 results."
Full policy: https://trysonar.app/privacy
The MCP server is a thin client around Sonar's REST API — it stores nothing locally and no data is logged by this package itself.
Bearer token. Sonar logs API requests (endpoint, status, timing) for rate limiting and abuse prevention."SONAR_API_KEY is not set — running in free mode" — Expected if you haven't configured a key: the free tools keep working with per-IP daily limits. If you DID configure a key, the MCP client did not pass the env var through — check the env section of your client's config file. Some clients require an absolute path to npx — try which npx and use that.
"Authentication failed" — Your key is invalid, expired, or your subscription lapsed. Visit trysonar.app/developers to check.
"Access denied. Endpoint may require Indie plan" — The 10 stateless read tools work on any plan with credits. The workspace read tools and write tools require an Indie plan (an active trial counts); write tools additionally need an API key created with the write scope. If you're on a setup or trial-expired plan, reactivate first.
Prefer the terminal? Use @sonarapp/cli (sonar binary) — same data, same API key.
MIT © Peter Sutarik
FAQs
Sonar MCP server — App Store Optimization tools for AI agents (Claude, Cursor, Cline)
The npm package @sonarapp/mcp receives a total of 428 weekly downloads. As such, @sonarapp/mcp popularity was classified as not popular.
We found that @sonarapp/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.