Creating global analysis tokens in SonarQube Server

Time to complete icon5 minutes to complete

Overview

This course explains how to use SonarQube Server global analysis tokens to manage secure, automated code analysis across all of your projects. It covers the purpose of these tokens and how to generate them within SonarQube.

Learning objectives

After completing this course, you’ll be able to:

  • Understand the purpose of SonarQube Server global analysis tokens
  • Generate a global analysis token in SonarQube
  • Identify best practices for using and securing global analysis tokens

Key topics

  • Purpose of global analysis tokens
  • How to create a global analysis token
  • The importance of the Global Execute Analysis permission
  • Setting an expiration date for a token 
  • Storing a newly generated token securely
  • How to use the token in CI/CD workflows and SonarScanner analysis 

Target audience

  • Administrator
  • DevOps engineer
  • Developer
  • Engineering leader
  • Analyst

Prerequisites

  • Access to a SonarQube Server instance
  • A user account with Global Execute Analysis permission