Your assistant writes the import. Guide checks the package first — Sonatype Guide checks the packages your AI coding assistant picks before they reach a commit — one MCP server for Claude Code, Copilot, Cursor and Kiro, with Sonatype's intelligence behind it and Enterprise policies, waivers and SBOMs on top.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Sonatype Guide — the SCA and governance product new customers buy in place of Lifecycle and SBOM Manager. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Checking the open source your code depends on — including the packages an AI assistant picks — for vulnerabilities, malware and licence risk, before they are committed.
What consolidation actually replaces, dimension by dimension.
| Dimension | CI scans after the code is written | Sonatype Guide |
|---|---|---|
| When a risky package is caught | In a CI scan, after the code is written | In the prompt, before the import is added |
| Who picks the version | The assistant’s training data | The assistant, checked against live intelligence |
| Policy exceptions | Waiver requests by email and ticket | Automated waivers on Enterprise |
| SBOMs | A separate tool, or a spreadsheet | Generated, validated and ingested in Guide |
| The price | Per-developer seats or a quote | Free; Pro $1,200 a year; Enterprise by quote |
| What it is NOT | — | Not a proxy firewall — that is Repository Firewall |
The cheapest test is free: point one team's assistant at the MCP server for a fortnight and count the versions it corrects.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
A remote MCP service at mcp.guide.sonatype.com. Claude Code, Copilot, Cursor, Kiro and other assistants call it with a personal access token before adding or upgrading a package.
Sonatype’s component and vulnerability database, with OSS Index, answers each query — version history, known vulnerabilities and malicious-package data for the component asked about.
The same intelligence is exposed through an API on every plan, Free included, so CI jobs and internal tools can check components without an AI assistant in the loop.
On Enterprise: custom policies, reachability-based prioritisation, automated waivers, SBOMs, licence and VEX reporting — the scope once sold as Lifecycle and SBOM Manager.
One MCP endpoint in the assistant, Sonatype's intelligence behind it — and Enterprise policy deciding what is allowed.
Sonatype Guide checks every package an AI assistant reaches for — and puts policy, waivers and SBOMs behind the answer.
Assistants ask the MCP server before adding a package, so the version they suggest is checked against Sonatype’s vulnerability and malware data.
Sonatype lists Claude Code, GitHub Copilot, Cursor, Windsurf, Gemini Code Assist, IntelliJ with Junie, AWS Kiro and Codex.
OSS Index and Sonatype’s component database through the API or MCP on every plan; Free allows unlimited developers per organisation.
Enterprise enforces open-source policy across development workflows and ranks vulnerabilities by reachability, not severity alone.
Enterprise automates waivers — the approved exceptions to a policy — and gives security teams one view across the organisation.
The pricing page lists autonomous upgrades (‘Agent P’) on Pro; Sonatype says they arrive as validated pull requests.
SBOM generation, validation and ingestion, with SPDX 3.0 support that Sonatype positions for AI transparency.
Licence-obligation and VEX reporting with audit-ready dashboards — the compliance scope carried over from SBOM Manager.
SBOM Manager’s page — its scope now sold as Guide — names SEBI, CERT-In, DORA, NIS2 and PCI-DSS among supported frameworks.
Guide with Claude, Copilot and AWS Kiro over MCP, and the waiver workflow behind its governance engine.
Guide steering Claude to safe versions.
The MCP server inside Copilot.
Secure AI-generated code in Kiro.
The waiver workflow behind governance.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
AI assistants choose packages from training data that can be out of date. Guide’s MCP server lets Claude Code, Copilot, Cursor or Kiro ask Sonatype for a current, non-vulnerable version first — so a risky choice is corrected in the prompt, not in a later scan.
New Sonatype customers buy Guide, not Lifecycle or SBOM Manager: the pricing page says Guide includes every Lifecycle capability and SBOM Manager’s compliance scope. Enterprise brings custom policies, automated waivers, SBOM, licence and VEX reporting.
Free costs nothing, with 500 credits and unlimited developers; Pro is $1,200 a year with 5,000 credits. Black Duck quotes; Mend publishes a per-developer ceiling. Enterprise is by quote, and what a credit buys is not published — ask before sizing.
Guide is new — launched in December 2025 — and runs as a cloud service whose hosting region Sonatype does not document. The Developer Trust Score and AI Agent for Dependency Management are marked Coming Soon. Blocking malware at the proxy is Repository Firewall, sold apart.
Open a free Guide account, create a personal access token and point one team’s Claude Code, Copilot or Cursor at it.
Log the versions the assistant proposes with and without Guide, and check both against your current SCA tool’s findings.
Take the pilot’s usage to Sonatype and ask how many credits Pro or Enterprise needs for your team — the rate is not public.
On Enterprise, turn licence and vulnerability rules into policies, and decide which exceptions waivers may approve.
Generate SBOMs for the products customers and regulators ask about, and file licence and VEX reports with your controls.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We wired the MCP server into Claude Code in an afternoon. The assistant stopped proposing package versions with known CVEs.”
“Pro at $1,200 a year cleared our procurement threshold without a committee. Ask how far the credits stretch before committing.”
“We still add Lifecycle licences for existing teams, but the new business unit was quoted Guide Enterprise. Plan for both for a while.”
“Our auditors asked where the SBOM data sits. Guide’s hosting region is not documented, so we had Sonatype put it in writing.”
“SEBI on the framework list got compliance to the table; the evidence still had to map to our own controls, clause by clause.”
“Copilot and Kiro users set it up with the same token and one URL. Covering a mixed-assistant team is why we picked it.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the software composition analysis market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
AI SCA plus Lifecycle-era governance; Pro $1,200/year.
The grid nobody publishes — how well it plugs into AI coding assistants vs how deep its policy and compliance controls go.
Hosted MCP for 8 assistants; policy, waivers, SBOM.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Snyk Open Source, Mend.io, Black Duck SCA, JFrog Xray and SonarQube Advanced Security — on AI-assistant support, deployment, price, analysis depth and India.
| Dimension | Sonatype Guide | Snyk Open Source | Mend.io | Black Duck SCA | JFrog Xray | SonarQube Advanced Security |
|---|---|---|---|---|---|---|
| What it is | AI SCA plus governance | Developer-first SCA | AppSec platform SCA | Composition analysis | SCA inside the registry | SCA + SAST in SonarQube |
| Deployment | Cloud service | SaaS; Broker for on-prem | SaaS-led | SaaS or self-hosted | SaaS, self-host, air-gap | Self-host or SaaS |
| Ecosystem coverage | 20+ via Lifecycle scope | Major ecosystems | Broad + reachability | Source and binaries | 25+ package types | 10 ecosystems |
| Pricing model | Credit-based plans | Credits on Enterprise | Per contributing dev | Quote only | Comes with a tier | Add-on subscription |
| Published entry price | Free; Pro $1,200/yr | Free; Team from $25/mo | Up to $1,000/dev/yr | Not published | $950/mo · $27k/yr | Not published |
| Included vs add-on | Governance on Enterprise | Priced per product | Broad bundle | Not published | Applicability is extra | Needs Enterprise first |
| Scale limits | Credit-bounded | Plan caps | No scan caps | Not published | Consumption-metered | Sized by lines of code |
| Analysis depth | Policy, reachability | Vulns, licences, malware | Reachability + malware | Snippets and binaries | CVE, licence, malware | SCA + library taint |
| Integrations and AI assistants | Remote MCP, 8 assistants | Local MCP via CLI | MCP in five assistants | MCP via Signal | IDE, CLI, JFrog MCP | 4 DevOps platforms |
| Governance and SSO | Enterprise; confirm SSO | Enterprise controls | Repo-level policy | Project policies | Watches + policies | Enterprise controls |
| India storage region | Region not documented | No India region | India region (2026) | Self-host in India | Mumbai · Pune | Self-host in India |
| Support | Priority support on Pro | NBD on Team | Confirm the SLA | Confirm the SLA | 24/7 SLA | Included from 30M LOC |
| Lock-in and exit | SBOMs stay portable | Registry-neutral | Tool-neutral | Tool-neutral | Tied to Artifactory | Tied to SonarQube |
| Best fit | AI-assisted teams | Developer-led teams | One AppSec bundle | Audit-heavy estates | Artifactory estates | SonarQube Enterprise |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Sonatype Guide is one of 35 developer tools products TechBag carries. The Developer Tools guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (developers; developer-hour cost). Estimates model developer time lost to vulnerable or disallowed packages chosen during AI-assisted coding — found later in a scan, then traced, replaced and re-tested — at an assumed 1.5 hours per developer a year, with 70% of it avoided when the assistant is steered to a safe version first. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Published: Sonatype Guide Free is $0 with 500 credits; Pro is $1,200 a year with 5,000 credits; Enterprise, which adds governance, custom policies and automated waivers, is priced by quote. Sonatype does not publish what a credit buys, and new customers buy Guide rather than Lifecycle or SBOM Manager. TechBag sizes the plan with Sonatype, then quotes in INR with GST.
Best for teams starting with AI SCA
Best for a broader rollout
Best for governance and compliance
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Do you need custom policies, automated waivers and compliance reporting? Those are Enterprise; Free and Pro cover intelligence, API and MCP.
How many credits will your team use in a year? Sonatype does not publish what a credit covers — get it stated in the quote.
Which AI assistants do your developers run, and is every one of them on Sonatype’s supported list for the MCP server?
Already a Lifecycle customer? You can still add licences — ask how and when a move to Guide changes your price and scope.
Guide’s hosting region is not documented. Where will component data and SBOMs be stored? Ask Sonatype in writing.
What does an assistant send to the MCP server with each query — package coordinates only, or more? Confirm before rollout.
Buying for the Developer Trust Score or the AI dependency agent? Both are marked Coming Soon — price what ships today.
Do you also need malicious packages blocked at the proxy? That is Repository Firewall, a separate purchase — scope both together.
Connect one team's AI assistant on the free plan first, or let a TechBag advisor size Pro or Enterprise with Sonatype and check the storage question.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.