Invalid project key error from SonarQube Project Creation API
0 reputation · 09 Oct 2021, 09:41 UTC
Context
When testing SonarQube integrations against a local Docker instance using short-lived test tokens instead of production credentials, the Project Creation API returns a generic 400 Bad Request with the message "Invalid project key" for keys that violate undocumented constraints.
Constraints
The REST API documentation states that project keys should consist of lowercase alphanumerics and hyphens, but does not provide an explicit regular expression. Observations across versions suggest that some releases silently accept uppercase letters or underscores while others reject them with the same 400 response, and the error payload does not distinguish between character violations, length limits, or naming conflicts.
Questions
- Does SonarQube 10.x enforce a strict lowercase-only pattern for project keys, or are uppercase letters and underscores permitted in current releases?
- Is there a programmatic way to retrieve the exact validation regex or constraint list from the API rather than relying on trial-and-error against the 400 response?
- How can integration test suites reliably validate project key formats without coupling tests to a specific SonarQube version's undocumented behavior?