Sentry 错误监控
安全与合规Sentry
by Sentry
搜索和分析 Sentry 错误报告,辅助调试。
把零散的 Sentry 错误报告变成可检索线索,帮你在海量报错里更快定位线上故障,排障调试明显省时。
什么是 Sentry 错误监控?
搜索和分析 Sentry 错误报告,辅助调试。
如何使用 Sentry 错误监控
安装命令
npx -y @sentry/mcp-server-sentryREADME
sentry-mcp
Sentry's MCP service is primarily designed for human-in-the-loop coding agents. Our tool selection and priorities are focused on developer workflows and debugging use cases, rather than providing a general-purpose MCP server for all Sentry functionality.
This remote MCP server acts as middleware to the upstream Sentry API, optimized for coding assistants like Cursor, Claude Code, and similar development tools. It's based on Cloudflare's work towards remote MCPs.
Getting Started
You'll find everything you need to know by visiting the deployed service in production:
If you're looking to contribute, learn how it works, or to run this for self-hosted Sentry, continue below.
Claude Code Plugin
Install as a Claude Code plugin for automatic subagent delegation:
claude plugin marketplace add getsentry/sentry-mcp
claude plugin install sentry-mcp@sentry-mcp
This provides a sentry-mcp subagent that Claude automatically delegates to when you ask about Sentry errors, issues, traces, or performance.
For forward-looking tool variants and features:
claude plugin install sentry-mcp@sentry-mcp-experimental
Stdio vs Remote
While this repository is focused on acting as an MCP service, we also support a stdio transport. This is still a work in progress, but is the easiest way to adapt run the MCP against a self-hosted Sentry install.
Note: The AI-powered search tools (search_events, search_issues, etc.) require an LLM provider (OpenAI, Azure OpenAI, Anthropic, or OpenRouter). These tools use natural language processing to translate queries into Sentry's query syntax. Without a configured provider, these specific tools will be unavailable, but all other tools will function normally.
To utilize the stdio transport, you'll need to create an User Auth Token in Sentry with the necessary scopes. As of writing this is:
org:read
project:read
project:write
team:read
team:write
event:write
Launch the transport:
npx @sentry/mcp-server@latest --access-token=sentry-user-token
Need to connect to a self-hosted deployment? Add <code>--host</code> (hostname only, e.g. <code>--host=sentry.example.com</code>) when you run the command. For isolated internal deployments that only expose plain HTTP, also add <code>--insecure-http</code>.
Some features (like Seer) may not be available on self-hosted instances. You can disable specific skills to prevent unsupported tools from being exposed:
npx @sentry/mcp-server@latest --access-token=TOKEN --host=sentry.example.com --disable-skills=seer
For self-hosted instances without TLS:
npx @sentry/mcp-server@latest --access-token=TOKEN --host=sentry.internal:9000 --insecure-http
Remote with an Explicit Sentry Token
Remote clients that support custom HTTP headers can pass an upstream Sentry API token directly to the Cloudflare transport:
{
"mcpServers": {
"sentry": {
"url": "https://mcp.sentry.dev/mcp",
"headers": {
"Authorization": "Sentry-Bearer ${SENTRY_ACCESS_TOKEN}"
}
}
}
}
Sentry-Bearer is intentionally separate from Bearer: Bearer is reserved
for MCP OAuth access tokens. With Sentry-Bearer, the worker does not store,
validate, exchange, or refresh the upstream token. It forwards the token through
the same Sentry API calls used by OAuth-backed sessions, and the client or
upstream provider remains responsible for token lifetime and refresh.
Direct remote auth defaults to all active MCP skills. You can narrow the exposed
tools with ?skills=inspect,triage or ?disable-skills=seer.
Environment Variables
SENTRY_ACCESS_TOKEN= # Required: Your Sentry auth token
# LLM Provider Configuration (required for AI-powered search tools)
EMBEDDED_AGENT_PROVIDER= # Required when multiple provider keys are set: 'openai', 'azure-openai', 'anthropic', or 'openrouter'
OPENAI_API_KEY= # Required if using OpenAI
ANTHROPIC_API_KEY= # Required if using Anthropic
OPENROUTER_API_KEY= # Required if using OpenRouter
OPENROUTER_MODEL= # Optional OpenRouter model, defaults to 'openai/gpt-5.6-luna'
OPENROUTER_REASONING_EFFORT= # Optional OpenRouter reasoning effort, defaults to 'high'
# Optional overrides
SENTRY_HOST= # For self-hosted deployments
MCP_DISABLE_SKILLS= # Disable specific skills (comma-separated, e.g. 'seer')
Important: Always set EMBEDDED_AGENT_PROVIDER to explicitly specify your LLM provider. Auto-detection based on API keys alone is deprecated and will be removed in a future release. See docs/operations/embedded-agents.md for detailed configuration options.
Example MCP Configuration
{
"mcpServers": {
"sentry": {
"command": "npx",
"args": ["@sentry/mcp-server"],
"env": {
"SENTRY_ACCESS_TOKEN": "your-token",
"EMBEDDED_AGENT_PROVIDER": "openai",
"OPENAI_API_KEY": "sk-..."
}
}
}
}
If you leave the host variable unset, the CLI automatically targets the Sentry SaaS service. Only set the override when you operate self-hosted Sentry.
For self-hosted instances that don't support Seer:
{
"mcpServers": {
"sentry": {
"command": "npx",
"args": ["@sentry/mcp-server"],
"env": {
"SENTRY_ACCESS_TOKEN": "your-token",
"SENTRY_HOST": "sentry.example.com",
"MCP_DISABLE_SKILLS": "seer"
}
}
}
}
MCP Inspector
MCP includes an Inspector, to easily test the service:
pnpm inspector
Enter the MCP server URL (http://localhost:5173) and hit connect. This should trigger the authentication flow for you.
Note: If you have issues with your OAuth flow when accessing the inspector on 127.0.0.1, try using localhost instead by visiting http://localhost:6274.
Local Development
To contribute changes, you'll need to set up your local environment:
-
Set up environment and agent skills:
shellmake setup-env # Creates .env files and installs shared agent skillsThis also runs
npx @sentry/dotagents installto install shared skills from getsentry/skills into.agents/skills/(symlinked into.claude/skillsand.cursor/skills). If you need to update skills later, run it directly:shellnpx @sentry/dotagents install -
Create an OAuth App in Sentry (Settings => API => Applications):
- Homepage URL:
http://localhost:5173 - Authorized Redirect URIs:
http://localhost:5173/oauth/callback - Note your Client ID and generate a Client secret
- Homepage URL:
-
Configure your credentials:
- Edit
.envin the root directory and add eitherOPENAI_API_KEYorOPENROUTER_API_KEY - Edit
packages/mcp-cloudflare/.envand add:SENTRY_CLIENT_ID=your_development_sentry_client_idSENTRY_CLIENT_SECRET=your_development_sentry_client_secretCOOKIE_SECRET=my-super-secret-cookie
- Edit
-
Start the development server:
shellpnpm dev
Verify
Run the server locally to make it available at http://localhost:5173
pnpm dev
To test the local server, enter http://localhost:5173/mcp into Inspector and hit connect. Once you follow the prompts, you'll be able to "List Tools".
Tests
There are three test suites included: unit tests, evaluations, and manual testing.
Unit tests can be run using:
pnpm test
Evaluations require a .env file in the project root with some config:
# .env (in project root)
OPENAI_API_KEY= # Use OpenAI-backed AI-powered tools
OPENROUTER_API_KEY= # Or use OpenRouter-backed AI-powered tools
Note: The root .env file provides defaults for all packages. Individual packages can have their own .env files to override these defaults during development.
Once that's done you can run them using:
pnpm eval
Manual testing (preferred for testing MCP changes):
# Test with local dev server (default: http://localhost:5173)
pnpm -w run cli "who am I?"
# Test against production
pnpm -w run cli --mcp-host=https://mcp.sentry.dev "query"
# Test with local stdio mode (requires SENTRY_ACCESS_TOKEN)
pnpm -w run cli --access-token=TOKEN "query"
Note: The CLI defaults to http://localhost:5173. Override with --mcp-host or set MCP_URL environment variable.
Comprehensive testing playbooks:
- Stdio testing: See
docs/testing/stdio.mdfor complete guide on building, running, and testing the stdio implementation (IDEs, MCP Inspector) - Remote testing: See
docs/testing/remote.mdfor complete guide on testing the remote server (OAuth, web UI, CLI client)
Development Notes
Automated Code Review
This repository uses automated code review tools (like Cursor BugBot) to help identify potential issues in pull requests. These tools provide helpful feedback and suggestions, but we do not recommend making these checks required as the accuracy is still evolving and can produce false positives.
The automated reviews should be treated as:
- ✅ Helpful suggestions to consider during code review
- ✅ Starting points for discussion and improvement
- ❌ Not blocking requirements for merging PRs
- ❌ Not replacements for human code review
When addressing automated feedback, focus on the underlying concerns rather than strictly following every suggestion.
Contributor Documentation
Looking to contribute or explore the full documentation map? See CLAUDE.md (also available as AGENTS.md) for contributor workflows and the complete docs index. The docs/ folder contains the per-topic guides and tool-integrated .md files.
常见问题
Sentry 错误监控 是什么?
搜索和分析 Sentry 错误报告,辅助调试。
如何安装 Sentry 错误监控?
运行命令:npx -y @sentry/mcp-server-sentry
相关 Skills
安全专家
by alirezarezvani
覆盖威胁建模、漏洞评估、安全架构设计、代码审计与渗透测试,内置 STRIDE、OWASP、加密模式和安全扫描流程,适合系统设计评审与上线前安全排查。
✎ 安全专家把威胁建模、漏洞分析到渗透测试串成一套流程,内置 STRIDE 与 OWASP 指南,做安全设计和排查更省心。
安全运营
by alirezarezvani
覆盖应用安全、漏洞管理与合规审计,支持代码/依赖扫描、CVE 评估、Secrets 检测和安全自动化,适合做安全基线落地、漏洞响应、审计检查与安全开发治理。
✎ 应用安全、漏洞管理和合规检查一套打通,还能自动化扫描与响应,帮团队更早发现并收敛风险。
安全审计
by alirezarezvani
安装前审计 Claude Code Skill 的代码执行、Prompt 注入和依赖供应链风险,支持本地目录或 Git 仓库扫描,输出 PASS/WARN/FAIL 结论及修复建议
✎ 把代码审查、漏洞扫描和合规检查串成一条线,帮团队更早发现风险,做安全治理更省心。
相关 MCP Server
by sinewaveai
为 AI agents 提供安全层:拦截 prompt injection、识别伪造 packages,并扫描漏洞风险。
✎ 给 AI Agent 补上关键安全层,能拦截 prompt 注入、识别伪造包并扫描漏洞风险,把防护前置更省心。
by pantheon-security
强化安全性的 NotebookLM MCP,集成 post-quantum encryption,提升数据防护能力。
by nomadu27
面向运行时的 AI-to-AI 安全监控器,覆盖 23 类异常与 OWASP MCP Top 10 风险。