Sentry MCP Setup: Investigate One Project Before You Widen Scope
To set up Sentry MCP, start with Sentry’s hosted OAuth endpoint, connect only the organization or project you need, and confirm read-only issue and event retrieval. Add natural-language search, Seer analysis, updates, or the local stdio server only when the investigation calls for them, then review data exposure and scopes.

To set up Sentry MCP, start with Sentry’s hosted OAuth endpoint, connect only the organization or project you need, and confirm read-only issue and event retrieval. Add natural-language search, Seer analysis, updates, or the local stdio server only when the investigation calls for them, then review data exposure and scopes.
Table of contents
- What Sentry MCP can investigate
- Choose hosted OAuth or local stdio
- Constrain the connection to an organization or project
- Verify issues, events, traces, and releases with reads
- Handle PII, AI search providers, Seer, and writes
- Fix OAuth, scope, missing-tool, and self-hosted failures
- FAQ
What Sentry MCP can investigate
Use Sentry MCP to investigate issues and events first, then expand to traces, performance, releases, projects, teams, or DSNs when those details are relevant.
Sentry’s official MCP server is primarily a hosted remote service at https://mcp.sentry.dev/mcp. It uses OAuth, so the hosted setup does not require pasting an API key into the client. The server is maintained by Sentry and is designed to let AI assistants query Sentry data. (Official Sentry MCP service, Sentry MCP repository)
A focused investigation can begin with:
- Reading a project’s issues and error details.
- Retrieving related events.
- Checking traces, performance data, or spans.
- Reviewing releases and project metadata.
- Looking up teams or DSNs when they help identify ownership or configuration.
- Searching Sentry documentation from the assistant.
The server also exposes search_events and search_issues, which translate natural-language questions into Sentry query syntax. Seer analysis is available through analyze_issue_with_seer when Seer is enabled for the Sentry organization.
For the practical connection details, use MCPtrove’s Sentry MCP Server directory entry. Keep the first session narrow: one organization, one project, and read requests that answer the current question.
Choose hosted OAuth or local stdio
Choose hosted OAuth when your MCP client supports remote MCP over HTTP and browser-based OAuth; choose local stdio when you need a local process or your client does not yet support remote OAuth MCP servers.
Hosted OAuth is the shorter operational path. Connect the client to https://mcp.sentry.dev/mcp, complete the OAuth flow in your browser, and approve access for the Sentry organization and projects you intend to investigate.
Local stdio is the fallback option. The same project ships @sentry/mcp-server, which runs locally with Node.js and a Sentry User Auth Token. The token may need scopes such as org:read, project:read/write, team:read/write, and event:write, depending on the operations required.
| Situation | Better starting point | Main requirement |
|---|---|---|
| Client supports remote HTTP MCP and OAuth | Hosted server | Complete browser OAuth |
| Client cannot use remote OAuth MCP | Local stdio | Node.js and a Sentry User Auth Token |
| Investigation needs only reads | Either option | Request the narrowest available access |
| Seer analysis is required | Either option | Seer enabled for the Sentry organization |
MCP separates the client, server, and authorization flow, so confirm which component handles OAuth before troubleshooting. (MCP architecture)

Constrain the connection to an organization or project
Constrain the connection to the organization or project path needed for the investigation, then verify that target with a small read before requesting broader Sentry data.
Use the client’s Sentry connection settings to select the relevant organization or project path. The exact control depends on the client, but the operational goal is the same: make the intended target explicit before searching.
A useful setup sequence is:
- Add the hosted endpoint
https://mcp.sentry.dev/mcpto the MCP client. - Complete OAuth in the browser.
- Select or confirm the Sentry organization and project path available to the connection.
- Ask for a small issue or event lookup.
- Confirm that the returned project and organization match the investigation.
Do not treat successful OAuth as proof that the session is limited to one project. OAuth establishes authorization; the connection target and request scope still need review. Keep the first prompt specific, such as asking for issues from the selected project, rather than requesting all accessible Sentry data.
For a client-specific setup path, consult the Claude client guide. If the connection appears malformed or broader than intended, Config Doctor can be the next diagnostic step.
Verify issues, events, traces, and releases with reads
Verify the connection with read-only requests in a fixed order: issue, event, trace or performance data, and then release information.
Start with one known issue or a narrow issue search. Confirm that the response identifies the expected project and includes enough issue detail to continue. Next, retrieve a related event and check that the event belongs to the same project and investigation.
Then expand only if necessary:
| Read check | What it confirms | If it fails |
|---|---|---|
| Issue lookup | Project access and issue retrieval | Recheck organization/project targeting |
| Event retrieval | Event-level access and relationship to the issue | Review scope and event availability |
| Trace, performance, or span lookup | Access to deeper execution data | Narrow the request and confirm the target |
| Release lookup | Access to release context | Check that the project and release are correct |
Natural-language search can be useful after the basic read works. For example, ask the assistant to find issues matching the incident description, then request related events. This tests the search tools without requiring you to invent Sentry query syntax.
The official server also provides documentation search, which can help distinguish a Sentry configuration question from an application error. Keep the sequence read-only until the evidence is sufficient. (Sentry MCP repository)
Handle PII, AI search providers, Seer, and writes
Treat Sentry data as potentially sensitive, keep AI-assisted searches narrow, and enable Seer or write-capable access only when the investigation requires it.
The OAuth grant exposes error and trace data from the authorized Sentry organization. Events may contain personally identifiable information, so review the organization’s scrubbing configuration and the data that the client may receive. Sentry documents its data-scrubbing controls separately. (Sentry data scrubbing)
If the client uses an AI search provider, treat the search prompt and returned event data as part of the same data path. Avoid including unrelated project names, customer details, or broad incident histories when a narrow issue or event query is enough. MCP security guidance also recommends reviewing authorization boundaries and handling sensitive credentials carefully. (MCP security best practices)
Use search_events or search_issues when natural-language filtering is useful. Use analyze_issue_with_seer only when Seer is enabled on the Sentry organization and root-cause analysis is needed.
Keep updates and other write operations separate from the initial diagnosis. If local stdio is used, treat SENTRY_ACCESS_TOKEN as a secret and do not place it in prompts, screenshots, or shared configuration.
Fix OAuth, scope, missing-tool, and self-hosted failures
Fix failures by identifying whether the problem is the browser OAuth flow, the authorized scope, the client’s remote-MCP support, or access to the selected self-hosted organization and projects.
| Symptom | Likely check | Next action |
|---|---|---|
| OAuth does not finish | Browser flow or endpoint | Reconnect to the exact hosted endpoint and complete OAuth |
| Issues are missing | Organization or project target | Confirm the selected path and account access |
| A tool is unavailable | Client capability or server mode | Confirm remote HTTP OAuth support, or use local stdio |
| Seer analysis is unavailable | Organization feature state | Confirm Seer is enabled before requesting analysis |
| Local connection fails | Node.js, token, or token scopes | Check the local prerequisites and required token access |
| Self-hosted data is absent | Account permissions | Confirm access to the target organization and projects |
The hosted prerequisite is an MCP client that supports remote MCP over HTTP with OAuth. The local prerequisite is Node.js plus a Sentry User Auth Token with the scopes needed for the requested operations. Do not add write scopes just to solve a read failure.
For systematic debugging, record the endpoint, connection mode, target organization or project, and the exact operation that failed. Then compare that information with the client’s MCP logs and the server’s documented behavior. (MCP debugging guide)
For a supported client setup example, start with the Claude client guide. For configuration symptoms that affect multiple MCP servers, use Config Doctor.