MCP Directory

Sentry MCP Setup: Investigate One Project Before You Widen Scope

To set up Sentry MCP, start with Sentry’s hosted OAuth endpoint, connect only the organization or project you need, and confirm read-only issue and event retrieval. Add natural-language search, Seer analysis, updates, or the local stdio server only when the investigation calls for them, then review data exposure and scopes.

MCPtrove·September 25, 2026·7 min read
Close-up of PHP code on a monitor, highlighting development and programming concepts.
Photo by Pixabay on Pexels

To set up Sentry MCP, start with Sentry’s hosted OAuth endpoint, connect only the organization or project you need, and confirm read-only issue and event retrieval. Add natural-language search, Seer analysis, updates, or the local stdio server only when the investigation calls for them, then review data exposure and scopes.

Table of contents

What Sentry MCP can investigate

Use Sentry MCP to investigate issues and events first, then expand to traces, performance, releases, projects, teams, or DSNs when those details are relevant.

Sentry’s official MCP server is primarily a hosted remote service at https://mcp.sentry.dev/mcp. It uses OAuth, so the hosted setup does not require pasting an API key into the client. The server is maintained by Sentry and is designed to let AI assistants query Sentry data. (Official Sentry MCP service, Sentry MCP repository)

A focused investigation can begin with:

  • Reading a project’s issues and error details.
  • Retrieving related events.
  • Checking traces, performance data, or spans.
  • Reviewing releases and project metadata.
  • Looking up teams or DSNs when they help identify ownership or configuration.
  • Searching Sentry documentation from the assistant.

The server also exposes search_events and search_issues, which translate natural-language questions into Sentry query syntax. Seer analysis is available through analyze_issue_with_seer when Seer is enabled for the Sentry organization.

For the practical connection details, use MCPtrove’s Sentry MCP Server directory entry. Keep the first session narrow: one organization, one project, and read requests that answer the current question.

Choose hosted OAuth or local stdio

Choose hosted OAuth when your MCP client supports remote MCP over HTTP and browser-based OAuth; choose local stdio when you need a local process or your client does not yet support remote OAuth MCP servers.

Hosted OAuth is the shorter operational path. Connect the client to https://mcp.sentry.dev/mcp, complete the OAuth flow in your browser, and approve access for the Sentry organization and projects you intend to investigate.

Local stdio is the fallback option. The same project ships @sentry/mcp-server, which runs locally with Node.js and a Sentry User Auth Token. The token may need scopes such as org:read, project:read/write, team:read/write, and event:write, depending on the operations required.

SituationBetter starting pointMain requirement
Client supports remote HTTP MCP and OAuthHosted serverComplete browser OAuth
Client cannot use remote OAuth MCPLocal stdioNode.js and a Sentry User Auth Token
Investigation needs only readsEither optionRequest the narrowest available access
Seer analysis is requiredEither optionSeer enabled for the Sentry organization

MCP separates the client, server, and authorization flow, so confirm which component handles OAuth before troubleshooting. (MCP architecture)

Tablet displaying stock market data on a desk with a candle and world clocks, symbolizing global trading.
Photo by AlphaTradeZone on Pexels

Constrain the connection to an organization or project

Constrain the connection to the organization or project path needed for the investigation, then verify that target with a small read before requesting broader Sentry data.

Use the client’s Sentry connection settings to select the relevant organization or project path. The exact control depends on the client, but the operational goal is the same: make the intended target explicit before searching.

A useful setup sequence is:

  1. Add the hosted endpoint https://mcp.sentry.dev/mcp to the MCP client.
  2. Complete OAuth in the browser.
  3. Select or confirm the Sentry organization and project path available to the connection.
  4. Ask for a small issue or event lookup.
  5. Confirm that the returned project and organization match the investigation.

Do not treat successful OAuth as proof that the session is limited to one project. OAuth establishes authorization; the connection target and request scope still need review. Keep the first prompt specific, such as asking for issues from the selected project, rather than requesting all accessible Sentry data.

For a client-specific setup path, consult the Claude client guide. If the connection appears malformed or broader than intended, Config Doctor can be the next diagnostic step.

Verify issues, events, traces, and releases with reads

Verify the connection with read-only requests in a fixed order: issue, event, trace or performance data, and then release information.

Start with one known issue or a narrow issue search. Confirm that the response identifies the expected project and includes enough issue detail to continue. Next, retrieve a related event and check that the event belongs to the same project and investigation.

Then expand only if necessary:

Read checkWhat it confirmsIf it fails
Issue lookupProject access and issue retrievalRecheck organization/project targeting
Event retrievalEvent-level access and relationship to the issueReview scope and event availability
Trace, performance, or span lookupAccess to deeper execution dataNarrow the request and confirm the target
Release lookupAccess to release contextCheck that the project and release are correct

Natural-language search can be useful after the basic read works. For example, ask the assistant to find issues matching the incident description, then request related events. This tests the search tools without requiring you to invent Sentry query syntax.

The official server also provides documentation search, which can help distinguish a Sentry configuration question from an application error. Keep the sequence read-only until the evidence is sufficient. (Sentry MCP repository)

Handle PII, AI search providers, Seer, and writes

Treat Sentry data as potentially sensitive, keep AI-assisted searches narrow, and enable Seer or write-capable access only when the investigation requires it.

The OAuth grant exposes error and trace data from the authorized Sentry organization. Events may contain personally identifiable information, so review the organization’s scrubbing configuration and the data that the client may receive. Sentry documents its data-scrubbing controls separately. (Sentry data scrubbing)

If the client uses an AI search provider, treat the search prompt and returned event data as part of the same data path. Avoid including unrelated project names, customer details, or broad incident histories when a narrow issue or event query is enough. MCP security guidance also recommends reviewing authorization boundaries and handling sensitive credentials carefully. (MCP security best practices)

Use search_events or search_issues when natural-language filtering is useful. Use analyze_issue_with_seer only when Seer is enabled on the Sentry organization and root-cause analysis is needed.

Keep updates and other write operations separate from the initial diagnosis. If local stdio is used, treat SENTRY_ACCESS_TOKEN as a secret and do not place it in prompts, screenshots, or shared configuration.

Fix OAuth, scope, missing-tool, and self-hosted failures

Fix failures by identifying whether the problem is the browser OAuth flow, the authorized scope, the client’s remote-MCP support, or access to the selected self-hosted organization and projects.

SymptomLikely checkNext action
OAuth does not finishBrowser flow or endpointReconnect to the exact hosted endpoint and complete OAuth
Issues are missingOrganization or project targetConfirm the selected path and account access
A tool is unavailableClient capability or server modeConfirm remote HTTP OAuth support, or use local stdio
Seer analysis is unavailableOrganization feature stateConfirm Seer is enabled before requesting analysis
Local connection failsNode.js, token, or token scopesCheck the local prerequisites and required token access
Self-hosted data is absentAccount permissionsConfirm access to the target organization and projects

The hosted prerequisite is an MCP client that supports remote MCP over HTTP with OAuth. The local prerequisite is Node.js plus a Sentry User Auth Token with the scopes needed for the requested operations. Do not add write scopes just to solve a read failure.

For systematic debugging, record the endpoint, connection mode, target organization or project, and the exact operation that failed. Then compare that information with the client’s MCP logs and the server’s documented behavior. (MCP debugging guide)

For a supported client setup example, start with the Claude client guide. For configuration symptoms that affect multiple MCP servers, use Config Doctor.

FAQ

Does hosted Sentry MCP require an API key?

No. The hosted server uses OAuth through https://mcp.sentry.dev/mcp, with authorization completed in the browser.

Can Sentry MCP be limited to one project?

Yes. Select the relevant organization or project path in the client’s connection settings and verify it with a narrow read before expanding the investigation.

When should I use the local stdio server?

Use local stdio when your client does not support remote MCP over HTTP with OAuth or when a local process is required. It needs Node.js and a Sentry User Auth Token.

When should I enable Seer or write access?

Enable Seer only when AI root-cause analysis is needed and Seer is enabled for the organization. Add write-capable scopes only when the investigation requires updates or other write operations.

Put this into practice

Browse MCP servers by capability, or check your own setup's tool budget and security.

More in Security

Browse all security articles.