Skip to content

feat(cli): add local MCP server command - #1401

Open
MathurAditya724 wants to merge 10 commits into
mainfrom
codex/cli-mcp-auth
Open

MathurAditya724 wants to merge 10 commits into
mainfrom
codex/cli-mcp-auth

Conversation

@MathurAditya724

Copy link
Copy Markdown
Member

The Sentry CLI now starts the local stdio MCP server with sentry mcp, using the active CLI session rather than a separate MCP login or token cache.

The command preserves CLI credential host scoping, directs users to sentry auth login when needed, and keeps the standalone sentry-mcp authentication flow unchanged.

Start the stdio MCP server through the CLI's active, host-scoped credentials so users do not need a separate MCP login.

Co-Authored-By: GPT-5 <noreply@openai.com>
Comment thread packages/cli/package.json Outdated
Comment thread packages/cli/src/cli.ts Outdated
Comment thread packages/cli/src/cli.ts Outdated
Comment thread packages/cli/src/lib/mcp.ts
MathurAditya724 and others added 2 commits October 5, 2026 13:24
Co-Authored-By: GPT-5 <noreply@openai.com>
Co-Authored-By: GPT-5 <noreply@openai.com>
Comment thread packages/cli/src/cli.ts
Comment thread packages/cli/src/cli.ts
Comment thread packages/cli/src/lib/mcp.ts
MathurAditya724 and others added 3 commits October 5, 2026 19:30
Co-Authored-By: GPT-5 <noreply@openai.com>
Co-Authored-By: GPT-5 <noreply@openai.com>
Run the bundle prerequisite before parallel E2E workers so cold CI builds cannot exceed per-suite setup timeouts.

Co-Authored-By: GPT-5 <noreply@openai.com>
mr-danya pushed a commit to mr-danya/sentry-mcp that referenced this pull request Oct 6, 2026
## Summary

Shared issue links use an org-scoped public endpoint that returns `id`.
The CLI was calling the retired unscoped endpoint and expecting
`groupID`, so valid links could not resolve.

Resolve the organization from the URL or existing context, validate the
shared issue ID, and fetch full details through the authenticated
org-scoped API. Support canonical
`/organizations/<org>/share/issue/<shareId>/` URLs alongside SaaS
subdomain links. Public share requests remain unauthenticated, with
existing host-scoped custom headers preserved. Legacy links without
organization context now produce a context error.

Supersedes getsentry#1401.

## Test plan

- 380 tests passed across the shared API, issue resolver, URL/argument
parsers, and host/header security suites.
- All six shared-link resolver regression cases fail against the
original `main` implementation and pass with this change.
- Full `tsc --noEmit`, `pnpm run lint`, `pnpm run check:errors`, and
`git diff --check` passed.
- Generated schema/docs/SDK prerequisites completed without tracked
generated changes.
- No live shared-link request, full unit suite, E2E suite, or packaging
build was run.
@betegon

betegon commented Oct 7, 2026

Copy link
Copy Markdown
Member

looked at this and also tried it out. some notes:

  • it doesn't trigger the log in when running it without being authenticated. it should. we have almost all commands in the CLI to work this way, it will check if it's TTY and launch the browser.
  • it doesn't refresh the token while running. it uses the token at the start and you need to re-run it to refresh it. see how sentry log list --follow checks the token in each request and refresh if there's a 401. i believe that logic is easy to reuse. and maybe we can do the check on each tool call / mcp request.
  • the mcp command can print a malformed token (e.g. a token with a breaking line). we just added normalizeAuthToken(token) to the CLI, so we could use it in resolveCliMcpAccessToken()

@MathurAditya724 MathurAditya724 added the jared Trigger the Jared agent to work on stuff label Oct 7, 2026
@MathurAditya724

Copy link
Copy Markdown
Member Author

Hey Jared, can you resolves these things mentioned by bete? In the previous message

Address review feedback on the MCP command's auth handling:

- Trigger the interactive login flow when `sentry mcp` starts without a
  usable CLI session in a TTY, matching the rest of the CLI; fall back to
  a clear AuthError when non-interactive (e.g. launched by an IDE).
- Refresh the credential on an upstream 401 during a tool call via a new
  `onUpstreamUnauthorized` hook so a long-running server picks up a fresh
  token without a restart, mirroring `log list --follow`.
- Normalize the resolved token with `normalizeAuthToken` so a malformed
  env token can't reach the MCP server as a broken Authorization header.
@MathurAditya724

Copy link
Copy Markdown
Member Author

Thanks @betegon — addressed all three in 08e6ab9:

  • Login on first use: sentry mcp now runs the interactive login flow (TTY → browser device code) when there's no usable CLI session, same as the rest of the CLI. When it's non-interactive (e.g. an IDE launching it over pipes) it fails fast with the usual "run sentry auth login" AuthError instead of hanging on a browser prompt.
  • Refresh while running: wired a new onUpstreamUnauthorized hook from the MCP server back into the CLI. On a tool-call 401 it force-refreshes the CLI token and writes it back into the live context, so the next tool call uses the fresh token without a restart — same model as log list --follow. (Tool handlers read context.accessToken fresh per call, so mutating it is enough; no api-client surgery needed.)
  • Malformed token: resolveCliMcpAccessToken() now runs normalizeAuthToken(token) before handing it off. Stored rows were already normalized, but env tokens (SENTRY_AUTH_TOKEN/SENTRY_TOKEN) bypassed that, so a pasted newline could reach the server as a broken header — now it's trimmed, and a token with embedded invalid chars throws MalformedAuthTokenError.

Added unit coverage for all three in mcp-auth.test.ts / mcp-start.test.ts.

Add regression coverage for the MCP command's lifecycle and host
handling so the previously-fixed edge cases can't silently regress:

- `runMcpCommand` leaves a running stdio server alone on success (no
  force-exit, no dispatcher close) and only tears down network
  resources when setup fails.
- `prepareMcpServerArgs` translates a `SENTRY_HOST=https://…` origin
  into a plain `--host` and preserves an explicit `--host
  --insecure-http` over a CLI http URL.

Exports `runMcpCommand` for testing, matching the existing `getMcpArgs`.
Resolve packages/cli/package.json conflict: keep the mcp-core/mcp-server
prebuild prefix on build/build:all/bundle/typecheck while adopting main's
oxlint/oxfmt lint commands. Reformat the MCP changes with oxfmt and
replace the stale biome-ignore with an oxlint-disable directive.
Post-merge cleanup after main's biome→oxc migration:

- Reformat the branch's MCP files (cli.ts, commands/mcp.ts,
  mcp-command.test.ts) with oxfmt so `pnpm --filter sentry lint` passes.
- Bump the generated `sentry-cli-mcp` skill reference to 0.48.0-dev.0 to
  match the version bump merged from main (all sibling references already
  updated), fixing the docs drift check.
@MathurAditya724
MathurAditya724 marked this pull request as ready for review October 7, 2026 14:51
@github-actions github-actions Bot added the risk: medium PR risk score: medium label Oct 7, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

jared Trigger the Jared agent to work on stuff risk: medium PR risk score: medium

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants