THRONE
See report Verify server

registry / record

@sentry/mcp-server

npm / sealed 2026-06-16 / No. 55a02590

Does @sentry/mcp-server MCP work in Claude Code and Cursor? Throne executed @sentry/mcp-server mcp in a single-use Firecracker microVM and replayed both recorded client behaviours. Compatibility verdict: needs your API key. Is @sentry/mcp-server mcp safe? Static security scan: 5 finding(s) to review under security ruleset v1. The full per-step results, security findings, scan date, and evidence hash are below.

> throne registry @sentry/mcp-server sealed
This server runs. It just needs your API keythe server installs and starts, then exits asking for an API key, Error: No access token was provided. Run `sentry-mcp auth login` interactively first, or pass `--access-token` / `SENTRY_ACCESS_TOKEN`. Usage: @sentry/mcp-server [--access-token=<token>] [--host=<host>] [--insecure-http] @sentry/mcp-server auth [login|logout|status] Commands: auth login Authenticate via device code flow (sentry.io only) auth logout Clear cached [...] re-http @sentry/mcp-server --access-token=TOKEN --host=sentry.example.com --disable-skills=seer @sentry/mcp-server --access-token=TOKEN --agent-provider=azure-openai --openai-base-url=https://example.openai.azure.com/openai/v1/ @sentry/mcp-server --access-token=TOKEN --agent-provider=anthropic
receiptsealed evidence
scan id
55a025905b754976a561bdb3ebc8d494
target
@sentry/mcp-server
sealed at
2026-06-16 18:19:08Z
evidence hash
sha256:648dc51b16bfa18370ff75f64872243b67b4441f53266ea891eae3ff57ac9c21
01connectFAIL0ms

server never launched: server process exited with code 1 before the MCP handshake, stderr: Error: No access token was provided. Run `sentry-mcp auth login` interactively first, or pass `--access-token` / `SENTRY_ACCESS_TOKEN`. Usage: @sentry/mcp-server [--access-token=<token>] [--host=<host>] [--insecure-http] @sentry/mcp-server auth [login|logout|status] Commands: auth login Authenticate via device code flow (sentry.io only) auth logout Clear cached [...] re-http @sentry/mcp-server --access-token=TOKEN --host=sentry.example.com --disable-skills=seer @sentry/mcp-server --access-token=TOKEN --agent-provider=azure-openai --openai-base-url=https://example.openai.azure.com/openai/v1/ @sentry/mcp-server --access-token=TOKEN --agent-provider=anthropic

02discoverSKIPPED0ms

not run, server never launched

03validate_schemasSKIPPED0ms

not run, server never launched

04smoke_test_toolsSKIPPED0ms

not run, server never launched

05error_handlingSKIPPED0ms

not run, server never launched

06streamingSKIPPED0ms

not run, server never launched

07resource_lifecycleSKIPPED0ms

not run, server never launched

08concurrent_callsSKIPPED0ms

not run, server never launched

09reconnectSKIPPED0ms

not run, server never launched

01connectFAIL0ms

server never launched: server process exited with code 1 before the MCP handshake, stderr: Error: No access token was provided. Run `sentry-mcp auth login` interactively first, or pass `--access-token` / `SENTRY_ACCESS_TOKEN`. Usage: @sentry/mcp-server [--access-token=<token>] [--host=<host>] [--insecure-http] @sentry/mcp-server auth [login|logout|status] Commands: auth login Authenticate via device code flow (sentry.io only) auth logout Clear cached [...] re-http @sentry/mcp-server --access-token=TOKEN --host=sentry.example.com --disable-skills=seer @sentry/mcp-server --access-token=TOKEN --agent-provider=azure-openai --openai-base-url=https://example.openai.azure.com/openai/v1/ @sentry/mcp-server --access-token=TOKEN --agent-provider=anthropic

02discoverSKIPPED0ms

not run, server never launched

03validate_schemasSKIPPED0ms

not run, server never launched

04smoke_test_toolsSKIPPED0ms

not run, server never launched

05error_handlingSKIPPED0ms

not run, server never launched

06streamingSKIPPED0ms

not run, server never launched

07resource_lifecycleSKIPPED0ms

not run, server never launched

08concurrent_callsSKIPPED0ms

not run, server never launched

09reconnectSKIPPED0ms

not run, server never launched

chatgpt desktop calibratingemulation profile pending real-traffic captureCOMING SOON
SECURITY: REVIEW / 5 finding(s) (4 medium) / review recommended
MEDIUMTHR-EXEC-04 / Arbitrary command execution from tool arguments

exec() called with a dynamically built command (heuristic, review): '`open ${JSON.stringify(url)}`);'

package/dist/device-code-flow-E2NU5-6y.js:93
MEDIUMTHR-EXEC-04 / Arbitrary command execution from tool arguments

exec() called with a dynamically built command (heuristic, review): '`start "" ${JSON.stringify(url)}`);'

package/dist/device-code-flow-E2NU5-6y.js:94
MEDIUMTHR-EXEC-04 / Arbitrary command execution from tool arguments

exec() called with a dynamically built command (heuristic, review): '`cmd.exe /c start "" ${JSON.stringify(url)}`);'

package/dist/device-code-flow-E2NU5-6y.js:95
MEDIUMTHR-EXEC-04 / Arbitrary command execution from tool arguments

exec() called with a dynamically built command (heuristic, review): '`xdg-open ${JSON.stringify(url)}`);'

package/dist/device-code-flow-E2NU5-6y.js:96
LOWTHR-NET-05 / Hardcoded outbound endpoints

6 non-local endpoint host(s) referenced in code, verify each is expected for this server's purpose: api.vercel.com (package/dist/token-util-CyoHfXBG.js:296), docs.sentry.io (package/dist/types-CRcGDSCR.js:6), example.openai.azure.com (package/dist/usage-BvMOKdze.js:55), mcp.sentry.dev (package/dist/version-0F5BJUB4.cjs:4), sentry.example.com (package/dist/constants-DGLkHYpN.js:307), vercel.com (package/dist/token-util-CyoHfXBG.js:170)

package/dist/constants-DGLkHYpN.js:307
VERDICT: NEEDS YOUR API KEYSANDBOXED RUN, submitted server executed in a disposable microVM, compatibility not assessable: needs credentials: the server installs and starts, then exits asking for an API key, Error: No access token was provided. Run `sentry-mcp auth login` interactively first, or pass `--access-token` / `SENTRY_ACCESS_TOKEN`. Usage: @sentry/mcp-server [--access-token=<token>] [--host=<host>] [--insecure-http] @sentry/mcp-server auth [login|logout|status] Commands: auth login Authenticate via device code flow (sentry.io only) auth logout Clear cached [...] re-http @sentry/mcp-server --access-token=TOKEN --host=sentry.example.com --disable-skills=seer @sentry/mcp-server --access-token=TOKEN --agent-provider=azure-openai --openai-base-url=https://example.openai.azure.com/openai/v1/ @sentry/mcp-server --access-token=TOKEN --agent-provider=anthropic / security: review, 5 finding(s), 0 highsealed by THRONE / No. 55a02590 / 2026-06-16
scopeattestation tuple
target
@sentry/mcp-server npm
engine
sandboxed
claude code
calibration: partial recorded=9,spec=0,assumed=9
cursor
calibration: partial recorded=11,spec=0,assumed=7
chatgpt desktop
calibration: unavailable recorded=0,spec=2,assumed=16
steps exercised
18 of 18
test suite
v1.0.0
security ruleset
v1.0.0
sealed at
2026-06-16 18:19:08Z
evidence hash
sha256:648dc51b16bfa18370ff75f64872243b67b4441f53266ea891eae3ff57ac9c21
valid until
2026-09-14
executed in a disposable microVM, created for this scan and destroyed after it. nothing outlives a run.

maintainer of this server? challenge this record: hello@usethrone.dev. tell us what we got wrong and we re-run it in the open.

this page renders the stored record of a real run. nothing on it is asserted without the execution that proved it.