OneCLI connects AI agents to Sentry through OAuth. Agents can read error events, manage issues, view project and team info, and work with releases. The gateway injects OAuth credentials into requests to the Sentry API automatically.
On self-hosted OneCLI, Sentry needs your own Sentry app first. See Self-hosted.
Skip this section on OneCLI Cloud. It’s only for self-hosted OneCLI without SENTRY_CLIENT_ID and SENTRY_CLIENT_SECRET set, or if you want your own company name on Sentry’s consent screen.
1. Create the Sentry integration
In Sentry, open Settings > Developer Settings > Custom Integrations > Create New Integration, and choose Public Integration. Name it OneCLI.
2. Add the redirect URL
In OneCLI, open Connections > Sentry > Custom credentials and copy the Redirect URI. In Sentry, paste it into Redirect URL.
Copy the Redirect URI from Custom credentials in OneCLI.
3. Set the permissions
Under Permissions, set these so they cover what OneCLI requests (org:read, project:read, project:releases, event:read, event:write, team:read, member:read):
Resource
Level
Project
Read
Release
Admin
Issue & Event
Read & Write
Team, Member, Organization
Read
Save the integration.
4. Connect with your integration
Copy the integration’s Client ID and Client Secret under Credentials. Paste both into Connections > Sentry > Custom credentials, select Save & Connect, and authorize in Sentry.
Access is per agent: grant the connection to each agent that needs it, choosing per tool what runs freely, what needs human approval, and what stays blocked — a read-only agent is a single grant. Organization rules add guardrails on top, like rate limits and blanket blocks. Everything is checked before credential injection, so a blocked request never reaches Sentry.