Skip to main content

Overview

OneCLI connects AI agents to Sentry through OAuth. Agents can read error events, manage issues, view project and team info, and work with releases. The gateway injects OAuth credentials into requests to the Sentry API automatically.
On self-hosted OneCLI, Sentry needs your own Sentry app first. See Self-hosted.

Setup

1

Go to Connections

Open the OneCLI dashboard and navigate to Connections > Sentry.
2

Authorize

Click Connect Sentry. You’ll be redirected to Sentry to authorize OneCLI. Review the requested permissions and click Authorize.
OneCLI connect window for Sentry on Cloud, showing the Connect to Sentry button.

The Sentry connect window on OneCLI Cloud.

3

Verify

After authorization, you’ll be redirected back to the dashboard. The connection will show as Connected with your Sentry account email.

Self-hosted: use your own Sentry app

Skip this section on OneCLI Cloud. It’s only for self-hosted OneCLI without SENTRY_CLIENT_ID and SENTRY_CLIENT_SECRET set, or if you want your own company name on Sentry’s consent screen.

1. Create the Sentry integration

In Sentry, open Settings > Developer Settings > Custom Integrations > Create New Integration, and choose Public Integration. Name it OneCLI.
In OneCLI, open Connections > Sentry > Custom credentials and copy the Redirect URI. In Sentry, paste it into Redirect URL.
OneCLI Custom credentials card for Sentry with the setup guide link, the Redirect URI and its copy button, and the client ID and secret fields.

Copy the Redirect URI from Custom credentials in OneCLI.

Under Permissions, set these so they cover what OneCLI requests (org:read, project:read, project:releases, event:read, event:write, team:read, member:read):Save the integration.
Copy the integration’s Client ID and Client Secret under Credentials. Paste both into Connections > Sentry > Custom credentials, select Save & Connect, and authorize in Sentry.

What agents can do

Use cases

  • Coding agents that check for regressions after deploying
  • On-call agents that triage and resolve Sentry issues
  • Monitoring agents that track error rates and alert on spikes
  • Release management agents that tag deploys and upload source maps

Controlling access

Access is per agent: grant the connection to each agent that needs it, choosing per tool what runs freely, what needs human approval, and what stays blocked — a read-only agent is a single grant. Organization rules add guardrails on top, like rate limits and blanket blocks. Everything is checked before credential injection, so a blocked request never reaches Sentry.