Skip to content

feat(cli): add local MCP server command - #1401

Open
MathurAditya724 wants to merge 10 commits into
mainfrom
codex/cli-mcp-auth
Open

MathurAditya724 wants to merge 10 commits into
mainfrom
codex/cli-mcp-auth

fix(cli): Format MCP files with oxfmt and sync skill version

4d4e0fc
Select commit
Loading
Failed to load commit list.
@sentry/warden / warden: code-review completed Oct 7, 2026

3 issues

code-review: Found 3 issues (2 medium, 1 low)

Medium

Interactive MCP auth logs into env host, not --host target - `apps/cli-docs/src/content/docs/contributing.md:93-123`

In a TTY, sentry mcp --host=<other> with no usable session runs OAuth against resolveEffectiveLoginHost() (env/default SaaS), stores those credentials, then fails host-scope checks for the MCP target.

CLI MCP refresh leaves later tool calls using the rejected token - `packages/mcp-server/src/index.ts:432-437`

After an upstream 401, the CLI refreshes the credential, but the server’s tool handlers retain a copied accessToken. Subsequent tool calls continue using the rejected token and fail until the server restarts.

Low

Windows prepare-e2e-bundle spawn fails without shell:true - `packages/cli/script/prepare-e2e-bundle.ts:3-10`

spawn('pnpm.cmd', …) without shell: true cannot run .cmd shims on Windows, so pnpm test:e2e fails at bundle prep with ENOENT instead of building the e2e bundle.


⏱ 14m 47s · 12.3M in / 175.2k out · $7.40

Annotations

Check warning on line 123 in apps/cli-docs/src/content/docs/contributing.md

See this annotation in the file changed.

@sentry-warden sentry-warden / warden: code-review

Interactive MCP auth logs into env host, not --host target

In a TTY, `sentry mcp --host=<other>` with no usable session runs OAuth against `resolveEffectiveLoginHost()` (env/default SaaS), stores those credentials, then fails host-scope checks for the MCP target.

Check warning on line 437 in packages/mcp-server/src/index.ts

See this annotation in the file changed.

@sentry-warden sentry-warden / warden: code-review

CLI MCP refresh leaves later tool calls using the rejected token

After an upstream 401, the CLI refreshes the credential, but the server’s tool handlers retain a copied `accessToken`. Subsequent tool calls continue using the rejected token and fail until the server restarts.

Check notice on line 10 in packages/cli/script/prepare-e2e-bundle.ts

See this annotation in the file changed.

@sentry-warden sentry-warden / warden: code-review

Windows prepare-e2e-bundle spawn fails without shell:true

`spawn('pnpm.cmd', …)` without `shell: true` cannot run `.cmd` shims on Windows, so `pnpm test:e2e` fails at bundle prep with ENOENT instead of building the e2e bundle.