MCP and epure-cli

Personal access tokens, epure-mcp (stdio MCP for any host), and epure-cli for queue, context, triage, and full /api/v1 automation.

MCP and epure-cli are two clients for the same backend: Epure’s dashboard HTTP API with a personal access token (PAT). They do not send exceptions — use a Sentry SDK + DSN for ingest: Quickstart.

HTTP reference: Agent API · Authentication · OpenAPI agent.openapi.yaml

What are MCP and epure-cli?

ClientWhen to use
epure-mcpStdio MCP server for any compatible host (Cursor, Claude Desktop, custom runners). Exposes tools such as epure_queue and epure_issue_context.
epure-cliRust binary for scripts, CI, SSH sessions, and one-off curls without an MCP host.

Both read EPURE_URL (your public app URL, same idea as EPURE_PUBLIC_URL in Configuration) and EPURE_TOKEN (epure_pat_…).

What do I need first?

  1. A running Epure instance (Installation).
  2. Admin or Owner on the workspace.
  3. A token from Settings → Agent tokens (/settings/agent): Settings.

Personal access token scopes

Every token includes read:agent (required). Add optional scopes when creating the token in the UI or via POST /api/v1/agent-tokens.

ScopeAllows
read:agentAll GET /api/v1/* (issues, events, stats, alerts, projects, agent queue/context, …)
write:triageIssue resolve/ignore/snooze/merge/bulk; alert patches
write:adminProjects, DSN keys, webhooks, alert rules, members, agent-token CRUD

RBAC still applies

Workspace Member role may get 403 on admin routes even if the token carries write:admin. Token scopes gate the PAT; role gates what your user may do in the product.

Rate limits (per instance): about 120 reads and 20 writes per minute per client IP and token prefix.

Environment variables

VariableMeaning
EPURE_URLBase URL, no trailing slash (default http://localhost:8080)
EPURE_TOKENFull secret epure_pat_… (shown once at create)

epure-cli also accepts --url and --token instead of env vars.

Install epure-mcp

The package @epure/mcp is not published to npm. Build from the product repo:

cd tools/epure-mcp
npm ci
npm run build

Entrypoint: tools/epure-mcp/dist/index.js (Node 18+).

Configure an MCP client

Add a stdio server to your host’s MCP config. Example shape (paths are absolute on your machine):

{
  "mcpServers": {
    "epure": {
      "command": "node",
      "args": ["/absolute/path/to/epure/tools/epure-mcp/dist/index.js"],
      "env": {
        "EPURE_URL": "http://localhost:8080",
        "EPURE_TOKEN": "epure_pat_…"
      }
    }
  }
}
  • Cursor: user or project MCP config (stdio).
  • Other hosts: same command / args / env; refer to your host’s MCP documentation.

If EPURE_TOKEN is missing, the server exits before serving tools.

MCP tools

ToolPurposeScope
epure_queuePrioritized unresolved issues — start hereread:agent
epure_issue_contextFix-ready markdown or JSON for one issueread:agent
epure_alerts_unreadUnread alerts (optional project_id, environment)read:agent
epure_triage_resolveResolve (optional release)write:triage
epure_triage_ignoreIgnorewrite:triage
epure_triage_reopenReopenwrite:triage
epure_issue_snoozeSnooze by mode (hours, 4h, 100, …)write:triage
epure_apiRaw GET/POST/PATCH/DELETE on any /api/v1/… pathPer route + scopes

Resource epure://api/catalog — text index of common /api/v1 routes (also embedded in the MCP server). Use epure_api for paths not wrapped as named tools (projects, DSN, webhooks, setup, stats).

Install epure-cli

Inside the Compose app container (binary ships in the GHCR image):

docker compose exec epure epure-cli auth whoami

From source (repo root):

cargo build --release --bin epure-cli
./target/release/epure-cli auth whoami

Set EPURE_URL and EPURE_TOKEN, or pass --url / --token.

epure-cli command cheat sheet

export EPURE_URL=https://errors.example.com
export EPURE_TOKEN=epure_pat_…

# Prioritized queue (table output)
epure-cli --output table queue --limit 20
epure-cli queue --project PROJECT_UUID --env production

# Fix context (markdown to stdout or file)
epure-cli context ISSUE_UUID --format markdown
epure-cli context ISSUE_UUID --format markdown --out /tmp/fix.md

# Issue summary
epure-cli issue show ISSUE_UUID

# Triage (needs write:triage on token)
epure-cli triage resolve ISSUE_UUID --release my-app@1.2.0
epure-cli triage ignore ISSUE_UUID
epure-cli triage reopen ISSUE_UUID
epure-cli triage snooze ISSUE_UUID --mode hours

# Alerts
epure-cli alerts --view unread --limit 50

# Token identity
epure-cli auth whoami

# Any dashboard route
epure-cli api GET '/api/v1/projects'
epure-cli api PATCH '/api/v1/issues/ISSUE_UUID' --body '{"status":"resolved"}'

Global flag --output: json (default) or table (queue only).

Suggested workflow

  1. epure_queue or epure-cli queue — pick an issue.
  2. epure_issue_context or epure-cli context … --format markdown — same class of output as ⌘⇧C in the UI: Issues.
  3. Patch your application repo; run tests.
  4. epure_triage_resolve or epure-cli triage resolve — only after you confirm the fix (do not auto-resolve in unattended loops without policy).

Admin tasks (new DSN, webhook): use epure_api or epure-cli api with a token that includes write:admin.

Not for ingest

PATs and MCP never replace the DSN. Browser and server exceptions still use the official Sentry SDK: Pick your SDK.

Can I commit EPURE_TOKEN to git?

No. Treat it like a password. Revoke and rotate from Settings → Agent tokens if it leaks.

What happens when I revoke a token?

MCP and CLI calls return 401 immediately. Create a new token and update your MCP env or shell exports.

Is a PAT the same as a session cookie?

No. The dashboard UI uses session cookies; MCP/CLI use Bearer PAT. DSN is ingest only. See Authentication.

Why 403 with write:triage on the token?

Missing scope, wrong org/project, or Member role on an admin-only route. Check epure-cli auth whoami and your workspace role on /team.