MCP and epure-cli
Personal access tokens, epure-mcp (stdio MCP for any host), and epure-cli for queue, context, triage, and full /api/v1 automation.
MCP and epure-cli are two clients for the same backend: Epure’s dashboard HTTP API with a personal access token (PAT). They do not send exceptions — use a Sentry SDK + DSN for ingest: Quickstart.
HTTP reference: Agent API · Authentication · OpenAPI agent.openapi.yaml
What are MCP and epure-cli?
| Client | When to use |
|---|---|
| epure-mcp | Stdio MCP server for any compatible host (Cursor, Claude Desktop, custom runners). Exposes tools such as epure_queue and epure_issue_context. |
| epure-cli | Rust binary for scripts, CI, SSH sessions, and one-off curls without an MCP host. |
Both read EPURE_URL (your public app URL, same idea as EPURE_PUBLIC_URL in Configuration) and EPURE_TOKEN (epure_pat_…).
What do I need first?
- A running Epure instance (Installation).
- Admin or Owner on the workspace.
- A token from Settings → Agent tokens (
/settings/agent): Settings.
Personal access token scopes
Every token includes read:agent (required). Add optional scopes when creating the token in the UI or via POST /api/v1/agent-tokens.
| Scope | Allows |
|---|---|
read:agent | All GET /api/v1/* (issues, events, stats, alerts, projects, agent queue/context, …) |
write:triage | Issue resolve/ignore/snooze/merge/bulk; alert patches |
write:admin | Projects, DSN keys, webhooks, alert rules, members, agent-token CRUD |
RBAC still applies
Workspace Member role may get 403 on admin routes even if the token carries write:admin. Token scopes gate the PAT; role gates what your user may do in the product.
Rate limits (per instance): about 120 reads and 20 writes per minute per client IP and token prefix.
Environment variables
| Variable | Meaning |
|---|---|
EPURE_URL | Base URL, no trailing slash (default http://localhost:8080) |
EPURE_TOKEN | Full secret epure_pat_… (shown once at create) |
epure-cli also accepts --url and --token instead of env vars.
Install epure-mcp
The package @epure/mcp is not published to npm. Build from the product repo:
cd tools/epure-mcp
npm ci
npm run buildEntrypoint: tools/epure-mcp/dist/index.js (Node 18+).
Configure an MCP client
Add a stdio server to your host’s MCP config. Example shape (paths are absolute on your machine):
{
"mcpServers": {
"epure": {
"command": "node",
"args": ["/absolute/path/to/epure/tools/epure-mcp/dist/index.js"],
"env": {
"EPURE_URL": "http://localhost:8080",
"EPURE_TOKEN": "epure_pat_…"
}
}
}
}- Cursor: user or project MCP config (stdio).
- Other hosts: same
command/args/env; refer to your host’s MCP documentation.
If EPURE_TOKEN is missing, the server exits before serving tools.
MCP tools
| Tool | Purpose | Scope |
|---|---|---|
epure_queue | Prioritized unresolved issues — start here | read:agent |
epure_issue_context | Fix-ready markdown or JSON for one issue | read:agent |
epure_alerts_unread | Unread alerts (optional project_id, environment) | read:agent |
epure_triage_resolve | Resolve (optional release) | write:triage |
epure_triage_ignore | Ignore | write:triage |
epure_triage_reopen | Reopen | write:triage |
epure_issue_snooze | Snooze by mode (hours, 4h, 100, …) | write:triage |
epure_api | Raw GET/POST/PATCH/DELETE on any /api/v1/… path | Per route + scopes |
Resource epure://api/catalog — text index of common /api/v1 routes (also embedded in the MCP server). Use epure_api for paths not wrapped as named tools (projects, DSN, webhooks, setup, stats).
Install epure-cli
Inside the Compose app container (binary ships in the GHCR image):
docker compose exec epure epure-cli auth whoamiFrom source (repo root):
cargo build --release --bin epure-cli
./target/release/epure-cli auth whoamiSet EPURE_URL and EPURE_TOKEN, or pass --url / --token.
epure-cli command cheat sheet
export EPURE_URL=https://errors.example.com
export EPURE_TOKEN=epure_pat_…
# Prioritized queue (table output)
epure-cli --output table queue --limit 20
epure-cli queue --project PROJECT_UUID --env production
# Fix context (markdown to stdout or file)
epure-cli context ISSUE_UUID --format markdown
epure-cli context ISSUE_UUID --format markdown --out /tmp/fix.md
# Issue summary
epure-cli issue show ISSUE_UUID
# Triage (needs write:triage on token)
epure-cli triage resolve ISSUE_UUID --release my-app@1.2.0
epure-cli triage ignore ISSUE_UUID
epure-cli triage reopen ISSUE_UUID
epure-cli triage snooze ISSUE_UUID --mode hours
# Alerts
epure-cli alerts --view unread --limit 50
# Token identity
epure-cli auth whoami
# Any dashboard route
epure-cli api GET '/api/v1/projects'
epure-cli api PATCH '/api/v1/issues/ISSUE_UUID' --body '{"status":"resolved"}'Global flag --output: json (default) or table (queue only).
Suggested workflow
epure_queueorepure-cli queue— pick an issue.epure_issue_contextorepure-cli context … --format markdown— same class of output as ⌘⇧C in the UI: Issues.- Patch your application repo; run tests.
epure_triage_resolveorepure-cli triage resolve— only after you confirm the fix (do not auto-resolve in unattended loops without policy).
Admin tasks (new DSN, webhook): use epure_api or epure-cli api with a token that includes write:admin.
Not for ingest
PATs and MCP never replace the DSN. Browser and server exceptions still use the official Sentry SDK: Pick your SDK.
FAQ
Can I commit EPURE_TOKEN to git?
No. Treat it like a password. Revoke and rotate from Settings → Agent tokens if it leaks.
What happens when I revoke a token?
MCP and CLI calls return 401 immediately. Create a new token and update your MCP env or shell exports.
Is a PAT the same as a session cookie?
No. The dashboard UI uses session cookies; MCP/CLI use Bearer PAT. DSN is ingest only. See Authentication.
Why 403 with write:triage on the token?
Missing scope, wrong org/project, or Member role on an admin-only route. Check epure-cli auth whoami and your workspace role on /team.