auth
Authenticate with Sentry
Commands
Section titled “Commands”sentry auth login
Section titled “sentry auth login”Authenticate with Sentry
Options:
| Option | Description |
|---|---|
--token <token> |
Authenticate using an API token instead of OAuth |
--timeout <timeout> |
Timeout for OAuth flow in seconds (default: 900) |
--force |
Re-authenticate without prompting |
--url <url> |
Sentry instance URL to authenticate against (e.g. https://sentry.example.com). Required for self-hosted; defaults to SaaS (https://sentry.io). |
--read-only |
Request only read-only OAuth scopes (project:read, org:read, event:read, member:read, team:read). Useful for handing tokens to AI agents or CI jobs that should not be able to mutate Sentry state. |
-s, --scope <scope>... |
Request specific OAuth scopes (repeatable, comma-separated). E.g. --scope project:read --scope org:read. Overrides the default scope set. |
sentry auth logout
Section titled “sentry auth logout”Log out of Sentry
sentry auth refresh
Section titled “sentry auth refresh”Refresh your OAuth access token
Options:
| Option | Description |
|---|---|
--force |
Force refresh even if the access token is still valid |
--read-only |
Re-authenticate with read-only OAuth scopes (project:read, org:read, event:read, member:read, team:read) |
-s, --scope <scope>... |
Re-authenticate with specific OAuth scopes (repeatable, comma-separated). E.g. --scope project:read --scope org:read |
sentry auth status
Section titled “sentry auth status”View authentication status
Options:
| Option | Description |
|---|---|
--show-token |
Show the stored token (masked by default) |
-f, --fresh |
Bypass cache, re-detect projects, and fetch fresh data |
sentry auth token
Section titled “sentry auth token”Print the stored authentication token
sentry auth whoami
Section titled “sentry auth whoami”Show the currently authenticated identity
Options:
| Option | Description |
|---|---|
-f, --fresh |
Bypass cache, re-detect projects, and fetch fresh data |
All commands support --json for machine-readable output and --fields to select specific JSON fields.
Examples
Section titled “Examples”OAuth login (recommended)
Section titled “OAuth login (recommended)”sentry auth login- A URL and device code will be displayed
- Open the URL in your browser
- Enter the code when prompted
- Authorize the application
- The CLI stores the OAuth credentials and, when the server provides a refresh token, automatically refreshes the access token
Token login
Section titled “Token login”sentry auth login --token YOUR_SENTRY_API_TOKENSelf-hosted Sentry
Section titled “Self-hosted Sentry”SENTRY_URL=https://sentry.example.com sentry auth loginFor token-based auth with self-hosted:
SENTRY_URL=https://sentry.example.com sentry auth login --token YOUR_TOKENSee Self-Hosted Sentry for details.
Logout
Section titled “Logout”sentry auth logoutRefresh the OAuth access token
Section titled “Refresh the OAuth access token”sentry auth refreshPrint stored token
Section titled “Print stored token”sentry auth tokenCheck auth status
Section titled “Check auth status”sentry auth status✓ AuthenticatedUser: usernameAccess token expires: in 4 weeksAutomatic refresh: enabled# Show the raw tokensentry auth status --show-token
# View current usersentry auth whoamiCredential Storage
Section titled “Credential Storage”Auth tokens are stored in the Sentry CLI configuration directory (~/.sentry/
by default, overridable with SENTRY_CONFIG_DIR) with restricted file
permissions.
OAuth access tokens expire. When the server provides a refresh token, the CLI
stores it and refreshes the access token automatically. Persist the
configuration directory across runs to keep automatic refresh working. For
ephemeral CI jobs or sandboxes that cannot persist stored credentials, provide
an API token with sentry auth login --token or SENTRY_AUTH_TOKEN.
Token Precedence
Section titled “Token Precedence”By default, the CLI checks for auth tokens in the following order:
- The stored credential from
sentry auth login SENTRY_AUTH_TOKENenvironment variableSENTRY_TOKENenvironment variable (legacy alias)
The stored credential takes priority. Stored OAuth credentials support
automatic refresh; manually provided API tokens do not use a refresh token. To
override this precedence and force environment tokens to win, set
SENTRY_FORCE_ENV_TOKEN=1.
When a token comes from an environment variable, the CLI skips expiry checks and automatic refresh.