Skip to content

fix(core): resolve MCP capture policy per operation - #23437

Open
betegon wants to merge 3 commits into
developfrom
bt/fix-mcp-capture-policy
Open

fix(core): resolve MCP capture policy per operation#23437
betegon wants to merge 3 commits into
developfrom
bt/fix-mcp-capture-policy

Conversation

@betegon

@betegon betegon commented Aug 14, 2026

Copy link
Copy Markdown
Member

MCP server instrumentation now honors the active Sentry client's GenAI input
and output collection settings even when the server was wrapped before that
client became available. Explicit wrapper overrides still win independently,
and the existing default remains unchanged when no policy is configured.

The capture decision belongs to the operation that starts the span.
Request/response pairs therefore retain one policy for their full lifetime
instead of allowing response timing or a different active scope to change what
gets recorded. Notifications resolve against the client active when their
operation begins. Explicit options are also snapshotted on the first wrap,
preserving the wrapper's idempotent behavior.

This is shared transport behavior, so it applies to sessionful MCP SDK v1 and
stable MCP SDK v2 without changing the public API. Packaged SDK coverage uses
the Node and Cloudflare MCP fixtures. A disposable Cloudflare Worker running
the packaged SDK also verified the policy matrix against Sentry for both modern
and legacy-compatible requests.

Root cause

wrapMcpServerWithSentry read dataCollection.genAI once, while the wrapper
was being constructed. Common Node import ordering and Cloudflare Durable
Object initialization can run that code before Sentry binds a client, causing
the true fallback to become the permanent capture policy for every operation
handled by that server.

Fixes #23436

betegon and others added 2 commits August 14, 2026 17:59
MCP servers can be wrapped before a Sentry client exists, causing
inherited data collection settings to be fixed to their fallback values.
Resolve inherited policy when an operation begins and retain request
policy through response correlation.

Co-Authored-By: OpenAI Codex <codex@openai.com>
Node module evaluation and Cloudflare Durable Object initialization can
wrap MCP servers before Sentry binds a client. Exercise both runtimes
with marker content so capture-policy regressions are observable.

Co-Authored-By: OpenAI Codex <codex@openai.com>
@github-actions

github-actions Bot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

Path Size % Change Change
@sentry/browser 30.3 kB - -
@sentry/browser - with treeshaking flags 28.47 kB - -
@sentry/browser - with treeshaking flags tracing without tracing 26.81 kB - -
@sentry/browser (incl. Tracing) 48.58 kB - -
@sentry/browser (incl. Tracing + Span Streaming) 48.59 kB - -
@sentry/browser (incl. Tracing, Profiling) 51.46 kB - -
@sentry/browser (incl. Tracing, Replay) 87.98 kB - -
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 77.36 kB - -
@sentry/browser (incl. Tracing, Replay with Canvas) 92.7 kB - -
@sentry/browser (incl. Tracing, Replay, Feedback) 105.39 kB - -
@sentry/browser (incl. Feedback) 47.65 kB - -
@sentry/browser (incl. sendFeedback) 35.13 kB - -
@sentry/browser (incl. FeedbackAsync) 40.28 kB - -
@sentry/browser (incl. Metrics) 31.24 kB - -
@sentry/browser (incl. Logs) 31.52 kB - -
@sentry/browser (incl. Metrics & Logs) 32.15 kB - -
@sentry/react 32.09 kB - -
@sentry/react (incl. Tracing) 50.77 kB - -
@sentry/vue 35.34 kB - -
@sentry/vue (incl. Tracing) 50.54 kB - -
@sentry/svelte 30.33 kB - -
CDN Bundle 31.61 kB - -
CDN Bundle (incl. Tracing) 48.9 kB - -
CDN Bundle (incl. Logs, Metrics) 33.8 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) 50.82 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) 74.31 kB - -
CDN Bundle (incl. Tracing, Replay) 86.48 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 88.31 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) 92.19 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 94.12 kB - -
CDN Bundle - uncompressed 93.84 kB - -
CDN Bundle (incl. Tracing) - uncompressed 146.75 kB - -
CDN Bundle (incl. Logs, Metrics) - uncompressed 100.14 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 152.44 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 229.08 kB - -
CDN Bundle (incl. Tracing, Replay) - uncompressed 266.01 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 271.68 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 279.71 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 285.37 kB - -
@sentry/nextjs (client) 53.29 kB - -
@sentry/sveltekit (client) 49 kB - -
@sentry/core/server 65.42 kB +0.06% +37 B 🔺
@sentry/core/browser 51.72 kB - -
@sentry/node 116.99 kB - -
@sentry/node/import (ESM hook with diagnostics-channel injection) 0 B added added
@sentry/node - without tracing 81.43 kB -0.01% -1 B 🔽
@sentry/aws-serverless 90.92 kB -0.01% -1 B 🔽
@sentry/cloudflare (withSentry) - minified 213.98 kB - -
@sentry/cloudflare (withSentry) 528.93 kB - -

View base workflow run

Keep the public input and output capture defaults protected when an MCP operation has no active client or explicit overrides.

Co-Authored-By: OpenAI Codex <codex@openai.com>
@betegon
betegon marked this pull request as ready for review August 14, 2026 19:37
@betegon
betegon requested a review from JPeer264 August 14, 2026 19:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

MCP server wrapper resolves genAI capture policy before a Sentry client is available

1 participant