SENTRY_AUTH_TOKEN, SENTRY_ORG_SLUG), plus a third (SENTRY_BASE_URL) if your organization’s data is stored in the EU or you run Sentry yourself.
Scope of this integration today. ConfigView reads who is in your Sentry organization and with what role, whether they use two-factor sign-in and SSO, when they were last active, open invitations, teams and who is on them, projects and their client keys (DSNs), every outside service and app connected to Sentry with the permissions it holds, where error data is sent outside Sentry by service hooks and data forwarding, the organization’s security settings, and the audit log of who changed what. ConfigView only reads. It never creates, changes or deletes anything, and it never reads issues, events, stack traces, replays or key secrets.
Step 1: Open the Sentry page in ConfigView
Open ConfigView in a second browser tab and leave it open:https://{companyname}.configview.com/admin/integrations/sentry
Step 2: Find your organization slug and address
- Sign in to Sentry and open Settings → General Settings
- Copy Organization Slug (it is also the first part of your Sentry address,
https://<slug>.sentry.io/). Paste it intoSENTRY_ORG_SLUGunder Credentials and click the save icon - On the same page, look at Data Storage Location:
Step 3: Create an internal integration for ConfigView
You need to be an organization Owner or Manager to create one.- Open Settings → Developer Settings → Custom Integrations and click Create New Integration
- Choose Internal Integration and click Next
- Name:
ConfigView. Leave Webhook URL empty and Alert Rule Action off - Under Permissions, set:
- Leave every Webhooks box unticked and click Save Changes
- Under Tokens, copy the token. Switch to the ConfigView tab, paste it into
SENTRY_AUTH_TOKENunder Credentials, and click the save icon
sntrys_... tokens under Developer Settings → Organization Tokens). Those are built for uploading source maps and can’t read members, teams or integrations.
Step 4: Connect and verify
- Back on
https://{companyname}.configview.com/admin/integrations/sentry, confirm the credentials show as saved - Click Connect. ConfigView creates its tables and schedules every collector at your default run time. Stop any you don’t want under Collectors:
- Click Verify now. The health check confirms the token can read your organization, then reads one record from each kind of data.
- “Sentry organization” fails with 401. The token is wrong, or the internal integration was deleted (that revokes its tokens). Create a new token under the integration’s Tokens section.
- “Sentry organization” fails with 404.
SENTRY_ORG_SLUGis not an organization this token belongs to. Check the slug, and for self-hosted Sentry setSENTRY_BASE_URL. - “Members”, “Teams” or “Projects” fails with “needs … Read”. That permission is set to No Access on the internal integration. Change it to Read, save, and verify again. The token updates in place.
- “data is stored at https://de.sentry.io”. Your organization’s data lives in the EU. Set
SENTRY_BASE_URLtohttps://de.sentry.ioso ConfigView’s requests stay in that region. - “Audit log” is skipped. The integration’s Organization permission is Read. Set it to Read & Write if you want the audit log (Step 3). Everything else still works.
- “Data forwarding” is skipped. Data Forwarding isn’t part of your Sentry plan, or nothing has been set up. The table stays empty and nothing fails.
Data Tables
Once the scripts run, these tables are created in your database. Each includes arun_at column. Every table keeps only the newest run, except sentry_audit_logs, which keeps every entry ever collected.
Things worth knowing
Invitations are members too.sentry_members includes invitations that haven’t been accepted yet (pending = 1). They have an email and a role but no user, sign-in or two-factor status. An invitation whose link has run out shows expired = 1.
Two-factor status comes from the person’s Sentry account. has_2fa is whether the member has two-factor sign-in on their Sentry account. Whether the organization requires it is sentry_organization.require_2fa. Members who sign in through SSO are usually covered by your identity provider’s own MFA instead; check sso_linked.
Internal integrations are installed apps. Every internal integration in the organization, including the one ConfigView uses, appears in sentry_app_installations with is_internal = 1 and the scopes its token carries. has_write_scope = 1 marks any app that may change something in Sentry.
Webhook and forwarding destinations are stored as hosts. webhook_host, url_host and target_host are the host data is sent to, never the full URL, which can carry a token. Data forwarding credentials (AWS access keys, Segment write keys, Splunk tokens) are never read into a table.
Service hooks are a plan feature. Only projects whose plan includes service hooks are asked; others are skipped without failing the run.
The audit log is incremental. The first run reads up to a year back. Each later run reads from the newest stored entry, and entries are never deleted from the table. Without Organization: Read & Write on the integration the table stays empty and nothing fails.
EU organizations. If your Data Storage Location is the EU, set SENTRY_BASE_URL to https://de.sentry.io. Requests to sentry.io still work, but going to the regional address keeps them inside the region.
Rate limits. Sentry sets limits per caller and endpoint and reports them on every response. ConfigView sends one request at a time, paces itself well below the limits and waits for the reset when one is nearly used up.
What isn’t collected
- The internal integration’s token or any other token, client secret or webhook signing secret
- Client key secrets and DSN URLs. Only each key’s public ID, name and settings
- Webhook URLs (only the host) and custom webhook headers
- Data forwarding configuration beyond where the data goes: no access keys, write keys or tokens
- Issues, events, stack traces, breadcrumbs, attachments, session replays and user feedback
- Integration configuration details beyond the connected account’s name and the permissions granted