The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Sequentum MCP listing page.
The Sequentum MCP Server connects your AI coding assistant to Sequentum using the Model Context Protocol (MCP), giving your AI tools the ability to create web scraping agents, run management, scheduling, analytics, and more. Sequentum hosts and manages a remote MCP server with OAuth authentication, so there's nothing to install.
sequentum-mcp exposes your Sequentum account data to MCP clients, allowing them to
view, run, and manage your web scraping agents. Keep your credentials secure and avoid
sharing sensitive information that you don't want accessible to MCP clients.
Add the Sequentum MCP server to your client with this configuration:
Most clients support the OAuth configuration. Claude.ai and Claude Desktop are simpler still — Sequentum MCP is listed in Claude's connector directory, so there is nothing to enter by hand; see Claude.ai and Claude Desktop below. For other clients, when you first connect, you'll be prompted to:
Once authenticated, all tools become available in your client. For client-specific setup details, see Set Up Your Client below.
Select your client below for specific setup instructions. All clients use the remote OAuth server at https://mcp.sequentum.com/mcp unless noted otherwise.
Go to Cursor > Settings > Cursor Settings > MCP and follow the prompts to add the Sequentum MCP server. Cursor 1.0+ includes native OAuth and Streamable HTTP support.
You can also add the server manually by editing your mcp.json file using the configuration above.
Sequentum MCP is listed in Claude's connector directory, so there is no URL to enter by hand and no custom connector to create.
Team and Enterprise workspaces: connector availability is governed at org level, so an admin may need to enable Sequentum MCP before members can connect from their own accounts.
Enabling per conversation: once connected, enable Sequentum in an individual conversation via the + button near the message composer, then select Connectors.
Note: While the Sequentum app is pending directory approval, you can connect via Developer Mode. Apps & Connectors → Developer Mode is currently available on Plus, Pro, Business, Enterprise, and Education plans (Education is web-only). On Business / Enterprise / Education accounts, only workspace owners and admins can access Advanced settings — regular members will not see the option. See OpenAI's Developer Mode documentation for current eligibility.
Sequentum and URL: https://mcp.sequentum.com/mcpOnce connected, enable Sequentum in a conversation via the + button near the message composer, then select your connector from the list.
Connect Sequentum MCP once from the connector directory (see Claude.ai and Claude Desktop above) and it is available in Claude Code on the same account.
To add it directly instead — useful per-project or in scripts:
Then launch Claude Code with claude and type /mcp to trigger the OAuth browser flow.
Open the Command Palette with Ctrl+Shift+P (or Cmd+Shift+P on macOS) and select MCP: Add Server. Enter the Sequentum MCP server URL:
Configure via the Configure MCP option in Cascade (Cmd+L or Ctrl+L). Add the Sequentum MCP server URL:
The Sequentum MCP Server follows standard MCP protocols and works with any client that supports:
Use the server URL https://mcp.sequentum.com/mcp in your client's MCP configuration.
The server supports Client ID Metadata Documents (CIMD) as the preferred client identification method, with Dynamic Client Registration (RFC 7591) as a fallback. MCP clients that support CIMD (such as Cursor) can use their own URL as a client_id without any prior registration.
Deprecated: Running the MCP server locally over the stdio transport, authenticated with
SEQUENTUM_API_KEY, is deprecated and will be removed in a future release. Thesequentum-mcpnpm package is deprecated along with it. Connect tohttps://mcp.sequentum.com/mcpover HTTP with OAuth 2.1 instead — see Set Up Your Client.This does not affect Sequentum API keys themselves, which remain fully supported for the REST API.
The MCP authorization specification directs stdio implementations not to use OAuth, and to take credentials from the environment instead. Moving the server to OAuth 2.1 therefore retires the stdio path along with it — the two deprecations are one decision, not two.
If you are running this configuration today, it keeps working — on Node 20 or later:
The API key is created in the Sequentum Control Center
under Settings > API Keys, and SEQUENTUM_API_URL overrides the Sequentum
instance it connects to (default https://dashboard.sequentum.com).
To migrate, delete that block and follow the setup instructions for your client above.
If you need Sequentum MCP somewhere that cannot reach mcp.sequentum.com, contact
support — there is no supported self-hosted deployment.
Once connected, try these prompts to start using Sequentum context in your AI assistant:
The Sequentum MCP Server provides 39 tools across 9 categories for interacting with the Sequentum platform. See the Tool Reference for detailed documentation.
The server includes 9 reusable prompt templates that guide the AI through common multi-step workflows. See the Prompts Reference for detailed documentation.
debug-agent -- Diagnose why an agent is failingcompare-runs -- Compare last successful vs failed runagent-health-check -- Comprehensive health overview for an agentdaily-operations-report -- Daily ops report across all agentsspace-overview -- Overview of all agents in a spacerun-and-monitor -- Start an agent and monitor until completionschedule-agent -- Walk through creating a schedulespending-report -- Spending and credits reportcost-analysis -- Analyze costs across agentsbuild-agent-from-prompt -- Build a new agent from a natural language descriptioninspect-agent-draft -- Inspect a build session and decide whether to save or discardThe server exposes 18 read-only resources (7 static + 11 templates) that AI clients can browse and pull into context. See the Resources Reference for detailed documentation.
sequentum://agents -- First page of all agentssequentum://spaces -- All accessible spacessequentum://billing/balance -- Current credits balancesequentum://billing/spending -- Monthly spending summarysequentum://billing/agents-usage -- Top agents by costsequentum://analytics/runs -- Runs in the last 24 hourssequentum://analytics/upcoming-schedules -- Scheduled runs for next 7 dayssequentum://agents/{agentId} -- Agent detail with configurationsequentum://agents/{agentId}/versions -- Agent version historysequentum://agents/{agentId}/schedules -- Agent scheduled taskssequentum://agents/{agentId}/cost-breakdown -- Agent cost by usage typesequentum://agents/{agentId}/runs -- Agent run historysequentum://agents/{agentId}/runs/{runId} -- Specific run statussequentum://agents/{agentId}/runs/{runId}/files -- Run output filessequentum://agents/{agentId}/runs/{runId}/diagnostics -- Run error diagnosticssequentum://agents/{agentId}/latest-failure -- Most recent failure diagnosticssequentum://spaces/{spaceId} -- Space detailssequentum://spaces/{spaceId}/agents -- Agents in a spacenpm run probe -- --env qa --mode log-only runs the real OAuth flow against QA (browser login
and consent, loopback callback, PKCE), then calls the V1 API directly and through this server
with tokens of three scope profiles and checks CloudWatch for the Control Center's scope-check
lines. See docs/oauth-scope-probe.md.
| Error | Solution |
|---|---|
| OAuth login not opening | Ensure your client supports OAuth and Streamable HTTP. Try restarting the client. For Claude.ai and Claude Desktop, connect from the connector directory rather than a config file. |
| Connection refused | Verify the URL is https://mcp.sequentum.com/mcp and check your network connection. |
SEQUENTUM_API_KEY required | Deprecated local stdio mode only. Add your API key to the env section of the MCP config, or migrate to the hosted server. |
API Error 401: Unauthorized | Your API key or OAuth token is invalid or expired. Re-authenticate or generate a new key. |
Insufficient Scope: This action requires the "…" scope | Disconnect and reconnect the Sequentum MCP server, then approve the requested permissions, to re-authorize with the scope named in the message. If it recurs right after reconnecting, the client may have cached a stale scope list — check the connector's OAuth settings. |
API Error 404: Not Found | The agent, run, or file doesn't exist, or you don't have access to it. |
API Error 429: Too Many Requests | Rate limit exceeded. Wait a moment and try again. |
For more troubleshooting help, see the Troubleshooting Guide.
The hosted server at mcp.sequentum.com runs the Streamable HTTP transport
(TRANSPORT_MODE=http) behind its own deployment configuration. The following
environment variables tune caching, rate limiting, and proxy trust for that transport;
they have no effect in the deprecated stdio mode. They are documented for readers of
this source — there is no supported self-hosted deployment, and no container image is
published.
HTTP mode is stateless as of 2.0.0. There is no Mcp-Session-Id header and no
per-client session state on the server: every request is handled independently by a
fresh MCP server instance. GET /mcp no longer opens an SSE stream — it now returns
405 Method Not Allowed (or 401 first if the request is unauthenticated). DELETE /mcp is a no-op that always answers 200, since there is no session left to tear
down. MAX_SESSIONS is no longer read.
| Variable | Default | Description |
|---|---|---|
TRANSPORT_MODE | stdio | Set to http to run the Streamable HTTP transport. The stdio default is deprecated and will be removed in a future release; the hosted server sets http. |
PORT | 3000 | HTTP server port. |
SEQUENTUM_API_URL | https://dashboard.sequentum.com | Base URL of the Sequentum API this server proxies to. |
SEQUENTUM_OAUTH_ISSUER | Value of SEQUENTUM_API_URL | This deployment's OAuth issuer identifier, advertised in /.well-known/oauth-protected-resource. Must be an absolute https URL with no query, fragment or userinfo, and must match the authorization server's issuer exactly. Set it only when the API base URL and the public OAuth issuer differ; a malformed value refuses to start. |
MCP_CANONICAL_ORIGIN | derived from the request Host header | This server's resource identifier, used to check the aud claim of incoming OAuth tokens. Set it to the public origin, e.g. https://mcp.sequentum.com. Only the origin is used — the value is normalised through new URL(...).origin, so a trailing slash or a path is harmless, and an aud naming any path on this origin is accepted. Unset, or set to a value new URL cannot parse, the server warns once at startup and falls back to the caller-supplied Host. An aud on a different origin is logged, not rejected. |
HOST | 0.0.0.0 | HTTP server bind address. |
LIST_CACHE_TTL_MS | 3600000 (1 hour) | Freshness hint (ttlMs) attached to cacheable list-shaped results (tools/list, prompts/list, resources/list, resources/templates/list, server/discover). Must be a non-negative integer string; a malformed value fails fast at startup instead of being silently truncated. |
MCP_RATE_LIMIT_WINDOW_MS | 60000 (1 minute) | Rate-limit window applied to the /mcp endpoint. |
MCP_RATE_LIMIT_MAX | 100 | Maximum /mcp requests per window, per process, per IP. See "Rate limiting across replicas" below before scaling horizontally. |
TRUST_PROXY | true | Passed to Express's trust proxy setting. Accepts true, false, a hop count (e.g. 1), or a comma-separated CIDR/IP allowlist. See "TRUST_PROXY and rate-limit evasion" below — the default has a known weakness. |
REQUIRE_AUTH | true | Set to false to bypass the OAuth Bearer-token requirement on /mcp. For local testing only: the connection succeeds, but tools still fail without a valid backend token. |
The rate limiter is per-process and keyed on req.ip; it holds no state shared across
replicas. With the stateless transport there is no session affinity, so a given
client's requests are not pinned to one replica — in a horizontally scaled deployment
of N replicas behind a load balancer, the effective cluster-wide ceiling becomes N × MCP_RATE_LIMIT_MAX per window, not MCP_RATE_LIMIT_MAX. To hold a specific global
rate, divide MCP_RATE_LIMIT_MAX by your replica count.
With the default TRUST_PROXY=true, Express trusts every proxy hop and resolves
req.ip from the client-supplied, leftmost entry of the X-Forwarded-For header.
Because the rate limiter keys on req.ip, a client that simply rotates that header
value can evade rate limiting entirely. Running behind a reverse proxy does not fix
this by itself: tunnels such as cloudflared and ngrok append to X-Forwarded-For
rather than overwrite it, so the attacker-controlled leftmost entry survives unless
TRUST_PROXY is configured correctly.
The remediation is to set TRUST_PROXY to the exact number of trusted reverse-proxy
hops in front of the server (e.g. 1), or to a comma-separated CIDR/IP allowlist of
your trusted proxies, so Express derives req.ip from the correct hop instead of
trusting a client-supplied header. This repository does not know your deployment
topology, so it deliberately does not choose a safer default for you.
Severity: this is an abuse/DoS-protection bypass, not an authentication or data exposure issue — no account data is exposed, and no tool call succeeds that would otherwise be rejected. It only lets a client avoid being rate-limited.
When the MCP server is accessed from a browser (e.g. the Claude web app or the ChatGPT connector), it checks the Origin header against an allowlist. By default the following origins are permitted:
https://claude.ai, https://claude.com, and all subdomains (e.g. team.claude.ai)https://chatgpt.com, https://platform.openai.com, and all subdomains under chatgpt.com (e.g. connector.chatgpt.com)https://dashboard.sequentum.comhttps://mcp.sequentum.comhttp://localhost:<port>, http://127.0.0.1:<port>, and http://[::1]:<port> when DEBUG=1To add your own origins (e.g. an internal dashboard), set the ALLOWED_ORIGINS environment variable to a comma-separated list of exact origins:
These origins are appended to the defaults — Claude, ChatGPT, and Sequentum access is preserved. Wildcards and regular expressions are not supported via the env var; if you need a subdomain wildcard, add a RegExp entry directly in src/server/cors.ts.
Note:
Originmatching is case-sensitive and does not include a path or query string. Native MCP clients (Cursor, Claude Desktop, Claude Code) send noOriginheader and are not affected by this allowlist.
The Sequentum MCP Server accesses your Sequentum account data — including agent metadata, run history, scheduled tasks, billing information, and output files — solely to fulfill the requests you make through your AI assistant. By default, the MCP server acts as an authenticated proxy between your MCP client and the Sequentum API: request data is forwarded to the API and responses are returned to your client without being persisted or shared with third parties.
Operators may enable verbose request logging via the DEBUG=1 environment variable for troubleshooting. In that mode the server redacts Authorization, Cookie, and x-api-key headers, but writes request bodies (which may include tool arguments) to stderr. The hosted server at mcp.sequentum.com does not run with DEBUG=1.
For the full Sequentum privacy policy, see https://www.sequentum.com/privacy-policy.
MIT © Sequentum