Back to Browse

Sequentum MCP Server

Developer ToolsModerate5.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Turn the web into structured, reliable, actionable enterprise data for AI Agents

About

Turn the web into structured, reliable, actionable enterprise data for AI Agents

Remote endpoints: streamable-http: https://mcp.sequentum.com/mcp

Security Report

5.2
Moderate5.2Moderate Risk

A well-structured MCP server for Sequentum web scraping platform with proper authentication (OAuth and API keys), reasonable permissions scoped to API calls and environment variables, and clean code patterns. Minor code quality observations exist around error handling and input validation, but no security vulnerabilities were identified. Supply chain analysis found 9 known vulnerabilities in dependencies (2 critical, 4 high severity).

3 files analyzed · 14 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Sequentum MCP

License: MIT

The Sequentum MCP Server connects your AI coding assistant to Sequentum using the Model Context Protocol (MCP), giving your AI tools the ability to create web scraping agents, run management, scheduling, analytics, and more. Sequentum hosts and manages a remote MCP server with OAuth authentication, so there's nothing to install.

Tool Reference | Prompts Reference | Resources Reference | Troubleshooting | Changelog

Key Features

  • Agent management: Build, list, search, and get detailed information about your web scraping agents.
  • Run automation: Start, stop, and monitor agent executions with real-time status tracking.
  • Schedule management: Create and manage automated schedules using cron expressions.
  • Analytics & diagnostics: Get run statistics, error analysis, and suggested fixes for failures.
  • Space organization: Manage agent workspaces and run batch operations across spaces.

Disclaimers

sequentum-mcp exposes your Sequentum account data to MCP clients, allowing them to view, run, and manage your web scraping agents. Keep your credentials secure and avoid sharing sensitive information that you don't want accessible to MCP clients.

Getting Started

Add the Sequentum MCP server to your client with this configuration:

{
  "mcpServers": {
    "sequentum": {
      "url": "https://mcp.sequentum.com/mcp"
    }
  }
}

Most clients support the OAuth configuration. Claude.ai and Claude Desktop are simpler still — Sequentum MCP is listed in Claude's connector directory, so there is nothing to enter by hand; see Claude.ai and Claude Desktop below. For other clients, when you first connect, you'll be prompted to:

  1. Log in with your Sequentum account
  2. Accept the OAuth authorization
  3. Grant access to the necessary permissions

Once authenticated, all tools become available in your client. For client-specific setup details, see Set Up Your Client below.

Set Up Your Client

Select your client below for specific setup instructions. All clients use the remote OAuth server at https://mcp.sequentum.com/mcp unless noted otherwise.

Cursor

Go to Cursor > Settings > Cursor Settings > MCP and follow the prompts to add the Sequentum MCP server. Cursor 1.0+ includes native OAuth and Streamable HTTP support.

You can also add the server manually by editing your mcp.json file using the configuration above.

Claude.ai and Claude Desktop

Sequentum MCP is listed in Claude's connector directory, so there is no URL to enter by hand and no custom connector to create.

  1. Open Settings and go to Connectors.
  2. Browse the Directory, select Connectors, and find Sequentum MCP.
  3. Click Connect and sign in with your Sequentum account.

Team and Enterprise workspaces: connector availability is governed at org level, so an admin may need to enable Sequentum MCP before members can connect from their own accounts.

Enabling per conversation: once connected, enable Sequentum in an individual conversation via the + button near the message composer, then select Connectors.

ChatGPT

Note: While the Sequentum app is pending directory approval, you can connect via Developer Mode. Apps & Connectors → Developer Mode is currently available on Plus, Pro, Business, Enterprise, and Education plans (Education is web-only). On Business / Enterprise / Education accounts, only workspace owners and admins can access Advanced settings — regular members will not see the option. See OpenAI's Developer Mode documentation for current eligibility.

  1. In ChatGPT, go to Settings > Apps & Connectors > Advanced settings and enable Developer mode.
  2. Navigate to Settings > Apps & Connectors and click Create app (it appears once Developer mode is enabled).
  3. Enter the connector name Sequentum and URL: https://mcp.sequentum.com/mcp
  4. Click Create. You'll be prompted to sign in with your Sequentum account via OAuth.

Once connected, enable Sequentum in a conversation via the + button near the message composer, then select your connector from the list.

Claude Code

Connect Sequentum MCP once from the connector directory (see Claude.ai and Claude Desktop above) and it is available in Claude Code on the same account.

To add it directly instead — useful per-project or in scripts:

claude mcp add --transport http sequentum https://mcp.sequentum.com/mcp

Then launch Claude Code with claude and type /mcp to trigger the OAuth browser flow.

VS Code / GitHub Copilot

Open the Command Palette with Ctrl+Shift+P (or Cmd+Shift+P on macOS) and select MCP: Add Server. Enter the Sequentum MCP server URL:

https://mcp.sequentum.com/mcp

Windsurf

Configure via the Configure MCP option in Cascade (Cmd+L or Ctrl+L). Add the Sequentum MCP server URL:

https://mcp.sequentum.com/mcp

Other Clients

The Sequentum MCP Server follows standard MCP protocols and works with any client that supports:

  • OAuth authentication (recommended)
  • Streamable HTTP with automatic SSE fallback

Use the server URL https://mcp.sequentum.com/mcp in your client's MCP configuration.

The server supports Client ID Metadata Documents (CIMD) as the preferred client identification method, with Dynamic Client Registration (RFC 7591) as a fallback. MCP clients that support CIMD (such as Cursor) can use their own URL as a client_id without any prior registration.

Deprecated: stdio and API-key auth

Deprecated: Running the MCP server locally over the stdio transport, authenticated with SEQUENTUM_API_KEY, is deprecated and will be removed in a future release. The sequentum-mcp npm package is deprecated along with it. Connect to https://mcp.sequentum.com/mcp over HTTP with OAuth 2.1 instead — see Set Up Your Client.

This does not affect Sequentum API keys themselves, which remain fully supported for the REST API.

The MCP authorization specification directs stdio implementations not to use OAuth, and to take credentials from the environment instead. Moving the server to OAuth 2.1 therefore retires the stdio path along with it — the two deprecations are one decision, not two.

If you are running this configuration today, it keeps working — on Node 20 or later:

{
  "mcpServers": {
    "sequentum": {
      "command": "npx",
      "args": ["-y", "sequentum-mcp"],
      "env": {
        "SEQUENTUM_API_KEY": "sk-your-api-key-here"
      }
    }
  }
}

The API key is created in the Sequentum Control Center under Settings > API Keys, and SEQUENTUM_API_URL overrides the Sequentum instance it connects to (default https://dashboard.sequentum.com).

To migrate, delete that block and follow the setup instructions for your client above. If you need Sequentum MCP somewhere that cannot reach mcp.sequentum.com, contact support — there is no supported self-hosted deployment.

Example Usage

Once connected, try these prompts to start using Sequentum context in your AI assistant:

What agents ran yesterday?
Run agent <agent name> now.
Is agent <agent name> still running?
What agents are scheduled to run today?
Download the extracted data from agent <agent name>.
How many records were found the last time <agent name> was run?
What is my current balance?
Which agents cost the most this month?
Schedule agent <agent name> to run every Monday at 9am.
Look at the run log for <agent name> run at 9:22am. What caused the agent to fail?
Show me the cost breakdown for agent <agent name> in January.
What were the most expensive runs for agent <agent name>?
How much did I spend on server time vs exports last week?

Available Tools

The Sequentum MCP Server provides 39 tools across 9 categories for interacting with the Sequentum platform. See the Tool Reference for detailed documentation.

Available Prompts

The server includes 9 reusable prompt templates that guide the AI through common multi-step workflows. See the Prompts Reference for detailed documentation.

Available Resources

The server exposes 18 read-only resources (7 static + 11 templates) that AI clients can browse and pull into context. See the Resources Reference for detailed documentation.

Troubleshooting

ErrorSolution
OAuth login not openingEnsure your client supports OAuth and Streamable HTTP. Try restarting the client. For Claude.ai and Claude Desktop, connect from the connector directory rather than a config file.
Connection refusedVerify the URL is https://mcp.sequentum.com/mcp and check your network connection.
SEQUENTUM_API_KEY requiredDeprecated local stdio mode only. Add your API key to the env section of the MCP config, or migrate to the hosted server.
API Error 401: UnauthorizedYour API key or OAuth token is invalid or expired. Re-authenticate or generate a new key.
API Error 404: Not FoundThe agent, run, or file doesn't exist, or you don't have access to it.
API Error 429: Too Many RequestsRate limit exceeded. Wait a moment and try again.

For more troubleshooting help, see the Troubleshooting Guide.

HTTP Mode Configuration

The hosted server at mcp.sequentum.com runs the Streamable HTTP transport (TRANSPORT_MODE=http) behind its own deployment configuration. The following environment variables tune caching, rate limiting, and proxy trust for that transport; they have no effect in the deprecated stdio mode. They are documented for readers of this source — there is no supported self-hosted deployment, and no container image is published.

HTTP mode is stateless as of 2.0.0. There is no Mcp-Session-Id header and no per-client session state on the server: every request is handled independently by a fresh MCP server instance. GET /mcp no longer opens an SSE stream — it now returns 405 Method Not Allowed (or 401 first if the request is unauthenticated). DELETE /mcp is a no-op that always answers 200, since there is no session left to tear down. MAX_SESSIONS is no longer read.

VariableDefaultDescription
TRANSPORT_MODEstdioSet to http to run the Streamable HTTP transport. The stdio default is deprecated and will be removed in a future release; the hosted server sets http.
PORT3000HTTP server port.
SEQUENTUM_API_URLhttps://dashboard.sequentum.comBase URL of the Sequentum API this server proxies to.
SEQUENTUM_OAUTH_ISSUERValue of SEQUENTUM_API_URLThis deployment's OAuth issuer identifier, advertised in /.well-known/oauth-protected-resource. Must be an absolute https URL with no query, fragment or userinfo, and must match the authorization server's issuer exactly. Set it only when the API base URL and the public OAuth issuer differ; a malformed value refuses to start.
MCP_CANONICAL_ORIGINderived from the request Host headerThis server's resource identifier, used to check the aud claim of incoming OAuth tokens. Set it to the public origin, e.g. https://mcp.sequentum.com. Only the origin is used — the value is normalised through new URL(...).origin, so a trailing slash or a path is harmless, and an aud naming any path on this origin is accepted. Unset, or set to a value new URL cannot parse, the server warns once at startup and falls back to the caller-supplied Host. An aud on a different origin is logged, not rejected.
HOST0.0.0.0HTTP server bind address.
LIST_CACHE_TTL_MS3600000 (1 hour)Freshness hint (ttlMs) attached to cacheable list-shaped results (tools/list, prompts/list, resources/list, resources/templates/list, server/discover). Must be a non-negative integer string; a malformed value fails fast at startup instead of being silently truncated.
MCP_RATE_LIMIT_WINDOW_MS60000 (1 minute)Rate-limit window applied to the /mcp endpoint.
MCP_RATE_LIMIT_MAX100Maximum /mcp requests per window, per process, per IP. See "Rate limiting across replicas" below before scaling horizontally.
TRUST_PROXYtruePassed to Express's trust proxy setting. Accepts true, false, a hop count (e.g. 1), or a comma-separated CIDR/IP allowlist. See "TRUST_PROXY and rate-limit evasion" below — the default has a known weakness.
REQUIRE_AUTHtrueSet to false to bypass the OAuth Bearer-token requirement on /mcp. For local testing only: the connection succeeds, but tools still fail without a valid backend token.

Rate limiting across replicas

The rate limiter is per-process and keyed on req.ip; it holds no state shared across replicas. With the stateless transport there is no session affinity, so a given client's requests are not pinned to one replica — in a horizontally scaled deployment of N replicas behind a load balancer, the effective cluster-wide ceiling becomes N × MCP_RATE_LIMIT_MAX per window, not MCP_RATE_LIMIT_MAX. To hold a specific global rate, divide MCP_RATE_LIMIT_MAX by your replica count.

TRUST_PROXY and rate-limit evasion

With the default TRUST_PROXY=true, Express trusts every proxy hop and resolves req.ip from the client-supplied, leftmost entry of the X-Forwarded-For header. Because the rate limiter keys on req.ip, a client that simply rotates that header value can evade rate limiting entirely. Running behind a reverse proxy does not fix this by itself: tunnels such as cloudflared and ngrok append to X-Forwarded-For rather than overwrite it, so the attacker-controlled leftmost entry survives unless TRUST_PROXY is configured correctly.

The remediation is to set TRUST_PROXY to the exact number of trusted reverse-proxy hops in front of the server (e.g. 1), or to a comma-separated CIDR/IP allowlist of your trusted proxies, so Express derives req.ip from the correct hop instead of trusting a client-supplied header. This repository does not know your deployment topology, so it deliberately does not choose a safer default for you.

Severity: this is an abuse/DoS-protection bypass, not an authentication or data exposure issue — no account data is exposed, and no tool call succeeds that would otherwise be rejected. It only lets a client avoid being rate-limited.

CORS Origin Allowlist

When the MCP server is accessed from a browser (e.g. the Claude web app or the ChatGPT connector), it checks the Origin header against an allowlist. By default the following origins are permitted:

  • https://claude.ai, https://claude.com, and all subdomains (e.g. team.claude.ai)
  • https://chatgpt.com, https://platform.openai.com, and all subdomains under chatgpt.com (e.g. connector.chatgpt.com)
  • https://dashboard.sequentum.com
  • https://mcp.sequentum.com
  • http://localhost:<port>, http://127.0.0.1:<port>, and http://[::1]:<port> when DEBUG=1

To add your own origins (e.g. an internal dashboard), set the ALLOWED_ORIGINS environment variable to a comma-separated list of exact origins:

ALLOWED_ORIGINS="https://my-dashboard.example.com,https://other.example.com"

These origins are appended to the defaults — Claude, ChatGPT, and Sequentum access is preserved. Wildcards and regular expressions are not supported via the env var; if you need a subdomain wildcard, add a RegExp entry directly in src/server/cors.ts.

Note: Origin matching is case-sensitive and does not include a path or query string. Native MCP clients (Cursor, Claude Desktop, Claude Code) send no Origin header and are not affected by this allowlist.

Privacy Policy

The Sequentum MCP Server accesses your Sequentum account data — including agent metadata, run history, scheduled tasks, billing information, and output files — solely to fulfill the requests you make through your AI assistant. By default, the MCP server acts as an authenticated proxy between your MCP client and the Sequentum API: request data is forwarded to the API and responses are returned to your client without being persisted or shared with third parties.

Operators may enable verbose request logging via the DEBUG=1 environment variable for troubleshooting. In that mode the server redacts Authorization, Cookie, and x-api-key headers, but writes request bodies (which may include tool arguments) to stderr. The hosted server at mcp.sequentum.com does not run with DEBUG=1.

For the full Sequentum privacy policy, see https://www.sequentum.com/privacy-policy.

Links

License

MIT © Sequentum

Reviews

No reviews yet

Be the first to review this server!