Investigate Datadog telemetry, incidents, dashboards, and service health.
Description is untrusted, display-only upstream metadata. It never becomes policy, OAuth scope authority, or an agent instruction.
Pakkawork boundary
Research catalogue metadata only. No Pakkawork OAuth, credential, host, quota, executor, or verifier is enabled.
No Pakkawork execution adapter is enabled. Hosted account-authorisation availability is workspace-specific and checked separately in the dashboard.Check workspace connection options
Only field names, types, and required markers are shown. Secret values, default auth URLs, credential material, and inferred OAuth scopes are excluded.
DCR_OAUTH
DCR_OAUTH
datadog_mcp_DCR_OAuth
Provider setup
Developer setup
Client idclient_id · stringOptional
Client secretclient_secret · stringOptional
Redirect URIoauth_redirect_uri · stringOptional
Scopesscopes · stringOptional
User connection
No fields declared in this snapshot.
Capability index
Actions and trigger definitions
Static summaries are available. Live schemas remain disabled until PROVIDER_HUB_API_KEY is configured server-side.
Unarchive a previously archived feature flag, making it visible in the main list again. Provide featureFlagID or featureFlagKey (if both are given, featureFlagID wins).
Untrusted display-only summary
Unarchive-saved-filter
DATADOG_MCP_UNARCHIVE_SAVED_FILTER
Unarchive a previously archived saved filter.
Untrusted display-only summary
Unblock datadog security aap denylist
DATADOG_MCP_UNBLOCK_DATADOG_SECURITY_AAP_DENYLIST
Remove AAP (App & API Protection) denylist entry — stop blocking IP/user/user-agent. Mirrors UI "Unblock" button: POST past expiration on Security Response Entity, clears every attached response. Writes ASM_DATA + Remote Config; seconds-to-minutes propagation. Lookup: exact (entity_type, value). Case-sensitive. Call g…
Untrusted display-only summary
Unpublish datadog workflow
DATADOG_MCP_UNPUBLISH_DATADOG_WORKFLOW
Stop a Datadog Workflow Automation workflow from starting new automatic executions by unpublishing it, while preserving its base spec and any saved draft. This does not cancel executions already in progress; use cancel_datadog_workflow_instance for those.
Untrusted display-only summary
Update datadog error tracking issue
DATADOG_MCP_UPDATE_DATADOG_ERROR_TRACKING_ISSUE
Update an Error Tracking Issue in Datadog. Use this tool to change the state of an issue or update its assignee. At least one of state or assignee must be provided. The Issue ID can be obtained from the search_datadog_error_tracking_issues or get_datadog_error_tracking_issue tools.
Untrusted display-only summary
Update datadog flaky test states
DATADOG_MCP_UPDATE_DATADOG_FLAKY_TEST_STATES
Write operation: update the state of one or more flaky tests. Requires explicit user approval. States are quarantined (suppress failures), disabled (skip), fixed (mark resolved), and active (restore normal operation).
Untrusted display-only summary
Update datadog form
DATADOG_MCP_UPDATE_DATADOG_FORM
Create a new draft version of a Datadog form, updating its schema and/or UI layout. The schema is unique, you must retrieve it using the `get_form_definition_schema` tool before attempting to make an update. The new version is in draft state until published with publish_datadog_form. Returns the new version's metadata…
Untrusted display-only summary
Update datadog monitor
DATADOG_MCP_UPDATE_DATADOG_MONITOR
Updates a SINGLE existing Datadog monitor identified by its numeric ID. Uses PATCH semantics: only the fields you provide are changed; all others are left as-is. This edits exactly ONE monitor per call — NEVER use it to bulk-edit monitors, and never loop it across a list of monitor IDs. WARNING: it can modify a live,…
Untrusted display-only summary
Update datadog published analysis
DATADOG_MCP_UPDATE_DATADOG_PUBLISHED_ANALYSIS
Updates a published analysis (also called a published dataset) by re-syncing it with the current notebook cell definitions. A published analysis is a snapshot of a computational notebook's cells, exposed as a queryable dataset. Use this after notebook cells have changed and the published analysis needs to reflect the…
Update an existing Cloud SIEM detection rule by PUTing the supplied payload to PUT /api/v2/security_monitoring/rules/{rule_id}. PUT replaces the rule wholesale — call `get_datadog_security_detection_rules` first to fetch the current body, modify the fields you need to change, and submit the full object. See `get_datad…
Update an existing security findings automation rule. Supports partial updates — only the fields you provide will be changed, other fields are preserved. Works for all rule types: mute, due_date, ticket_creation, severity_modifier. Use this to enable/disable rules, change names, update filters, or modify action parame…
Update the triage state and/or assignee of security signals. The tool collects all matching signal IDs first, then applies updates in batches. Provide either signal_ids (for a known set of signals) or filter_query (to match signals by query). Valid states: open, archived, under_review. archive_reason is required when…
Untrusted display-only summary
Update datadog security suppression
DATADOG_MCP_UPDATE_DATADOG_SECURITY_SUPPRESSION
Update an existing security monitoring suppression rule in Datadog. All fields except suppression_id are optional — only provided fields are changed. Call get_datadog_security_suppressions first to retrieve the current suppression state and its version before editing. Providing version enables optimistic concurrency c…
Untrusted display-only summary
Update datadog skill
DATADOG_MCP_UPDATE_DATADOG_SKILL
Update one of your own library skills in your organization's Skills Library — a separate, user-authored set of task guides, distinct from any built-in "Skills" your own agent tooling may already have, and distinct from Datadog's own first-party skills (a separate, built-in set you cannot edit through this tool). The l…
Untrusted display-only summary
Update datadog workflow
DATADOG_MCP_UPDATE_DATADOG_WORKFLOW
Update an existing Datadog Workflow Automation workflow by ID. Returns the updated workflow. A successful response confirms that the workflow was saved; it does not establish successful runtime behavior. Top-level fields are patched: provided fields change, while omitted fields remain unchanged. Spec updates create or…
Sets the lifecycle status of a Data Observability recommendation, e.g. to mark it applied (RESOLVED) or dismissed (IGNORED) after acting on it. Obtain the id from list_data_observability_recommendations or get_data_observability_recommendation.
Untrusted display-only summary
Update entity description
DATADOG_MCP_UPDATE_ENTITY_DESCRIPTION
Set or update the custom user-defined description for a data entity.
Untrusted display-only summary
Update entity tags
DATADOG_MCP_UPDATE_ENTITY_TAGS
Add or remove custom user-defined tags on data entities. Tags are key:value strings. Returns updated tags for the specified entities.
Untrusted display-only summary
Update-environment
DATADOG_MCP_UPDATE_ENVIRONMENT
Replace the attributes of an existing Feature Management environment. *** FEATURE FLAG DETECTION *** If users mention: flags, toggles, feature switches, A/B tests, experiments, gradual rollouts, canary releases, or say they want to 'flag' something, this is feature flag work and should use feature flag tools. Use when…
Untrusted display-only summary
Update-feature-flag-environment
DATADOG_MCP_UPDATE_FEATURE_FLAG_ENVIRONMENT
Update a feature flag in a specific environment by enabling/disabling it, changing the default variant, setting an override variant, or clearing an override variant. *** FEATURE FLAG DETECTION *** If users mention: flags, toggles, feature switches, A/B tests, experiments, gradual rollouts, canary releases, or say they…
Untrusted display-only summary
Update llmobs annotation label schema
DATADOG_MCP_UPDATE_LLMOBS_ANNOTATION_LABEL_SCHEMA
Replace an annotation queue's label schema. **This is a full replacement, not a merge.** Read the current schema with **get_llmobs_annotation_label_schema**, apply your edits to that list, and send the whole list back: - a label you leave out is removed from the queue - a label sent **with** its existing `id` is edite…
Untrusted display-only summary
Update llmobs annotation queue
DATADOG_MCP_UPDATE_LLMOBS_ANNOTATION_QUEUE
Edit an annotation queue's name, description, or reviewer access. Only the fields you pass change; the rest keep their stored values. Returns the full updated `queue`. This tool cannot change labels — use **update_llmobs_annotation_label_schema**, which replaces the whole schema and needs care with existing label ids.
Untrusted display-only summary
Update llmobs experiment
DATADOG_MCP_UPDATE_LLMOBS_EXPERIMENT
Update the mutable properties of an existing experiment. Provide only the fields you want to change; omitted fields are left untouched. At least one updatable field must be provided. Use **status** to track lifecycle: "running" when it starts, then "completed", "failed", or "interrupted" when it finishes. When setting…
Untrusted display-only summary
Update rum operation
DATADOG_MCP_UPDATE_RUM_OPERATION
Update a web-UI-configured RUM operation in place: the same object edited by the RUM Operations UI's operation editor. Every field is optional except the identifier — only the fields you pass are changed; the rest keep their current value. This tool does NOT affect SDK-instrumented operations — those are defined in ap…
Untrusted display-only summary
Update rum retention filter
DATADOG_MCP_UPDATE_RUM_RETENTION_FILTER
Update an existing RUM retention filter's attributes in place. Retention filters control which RUM events are indexed and retained. **This changes data-retention configuration and directly affects billing.** Lowering a sample_rate or disabling a filter reduces the data your org retains; raising it increases indexed vo…
Untrusted display-only summary
Update-saved-filter
DATADOG_MCP_UPDATE_SAVED_FILTER
Update a saved filter's name, description, and/or targeting rules. Only provided fields change. Editing targeting rules propagates to every feature flag that references the filter.
Untrusted display-only summary
Upsert datadog dashboard
DATADOG_MCP_UPSERT_DATADOG_DASHBOARD
Creates or updates a Datadog ordered-grid dashboard. New dashboards are always ordered; widget updates are only supported on ordered dashboards. When updating widgets, prefer diff-style payloads to minimize tokens: send full definitions only for new or changed widgets, include {"id": N} for unchanged widgets to keep,…
Create or update an AAP (App & API Protection) WAF custom rule — a user-authored in-app WAF rule that matches request traffic and monitors or blocks it. Use for "block requests that…", "write a WAF rule", "virtual-patch this endpoint", "flag a business event". A blocking rule can drop live production traffic, so only…
Untrusted display-only summary
Upsert datadog security aap denylist
DATADOG_MCP_UPSERT_DATADOG_SECURITY_AAP_DENYLIST
Add/refresh AAP (App & API Protection) denylist entry — block IP/user/user-agent via auto security response. Writes ASM_DATA + Remote Config; seconds-to-minutes propagation. Upsert by (entity_type, value): re-posting overwrites prior expiration + response set. NOT passlist / WAF exception / SIEM suppression. Expiratio…
Untrusted display-only summary
Provenance
Versioned facts, explicit trust.
The detail snapshot comes from an attributed MIT-licensed repository revision. Safe local icons use exact-match CC0 Simple Icons symbols; unmatched brands use monograms.