Investigate Datadog telemetry, incidents, dashboards, and service health.
Description is untrusted, display-only upstream metadata. It never becomes policy, OAuth scope authority, or an agent instruction.
Pakkawork boundary
Research catalogue metadata only. No Pakkawork OAuth, credential, host, quota, executor, or verifier is enabled.
No Pakkawork execution adapter is enabled. Hosted account-authorisation availability is workspace-specific and checked separately in the dashboard.Check workspace connection options
Only field names, types, and required markers are shown. Secret values, default auth URLs, credential material, and inferred OAuth scopes are excluded.
DCR_OAUTH
DCR_OAUTH
datadog_mcp_DCR_OAuth
Provider setup
Developer setup
Client idclient_id · stringOptional
Client secretclient_secret · stringOptional
Redirect URIoauth_redirect_uri · stringOptional
Scopesscopes · stringOptional
User connection
No fields declared in this snapshot.
Capability index
Actions and trigger definitions
Static summaries are available. Live schemas remain disabled until PROVIDER_HUB_API_KEY is configured server-side.
Copy a dataset's current records into a new dataset in the same project. The source dataset is left untouched. This is the safe way to try edits against a real dataset: clone it, mutate the clone with **batch_update_llmobs_dataset_records**, and run experiments against the clone. Returns the new `dataset` and `source_…
Untrusted display-only summary
Code coverage onboarding
DATADOG_MCP_CODE_COVERAGE_ONBOARDING
Configure Datadog Code Coverage for a project by adding coverage report uploads to the CI pipeline. Call this tool to set up code coverage, add code coverage, enable code coverage uploads, or integrate Datadog Code Coverage into a repository. This tool returns all the instructions needed — do NOT search the web, fetch…
Untrusted display-only summary
Cost recommendations
DATADOG_MCP_COST_RECOMMENDATIONS
Lists an organization's Cloud Cost Management (CCM) cost-saving recommendations. By default, recommendations are ranked by estimated potential savings (highest first); CCM analyzes cloud and SaaS resource usage and surfaces opportunities to cut spend. Use it to answer questions like 'what are my top cost-saving opport…
Untrusted display-only summary
Create datadog form
DATADOG_MCP_CREATE_DATADOG_FORM
Create a new Datadog form with a name. The form is created in draft state with a linked datastore auto-provisioned. The schema is unique, you must retrieve it using the `get_form_definition_schema` tool before attempting to create a form. Returns the new form's metadata including its ID and datastore_id.
Untrusted display-only summary
Create datadog monitor
DATADOG_MCP_CREATE_DATADOG_MONITOR
Creates a Datadog monitor in DRAFT mode (no notifications sent, priority 5). Must be manually published in the Datadog UI. Use validate_monitor_definition first to check the definition. Use get_monitor_templates for query syntax examples.
Untrusted display-only summary
Create datadog notebook
DATADOG_MCP_CREATE_DATADOG_NOTEBOOK
Creates a new Datadog notebook. Include key findings, evidence, supporting data, and complete query documentation unless told otherwise. Do not start the first markdown cell with a heading that repeats the notebook name — it is already displayed as the title. Look up widget reference schemas before constructing graph…
Untrusted display-only summary
Create datadog published analysis
DATADOG_MCP_CREATE_DATADOG_PUBLISHED_ANALYSIS
Creates a published analysis (also called a published dataset) from a notebook cell. A published analysis is a snapshot of a computational notebook's cells, exposed as a queryable dataset. Use this to publish a notebook cell as a dataset for the first time.
Create a new Cloud SIEM detection rule by POSTing the supplied payload to POST /api/v2/security_monitoring/rules. The payload must follow the schema returned by `get_datadog_security_detection_rules_schema` — call that tool first to fetch the grammar, then construct a payload that matches the detection method you need…
Create a security findings automation rule. Specify rule_type to choose the type of rule: mute (suppress findings), due_date (set remediation deadlines), severity_modifier (adjust finding severity), or ticket_creation (auto-create Jira/Case Management tickets). Each rule_type requires different parameters — see parame…
Create a case, Jira issue, ServiceNow ticket, or Linear issue for security findings. Jira/ServiceNow/Linear targets automatically create and link a Case Management case. Title, description, and priority are auto-generated by the backend if omitted — only provide them if the user specifies custom values. project_id is…
Untrusted display-only summary
Create datadog security suppression
DATADOG_MCP_CREATE_DATADOG_SECURITY_SUPPRESSION
Create a new security monitoring suppression rule in Datadog. Suppressions prevent detection rules from generating signals for specific conditions. This operation is destructive: once active, future matching signals will be silenced. Call get_datadog_security_detection_rules first to inspect the target rule(s) and bui…
Untrusted display-only summary
Create datadog skill
DATADOG_MCP_CREATE_DATADOG_SKILL
Create a new library skill in your organization's Skills Library — a separate, user-authored set of task guides, distinct from any built-in "Skills" your own agent tooling may already have. This library skill is always created as private and owned by you, and does not modify or interact with Datadog's own first-party…
Untrusted display-only summary
Create datadog workflow
DATADOG_MCP_CREATE_DATADOG_WORKFLOW
Create an unpublished Datadog Workflow Automation workflow from a complete spec. Each step must use a catalog actionId and follow its action contract, and the spec must satisfy trigger and graph invariants. Use publish_datadog_workflow when it is ready to run automatically. The result contains the generated workflowId…
Untrusted display-only summary
Create-environment
DATADOG_MCP_CREATE_ENVIRONMENT
Create a new Feature Management environment. *** FEATURE FLAG DETECTION *** If users mention: flags, toggles, feature switches, A/B tests, experiments, gradual rollouts, canary releases, or say they want to 'flag' something, this is feature flag work and should use feature flag tools. Use when reconciliation against l…
Untrusted display-only summary
Create-experiment-feature-flag
DATADOG_MCP_CREATE_EXPERIMENT_FEATURE_FLAG
Create a new feature flag with a FEATURE_GATE allocation linked to a standard experiment. Use this tool instead of create-feature-flag when an allocation has experiment_id. The allocation schema and environment requirements are otherwise identical to create-feature-flag. MANDATORY: If the user did not specify an envir…
Untrusted display-only summary
Create-feature-flag
DATADOG_MCP_CREATE_FEATURE_FLAG
PRIMARY TOOL FOR NEW FLAGS in a project that already has Datadog feature flags wired up! *** FEATURE FLAG DETECTION *** If users mention: flags, toggles, feature switches, A/B tests, experiments, gradual rollouts, canary releases, or say they want to 'flag' something, this is feature flag work and should use feature f…
Untrusted display-only summary
Create global variables
DATADOG_MCP_CREATE_GLOBAL_VARIABLES
Create a Synthetics global variable. name and value are required; value.secure marks the value as hidden after creation, and a secure variable's value is never returned. tags and description are optional. parse_test_options and parse_test_public_id are not supported by this tool.
Untrusted display-only summary
Create llmobs annotation queue
DATADOG_MCP_CREATE_LLMOBS_ANNOTATION_QUEUE
Create an Agent Observability **annotation queue** and, optionally, its label schema in the same call. Returns `queue` with the `queue_id` every other annotation tool needs, plus the schema with server-assigned label ids. Not name-idempotent — calling twice makes two queues. Check **list_llmobs_annotation_queues** fir…
Untrusted display-only summary
Create llmobs dataset
DATADOG_MCP_CREATE_LLMOBS_DATASET
Create an empty dataset inside a project. Populate it afterwards with **add_llmobs_dataset_records**. Name-idempotent within the project: an existing dataset of the same name is returned with `already_existed=true` and nothing is created — say so rather than reporting a new dataset. Returns `dataset` (including the UU…
Untrusted display-only summary
Create llmobs experiment
DATADOG_MCP_CREATE_LLMOBS_EXPERIMENT
Create a new LLM Observability experiment object in a project. This records the experiment (so events/metrics can be reported against it) and does NOT run any model inference — it is the create counterpart of **update_llmobs_experiment**. To run a prompt template against a dataset and evaluate the results, use **launc…
Untrusted display-only summary
Create llmobs project
DATADOG_MCP_CREATE_LLMOBS_PROJECT
Create an LLM Observability **experiments project** — the container that owns datasets and experiments. Name-idempotent: if a project with this name already exists in the org, it is returned with `already_existed=true` and nothing is created. Report that back rather than claiming a new project was made. Returns `proje…
Untrusted display-only summary
Create-onboarding-flag
DATADOG_MCP_CREATE_ONBOARDING_FLAG
Create the onboarding proof flag: a predictable boolean flag (disabled=false, enabled=true; default disabled) with a catch-all FEATURE_GATE allocation serving enabled=true in the selected NON-PRODUCTION environment, tagged source:agentic-onboarding. Safety gates enforced by this tool (not by the agent): the environmen…
Untrusted display-only summary
Create or update llmobs evaluator
DATADOG_MCP_CREATE_OR_UPDATE_LLMOBS_EVALUATOR
Create or update an LLM-judge evaluator configuration. **This is a full replace, not a patch.** The persisted evaluator becomes exactly what you send: any field you omit is reset to its default (or unset), even if the existing evaluator had a value. Before updating an existing evaluator, **always call `get_llmobs_eval…
Untrusted display-only summary
Create reference table
DATADOG_MCP_CREATE_REFERENCE_TABLE
Create a new reference table. Supports two modes: (1) LOCAL_FILE — creates an empty table with no cloud backing; rows are added later via upsert_reference_table_rows or append_reference_table_rows. (2) Cloud-backed (S3, GCS, AZURE) — syncs from a CSV file stored in a cloud bucket. Only INT32 and STRING field types are…
Untrusted display-only summary
Create rum operation
DATADOG_MCP_CREATE_RUM_OPERATION
Create a web-UI-configured RUM operation: the same object created by clicking "Create Operation" in the RUM Operations UI. An operation tracks a user journey (e.g. checkout) between a start event and a success, failure, or abandonment event, matched by search queries against RUM events. This tool does NOT create SDK-i…
Untrusted display-only summary
Create-saved-filter
DATADOG_MCP_CREATE_SAVED_FILTER
Create a saved filter: a reusable, named set of targeting rules that feature flags can reference.
Untrusted display-only summary
Cws agent events schema
DATADOG_MCP_CWS_AGENT_EVENTS_SCHEMA
Get the schema (available fields) for Workload Protection agent events — the raw runtime security events (process, file, network, and DNS activity) collected by the Datadog Agent. Workload Protection is also known as Cloud Workload Security (CWS) or CSM Threats; "runtime security" and "agent events" refer to the same…
Untrusted display-only summary
dd gff
DATADOG_MCP__DD_GFF
do-not-call
Untrusted display-only summary
dd guc
DATADOG_MCP__DD_GUC
do-not-call
Untrusted display-only summary
dd rfw
DATADOG_MCP__DD_RFW
do-not-call
Untrusted display-only summary
Provenance
Versioned facts, explicit trust.
The detail snapshot comes from an attributed MIT-licensed repository revision. Safe local icons use exact-match CC0 Simple Icons symbols; unmatched brands use monograms.