Investigate Datadog telemetry, incidents, dashboards, and service health.
Description is untrusted, display-only upstream metadata. It never becomes policy, OAuth scope authority, or an agent instruction.
Pakkawork boundary
Research catalogue metadata only. No Pakkawork OAuth, credential, host, quota, executor, or verifier is enabled.
No Pakkawork execution adapter is enabled. Hosted account-authorisation availability is workspace-specific and checked separately in the dashboard.Check workspace connection options
Only field names, types, and required markers are shown. Secret values, default auth URLs, credential material, and inferred OAuth scopes are excluded.
DCR_OAUTH
DCR_OAUTH
datadog_mcp_DCR_OAuth
Provider setup
Developer setup
Client idclient_id · stringOptional
Client secretclient_secret · stringOptional
Redirect URIoauth_redirect_uri · stringOptional
Scopesscopes · stringOptional
User connection
No fields declared in this snapshot.
Capability index
Actions and trigger definitions
Static summaries are available. Live schemas remain disabled until PROVIDER_HUB_API_KEY is configured server-side.
Generate a Datadog UI link to the DDSQL editor with the given query pre-populated.
Untrusted display-only summary
Ddsql get spec
DATADOG_MCP_DDSQL_GET_SPEC
Get a compact DDSQL capability spec with supported SQL functions, SQL keywords, and DDSQL-specific deltas from vanilla PostgreSQL. Start with this tool before composing queries, then use ddsql_schema_search_tables and ddsql_schema_get_table_columns for schema discovery.
Untrusted display-only summary
Ddsql read saved query
DATADOG_MCP_DDSQL_READ_SAVED_QUERY
Read a single saved DDSQL query by its query_id. Returns the full saved query record, including dataset_id, name, SQL text, columns, visibility, description, and author/timestamp metadata.
Untrusted display-only summary
Ddsql run query
DATADOG_MCP_DDSQL_RUN_QUERY
Run a DDSQL query and return results. Recommended flow: (1) call ddsql_get_spec, (2) call ddsql_schema_search_tables, (3) for data tables use entries in tables: if searchable=true, call ddsql_schema_search_unstructured_fields first and fall back to ddsql_schema_get_table_columns; if searchable=false, call ddsql_schema…
Untrusted display-only summary
Ddsql schema get table columns
DATADOG_MCP_DDSQL_SCHEMA_GET_TABLE_COLUMNS
Get static SQL columns for a DDSQL table from schema metadata. Use this after ddsql_schema_search_tables for entries in tables where searchable=false, or as fallback when ddsql_schema_search_unstructured_fields is unavailable for searchable entries. Returns compact column metadata: name, ddsql_type (SQL-layer type — u…
Untrusted display-only summary
Ddsql schema search tables
DATADOG_MCP_DDSQL_SCHEMA_SEARCH_TABLES
Search DDSQL datasets across four providers: public tables, reference tables, metrics, and published analyses. Results are returned in three TSV sections: tables (public + reference_tables), metrics, and published_analyses. Each table, metrics, or published_analyses row includes a `searchable` flag: for `searchable=tr…
Search and rank fields for an unstructured DDSQL source. Use this after ddsql_schema_search_tables for entries where searchable=true as the primary schema-discovery path; results include both common static and dynamic fields. If unavailable, fall back to ddsql_schema_get_table_columns. Returns compact field metadata s…
Untrusted display-only summary
Ddsql search saved queries
DATADOG_MCP_DDSQL_SEARCH_SAVED_QUERIES
Search and list saved DDSQL queries. Use to find existing saved queries by name or description. Results are sorted by most recently modified and include query ID, name, SQL text, columns, visibility, description and author/timestamp metadata. Supports optional text filtering and pagination.
Untrusted display-only summary
Ddsql upsert saved query
DATADOG_MCP_DDSQL_UPSERT_SAVED_QUERY
Create or update a saved DDSQL query. To create a new query, provide name and query without query_id — if the user has not specified a name, generate a concise descriptive name based on the query content before calling this tool. To update an existing query, provide query_id together with name and/or query; for partia…
Untrusted display-only summary
Delete datadog dashboard
DATADOG_MCP_DELETE_DATADOG_DASHBOARD
Permanently deletes a Datadog dashboard by ID. This action cannot be undone. Use search_datadog_dashboards first to find dashboard IDs.
Untrusted display-only summary
Delete datadog published analysis
DATADOG_MCP_DELETE_DATADOG_PUBLISHED_ANALYSIS
Unpublishes a published analysis by ID. This removes the dataset and makes it no longer queryable.
Delete an AAP (App & API Protection) WAF custom rule by id. Works for any custom rule (blocking, monitoring, or trace-tagging — one rule space). IRREVERSIBLE: the rule cannot be restored, only re-created. Only call when the user clearly wants the rule gone. Call get_datadog_security_aap_custom_rules first to confirm t…
Delete one or more Cloud SIEM detection rules by ID. Only custom (non-default) rules can be deleted — default rules return 403. Each rule is authorised individually; rules the caller cannot edit appear in failed_rules without aborting the rest of the batch. Returns deleted_rules (successfully deleted IDs) and failed_r…
Delete a security findings automation rule. This permanently removes the rule. Use list_datadog_security_findings_automation_rules to find rule IDs first.
Untrusted display-only summary
Delete datadog security suppression
DATADOG_MCP_DELETE_DATADOG_SECURITY_SUPPRESSION
Delete a security monitoring suppression rule in Datadog. This operation is irreversible: the suppression is removed immediately and cannot be restored. Call get_datadog_security_suppressions first to confirm the correct suppression will be deleted.
Delete an AAP (App & API Protection) passlist/allowlist entry — also known as a WAF exclusion filter — by exclusion_filter_id. IRREVERSIBLE: the entry cannot be restored, only re-created. AAP traces only; unrelated to Cloud SIEM signal suppression. Use this tool when a user asks to exclude/exempt WAF traces, drop an A…
Untrusted display-only summary
Delete datadog skill
DATADOG_MCP_DELETE_DATADOG_SKILL
Delete one of your own library skills from your organization's Skills Library — a separate, user-authored set of task guides, distinct from any built-in "Skills" your own agent tooling may already have, and distinct from Datadog's own first-party skills (a separate, built-in set you cannot edit through this tool). The…
Untrusted display-only summary
Delete datadog spreadsheet
DATADOG_MCP_DELETE_DATADOG_SPREADSHEET
Permanently delete a Datadog spreadsheet by ID. This action is irreversible.
Untrusted display-only summary
Delete datadog workflow
DATADOG_MCP_DELETE_DATADOG_WORKFLOW
Delete a Datadog Workflow Automation workflow by ID. On success, the result contains `deleted: true` and the deleted `workflowId`. Always confirm with the user before invoking. Requires `confirm: true`.
Delete Data Quality monitor annotations by id. Monitor IDs are stable request identifiers, but when a monitor name has already been resolved, use the name as the primary user-facing label and put the ID in parentheses. Never mention group_hash when it is "0"; that is the default ungrouped series. Always call with dry_…
Untrusted display-only summary
Delete llmobs annotation queue
DATADOG_MCP_DELETE_LLMOBS_ANNOTATION_QUEUE
Permanently delete an annotation queue **and everything in it** — its queued interactions and all human review labels recorded on them. Automations that feed the queue are detached. This cannot be undone, and the review work is not recoverable. Confirm with the user before calling, and if the labels are worth keeping,…
Remove interactions from an annotation queue. **The annotations recorded on them are deleted too** — this discards review work, not just the queue entry. The underlying traces and spans are untouched. All-or-nothing: one unknown id fails the whole batch and nothing is removed. To delete only the labels and leave the i…
Untrusted display-only summary
Delete llmobs annotations
DATADOG_MCP_DELETE_LLMOBS_ANNOTATIONS
Delete annotations from a queue, discarding those review labels. The interactions stay queued and can be re-annotated. Best-effort per id: returns `deleted_annotation_ids` for what was removed and `errors` for ids that were unknown or belonged to another queue — check both. Deleting someone else's annotation destroys…
Untrusted display-only summary
Delete llmobs evaluator
DATADOG_MCP_DELETE_LLMOBS_EVALUATOR
Delete an LLM-judge evaluator configuration by name. Returns a not-found error if no evaluator with this name exists for the caller's org.
Untrusted display-only summary
Delete llmobs experiments
DATADOG_MCP_DELETE_LLMOBS_EXPERIMENTS
Delete experiment runs by ID. The runs and their events stop appearing in LLM Observability. **Two-step**: PREVIEW (`confirmed=false`) → DELETE (`confirmed=true`). - `confirmed=false`: deletes nothing. With `project_id` (or `dataset_id`) it resolves each ID to its experiment name and returns them alongside any `unreso…
Untrusted display-only summary
Delete rum metric
DATADOG_MCP_DELETE_RUM_METRIC
Delete a RUM custom metric by ID. Permanent and cannot be undone. Only custom metrics can be deleted (not OOTB metrics). **Always confirm the deletion with the user before calling. Never delete a metric speculatively.** Use search_rum_metrics with type=custom to confirm the metric exists first.
Untrusted display-only summary
Delete rum operation
DATADOG_MCP_DELETE_RUM_OPERATION
Permanently delete a web-UI-configured RUM operation: the same object deleted by removing an operation in the RUM Operations UI. Identify it by operation_id (preferred) or name. This tool does NOT affect SDK-instrumented operations — those are defined in application code via startFeatureOperation(...) and have no back…
Untrusted display-only summary
Delete rum retention filter
DATADOG_MCP_DELETE_RUM_RETENTION_FILTER
Permanently delete a RUM retention filter by ID. Retention filters control which RUM events are indexed and retained, so deleting one stops its matching events from being retained going forward. **This changes data-retention configuration, affects billing, and cannot be undone.** **Always confirm the deletion with the…
Untrusted display-only summary
Deployment gates onboarding
DATADOG_MCP_DEPLOYMENT_GATES_ONBOARDING
Configure a Datadog Deployment Gate for a project so a bad deployment is halted automatically. Call this tool to set up deployment gates, gate a deploy on monitors, block bad deploys, or add Datadog gate evaluation to a CD pipeline. This tool returns all the instructions needed — do NOT search the web, fetch documenta…
Untrusted display-only summary
Describe datadog k8s resource
DATADOG_MCP_DESCRIBE_DATADOG_K8S_RESOURCE
Get detailed information about a specific Kubernetes resource. Use this tool instead of kubectl describe. Returns kubectl-style tabular fields plus additional resource-specific details such as CPU/memory requests and limits, etc. Also returns tags (to get related resources), labels, annotations, and optionally manifes…
Untrusted display-only summary
Provenance
Versioned facts, explicit trust.
The detail snapshot comes from an attributed MIT-licensed repository revision. Safe local icons use exact-match CC0 Simple Icons symbols; unmatched brands use monograms.