Investigate Datadog telemetry, incidents, dashboards, and service health.
Description is untrusted, display-only upstream metadata. It never becomes policy, OAuth scope authority, or an agent instruction.
Pakkawork boundary
Research catalogue metadata only. No Pakkawork OAuth, credential, host, quota, executor, or verifier is enabled.
No Pakkawork execution adapter is enabled. Hosted account-authorisation availability is workspace-specific and checked separately in the dashboard.Check workspace connection options
Only field names, types, and required markers are shown. Secret values, default auth URLs, credential material, and inferred OAuth scopes are excluded.
DCR_OAUTH
DCR_OAUTH
datadog_mcp_DCR_OAuth
Provider setup
Developer setup
Client idclient_id · stringOptional
Client secretclient_secret · stringOptional
Redirect URIoauth_redirect_uri · stringOptional
Scopesscopes · stringOptional
User connection
No fields declared in this snapshot.
Capability index
Actions and trigger definitions
Static summaries are available. Live schemas remain disabled until PROVIDER_HUB_API_KEY is configured server-side.
Retrieve explain plans for a query or plan signature within a timeframe. Returns simplified plan structures optimized for analysis, including operator trees, index usage, estimated costs, and temporal metadata (first seen, last seen, occurrence count). Plans are sorted by estimated cost in descending order. When you a…
Untrusted display-only summary
Get datadog database health signals
DATADOG_MCP_GET_DATADOG_DATABASE_HEALTH_SIGNALS
Run database health checks to identify potential issues. Returns evidence-based signals about database health including CPU saturation, restarts, query latency, blocking, and more. Compares a regression timeframe (showing the issue) against a baseline period.
Analyze a specific SQL query's performance — use when investigating slow queries, high database load, or resource-intensive queries. Returns throughput, average latency, execution time, rows per execution, cache hit ratio, I/O stats, connection activity, wait events, and transaction duration. Each metric includes over…
Untrusted display-only summary
Get datadog database query statement
DATADOG_MCP_GET_DATADOG_DATABASE_QUERY_STATEMENT
Retrieve the SQL statement text for a given query signature. The query signature is a stable hash fingerprint of the normalized SQL; use this tool to map signatures back to concrete SQL for investigation and reporting.
Untrusted display-only summary
Get datadog database recommendations
DATADOG_MCP_GET_DATADOG_DATABASE_RECOMMENDATIONS
Retrieve live database recommendations for a database, query, table, host, or index. Returns the matching recommendations, current status, severity, raw recommendation context, and a normalized scope block that highlights affected database instances, query signatures, tables, indexes, services, plans, and infrastructu…
Untrusted display-only summary
Get datadog database schemas
DATADOG_MCP_GET_DATADOG_DATABASE_SCHEMAS
Fetch schema definitions (columns, indexes, foreign keys, partitions) for one or more database objects. Accepts a list of database objects with varying levels of specificity — from just a table name to a fully qualified table+schema+database+instance. Indexes, foreign keys, and partitions are not part of the table sig…
Untrusted display-only summary
Get datadog error tracking issue
DATADOG_MCP_GET_DATADOG_ERROR_TRACKING_ISSUE
Get detailed information about a specific Error Tracking Issue from Datadog. Use this tool to retrieve full details for a single Issue by its ID. The Issue ID can be obtained from the search_datadog_error_tracking_issues tool or from Logs, Traces or RUM Errors (issue.id attribute).
Untrusted display-only summary
Get datadog flaky tests
DATADOG_MCP_GET_DATADOG_FLAKY_TESTS
Search flaky tests from Datadog Test Optimization. Results include failure-rate stats, flaky state and category, ownership context, branch and SHA history, test-run metadata, and CI-pipeline impact. Use page cursors from meta.pagination.next_page to continue a search.
Return Flaky Tests Management policies for a repository, including quarantine, disable, and attempt-to-fix settings.
Untrusted display-only summary
Get datadog form
DATADOG_MCP_GET_DATADOG_FORM
Get a specific Datadog form by its ID, including full metadata and datastore configuration.
Untrusted display-only summary
Get datadog incident
DATADOG_MCP_GET_DATADOG_INCIDENT
Get detailed information about a specific Datadog incident by ID, including status, severity, timeline, associated users, and attachments.
Untrusted display-only summary
Get datadog k8s manifest
DATADOG_MCP_GET_DATADOG_K8S_MANIFEST
Get the YAML manifest for a specific Kubernetes resource. Use this tool instead of kubectl get -o yaml. Returns the manifest in YAML format. If the manifest exceeds max_tokens, it will be truncated and metadata will indicate truncation occurred. Use json_path to extract a specific subtree (e.g., 'spec.containers') whe…
Untrusted display-only summary
Get datadog metric
DATADOG_MCP_GET_DATADOG_METRIC
Query metrics data from Datadog. Use response_format='timeseries' (default) to get time-indexed data points for graphs and trend analysis. Use response_format='scalar' to get a single aggregated value per group, useful for current state, summaries, and comparisons. For response_format='scalar', use structured query ob…
Untrusted display-only summary
Get datadog metric context
DATADOG_MCP_GET_DATADOG_METRIC_CONTEXT
Get metadata (description, type, unit, integration), available tags/dimensions, and optionally related assets for a metric. Useful for exploring metrics before querying them. Set use_cloud_cost=true for Cloud Cost Management metrics.
Untrusted display-only summary
Get datadog notebook
DATADOG_MCP_GET_DATADOG_NOTEBOOK
Retrieve information about a specific Datadog notebook by ID. This tool provides details including name, status, and associated author. The ID can also be extracted from a URL. The ID will be the last component, for example, /notebook/ .
Get the org-wide AAP (App & API Protection, formerly ASM / Application Security Monitoring) blocking configuration. Returns blocking_enabled, which controls default AAP attack blocking, and denylist_enabled, which controls whether AAP denylist entries are enforced. Call this FIRST when a user reports that AAP/ASM atta…
Untrusted display-only summary
Get datadog security aap custom rules
DATADOG_MCP_GET_DATADOG_SECURITY_AAP_CUSTOM_RULES
Get AAP (App & API Protection, formerly ASM / Application Security Monitoring) WAF custom rules — user-authored in-app WAF rules that match request traffic and either monitor it or block it. Each rule has match conditions, an optional service/env scope, and a category + type tag. Answers: "what custom WAF rules do we…
Untrusted display-only summary
Get datadog security aap denylist
DATADOG_MCP_GET_DATADOG_SECURITY_AAP_DENYLIST
List AAP (App & API Protection) denylist entries — IPs, users, user-agents AAP currently BLOCKS or monitors via automated security response. Each entry = Security Response Entity (aka "ASM Block" / "AAP block"). Store: ASM_DATA + RC. Answers: "what's blocked", "who/what is AAP blocking", "show blocklist/denylist/block…
Untrusted display-only summary
Get datadog security detection rules
DATADOG_MCP_GET_DATADOG_SECURITY_DETECTION_RULES
Get security detection rules. This tool supports two modes based on the arguments provided: 1. Get a single rule by ID: provide rule_id — always returns the full rule object regardless of fields or full_rule. 2. List rules: call without rule_id (optionally filter with query, limit response with max_tokens). IMPORTANT:…
Return the schema / authoring reference for Datadog Cloud SIEM detection rules. Includes log_detection plus supported workload_security, application_security, api_security, and ai_guard sections. Customer-authorable detection methods covered here are threshold, new_value, anomaly_detection, impossible_travel, third_pa…
Untrusted display-only summary
Get datadog security findings schema
DATADOG_MCP_GET_DATADOG_SECURITY_FINDINGS_SCHEMA
Call this first before using analyze_datadog_security_findings. Returns the schema (available fields and their types) for security findings, which you need to construct correct SQL queries. IMPORTANT: Use exact field names from this schema in 'columns => ARRAY[...]'. Do not guess field paths — especially for remediati…
Get ranked project and integration suggestions for creating Jira issues, ServiceNow tickets, or Linear issues. Call this when you don't know which project_id to use for create_datadog_security_findings_ticket. Returns available Case Management projects ranked by 30-day historical usage, with a suggested_project_id whe…
Untrusted display-only summary
Get datadog security ioc indicator
DATADOG_MCP_GET_DATADOG_SECURITY_IOC_INDICATOR
Retrieve full detail for one IoC indicator by value (score, category, AS info, GeoIP, log sources, services, signal counts, OCSF fields).
Untrusted display-only summary
Get datadog security ioc schema
DATADOG_MCP_GET_DATADOG_SECURITY_IOC_SCHEMA
Discover filterable fields and their values for IoC Explorer. Call without `filter` first to list all available field names. Then supply `filter` with an exact field name from that list to get `[{value, count}]` for that field. Use `query` to scope counts to a subset of indicators.
Untrusted display-only summary
Get datadog security signal
DATADOG_MCP_GET_DATADOG_SECURITY_SIGNAL
Get the full details of a single Datadog security signal by ID. Returns the complete signal data including attributes, rule information, triage state, tags, and case correlations. IMPORTANT: Before using this tool, call get_datadog_security_signals_schema first to understand the available fields in the signal response…
Untrusted display-only summary
Get datadog security signals schema
DATADOG_MCP_GET_DATADOG_SECURITY_SIGNALS_SCHEMA
Get the schema (available fields) for security signals. Use this tool to discover what fields can be used to filter or query security signals. Returns field names, types, and optionally descriptions and enum values. Signal types use @workflow.rule.type values directly: 'Log Detection', 'Signal Correlation', 'Applicati…
Untrusted display-only summary
Get datadog security suppressions
DATADOG_MCP_GET_DATADOG_SECURITY_SUPPRESSIONS
Retrieve security monitoring suppressions from Datadog. Suppressions prevent detection rules from generating signals for specific conditions. This tool supports three modes based on the arguments provided: 1. List all suppressions: call with no ID arguments (optionally filter with query, sort, page_size, page_number)…
Untrusted display-only summary
Get datadog security trace passlist
DATADOG_MCP_GET_DATADOG_SECURITY_TRACE_PASSLIST
List all AAP (App & API Protection) allowlist / passlist entries that exempt specific traces from AAP security analysis and WAF blocking. This tool operates on AAP traces only; it is unrelated to Cloud SIEM signal suppression — use the detection-rule tools for that. Use this to answer: what traces, services, IPs, path…
Untrusted display-only summary
Get datadog spreadsheet
DATADOG_MCP_GET_DATADOG_SPREADSHEET
Retrieve a Datadog spreadsheet by ID. Returns tables (tables[].id), pivots (pivots[].id), and sheets (sheets[].id) with their configurations. Each table includes schema[].label (all column labels), calculated_columns[].column_id, and calculated_columns[].formula. Pivot source table UUID is a tables[].id value.
Untrusted display-only summary
Get datadog spreadsheet reference
DATADOG_MCP_GET_DATADOG_SPREADSHEET_REFERENCE
Returns the field reference guides for building inputs to upsert_datadog_spreadsheet. Sections: - "table" — field reference: import types, schema, calculated columns, lookups, filters, sort - "pivot" — field reference: dimensions, calculations, sort, display settings, visualizations - "sheet" — field reference: cells,…
Untrusted display-only summary
Provenance
Versioned facts, explicit trust.
The detail snapshot comes from an attributed MIT-licensed repository revision. Safe local icons use exact-match CC0 Simple Icons symbols; unmatched brands use monograms.