Investigate Datadog telemetry, incidents, dashboards, and service health.
Description is untrusted, display-only upstream metadata. It never becomes policy, OAuth scope authority, or an agent instruction.
Pakkawork boundary
Research catalogue metadata only. No Pakkawork OAuth, credential, host, quota, executor, or verifier is enabled.
No Pakkawork execution adapter is enabled. Hosted account-authorisation availability is workspace-specific and checked separately in the dashboard.Check workspace connection options
Only field names, types, and required markers are shown. Secret values, default auth URLs, credential material, and inferred OAuth scopes are excluded.
DCR_OAUTH
DCR_OAUTH
datadog_mcp_DCR_OAuth
Provider setup
Developer setup
Client idclient_id · stringOptional
Client secretclient_secret · stringOptional
Redirect URIoauth_redirect_uri · stringOptional
Scopesscopes · stringOptional
User connection
No fields declared in this snapshot.
Capability index
Actions and trigger definitions
Static summaries are available. Live schemas remain disabled until PROVIDER_HUB_API_KEY is configured server-side.
Check whether Datadog App and API Protection (AAP) can be enabled for a service via Remote Configuration (RC), with no code changes. Use when the user asks to install, set up, enable, or onboard AAP for a service and environment. Returns a verdict with a recommended navigation action: the Service Inventory side-panel…
Untrusted display-only summary
Aap onboarding
DATADOG_MCP_AAP_ONBOARDING
Step-by-step instructions for enabling Datadog App and API Protection (AAP) to monitor and secure your application. AAP detects security threats, vulnerabilities, and attacks in real time by using Datadog tracing libraries for application deployments, the Datadog security processor for Envoy deployments, the Datadog S…
Queue traces, sessions, or spans for human review in an annotation queue. This is how findings become review work: use **search_llmobs_spans** or **find_llmobs_error_spans** to identify the traces worth grading, then queue them here. Returns `interactions` — each with the `id` that **upsert_llmobs_annotations** writes…
Untrusted display-only summary
Add llmobs dataset records
DATADOG_MCP_ADD_LLMOBS_DATASET_RECORDS
Create records in a dataset. **Two-step**: PREVIEW (`confirmed=false`) → INSERT (`confirmed=true`). - `confirmed=false`: does NOT insert. Validates that the (project_id, dataset_id) pair exists, then returns `AddDatasetRecordsPreview` with the resolved IDs, planned record count, tag union, first-record content, and a…
Untrusted display-only summary
Aggregate datadog ci pipeline events
DATADOG_MCP_AGGREGATE_DATADOG_CI_PIPELINE_EVENTS
Aggregate and analyze CI pipeline events to produce statistics, metrics, and grouped analytics. Use it for questions such as average pipeline duration or failed builds per pipeline. For individual event details or error messages, use search_datadog_ci_pipeline_events instead. aggregation is required and must be one of…
Untrusted display-only summary
Aggregate datadog test events
DATADOG_MCP_AGGREGATE_DATADOG_TEST_EVENTS
Aggregate Datadog test events for reliability, performance, and execution trends. Use search_datadog_test_events for individual event details. aggregation is required and must be one of count, cardinality, avg, sum, min, max, pc50, pc75, pc90, pc95, or pc99. Use cardinality with metric set to a facet (such as @test.na…
Untrusted display-only summary
Aggregate dora events
DATADOG_MCP_AGGREGATE_DORA_EVENTS
Aggregate DORA events into scalar values or timeseries using composable queries and formulas. Each query selects a DORA index, optional metric, aggregation, filter, and group_by facets. Use get_dora_fields to discover valid indexes, measures, facets, cardinality fields, and aggregations.
Untrusted display-only summary
Aggregate events
DATADOG_MCP_AGGREGATE_EVENTS
Aggregate Datadog events to compute counts, sums, averages, min, max, cardinality, and percentiles (P50, P75, P90, P95, P98, P99), with optional grouping by fields or time intervals. Use this for aggregated analysis such as event counts by source, event frequency over time, or grouped summaries across tags. For raw ev…
Untrusted display-only summary
Aggregate rum events
DATADOG_MCP_AGGREGATE_RUM_EVENTS
Aggregate Datadog RUM events to compute counts, sums, averages, min, max, cardinality, and percentiles (P50, P75, P90, P95, P98, P99), with optional grouping by fields or time intervals. Use this for aggregated analysis of RUM data such as session counts over time, error counts by page, or p95 loading times by browser…
Untrusted display-only summary
Aggregate spans
DATADOG_MCP_AGGREGATE_SPANS
Aggregate Datadog APM spans to compute counts, sums, averages, min, max, cardinality, and percentiles (P50, P75, P90, P95, P98, P99), with optional grouping by fields or time intervals. Use this for aggregated analysis such as request counts over time, p95 duration by service or resource, or error counts grouped by en…
Untrusted display-only summary
Analyse datadog k8s rollout
DATADOG_MCP_ANALYSE_DATADOG_K8S_ROLLOUT
Assemble a Kubernetes Deployment rollout in one call: status, progress, timing (ETA while in progress, duration once finished), the new/previous/old ReplicaSet split by revision, and before/after impact series (RED, resource utilization, log counts). Prefer this over stitching together search_datadog_k8s_resources and…
Untrusted display-only summary
Analyze cloud network monitoring
DATADOG_MCP_ANALYZE_CLOUD_NETWORK_MONITORING
Queries Cloud Network Monitoring (CNM) data to view network/transport level information. Use to investigate netork latency, packet loss, TCP failed connections, dial timeouts, or spikes in TCP throughput. Each query accepts a 'scope' field to select which slice of CNM data to query: - 'tcp' (default): service-to-servi…
Untrusted display-only summary
Analyze datadog error tracking errors
DATADOG_MCP_ANALYZE_DATADOG_ERROR_TRACKING_ERRORS
Analyze Datadog Error Tracking error samples with SQL — aggregations, breakdowns by tag/service/version, or raw sample inspection. Runs against a virtual 'errors' table of individual error events (not Issues, which are groups of errors). Column names: no @ = root/tag attribute (e.g. usr.id, service), @ = custom attrib…
Untrusted display-only summary
Analyze datadog logs
DATADOG_MCP_ANALYZE_DATADOG_LOGS
Analyze Datadog logs using SQL. Runs against a virtual 'logs' table filtered by your search query. Good for aggregations, counts, group-bys, or peeking at recent logs with LIMIT. To discover custom attributes for extra_columns, first call search_datadog_logs with extra_fields. If a query times out, try a shorter time…
Untrusted display-only summary
Analyze datadog security findings
DATADOG_MCP_ANALYZE_DATADOG_SECURITY_FINDINGS
Primary tool for analyzing security findings. Use this for all security findings analysis tasks. REQUIRED: Call get_datadog_security_findings_schema FIRST to get available fields and their types before writing SQL. Queries live data from the last 24 hours using flexible SQL aggregations, filtering, and grouping. IMPOR…
Untrusted display-only summary
Analyze datadog security signals
DATADOG_MCP_ANALYZE_DATADOG_SECURITY_SIGNALS
Count, group, or trend security signals using DDSQL — for any aggregate question: 'how many', 'top N', 'by severity', 'over time', or breakdown. Do NOT use for listing, retrieving, or checking existence of specific signals — use search_datadog_security_signals instead. IMPORTANT: When constructing the SQL query, ALWAY…
Untrusted display-only summary
Analyze security findings
DATADOG_MCP_ANALYZE_SECURITY_FINDINGS
Primary tool for analyzing security findings. (Also available as analyze_datadog_security_findings.) Use this for all security findings analysis tasks. REQUIRED: Call security_findings_schema FIRST to get available fields and their types before writing SQL.
Untrusted display-only summary
Append new rum retention filter
DATADOG_MCP_APPEND_NEW_RUM_RETENTION_FILTER
Create a new RUM retention filter, appended at the end of the evaluation order. Retention filters control which RUM events are indexed and retained. **This changes data-retention configuration and directly affects billing.** Adding a filter or enabling cross-product sampling increases indexed volume and cost. **Always…
Untrusted display-only summary
Append reference table rows
DATADOG_MCP_APPEND_REFERENCE_TABLE_ROWS
Append (add) new rows to an existing reference table. Prefer upsert_reference_table_rows when you may need to update existing rows — it handles both inserts and updates. Use this tool only when you are certain all rows are new. Each row must include all required fields from the table's schema, including the primary ke…
Untrusted display-only summary
Archive-feature-flag
DATADOG_MCP_ARCHIVE_FEATURE_FLAG
Archive a single feature flag by ID or key; pair with list-stale-feature-flags to discover candidates. Provide featureFlagID or featureFlagKey (if both are given, featureFlagID wins).
Untrusted display-only summary
Archive-saved-filter
DATADOG_MCP_ARCHIVE_SAVED_FILTER
Archive a saved filter (reversible via unarchive-saved-filter).
Untrusted display-only summary
Ask widget expert
DATADOG_MCP_ASK_WIDGET_EXPERT
Get targeted instructions for building a Datadog widget. Returns a concise how-to guide — widget type recommendations, required fields, schema patterns, and an annotated example — that you use to build the widget definition yourself. The expert has deep knowledge of all widget types and schemas but does NOT have acces…
Untrusted display-only summary
Assign datadog security findings
DATADOG_MCP_ASSIGN_DATADOG_SECURITY_FINDINGS
Assign or unassign security findings to a user. Assignment cascades to linked cases — assigning a finding auto-assigns its linked case. Use analyze_datadog_security_findings or search_datadog_security_findings to find specific finding IDs first. To unassign, omit assignee. IMPORTANT: Always confirm with the user befor…
Untrusted display-only summary
Batch update llmobs dataset records
DATADOG_MCP_BATCH_UPDATE_LLMOBS_DATASET_RECORDS
Insert, update, and delete dataset records in one versioned operation. Use this to edit or remove existing records; **add_llmobs_dataset_records** is the append-only path and is preferable when you are only adding. **Two-step**: PREVIEW (`confirmed=false`) → APPLY (`confirmed=true`). - `confirmed=false`: writes nothin…
Untrusted display-only summary
Browser onboarding
DATADOG_MCP_BROWSER_ONBOARDING
Step-by-step instructions for adding initial Datadog setup to a frontend browser-based project environment. You must first review the user's project and this tool's arguments (including nested arguments) and fill out as many of them as possible before calling this tool. Check project files and dependencies to determin…
Untrusted display-only summary
Build audit trail query
DATADOG_MCP_BUILD_AUDIT_TRAIL_QUERY
Translates a natural-language description into a correct Audit Trail query string. Returns query/from/to fields (plus optional visualization hints) that can be used wherever an Audit Trail query is needed — e.g. feed them to search_audit_events, link the user to the Audit Trail Explorer, or use them in any other Audit…
Untrusted display-only summary
Cancel datadog workflow instance
DATADOG_MCP_CANCEL_DATADOG_WORKFLOW_INSTANCE
Cancel a running Datadog Workflow Automation execution instance. Invoke only when the user intends to stop the run. The instanceId can come from execute_datadog_workflow or list_datadog_workflow_instances. Cancellation cannot be resumed. On success, the result contains `cancelled: true`, `workflowId`, and `instanceId`.
Untrusted display-only summary
Check-flag-implementation
DATADOG_MCP_CHECK_FLAG_IMPLEMENTATION
PRIMARY TOOL FOR EXISTING FLAGS! This tool should be used to check how a feature flag should be implemented in codebase. Use this when asked: - Check my flags are used properly? - Use an existing flag to control some functionality in my code? - Use the flag 'some-flag' to control something in my code? (This implies th…
Untrusted display-only summary
Clean-up-flag
DATADOG_MCP_CLEAN_UP_FLAG
Clean up a stale feature flag by key — auto-archives if no code references are known, otherwise returns the repos and files where the flag is still referenced plus a Datadog UI link and instructs the user to use Bits dev in the UI to remove those references (archiving stays blocked until they are gone).
Untrusted display-only summary
Clone datadog form
DATADOG_MCP_CLONE_DATADOG_FORM
Clone an existing Datadog form. Creates a copy of the form with all its current settings and latest version definition. Returns the cloned form's metadata including its new ID and datastore_id.
Untrusted display-only summary
Provenance
Versioned facts, explicit trust.
The detail snapshot comes from an attributed MIT-licensed repository revision. Safe local icons use exact-match CC0 Simple Icons symbols; unmatched brands use monograms.