Skip to main content

Datadog MCP

The Datadog Model Context Protocol (MCP) server acts as a bridge between your observability data in Datadog and AI agents that support MCP. Connect through Cequence AI Gateway to query logs, metrics, traces, dashboards, monitors, incidents, and more directly from your AI client.

Overview​

Datadog MCP is a remote, vendor-hosted MCP server. You connect to it from Cequence AI Gateway; the server uses Streamable HTTP and is reached at a site-specific endpoint.

  • Server URL (template): https://mcp.{site}/v1/mcp
  • Default site: datadoghq.com (US1)
  • Transport: HTTP (Streamable HTTP)
  • Hosted by: Datadog

The server is fully remote and does not require local installation.

Choose the endpoint for your Datadog site​

Datadog hosts your organization on one of several sites, and each has its own MCP endpoint. Use the row that matches the site you log in to. If you are not sure which one you use, check the URL of your Datadog app or see Datadog sites.

Datadog siteDatadog app URLMCP server endpoint
US1 (default)app.datadoghq.comhttps://mcp.datadoghq.com/v1/mcp
US3us3.datadoghq.comhttps://mcp.us3.datadoghq.com/v1/mcp
US5us5.datadoghq.comhttps://mcp.us5.datadoghq.com/v1/mcp
EU1app.datadoghq.euhttps://mcp.datadoghq.eu/v1/mcp
AP1ap1.datadoghq.comhttps://mcp.ap1.datadoghq.com/v1/mcp
AP2ap2.datadoghq.comhttps://mcp.ap2.datadoghq.com/v1/mcp
UK1uk1.datadoghq.comhttps://mcp.uk1.datadoghq.com/v1/mcp
US1-FED / US2-FEDapp.ddog-gov.com, us2.ddog-gov.comNot supported — the Datadog MCP server is not GovCloud compatible
note

The endpoint pattern is not uniform across sites. US1 has no site prefix (mcp.datadoghq.com) and EU1 uses a different domain ending (mcp.datadoghq.eu). Copy the endpoint from the table rather than building it by hand.

When you create the MCP server in Cequence AI Gateway, set the site value to the middle part of the endpoint — for example datadoghq.com for US1, us3.datadoghq.com for US3, or datadoghq.eu for EU1.

Supported authentication types​

TypeSupportedNotes
OAuth 2.1YesRecommended for Cequence AI Gateway. Uses Dynamic Client Registration (DCR) with PKCE, so you do not need to pre-create a client in Datadog. Sign in with your existing Datadog organization.
Access tokenYesA Datadog Personal Access Token (PAT) for an individual, or a Service Access Token (SAT) for a service account, sent as a bearer token. Use this when the OAuth sign-in flow cannot be completed, for example for an unattended service. See Datadog access tokens.
API and application keysYesA Datadog API key plus application key. Datadog recommends scoping both to a service account that has only the permissions you need.

The MCP server always acts as the authenticated user. It cannot reach anything that user cannot already see in the Datadog UI, and write tools are rejected for read-only users.

Required Datadog permissions​

Every tool call needs a Datadog MCP permission plus the normal permission for the underlying data:

PermissionRequired for
MCP ReadTools that read data, such as searching logs or retrieving dashboards
MCP WriteTools that create or modify resources, such as creating a monitor or muting a host

For example, reading monitors needs both MCP Read and Monitors Read. Users with the Datadog Standard Role already have both MCP permissions. If your organization uses custom roles, an administrator adds them under Organization Settings > Roles.

What can you do with this MCP server​

With the Datadog MCP server, you can:

  • Search and analyze logs — Query logs across services and environments and summarize what changed.
  • Query metrics — Retrieve historical or real-time metric data, and discover which tags are available for filtering and grouping.
  • Investigate traces and spans — Fetch a full APM trace by ID or search spans to find latency and errors.
  • Review monitors and incidents — List alerting monitors, retrieve incident details, and search incident history.
  • Explore dashboards and notebooks — Find dashboards, read widget definitions, and create or edit notebooks.
  • Inspect infrastructure — Search hosts, services, service dependencies, and events such as deployments.

Datadog groups its tools into toolsets so you can enable only what you need. By default the endpoint exposes the core toolset (logs, metrics, traces, dashboards, monitors, incidents, hosts, services, events, and notebooks). Additional toolsets cover areas such as alerting, audit trail, cloud cost, dashboards, data observability, database monitoring, DDSQL, error tracking, feature flags, Kubernetes, networks, profiling, RUM, security, software delivery, synthetics, widgets, and workflows.

To enable more toolsets, add a toolsets value to the end of the server URL when you create the MCP server. For example:

https://mcp.datadoghq.com/v1/mcp?toolsets=core,error-tracking,software-delivery

Use toolsets=all to enable every generally available toolset. A few toolsets are in Preview and are not included in all; request those from Datadog by name. For the full list of tools in each toolset, see Datadog MCP Server Tools.

tip

Enabling every toolset sends a large number of tool definitions to your AI client and consumes context window space. Start with the tools your team actually needs and add more later.

Prerequisites​

Before adding Datadog MCP in Cequence AI Gateway, ensure you have:

  • Access to Cequence AI Gateway at aigateway.cequence.ai
  • A Datadog account on a supported site, with access to the data you want to query
  • The site your organization uses (see the table above), so the server URL matches your organization
  • MCP Read permission, plus MCP Write if you want tools that create or modify resources, and the standard Datadog permissions for the data you want to reach
  • For OAuth authentication: an auth app with client credentials in your vendor account, unless the server supports Dynamic Client Registration (DCR). Datadog MCP supports DCR, so you typically do not need to create an OAuth client in Datadog.

What to ask your IT team​

Ask forWhy you need it
Which Datadog site the organization usesDetermines the MCP server endpoint
MCP Read (and MCP Write if needed) on your roleEvery MCP tool call checks this permission
The resource permissions you need, for example Logs Read or Monitors ReadMCP permissions alone are not enough to read the data
The gateway callback URL added to MCP OAuth Redirect URLsDatadog can restrict which redirect URLs may complete the OAuth flow
Whether the IP allowlist is enabledIf enabled, connections from unapproved networks are refused

Example workflows​

  • “Show me CPU utilization for all hosts in the last 4 hours.”
  • “List all monitors that are currently alerting.”
  • “Find errors in the payment service logs from the past hour and summarize them.”
  • “Get the complete trace for ID 7d5d747be160e280504c099d984bcfe0.”
  • “What’s the status of incident ABC123?”
  • “Show me all deployment events from the last 24 hours.”
  • “What tags are available for the system.cpu.user metric?”

Connecting MCP server from Cequence AI Gateway​

  1. Log in to Cequence AI Gateway.
  2. Choose your tenant.
  3. Go to App catalogue.
  4. Filter by Remote MCP server.
  5. Search for Datadog MCP and then select it.
  6. Select Create MCP server.
  7. Choose auth method. If OAuth, you need an auth app with client credentials in your vendor account (see Prerequisites). Datadog supports DCR, so OAuth setup is usually straightforward.
  8. If prompted, set the site (for example datadoghq.com, us3.datadoghq.com, datadoghq.eu) so the server URL matches your Datadog site.
  9. Complete the setup as prompted, select tools, and deploy.

Use the generated MCP server URL in your client as described in the Client Configuration docs. For detailed UI steps and screenshots, see Create a third-party MCP Server.

Additional information​

  • Site-specific endpoints: The MCP endpoint depends on your Datadog site. Use the table above rather than assuming a pattern; US1 and EU1 do not follow the same shape as the other sites.
  • Fair-use limits: Datadog applies a burst limit of 50 requests per 10 seconds and 100,000 tool calls per month. Contact Datadog support if your use case needs more.
  • Auditing: Every tool call is recorded in the Datadog Audit Trail under the event name MCP Server, including the tool name, arguments, user identity, and which client was used. Datadog also emits usage metrics you can alert on.
  • Data handling: The MCP server does not send your Datadog data to a third-party AI provider — your AI client and its model decide what leaves Datadog. Most tools query Datadog backends directly; a small number use AI models hosted by Datadog's own providers, which your organization can disable through Datadog support.
  • Compliance: The Datadog MCP server is HIPAA-eligible. It is not GovCloud compatible, so US1-FED and US2-FED organizations cannot use it.
  • Restricting access: Use Datadog role-based access control, Data Access Control, and log restriction queries to limit what an MCP user can retrieve. The IP allowlist controls which networks may connect at all.
  • Timeout: The remote server uses a 30-second timeout for requests.
  • Official documentation: Datadog MCP Server, Set Up the Datadog MCP Server, Datadog MCP Server Tools, Datadog sites.