# Datadog (US5) MCP connector

Datadog (US5) connects to Elaichi over OAuth so Claude, ChatGPT, Cursor, and any MCP client can search logs, monitors, incidents, traces, and dashboards as the person who signed in, with every call logged.

Source: https://elaichi.ai/connectors/datadog-us5/

## Facts

| | |
| --- | --- |
| Application | Datadog (US5) |
| Category | Observability |
| AI tools | 352 |
| Authentication | Connects over OAuth |
| Bring your own OAuth app | No |
| Native MCP | Yes. Datadog (US5) builds and runs this MCP server. Elaichi adds sign-in, access controls and an audit log on top |
| Support for its tools | help.datadoghq.com/hc/en-us |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | No. Connected tools are never listed one by one, however few there are. The endpoint advertises `search_tools` and `execute_tool` instead |

## What you can ask once Datadog (US5) is connected

- Which monitors fired on the checkout service in the last hour?
- Summarize the open incidents and who is assigned to each.
- Show error logs for api-gateway since the 9am deploy.

## Connect Datadog (US5) in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Datadog (US5).
2. Optionally set Share with, then press Connect.
3. Approve it in Datadog (US5). Datadog (US5)'s own window opens. Whoever approves it decides what this connection can reach.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Datadog (US5) tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Datadog (US5) MCP connector for Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Datadog (US5) MCP connector for ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Datadog (US5) MCP connector for Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Datadog (US5) to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a Datadog (US5) tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Datadog (US5) through Elaichi

### Find out what broke before the call starts

On-call. Ask for the open incidents and the monitors that fired in the last hour, then pull the matching logs and traces without opening six tabs.

### Chase a slow request through its traces

Engineering. Pull the trace for a request, aggregate the spans around it, and see which service is holding things up.

### Check a customer's session before replying

Support. Search RUM events for the customer's session and see the errors they hit, so the reply is about what actually happened.

### Spot hosts that stopped reporting

Platform. Search hosts by tag or environment and ask which ones have gone quiet since the last deploy.

### Write the postmortem in a notebook

Engineering. Get the incident, pull the timeline from events and logs, and create a notebook in Datadog that the team can edit afterward.

### Analyze logs for a suspicious pattern

Security. Search and analyze logs for repeated failed logins or unusual source addresses, and summarize what the pattern looks like over the day.

## Elaichi vs Zapier MCP vs Composio for Datadog (US5)

All three can connect Datadog (US5) to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

| What to check | Elaichi | Zapier MCP | Composio |
| --- | --- | --- | --- |
| Where the AI connects | One address for the whole organization. Endpoint: https://api.elaichi.ai/mcp | A server per member, created at sign-in. | An MCP endpoint per team, or an SDK. |
| Control over Datadog (US5) tools | Allow or restrict single Datadog (US5) tools, per role or user. | App and action restrictions on the account. | Role permissions, down to the action. |
| Record of calls | One audit entry per Datadog (US5) call. | A History tab of tool calls. | A log of every tool call. |
| Single sign-on | SAML or OIDC, plus SCIM, on Gold. | SAML on Enterprise. | SAML and OIDC on Enterprise. |
| Price | $15 per user per month. | 2 tasks per successful call. | Billed per tool call. |

Sources: Zapier MCP [docs](https://docs.zapier.com/mcp/get-started/quickstart), [security](https://docs.zapier.com/mcp/manage/security), [usage](https://docs.zapier.com/mcp/features/usage); Composio [docs](https://docs.composio.dev/docs/composio-connect), [gateway](https://composio.dev/mcp-gateway), [enterprise](https://composio.dev/enterprise), [pricing](https://composio.dev/pricing). Checked September 2026.

Longer take: [Zapier MCP alternative](/blog/zapier-mcp-alternative/) and [when you don't need an MCP gateway](/blog/when-you-dont-need-an-mcp-gateway/).

## Frequently asked questions

### How do I connect Datadog (US5) to Claude?

In Elaichi, choose Datadog (US5) and connect it. Datadog in US5 connects over OAuth, so you sign in to your Datadog account and approve access, with no OAuth application to register and no client ID or secret to generate. Then in Claude open Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. That is the whole setup, and it takes a few minutes.

### Does Datadog (US5) work with ChatGPT and Cursor as well as Claude?

Yes. Once Datadog in US5 is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent. You connect Datadog (US5) once and every client picks it up.

### What can an AI agent actually do with my Datadog (US5) data?

With Datadog in US5 connected, an agent can search logs, events, hosts, monitors, incidents, metrics, traces, spans, and RUM events, pull up a dashboard or notebook, and create or edit notebooks. It can also analyze logs and aggregate spans or RUM events to answer questions like which service is slowest this morning. Short, concrete asks such as "open incidents in the last six hours" work better than long paragraphs.

### Does connecting Datadog (US5) give the AI access to everything in my Datadog organization?

No. Every call to Datadog in US5 runs as the person who signed in, so the agent sees only the logs, dashboards, monitors, and incidents that person can already see in Datadog. Elaichi can narrow that access further with restrictions, and it can never widen it.

### Can my team share one Datadog (US5) connection?

Yes. One person connects Datadog in US5 and shares it with a team in Elaichi, and nobody else ever handles a Datadog credential. Each teammate still signs in to Elaichi as themselves, so the audit log names who searched which logs or edited which notebook.

### Can I stop an agent from changing things in Datadog (US5)?

Yes. Restrictions in Elaichi apply per action, so you can allow searching logs, monitors, and incidents in Datadog (US5) while blocking notebook creation and edits. A restricted action is never advertised to Claude, ChatGPT, or Cursor, so no prompt can reach it in Datadog in US5.

### What happens to a Datadog (US5) connection when someone leaves?

Offboarding that person in Elaichi ends their access to Datadog in US5 at once, in every client. A shared Datadog (US5) connection keeps working for everyone else on the team. If you want it gone entirely, disconnecting Datadog (US5) once in Elaichi removes it from Claude, ChatGPT, Cursor, and every other client.

### Does the Datadog (US5) MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Datadog (US5) is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

### Is Elaichi an alternative to Zapier MCP for Datadog (US5)?

Yes. Both let Claude, ChatGPT or Cursor use Datadog (US5). Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every Datadog (US5) call.

### How is Elaichi different from Composio for Datadog (US5)?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to Datadog (US5): one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

## All 352 Datadog (US5) tools

Every tool below is callable through https://api.elaichi.ai/mcp once Datadog (US5) is connected, subject to the toolbox it is in and the restrictions on the caller.

- **Search datadog events** (Search). Searches events like monitor alerts, deployment notifications, infrastructure changes, security findings, and service status changes.
- **Get datadog incident** (Get). Retrieves detailed information about an incident.
- **Get datadog metric** (Get). Queries and analyzes historical or real-time metric data, supporting custom queries and aggregations.
- **Get datadog metric context** (Get). Retrieves detailed information about a metric including metadata, available tags, and tag values for filtering and grouping.
- **Search datadog monitors** (Search). Retrieves information about Datadog monitors, including their statuses, thresholds, and alert conditions.
- **Get datadog trace** (Get). Fetches a complete trace from Datadog APM using a trace ID.
- **Search datadog dashboards** (Search). Lists available Datadog dashboards and key details.
- **Get datadog notebook** (Get). Retrieves detailed information about a specific notebook by ID, including name, status, and author.
- **Search datadog notebooks** (Search). Lists and searches Datadog notebooks with filtering by author, tags, and content.
- **Search datadog hosts** (Search). Lists and provides information about monitored hosts, supporting filtering and searching.
- **Search datadog incidents** (Search). Retrieves a list of Datadog incidents, including their state, severity, and metadata.
- **Search datadog metrics** (Search). Lists available metrics, with options for filtering and metadata.
- **Search datadog entities** (Search). Searches Datadog's Catalog for service identity, ownership and upstream and downstream dependencies.
- **Search datadog spans** (Search). Retrieves spans from APM traces with filters such as service, time, resource, and so on.
- **Aggregate spans** (Action). Aggregates APM spans to compute counts, sums, averages, minimums, maximums, cardinality, and percentiles (p50 to p99). Group results by fields such as service or resource, or set `group_by.interval` in milliseconds to return a timeseries.
- **Analyze datadog logs** (Action). Analyze Datadog logs using SQL queries for counting, aggregations, and numerical analysis. Use this for statistical analysis.
- **Search datadog logs** (Search). Searches logs with filters (time, query, service, host, storage tier, and so on) and returns log details. Renamed from `get_logs`.
- **Search datadog rum events** (Search). Search Datadog RUM events using advanced query syntax.
- **Aggregate rum events** (Action). Aggregates RUM events to compute counts, sums, averages, min, max, cardinality, and percentiles, with grouping support. Use this for statistical analysis and trend data, not for inspecting individual events.
- **Create datadog notebook** (Create). Creates a new Datadog notebook.
- **Edit datadog notebook** (Action). Edits an existing Datadog notebook.
- **Validate datadog monitor** (Validate). Validates a monitor definition for correctness before creating or updating it.
- **Get datadog monitor templates** (Get). Retrieves available monitor templates to help you create monitors.
- **Search datadog monitor groups** (Search). Searches monitor groups by name or criteria.
- **Search datadog slos** (Search). Searches Datadog SLOs by name, tags, or type. Supports query syntax for filtering by service, team, or other attributes.
- **Create datadog monitor** (Create). Creates a Datadog monitor in draft mode. Monitors created with this tool do not send notifications and are set to priority 5 (low). Use `validate_datadog_monitor` to check the definition before creating and `get_datadog_monitor_templates` for query syntax examples. After…
- **Get monitor coverage** (Get). Finds monitoring gaps and coverage for services or hosts. Returns which signals (such as error rate, latency, and request rate) are covered by existing monitors and which are missing. Use with `create_datadog_monitor` to fill gaps.
- **Apm query trace** (Search). Runs a read-only SQL query against a trace's spans to answer a specific question, such as ranking spans by self-time or isolating one span's attributes. Complements `get_datadog_trace`, which shows a trace's overall shape.
- **Apm discover span tags** (Action). Discovers available tag keys on spans within a time range.
- **Apm get primary tag keys** (Get). Retrieves the primary tag keys configured for the organization.
- **Apm get service health** (Get). Retrieves the current health status (ok/warning/critical) for one or more APM services plus the signals driving it (paging monitors, incidents, Watchdog anomalies, DBM regressions). Returns present state only; no historical trends.
- **Apm latency bottleneck summary** (Action). Analyzes latency bottlenecks across traces in an anomaly period using self-time calculations. Identifies which service and resource combinations consume the most self-time, detects cascading call patterns, and surfaces root causes of latency spikes.
- **Apm search recommendations** (Search). Searches for APM recommendations from Datadog.
- **Apm get recommendation** (Get). Retrieves full details of a specific APM recommendation by ID.
- **Search apm sampling rules** (Search). Lists remote sampling rules that set a fixed sample rate for spans matching a service, environment, and resource. Filter by service, environment, or both.
- **Create apm sampling rule** (Create). Creates a remote sampling rule that sets a sample rate for a service, environment, and resource, with no redeploy needed. A low rate can drop most of a service's traces. If a rule already exists for that target, use `update_apm_sampling_rule` instead. The tool requires…
- **Update apm sampling rule** (Update). Changes the sample rate of an existing remote sampling rule, identified by its service, environment, and resource. To change the rule's target, delete the rule and create a new one. The tool requires explicit confirmation before it applies changes.
- **Delete apm sampling rule** (Delete). Permanently deletes a remote sampling rule, identified by its service, environment, and resource. Matching spans fall back to the next applicable sampling mechanism. The tool requires explicit confirmation before it deletes the rule. This operation is idempotent.
- **Search apm service remapping rules** (Search). Lists the organization's service remapping rules in evaluation order, or retrieves one rule by ID. Each result includes the rule's filter, new name, and current version.
- **Create apm service remapping rule** (Create). Creates a service remapping rule that renames services or inferred entities on matching spans, which changes how they appear across APM, monitors, and dashboards. New rules are evaluated after existing rules. You can also specify a different tag for the rule to rewrite. The…
- **Update apm service remapping rule** (Update). Updates an existing service remapping rule's name, filter, the name it assigns to matching services or inferred entities, or the tag it rewrites (`service` or `peer.service` by default). The rule type cannot be changed, and rules with multiple rewrite mappings must be edited…
- **Reorder apm service remapping rules** (Action). Sets the evaluation order of all service remapping rules. The first matching rule applies, so order determines which rule wins when a span matches more than one. The tool requires explicit confirmation before it applies changes.
- **Delete apm service remapping rule** (Delete). Permanently deletes a service remapping rule by ID. New spans that matched the rule keep their original service name. Data that's already indexed doesn't change. The tool requires explicit confirmation before it deletes the rule. This operation is idempotent.
- **Send message to assistant** (Send). Sends a message to the Datadog Assistant and returns its response. Optionally continues an existing conversation by providing a `conversation_id`.
- **Get assistant conversation history** (Get). Retrieves the full conversation history for a specific assistant conversation by its ID.
- **List assistant conversations** (List). Lists all Datadog Assistant conversations for the current user.
- **Search audit events** (Search). Searches for Audit Trail events using Datadog query syntax with support for pagination. Use when you need to find and filter events by specific attributes. Returns Audit Trail events without metadata and previous or new asset values unless requested.
- **List audit events** (List). Lists Audit Trail events over a time window with support for pagination and an optional query. Use to scan recent Audit Trail events. Returns Audit Trail events without metadata and previous or new asset values unless requested.
- **Build audit trail query** (Search). Translates a natural-language description into an Audit Trail query string. If you are uncertain of query syntax when searching Audit Trail events, use this tool first with a description of the events you would like to retrieve, then pass the returned query and timestamps…
- **Search datadog cases** (Search). Searches Work Management work items (cases) with filters including status, priority, project, and assignee. Supports time range filtering and pagination.
- ...and 302 more tools. Call `tools/list` via the MCP endpoint, or see the full catalog via the API, for the complete set.
