# Datadog (US1) MCP connector

The Datadog (US1) connector brings monitors, incidents, logs, traces, metrics and dashboards from Datadog's US1 region into Claude, ChatGPT, Cursor and the Elaichi Agent, so your team can ask about production in plain language.

Source: https://elaichi.ai/connectors/datadog/

## Facts

| | |
| --- | --- |
| Application | Datadog (US1) |
| Category | Observability |
| AI tools | 352 |
| Authentication | Connects over OAuth |
| Bring your own OAuth app | No |
| Native MCP | Yes. Datadog (US1) builds and runs this MCP server. Elaichi adds sign-in, access controls and an audit log on top |
| Support for its tools | help.datadoghq.com/hc/en-us |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | No. Connected tools are never listed one by one, however few there are. The endpoint advertises `search_tools` and `execute_tool` instead |

## What you can ask once Datadog (US1) is connected

- Which monitors are alerting right now and on which hosts?
- Summarize the error logs for the checkout service in the last hour.
- Draft a notebook with the timeline of incident 4821.

## Connect Datadog (US1) in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Datadog (US1).
2. Optionally set Share with, then press Connect.
3. Approve it in Datadog (US1). Datadog (US1)'s own window opens. Whoever approves it decides what this connection can reach.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Datadog (US1) tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Datadog (US1) MCP connector for Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Datadog (US1) MCP connector for ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Datadog (US1) MCP connector for Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Datadog (US1) to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a Datadog (US1) tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Datadog (US1) through Elaichi

### Pull the picture together during an incident

SRE. Ask what fired, which hosts are affected and what the error logs say while the incident in Datadog (US1) is still open. Get the answer in one place instead of six tabs.

### Trace a slow request to its cause

Engineering. Find the spans behind a slow endpoint, compare them with the metric for that service and see where the time goes.

### Check whether a customer's problem is real

Support. When a customer reports errors, look up the RUM events and logs for their session in Datadog (US1) before replying, so the answer is grounded in what actually happened.

### Review monitors before they go live

Platform. Validate a new monitor against Datadog (US1), compare it with the monitor templates your team already uses and check which monitor group it belongs in.

### Write the postmortem from the real timeline

Engineering leadership. Search events and incidents for the window in question, then create a notebook in Datadog (US1) with the timeline and the metrics that mattered, ready for the review.

### Look for unusual activity in logs

Security. Analyze logs across hosts in Datadog (US1) for failed logins, unexpected geographies or spikes from a single source, and search the dashboards your team already built for the same signal.

## Elaichi vs Zapier MCP vs Composio for Datadog (US1)

All three can connect Datadog (US1) to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

| What to check | Elaichi | Zapier MCP | Composio |
| --- | --- | --- | --- |
| Where the AI connects | One address for the whole organization. Endpoint: https://api.elaichi.ai/mcp | A server per member, created at sign-in. | An MCP endpoint per team, or an SDK. |
| Control over Datadog (US1) tools | Allow or restrict single Datadog (US1) tools, per role or user. | App and action restrictions on the account. | Role permissions, down to the action. |
| Record of calls | One audit entry per Datadog (US1) call. | A History tab of tool calls. | A log of every tool call. |
| Single sign-on | SAML or OIDC, plus SCIM, on Gold. | SAML on Enterprise. | SAML and OIDC on Enterprise. |
| Price | $15 per user per month. | 2 tasks per successful call. | Billed per tool call. |

Sources: Zapier MCP [docs](https://docs.zapier.com/mcp/get-started/quickstart), [security](https://docs.zapier.com/mcp/manage/security), [usage](https://docs.zapier.com/mcp/features/usage); Composio [docs](https://docs.composio.dev/docs/composio-connect), [gateway](https://composio.dev/mcp-gateway), [enterprise](https://composio.dev/enterprise), [pricing](https://composio.dev/pricing). Checked September 2026.

Longer take: [Zapier MCP alternative](/blog/zapier-mcp-alternative/) and [when you don't need an MCP gateway](/blog/when-you-dont-need-an-mcp-gateway/).

## Frequently asked questions

### How do I connect Datadog (US1) to Claude?

Connect Datadog (US1) in Elaichi first, then in Claude open Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. Datadog's own step is a normal OAuth sign-in: you log in to your Datadog US1 account and approve access. There is no OAuth application to register and no client ID or secret to generate.

### Does Datadog (US1) work with ChatGPT and Cursor as well as Claude?

Yes. Once Datadog (US1) is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, any other MCP client and the Elaichi Agent. You connect Datadog in US1 once and every client picks it up.

### What can an AI agent actually do with my Datadog (US1) data?

It can search monitors, incidents, events, logs, traces, spans, hosts, metrics, RUM events and dashboards in Datadog (US1), and it can create or edit notebooks and validate a monitor definition before you save it. Ask it which monitors are alerting right now, what the error logs for a service say, or to draft a notebook with an incident's timeline. Short, concrete asks like these work better than long sentences.

### Does connecting Datadog (US1) give the AI access to my whole organization?

No. Every call to Datadog in US1 runs as the person who signed in, so the AI sees exactly the dashboards, logs and monitors that person can already see in Datadog, and nothing more. Elaichi can narrow that access further with restrictions, but it can never widen it beyond what Datadog itself grants.

### Can my team share one Datadog (US1) connection?

Yes. One person connects Datadog (US1) in Elaichi and shares it with a team, and nobody else ever handles a credential. Each teammate still signs in to Elaichi as themselves, so the audit log names the person behind every search of Datadog in US1.

### Can I stop an agent from changing things in Datadog (US1)?

Yes. Restrictions in Elaichi apply per action, so you can allow searching monitors, logs and incidents in Datadog (US1) while blocking the creation or editing of notebooks. A restricted action is never advertised to the AI client at all, so no prompt, however worded, can reach it.

### What happens to a Datadog (US1) connection when someone leaves?

Offboarding that person in Elaichi ends their access to Datadog in US1 at once, across Claude, ChatGPT, Cursor and every other client. If they had shared a Datadog (US1) connection with a team, it keeps working for everyone else. Disconnecting Datadog (US1) once in Elaichi removes it from every client.

### Does the Datadog (US1) MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Datadog (US1) is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

### Is Elaichi an alternative to Zapier MCP for Datadog (US1)?

Yes. Both let Claude, ChatGPT or Cursor use Datadog (US1). Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every Datadog (US1) call.

### How is Elaichi different from Composio for Datadog (US1)?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to Datadog (US1): one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

## All 352 Datadog (US1) tools

Every tool below is callable through https://api.elaichi.ai/mcp once Datadog (US1) is connected, subject to the toolbox it is in and the restrictions on the caller.

- **Search Datadog (US1) events** (Search). Searches events like monitor alerts, deployment notifications, infrastructure changes, security findings, and service status changes.
- **Get Datadog (US1) incident** (Get). Retrieves detailed information about an incident.
- **Get Datadog (US1) metric** (Get). Queries and analyzes historical or real-time metric data, supporting custom queries and aggregations.
- **Get Datadog (US1) metric context** (Get). Retrieves detailed information about a metric including metadata, available tags, and tag values for filtering and grouping.
- **Search Datadog (US1) monitors** (Search). Retrieves information about Datadog monitors, including their statuses, thresholds, and alert conditions.
- **Get Datadog (US1) trace** (Get). Fetches a complete trace from Datadog APM using a trace ID.
- **Search Datadog (US1) dashboards** (Search). Lists available Datadog dashboards and key details.
- **Get Datadog (US1) notebook** (Get). Retrieves detailed information about a specific notebook by ID, including name, status, and author.
- **Search Datadog (US1) notebooks** (Search). Lists and searches Datadog notebooks with filtering by author, tags, and content.
- **Search Datadog (US1) hosts** (Search). Lists and provides information about monitored hosts, supporting filtering and searching.
- **Search Datadog (US1) incidents** (Search). Retrieves a list of Datadog incidents, including their state, severity, and metadata.
- **Search Datadog (US1) metrics** (Search). Lists available metrics, with options for filtering and metadata.
- **Search Datadog (US1) entities** (Search). Searches Datadog's Catalog for service identity, ownership and upstream and downstream dependencies.
- **Search Datadog (US1) spans** (Search). Retrieves spans from APM traces with filters such as service, time, resource, and so on.
- **Aggregate spans** (Action). Aggregates APM spans to compute counts, sums, averages, minimums, maximums, cardinality, and percentiles (p50 to p99). Group results by fields such as service or resource, or set `group_by.interval` in milliseconds to return a timeseries.
- **Analyze Datadog (US1) logs** (Action). Analyze Datadog logs using SQL queries for counting, aggregations, and numerical analysis. Use this for statistical analysis.
- **Search Datadog (US1) logs** (Search). Searches logs with filters (time, query, service, host, storage tier, and so on) and returns log details. Renamed from `get_logs`.
- **Search Datadog (US1) rum events** (Search). Search Datadog RUM events using advanced query syntax.
- **Aggregate rum events** (Action). Aggregates RUM events to compute counts, sums, averages, min, max, cardinality, and percentiles, with grouping support. Use this for statistical analysis and trend data, not for inspecting individual events.
- **Create Datadog (US1) notebook** (Create). Creates a new Datadog notebook.
- **Edit Datadog (US1) notebook** (Action). Edits an existing Datadog notebook.
- **Validate Datadog (US1) monitor** (Validate). Validates a monitor definition for correctness before creating or updating it.
- **Get Datadog (US1) monitor templates** (Get). Retrieves available monitor templates to help you create monitors.
- **Search Datadog (US1) monitor groups** (Search). Searches monitor groups by name or criteria.
- **Search Datadog (US1) slos** (Search). Searches Datadog SLOs by name, tags, or type. Supports query syntax for filtering by service, team, or other attributes.
- **Create Datadog (US1) monitor** (Create). Creates a Datadog monitor in draft mode. Monitors created with this tool do not send notifications and are set to priority 5 (low). Use `validate_datadog_monitor` to check the definition before creating and `get_datadog_monitor_templates` for query syntax examples. After…
- **Get monitor coverage** (Get). Finds monitoring gaps and coverage for services or hosts. Returns which signals (such as error rate, latency, and request rate) are covered by existing monitors and which are missing. Use with `create_datadog_monitor` to fill gaps.
- **Apm query trace** (Search). Runs a read-only SQL query against a trace's spans to answer a specific question, such as ranking spans by self-time or isolating one span's attributes. Complements `get_datadog_trace`, which shows a trace's overall shape.
- **Apm discover span tags** (Action). Discovers available tag keys on spans within a time range.
- **Apm get primary tag keys** (Get). Retrieves the primary tag keys configured for the organization.
- **Apm get service health** (Get). Retrieves the current health status (ok/warning/critical) for one or more APM services plus the signals driving it (paging monitors, incidents, Watchdog anomalies, DBM regressions). Returns present state only; no historical trends.
- **Apm latency bottleneck summary** (Action). Analyzes latency bottlenecks across traces in an anomaly period using self-time calculations. Identifies which service and resource combinations consume the most self-time, detects cascading call patterns, and surfaces root causes of latency spikes.
- **Apm search recommendations** (Search). Searches for APM recommendations from Datadog.
- **Apm get recommendation** (Get). Retrieves full details of a specific APM recommendation by ID.
- **Search apm sampling rules** (Search). Lists remote sampling rules that set a fixed sample rate for spans matching a service, environment, and resource. Filter by service, environment, or both.
- **Create apm sampling rule** (Create). Creates a remote sampling rule that sets a sample rate for a service, environment, and resource, with no redeploy needed. A low rate can drop most of a service's traces. If a rule already exists for that target, use `update_apm_sampling_rule` instead. The tool requires…
- **Update apm sampling rule** (Update). Changes the sample rate of an existing remote sampling rule, identified by its service, environment, and resource. To change the rule's target, delete the rule and create a new one. The tool requires explicit confirmation before it applies changes.
- **Delete apm sampling rule** (Delete). Permanently deletes a remote sampling rule, identified by its service, environment, and resource. Matching spans fall back to the next applicable sampling mechanism. The tool requires explicit confirmation before it deletes the rule. This operation is idempotent.
- **Search apm service remapping rules** (Search). Lists the organization's service remapping rules in evaluation order, or retrieves one rule by ID. Each result includes the rule's filter, new name, and current version.
- **Create apm service remapping rule** (Create). Creates a service remapping rule that renames services or inferred entities on matching spans, which changes how they appear across APM, monitors, and dashboards. New rules are evaluated after existing rules. You can also specify a different tag for the rule to rewrite. The…
- **Update apm service remapping rule** (Update). Updates an existing service remapping rule's name, filter, the name it assigns to matching services or inferred entities, or the tag it rewrites (`service` or `peer.service` by default). The rule type cannot be changed, and rules with multiple rewrite mappings must be edited…
- **Reorder apm service remapping rules** (Action). Sets the evaluation order of all service remapping rules. The first matching rule applies, so order determines which rule wins when a span matches more than one. The tool requires explicit confirmation before it applies changes.
- **Delete apm service remapping rule** (Delete). Permanently deletes a service remapping rule by ID. New spans that matched the rule keep their original service name. Data that's already indexed doesn't change. The tool requires explicit confirmation before it deletes the rule. This operation is idempotent.
- **Send message to assistant** (Send). Sends a message to the Datadog Assistant and returns its response. Optionally continues an existing conversation by providing a `conversation_id`.
- **Get assistant conversation history** (Get). Retrieves the full conversation history for a specific assistant conversation by its ID.
- **List assistant conversations** (List). Lists all Datadog Assistant conversations for the current user.
- **Search audit events** (Search). Searches for Audit Trail events using Datadog query syntax with support for pagination. Use when you need to find and filter events by specific attributes. Returns Audit Trail events without metadata and previous or new asset values unless requested.
- **List audit events** (List). Lists Audit Trail events over a time window with support for pagination and an optional query. Use to scan recent Audit Trail events. Returns Audit Trail events without metadata and previous or new asset values unless requested.
- **Build audit trail query** (Search). Translates a natural-language description into an Audit Trail query string. If you are uncertain of query syntax when searching Audit Trail events, use this tool first with a description of the events you would like to retrieve, then pass the returned query and timestamps…
- **Search Datadog (US1) cases** (Search). Searches Work Management work items (cases) with filters including status, priority, project, and assignee. Supports time range filtering and pagination.
- ...and 302 more tools. Call `tools/list` via the MCP endpoint, or see the full catalog via the API, for the complete set.
