Skip to content
Last updated

Datadog integration

Datadog can be connected to Agen.co two ways, matching the Official / In-house filter in the connector picker:

  • Official — Agen.co connects through Datadog's own hosted MCP server, so your AI agents use the same toolset-based tools (logs, metrics, monitors, dashboards, incidents, and more) Datadog exposes to MCP clients like Claude, Cursor, and ChatGPT.
  • In-house — Agen.co wraps the Datadog API directly through its own integration layer, using a dedicated API Key and Application Key.

Pick Official if the toolset-based MCP tools cover what your agents need. Fall back to In-house if you need broader API coverage.


Connect via the official MCP server

Prerequisites

  • A Datadog account with access to Organization Preferences
  • The connecting user needs the mcp_read permission (and mcp_write for any write-capable tools), plus the usual resource-level permissions for whatever toolsets you enable — the built-in Datadog Standard Role has both by default. An organization admin controls both overall MCP access and MCP write access for the org from Organization Settings, and can add MCP Read / MCP Write to a custom role under Organization Settings → Roles.
  • Datadog's Government (ddog-gov.com) sites are not supported by the MCP server

Connect Datadog in Agen.co

  1. In the Agen.co portal, go to Connectors → My connectors and click Add connector.
  2. In the Select connector drawer, search for Datadog and select it. The Add Datadog panel opens.
  3. The form comes pre-filled with defaults — adjust the fields as needed:
FieldRequiredDescription
Instance SlugNoDistinguishes multiple instances of this MCP connector — it prefixes each imported tool as slug__tool. Use lowercase kebab-case; leave empty for a single instance. This value is immutable after creation.
Datadog siteYesYour Datadog site domain (for example, datadoghq.com for US1, datadoghq.eu for EU, us3.datadoghq.com, us5.datadoghq.com, ap1.datadoghq.com, ap2.datadoghq.com, or uk1.datadoghq.com). Match this to the site you sign in to — check the URL you use to log in to Datadog if unsure. Defaults to datadoghq.com.
ToolsetsYesOne or more Datadog MCP toolsets to expose (see table below). Defaults to core.
AuthenticationYesOAuth (default) or API token. Switching to API token replaces the steps below with a single API key field and skips the redirect-URL registration entirely — see the note below.

Double-check Datadog site before continuing — it must match the site you actually sign in to. Picking the wrong one causes the approval step below to fail or route you to the wrong Datadog account.

  1. With Authentication left on OAuth, register Agen.co's redirect URLs with Datadog before clicking Connect:
    1. In a separate tab, open Datadog, click your profile icon in the bottom-left corner, and select Organization Settings.
    2. In the sidebar, under General, select Preferences.
    3. If your agents need to create or modify Datadog resources (not just read them), enable MCP write access. An organization admin may also need to confirm overall MCP access is enabled for the org here — if Connect fails even with a correct redirect URL, check this first.
    4. Scroll down to the MCP OAuth Redirect URLs section and paste in both the Callback URL and Gateway callback URL values shown on the Agen.co panel.
    5. Save your changes.
  2. Back in Agen.co, click Connect as soon as the redirect URLs are saved. You're redirected to Datadog to approve access — no separate sign-in is required.

If this redirect lands you on a Datadog sign-in screen instead of an approval screen, the site/region selector on that screen probably doesn't match the Datadog site you entered in step 3. Use the dropdown on the sign-in screen to pick the correct site manually.

Don't let the authorization sit

The OAuth state Agen.co generates when you click Connect expires after a few minutes. If you spend a while registering the redirect URLs in Datadog first, or come back to this panel later, approving access can fail with InvalidStateError. If that happens, close the panel, click Add connector again, and run Connect right after the redirect URLs are already saved.

  1. On Datadog's consent screen, choose Limited access for read-only tools, or the full-access option if your agents also need write-capable tools — this is where the mcp_read / mcp_write permissions from the Prerequisites actually get exercised. Approve access, and you're returned to Agen.co with a list of the tools this connector will expose.
  2. Click Add below the tools list to finish setting up the connector.

Skipping OAuth with an API token

Switching Authentication to API token replaces steps 4–6 with a single API key field and no redirect-URL setup. Despite the field's name, Datadog expects a Personal Access Token (PAT) or Service Access Token (SAT) here, sent as a Bearer token — not a classic Datadog API Key from the API Keys page, which doesn't carry the mcp_read / mcp_write permission. Generate one from Personal Settings → Access Tokens (PAT) or an org's service account (SAT).

Available toolsets, exactly as the Toolsets dropdown lists them:

ToolsetWhat it covers
allEnable every available Datadog toolset
core (default)Logs, metrics, traces, dashboards, monitors, incidents, hosts, services, events, and notebooks
alertingValidate and create monitors, search monitor groups, retrieve monitor templates, analyze monitor coverage, and search SLOs
casesCase Management: create, search, and update cases; manage projects; and link Jira issues
costCloud Cost Management, including cost-saving recommendations ranked by estimated potential daily savings
dashboardsRetrieve, create, update, and delete dashboards, plus widget schema reference and validation
dbmInteract with Database Monitoring
ddsqlQuery Datadog data using DDSQL across infrastructure resources, logs, metrics, RUM, spans, and other sources
error-trackingInteract with Datadog Error Tracking
feature-flagsManage feature flags, including creating, listing, and updating flags and their environments
kubernetesSearch and describe Kubernetes resources and retrieve manifests across all clusters
llmobsSearch and analyze Agent Observability spans and experiments
networksCloud Network Monitoring analysis and Network Device Monitoring
onboardingAgentic onboarding tools for guided Datadog setup and configuration
product-analyticsInteract with Product Analytics queries
profilingDiscover, explore, and analyze Continuous Profiler data
reference-tablesManage Reference Tables, including listing tables, reading and appending rows, and creating tables from cloud storage
rumReal User Monitoring: resolve applications, summarize performance, explore metrics, and manage retention filters and custom RUM metrics
securityCode security scanning and searching security signals and findings
software-deliveryInteract with Software Delivery (CI Visibility and Test Optimization)
syntheticsInteract with Datadog Synthetic tests
widgetsDashboard and notebook widget visualization, validation, and type conversion
workflowsWorkflow Automation: list, inspect, execute, and configure workflows for agent use

Datadog's own MCP server documents additional toolsets — data-observability, assistant, audit-trail, code-exec, notebooks, sheets, and several Preview toolsets — that aren't in this connector's Toolsets dropdown yet. Only the toolsets listed above can be selected here.

Enabling the Datadog connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.

Connect via the Datadog API

Datadog is a cloud monitoring and observability platform that provides metrics, logs, traces, and dashboards for your infrastructure and applications. This integration connects Datadog to Frontegg using an API Key and Application Key, enabling your AI agent to query metrics, monitors, dashboards, logs, incidents, and more.

Prerequisites

  • A Datadog account with admin access
  • Permission to create API Keys and Application Keys under Organization Settings
  • The Datadog region your account is hosted in: US1, EU1, US3, US5, or AP1

Connect Datadog

Step 1: Log in to Datadog

Go to app.datadoghq.com and log in to your Datadog account.

Datadog login page

Step 2: Navigate to API Keys

Open Organisation Settings from the top navigation and select API Keys from the left sidebar under Access.

Datadog API Keys page

Step 3: Create a new API Key

Click + New Key, enter Frontegg Integration as the name, and click Create Key.

Create new API Key dialog

Step 4: Copy the API Key

After the key is created, click Copy to copy the full API Key value. Save it — you will not be able to view the key again after closing this dialog.

Copy the key now

Datadog only shows the full API Key once, immediately after creation. Copy it before closing the dialog.

Copy the API Key value

Step 5: Navigate to Application Keys

In the left sidebar under Access, click Application Keys.

Datadog Application Keys page

Step 6: Create a new Application Key

Click + New Key, enter Frontegg Integration as the name, and click Create Key.

Create new Application Key dialog

Step 7: Copy the Application Key

After the key is created, click Copy to copy the full Application Key value. Save it — you will not be able to view the key again after closing this dialog.

Copy the key now

Datadog only shows the full Application Key once, immediately after creation. Copy it before closing the dialog.

Copy the Application Key value

Step 8: Check the Application Key scopes

An Application Key can be left unscoped, in which case it inherits your own permissions, or narrowed to a specific list of scopes. If you scope the key, grant the scopes below — each one covers a part of the integration, and omitting one disables the matching operations.

ScopeCovers
metrics_readReading metric metadata and the list of active metrics
timeseries_queryQuerying metric time series
hosts_readListing hosts and host totals
monitors_readReading monitors
monitors_writeCreating, updating, deleting, muting, and unmuting monitors
dashboards_readReading dashboards
dashboards_writeCreating, updating, and deleting dashboards
events_readReading events
logs_read_dataSearching and aggregating logs
apm_readSearching and aggregating APM spans
synthetics_readReading synthetic tests and their results
incident_readReading incidents
incident_writeCreating and updating incidents
teams_readReading teams and their members
user_access_readReading users
user_access_inviteInviting users
user_access_manageUpdating users

Creating events needs no scope

Creating an event, and muting or unmuting a host, are authorized by the API Key alone and do not require an Application Key scope.

Configure the Frontegg portal

Once you have obtained your API Key and Application Key from the steps above, enter them in the integration configuration page of the Frontegg portal:

  1. Open the Frontegg portal and navigate to [ENVIRONMENT] → Integrations → Datadog.
  2. Enter the API Key in the API Key field.
  3. Enter the Application Key in the Application Key field.
  4. Select your Region — US1, EU1, US3, US5, or AP1.
  5. Click Save.

The region must match your account

Datadog runs separate regional services and keys are valid only in the region that issued them. Selecting the wrong region fails every call even when both keys are correct. If you are unsure, the region is the domain you use to sign in — datadoghq.com is US1, datadoghq.eu is EU1, and us3, us5, or ap1 appear in the domain for the others.

Keep your credentials secure

Never share or commit your API Key or Application Key to version control.

Capabilities

  • Users can be listed a page at a time, which keeps responses small — an unbounded listing of a large organization returns far more data than an agent can work with.
  • Metric queries return real time series over a requested window, rather than only the current value.
  • Dashboards can be filtered to shared or deleted ones when listing them.

Provider limitations

  • Searching logs or APM spans requires Log Management or APM to be provisioned on your account with at least one index configured. Without one, those searches are rejected outright — this is an account entitlement, not a permission you can grant.
  • Events cannot be deleted. Datadog offers no delete operation, so an event created through the integration stays in your event stream permanently.
  • Host listings return at most 1000 hosts per request and default to 100; most other listings return at most 100 per page.
  • Reading users returns a large amount of related role data alongside each user, so listings should be paged rather than fetched whole.
  • Muting a host or a monitor is authorized by the API Key alone, so restricting the Application Key's scopes does not prevent it.

Additional resources