Skip to main content
Connect your Datadog account to enable CloudThinker agents to search logs, query metrics, monitor infrastructure, and investigate incidents across your entire stack. Datadog authenticates with an API key and a scoped Application key pair.

Supported platforms

GovCloud (US1-FED) is not supported by the Datadog MCP server.

Prerequisites

You need a Datadog API key and a scoped Application key. Create an API key:
  1. Go to Organization Settings → API Keys in your Datadog account.
  2. Click + New Key, name it (e.g., CloudThinker), and save.
  3. Copy the key value.
Create a scoped Application key:
  1. Go to Organization Settings → Application Keys.
  2. Click + New Key, name it (e.g., CloudThinker).
  3. Under Scopes, select the permissions listed in Required permissions.
  4. Save and copy the key value.
Always use scoped Application keys instead of unscoped ones. An unscoped key inherits all permissions from the user who created it.

Setup

1

Open CloudThinker

Navigate to Connections → Datadog in your CloudThinker workspace.
2

Select your Datadog site

Choose the Datadog site that matches your account (e.g., US1 for datadoghq.com, EU1 for datadoghq.eu).
3

Enter your API key

Paste your Datadog API key.
4

Enter your Application key

Paste your Datadog Application key.
5

Connect

Click Connect. CloudThinker verifies the credentials and shows a Connected status.

Connection details


Required permissions

Select these scopes when creating your Application key. Read scopes cover all investigation tools; notebooks_write is optional and enables notebook creation.
Start with read scopes only. Add notebooks_write only for workflows where agents need to create investigation notebooks.

Agent capabilities

Once connected, agents can perform read and write operations across your Datadog environment.
Notebook write operations require user approval before execution.

Verify the connection

Example prompts


Troubleshooting

Verify your API key is valid and not revoked. Confirm your Application key has the required scopes and that both keys belong to the same Datadog organization.
Check that your Application key scopes include the data type you are querying (e.g., logs_read_data for logs). Verify your Datadog retention settings and confirm the service or host is actively sending data.
If queries return empty results, you may have selected the wrong site. Check your Datadog URL — app.datadoghq.com is US1, us3.datadoghq.com is US3, app.datadoghq.eu is EU1. Disconnect and reconnect with the correct site.
Both keys are required and serve different roles. The API key authenticates requests. The Application key controls which Datadog features and data the agent can access. One alone is not sufficient.

Security

  • Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
  • Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
  • Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
  • Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
  • Scoped Application keys — always specify explicit scopes; an unscoped key inherits the creating user’s full permissions.
  • Separate keys per integration — create dedicated API and Application keys for CloudThinker so you can revoke them independently.

Grafana Connection

Alternative metrics and dashboards

PagerDuty Connection

Incident alerting and on-call