> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rootly.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Datadog MCP Connector

> Connect Rootly AI to Datadog through read-only OAuth, with API and application keys available as a fallback.

The **Datadog MCP** connector lets Rootly AI query operational data during investigations. It can inspect services, logs, metrics, monitors, application performance monitoring (APM) spans and traces, and Real User Monitoring (RUM) events through Datadog's hosted Model Context Protocol (MCP) server.

OAuth 2.0 is the recommended authentication method. Rootly also supports Datadog API and application keys for organizations that can't use OAuth.

<Info>
  Rootly requests read permissions only and exposes a reviewed investigation tool set. It doesn't request Datadog's `mcp_write` permission or expose Datadog tools that create or modify resources.
</Info>

<Note>
  This connector is independent of the Datadog [Alert Source](/alerts/alerts). The Alert Source sends Datadog alerts into Rootly. The Datadog MCP connector lets Rootly AI query Datadog on demand. You can configure both for the same Rootly team.
</Note>

## Before You Start

You need:

* A Datadog account with access to the data Rootly AI should query.
* Permission in Rootly to manage AI connectors.
* A supported Datadog site: US1, US3, US5, EU1, AP1, or AP2. Datadog's hosted MCP server isn't available for GovCloud.
* The Datadog role permissions listed below.

### Required: Allow Rootly's OAuth Callback

<Warning>
  Complete this prerequisite before starting OAuth. Otherwise, Datadog rejects the authorization request or can't return the user to Rootly.
</Warning>

A Datadog administrator must allowlist Rootly's callback URL before anyone connects with OAuth.

In Datadog, open **Organization Settings → Organization Preferences → MCP OAuth Redirect URLs** and add:

```text theme={null}
https://rootly.com/account/ai-sre/remote_mcp_sources/callback
```

If Rootly support gave you a different Rootly environment, replace `https://rootly.com` with that environment's base URL. Keep the `/account/ai-sre/remote_mcp_sources/callback` path unchanged.

## Required Permissions

The Datadog user authorizing OAuth needs these permissions through their role. Rootly requests the matching OAuth scopes.

| Capability | Datadog permission or OAuth scope |
| - | - |
| MCP data access | `mcp_read` |
| Metrics | `metrics_read`, `timeseries_query` |
| Monitors | `monitors_read` |
| APM traces and service catalog | `apm_read`, `apm_service_catalog_read` |
| Logs | `logs_read_data`, `logs_read_index_data` |
| RUM applications | `rum_apps_read` |
| Database Monitoring | `dbm_read` |

Datadog applies the authorizing user's role permissions in addition to the OAuth scopes. Rootly AI can't retrieve data the user can't access.

<Note>
  `dbm_parameterized_queries_read` is a valid Datadog role and application-key permission, but Datadog's MCP OAuth client doesn't authorize that scope. OAuth can investigate Database Monitoring metrics and spans with `dbm_read`; use API and application keys when an investigation needs parameterized query-pattern access.
</Note>

<Note>
  Rootly doesn't request `mcp_write`. A custom Datadog role only needs **MCP Read** and the resource-level read permissions for the data Rootly should access.
</Note>

### Additional Permissions for API and Application Keys

The key-based fallback validates the application key's scopes before saving the connection. The application key and the user or service account that owns it need every permission below:

This broader list intentionally preserves the existing key-based connector's legacy read surface for backward compatibility. Use OAuth when you want the smallest permission set supported by the Datadog MCP connector.

* `user_app_keys`
* `mcp_read`
* `apm_read`
* `apm_service_catalog_read`
* `containers_read`
* `logs_read_data`
* `logs_read_index_data`
* `monitors_read`
* `apm_api_catalog_read`
* `apm_pipelines_read`
* `apm_remote_configuration_read`
* `apm_retention_filter_read`
* `apm_service_ingest_read`
* `continuous_profiler_pgo_read`
* `continuous_profiler_read`
* `debugger_read`
* `dashboards_read`
* `dbm_parameterized_queries_read`
* `dbm_read`
* `error_tracking_read`
* `events_read`
* `logs_read_archives`
* `logs_read_config`
* `logs_read_workspaces`
* `metrics_read`
* `timeseries_query`
* `notebooks_read`
* `on_call_read`
* `rum_apps_read`
* `cd_visibility_read`
* `ci_visibility_read`
* `synthetics_default_settings_read`
* `synthetics_global_variable_read`
* `synthetics_private_location_read`
* `synthetics_read`
* `teams_read`

The API key identifies the Datadog organization and doesn't carry permissions. The `user_app_keys` permission lets Rootly inspect the submitted application key's scopes during setup.

***

## Connect Datadog With OAuth

Before continuing, confirm that a Datadog administrator completed [Required: Allow Rootly's OAuth Callback](#required-allow-rootlys-oauth-callback).

<Steps>
  <Step title="Open AI Connectors">
    In Rootly, go to **AI SRE → Atlas → Connectors** (**AI & Agents → Connectors** if your sidebar doesn't have an **AI SRE** item), find **Datadog MCP**, and click **Connect**. Enter a distinct **Connection name** for this organization.
  </Step>

  <Step title="Choose Your Datadog Site">
    Select the site that hosts your Datadog organization:

    | Site | API host | Stable MCP endpoint |
    | - | - | - |
    | US1 | `api.datadoghq.com` | `https://mcp.datadoghq.com/v1/mcp` |
    | US3 | `api.us3.datadoghq.com` | `https://mcp.us3.datadoghq.com/v1/mcp` |
    | US5 | `api.us5.datadoghq.com` | `https://mcp.us5.datadoghq.com/v1/mcp` |
    | EU1 | `api.datadoghq.eu` | `https://mcp.datadoghq.eu/v1/mcp` |
    | AP1 | `api.ap1.datadoghq.com` | `https://mcp.ap1.datadoghq.com/v1/mcp` |
    | AP2 | `api.ap2.datadoghq.com` | `https://mcp.ap2.datadoghq.com/v1/mcp` |

    Choose the site that matches your Datadog login URL. Each site has its own MCP and OAuth endpoints.
  </Step>

  <Step title="Start OAuth">
    Click **Connect with OAuth**. You don't need to create or share an API key, application key, client ID, or client secret.
  </Step>

  <Step title="Choose the Datadog Organization">
    Sign in to Datadog. If your account belongs to more than one organization, select the organization Rootly AI should query.
  </Step>

  <Step title="Authorize Rootly">
    Review the requested read permissions and authorize Rootly. Datadog returns you to Rootly after approval.
  </Step>

  <Step title="Confirm the Connection">
    Return to **AI SRE → Atlas → Connectors** (**AI & Agents → Connectors** if your sidebar doesn't have an **AI SRE** item). The Datadog MCP card shows **Connected** after Rootly validates the OAuth grant and Datadog tool catalog.
  </Step>
</Steps>

Rootly uses OAuth 2.0 with Dynamic Client Registration and Proof Key for Code Exchange (PKCE). Access and refresh credentials are encrypted at rest.

When you reauthorize an existing Datadog connection through **Configure**, Rootly keeps it active until the replacement authorization and validation succeed. Use **Add a connection** for another Datadog organization.

## Connect With API and Application Keys

Use this fallback when your organization can't complete the OAuth flow.

<Steps>
  <Step title="Create Scoped Datadog Keys">
    Create a Datadog API key and a scoped application key owned by a dedicated service account. Grant the application key and its owner every permission under [Additional Permissions for API and Application Keys](#additional-permissions-for-api-and-application-keys).
  </Step>

  <Step title="Open the Key Form">
    In Rootly, open **AI SRE → Atlas → Connectors** (**AI & Agents → Connectors** if your sidebar doesn't have an **AI SRE** item), find **Datadog MCP**, and click **Connect**. Enter a distinct **Connection name**, choose the correct Datadog site, then expand **Use API and application keys instead**.
  </Step>

  <Step title="Connect With Keys">
    Enter the API key and application key, then click **Connect with keys**. Rootly validates the credentials and application key permissions before saving the connection.
  </Step>
</Steps>

Rootly encrypts the API and application keys at rest.

***

## What Rootly AI Can Read

Rootly connects to Datadog's `core` MCP toolset and exposes reviewed, read-only investigation tools.

| Category | What Rootly AI can inspect |
| - | - |
| Services and environments | Service catalog entries and observed environment values used to scope later queries. |
| Logs | Bounded log searches, individual log details, counts, grouped signatures, and incident-to-baseline comparisons. |
| Metrics | Metric discovery, metadata and tags, timeseries values, contributor breakdowns, and matched-window comparisons. |
| APM | Bounded span searches and aggregations, slow-operation comparisons, and trace details. |
| Monitors | Monitor definitions and states filtered by query, tags, or environment. |
| RUM | Aggregated browser and mobile events for user-impact analysis. |
| Database signals | Blocking-condition, workload, and substrate comparisons when Datadog reports the required metrics and spans. Parameterized query-pattern access requires API and application keys. |

Rootly filters Datadog's upstream catalog before every call. A new tool added by Datadog doesn't become available automatically, and tools that write Datadog data remain blocked.

## Questions To Ask

Include a service, environment, and bounded time range when possible. These prompts work in Rootly AI SRE and the Slack agent:

* "Which services emitted new error log signatures in `prod` during the last 30 minutes compared with the preceding 30 minutes?"
* "Break down `checkout-api` p95 latency by resource for the incident window. Which endpoint regressed most against baseline?"
* "Find error spans for `payment-api` between 14:00 and 14:20 UTC, then expand the slowest trace and identify the failing dependency."
* "Did the checkout error-rate monitor alert because of one environment, region, or host? Show the metric contributors."
* "Compare blocked database sessions during the incident with the same window yesterday. Which wait type or query pattern changed?"
* "How many RUM checkout errors occurred in the incident window, grouped by browser and country?"
* "List the exact Datadog service and environment names before querying logs for the authentication failure."

If a broad question returns irrelevant results, add the exact service, environment, signal type, and UTC time range.

***

## Data Handling and Permissions

* **On-demand queries.** Rootly AI calls Datadog when an investigation or direct question needs current data.
* **Datadog permissions apply.** Results are limited by the OAuth user's role or the application key owner's access.
* **Read-only boundary.** Rootly requests read scopes and enforces a reviewed tool set before every call.
* **Encrypted credentials.** Rootly encrypts OAuth credentials and API or application keys at rest.
* **AI traces may contain results.** Datadog responses can appear in Rootly AI model and observability traces. See [Data Privacy for Rootly AI](/ai/data-privacy-for-rootly-ai) for retention details.
* **Datadog rate limits apply.** Investigation queries count against your Datadog organization's API limits.

## Manage the Connection

Open **AI SRE → Atlas → Connectors** (**AI & Agents → Connectors** if your sidebar doesn't have an **AI SRE** item) and find the Datadog MCP card.

* Click **Configure** to authorize a different Datadog organization, choose another site, or switch authentication methods. Rootly keeps the current connection active until the replacement is authorized and validated.
* Click **Disconnect** to remove the connection and stop future Datadog queries.

Disconnecting doesn't change or delete data in Datadog.

***

## Troubleshooting

<AccordionGroup>
  <Accordion title="Datadog rejects the OAuth redirect URL" icon="link">
    Ask a Datadog administrator to add Rootly's exact callback URL under **Organization Settings → Organization Preferences → MCP OAuth Redirect URLs**. The scheme, host, path, and trailing slash must match. For Rootly's production environment, use `https://rootly.com/account/ai-sre/remote_mcp_sources/callback` without a trailing slash.
  </Accordion>

  <Accordion title="Clicking the Datadog organization doesn't continue" icon="building">
    Confirm the callback URL is allowlisted in that Datadog organization, then restart the connection from Rootly. If you belong to several organizations, make sure you select the organization where an administrator added the callback URL.
  </Accordion>

  <Accordion title="Authorization finishes but the card isn't Connected" icon="plug-circle-xmark">
    Rootly validates the OAuth grant and required Datadog tools before replacing the current connection. Confirm the authorizing user has `mcp_read` and the resource-level permissions listed on this page, then connect again. A failed replacement leaves the previous working connection unchanged.
  </Accordion>

  <Accordion title="A query returns a permission error" icon="key">
    Confirm the OAuth user or application key owner has `mcp_read` plus the read permission for that resource. For example, monitor queries need `mcp_read` and `monitors_read`; log queries need `mcp_read`, `logs_read_data`, and `logs_read_index_data`.
  </Accordion>

  <Accordion title="The key-based connection can't inspect application-key permissions" icon="key">
    Grant `user_app_keys` to both the scoped application key and its owner, then connect again. Rootly rejects a key-based connection when it can't verify the application key's scopes.
  </Accordion>

  <Accordion title="The connection succeeds but queries return no data" icon="globe">
    Confirm you selected the Datadog site that contains the data. US1, US3, US5, EU1, AP1, and AP2 use different regional MCP endpoints. Click **Configure** on the connected Datadog MCP card and reconnect to change sites.
  </Accordion>

  <Accordion title="Some services or environments are missing" icon="filter">
    Rootly AI can only see data available to the OAuth user or application key owner. Check that identity's Datadog role, then retry with the exact service and environment names and a bounded time range.
  </Accordion>
</AccordionGroup>

***

## Frequently Asked Questions

<AccordionGroup>
  <Accordion title="Is the Datadog MCP connector the same as the Datadog Alert Source?" icon="shapes">
    No. The Alert Source ingests Datadog monitor alerts into Rootly. The Datadog MCP connector lets Rootly AI query Datadog during investigations. Most teams use both.
  </Accordion>

  <Accordion title="Does OAuth require Datadog API or application keys?" icon="key">
    No. Rootly registers an OAuth client and stores the resulting credentials. API and application keys are an independent fallback.
  </Accordion>

  <Accordion title="Can Rootly AI modify Datadog resources?" icon="shield">
    No. Rootly doesn't request `mcp_write`, and its reviewed Datadog tool set excludes resource creation, updates, and deletion.
  </Accordion>

  <Accordion title="Can I connect multiple Datadog organizations?" icon="building">
    Yes. Add a separate Datadog connection for each organization, and give each a distinct **Connection name** so investigations can select the right one. Use **Configure** on an existing connection when you need to replace its authorization.
  </Accordion>

  <Accordion title="Which Datadog sites are supported?" icon="globe">
    Rootly supports US1, US3, US5, EU1, AP1, and AP2. Datadog doesn't provide its hosted MCP server for GovCloud.
  </Accordion>

  <Accordion title="Does Rootly cache Datadog data?" icon="floppy-disk">
    Rootly queries Datadog on demand. Short-lived references may be cached within an investigation so Rootly AI can expand a selected log or trace safely.
  </Accordion>
</AccordionGroup>

***

## Related Pages

<CardGroup cols={2}>
  <Card title="AI Connectors" icon="sparkles" href="/ai/connectors/overview">
    Browse every data source Rootly AI can use during an investigation.
  </Card>

  <Card title="Datadog Alert Source" icon="bell" href="/integrations/datadog/datadog">
    Configure Datadog monitor alerts to create Rootly alerts.
  </Card>

  <Card title="Rootly AI Data Privacy" icon="shield" href="/ai/data-privacy-for-rootly-ai">
    Review encryption, retention, trace handling, and model controls.
  </Card>

  <Card title="Datadog MCP Server Setup" icon="arrow-up-right-from-square" href="https://docs.datadoghq.com/mcp_server/setup/">
    Review Datadog's MCP authentication, permissions, sites, and toolsets.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.