CCM
/MCP
SkillsMCPMarketplacesDigestToolsAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Sales & MarketingWeb & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web Crawling
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Skill index
  • MCP index
  • Marketplace index
  • Plugins Reference

Community

  • About
  • Tools
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by mertbuilds.com

Independent project, not affiliated with Anthropic
grafana avatar

Mcp Grafana

grafana/mcp-grafana
3.1kauthSTDIO, HTTPregistry active
Summary

Connects to Grafana instances (self-hosted or Cloud) via service account tokens and exposes dashboards, datasources, and query execution. You get CRUD operations on dashboards with JSONPath support for targeted updates, plus native querying against Prometheus, Loki, ClickHouse, CloudWatch, Athena, Snowflake, InfluxDB, and Graphite datasources. Most query tools are opt-in via flags to keep the surface area manageable. The run panel query feature lets you execute dashboard panel queries with custom time ranges and variable overrides. Useful when you want to pull observability data or modify dashboards programmatically without switching contexts to the Grafana UI. Requires Grafana 9.0 or later for full API support.

CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
inference shell
inference shell
create and run specialised agents in minutes
build now →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
inference shell
inference shell
create and run specialised agents in minutes
build now →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →

Grafana MCP server

Unit Tests Integration Tests E2E Tests Go Reference MCP Catalog

A [Model Context Protocol][mcp] (MCP) server for Grafana.

This provides access to your Grafana instance and the surrounding ecosystem.

Quick Start

Requires uv. Add the following to your MCP client configuration (e.g. Claude Desktop, Cursor):

{
  "mcpServers": {
    "grafana": {
      "command": "uvx",
      "args": ["mcp-grafana"],
      "env": {
        "GRAFANA_URL": "http://localhost:3000",
        "GRAFANA_SERVICE_ACCOUNT_TOKEN": "<your service account token>"
      }
    }
  }
}

For Grafana Cloud, replace GRAFANA_URL with your instance URL (e.g. https://myinstance.grafana.net). See Usage for more installation options including Docker, binary, and Helm.

Requirements

  • Grafana version 9.0 or later is required for full functionality. Some features, particularly datasource-related operations, may not work correctly with earlier versions due to missing API endpoints.

Features

The following features are currently available in MCP server. This list is for informational purposes only and does not represent a roadmap or commitment to future features.

Dashboards

  • Search for dashboards: Find dashboards by title or other metadata
  • Get dashboard by UID: Retrieve full dashboard details using its unique identifier. Warning: Large dashboards can consume significant context window space.
  • Get dashboard summary: Get a compact overview of a dashboard including title, panel count, panel types, variables, and metadata without the full JSON to minimize context window usage
  • Get dashboard property: Extract specific parts of a dashboard using JSONPath expressions (e.g., $.title, $.panels[*].title) to fetch only needed data and reduce context window consumption
  • Update or create a dashboard: Modify existing dashboards or create new ones. Warning: Requires full dashboard JSON which can consume large amounts of context window space.
  • Patch dashboard: Apply specific changes to a dashboard without requiring the full JSON, significantly reducing context window usage for targeted modifications
  • Get panel queries and datasource info: Get the title, query string, and datasource information (including UID and type, if available) from every panel in a dashboard

Run Panel Query

Note: Run panel query tools are disabled by default. To enable them, add runpanelquery to your --enabled-tools flag.

  • Run panel query: Execute a dashboard panel's query with custom time ranges and variable overrides.
Context Window Management

The dashboard tools now include several strategies to manage context window usage effectively (issue #101):

  • Use get_dashboard_summary for dashboard overview and planning modifications
  • Use get_dashboard_property with JSONPath when you only need specific dashboard parts
  • Avoid get_dashboard_by_uid unless you specifically need the complete dashboard JSON

Datasources

  • List and fetch datasource information: View all configured datasources and retrieve detailed information about each.
    • Supported datasource types: Prometheus, Loki, ClickHouse, CloudWatch, Elasticsearch, OpenSearch, Snowflake, Athena.

Query Examples

Note: Query examples tools are disabled by default. To enable them, add examples to your --enabled-tools flag.

  • Get query examples: Retrieve example queries for different datasource types to learn query syntax.

Prometheus Querying

  • Query Prometheus: Execute PromQL queries (supports both instant and range metric queries) against Prometheus datasources.
  • Query Prometheus metadata: Retrieve metric metadata, metric names, label names, and label values from Prometheus datasources.
  • Query histogram percentiles: Calculate histogram percentile values (p50, p90, p95, p99) using histogram_quantile.

Loki Querying

  • Query Loki logs and metrics: Run both log queries and metric queries using LogQL against Loki datasources.
  • Query Loki metadata: Retrieve label names, label values, and stream statistics from Loki datasources.
  • Query Loki patterns: Retrieve log patterns detected by Loki to identify common log structures and anomalies.

InfluxDB Querying

Note: InfluxDB tools are disabled by default. To enable them, add influxdb to your --enabled-tools flag.

  • Query InfluxDB: Execute queries against InfluxDB datasources using either InfluxQL (v1.x) or Flux (v2.x). The dialect is inferred from the datasource configuration, or can be set explicitly via the dialect parameter.

ClickHouse Querying

Note: ClickHouse tools are disabled by default. To enable them, add clickhouse to your --enabled-tools flag.

  • List ClickHouse tables: List all tables in a ClickHouse database with row counts and sizes.
  • Describe table schema: Get column names, types, and metadata for a ClickHouse table.
  • Query ClickHouse: Execute SQL queries with Grafana macro and variable substitution support.

CloudWatch Querying

Note: CloudWatch tools are disabled by default. To enable them, add cloudwatch to your --enabled-tools flag.

  • List CloudWatch namespaces: Discover available AWS CloudWatch namespaces.
  • List CloudWatch metrics: List metrics available in a specific namespace.
  • List CloudWatch dimensions: Get dimensions for filtering metric queries.
  • Query CloudWatch: Execute CloudWatch metric queries with time range support.

Graphite Querying

Note: Graphite tools are disabled by default. To enable them, add graphite to your --enabled-tools flag.

  • Query Graphite: Execute Graphite render API queries against a Graphite datasource.
  • List Graphite metrics: Browse and discover Graphite metric paths.
  • List Graphite tags: List available Graphite tags and tag values.
  • Query Graphite density: Query Graphite metric density for a given pattern.

Athena Querying

Note: Athena tools are disabled by default. To enable them, add athena to your --enabled-tools flag.

  • List Athena catalogs: Discover available data catalogs (e.g. AwsDataCatalog, Iceberg connectors).
  • List Athena databases: List databases in an Athena catalog.
  • List Athena tables: List tables in an Athena database.
  • Describe Athena table: Get column names for an Athena table.
  • Query Athena: Execute SQL queries against Amazon Athena via Grafana with macro substitution, limit enforcement, and template variable support.

Snowflake Querying

Note: Snowflake tools are disabled by default. To enable them, add snowflake to your --enabled-tools flag.

Queries go through Grafana's Snowflake datasource (Grafana Enterprise plugin grafana-snowflake-datasource), so authentication is handled by the datasource configuration in Grafana — credentials are never seen by the MCP server. This is the same model used for the ClickHouse tools.

  • List Snowflake tables: Discover tables (with database, schema, kind, row count, and size) via INFORMATION_SCHEMA.TABLES. Optional database/schema filters.
  • Describe table schema: Get column names, data types, nullability, defaults, and comments for a Snowflake table.
  • Query Snowflake: Execute SQL queries with macro and variable substitution support. Useful for querying Snowflake's event tables (e.g. SNOWFLAKE.TELEMETRY.EVENTS) for logs and traces, or any user table.
    • Supported macros: $__timeFilter(column), $__timeFrom, $__timeTo, $__from, $__to (Unix ms), $__interval (seconds), $__interval_ms, and ${varname} for template variable substitution.

Elasticsearch/OpenSearch Querying

Note: Elasticsearch/OpenSearch tools are disabled by default. To enable them, add elasticsearch to your --enabled-tools flag.

  • Query Elasticsearch/OpenSearch: Execute search queries against Elasticsearch or OpenSearch datasources using either Lucene query syntax or Elasticsearch Query DSL. Supports filtering by time range and retrieving logs, metrics, or any indexed data. Returns documents with their index, ID, source fields, and optional relevance score.

Quickwit Querying

Note: Quickwit tools are disabled by default. To enable them, add quickwit to your --enabled-tools flag.

  • Query Quickwit: Execute search queries against Quickwit datasources using Lucene query syntax or partial Elasticsearch-compatible Query DSL. Supports filtering by time range and retrieving logs or other indexed documents. Returns documents with their index, ID, source fields, and optional relevance score.

Agent Observability

Note: Agent Observability tools are disabled by default and work only in Grafana Cloud. To enable them, add agento11y to your --enabled-tools flag.

  • List and search conversations: List recent LLM conversations or search them with a filter expression (model, provider, agent, status, error type, eval results, and more) over a time range. Search results include error counts, rating summaries, evaluation summaries, and trace IDs.
  • Get conversation detail: Fetch a single conversation with all its generations, including prompts and outputs.
  • Get generation detail and scores: Fetch a single generation by ID, and its evaluation scores (evaluator, score key, value, passed, explanation).
  • Read the agent catalog: List the agents that send telemetry, fetch one agent version in full (complete system prompt, every tool with its JSON schema, and the models it ran on), walk an agent's version history, and compare evaluation score aggregates per version. Effective versions are sha256: hashes that a tool change never affects; for an agent that reports no version of its own they hash the system prompt, so a prompt edit mints a new version. Catalog and version rows carry a token_estimate, which is worth checking before fetching a full prompt.
  • Inspect evaluators and templates: Read the evaluators a score came from, the templates they were derived from, and the judge providers and models available to LLM-judge evaluators. With write tools enabled, also create, fork, test, and delete evaluators.
  • Inspect eval rules and guards: Read the asynchronous eval rules that bind evaluators to production traffic, and the guards (hook rules) that run inline and can warn or deny. With write tools enabled, also create, update, preview, and delete them. Writes and the non-persisting preview_rule and test_evaluator operations need the grafana-agento11y-app.eval:write permission, granted by the Agento11y Admin role.
  • Curate saved conversations and collections: Read the saved conversations (bookmarks that give a conversation a stable ID, name, and tags) and the collections that group them, including each collection's member count and the collections embedded in every saved-conversation row. With write tools enabled, also bookmark a conversation, create and edit collections, and add or remove members. These writes need the same grafana-agento11y-app.eval:write permission.
  • Read and edit test suites: List the versioned test suites that offline experiments run against, read one with its full version history, and page through the test cases of a version. With write tools enabled, also create a suite, rename or retag it, open a draft version, publish it, and write or delete its test cases. A published version is frozen, so an edit means opening a new draft. These writes need grafana-agento11y-app.eval:write.
  • Read offline experiments: List the evaluation runs over a test suite and read one with its headline pass rate, cost, and token totals. Drill down through a per-test-case report to trials, their scores with each judge's explanation, and their artifact metadata. With write tools enabled, also rename or retag an experiment and cancel a running one, which need grafana-agento11y-app.eval:write. Experiments are created by SDK runners, not by this tool.

Grafana Assistant

Note: Assistant tools are disabled by default and require the Grafana Assistant plugin (grafana-assistant-app) to be installed on the target Grafana instance. They are also write tools (the assistant may mutate stack state), so they are skipped when --disable-write is set. To enable them, add assistant to your --enabled-tools flag.

  • Ask the assistant: Send a natural-language prompt to Grafana Assistant and wait for the full text reply. The assistant may use tools, metrics, logs, and other stack context—broader than firing one isolated data-source query. Pass the returned contextId back in a follow-up call to continue the same conversation. Complex tasks can take several minutes; the call blocks until the reply is done or the request times out (5 minutes).

Incidents

  • Search, create, and update incidents: Manage incidents in Grafana Incident, including searching, creating, adding activities, and reading or setting custom fields.

Sift Investigations

  • List Sift investigations: Retrieve a list of Sift investigations, with support for a limit parameter.
  • Get Sift investigation: Retrieve details of a specific Sift investigation by its UUID.
  • Get Sift analyses: Retrieve a specific analysis from a Sift investigation.
  • Find error patterns in logs: Detect elevated error patterns in Loki logs using Sift.
  • Find slow requests: Detect slow requests using Sift (Tempo).

Alerting

  • List and fetch alert rule information: View alert rules and their statuses (firing/normal/error/etc.) in Grafana. Supports both Grafana-managed rules and datasource-managed rules from Prometheus or Loki datasources.
  • Create and update alert rules: Create new alert rules or modify existing ones.
  • Delete alert rules: Remove alert rules by UID.
  • Manage alerting routing: View notification policies, contact points, and time intervals. Supports both Grafana-managed contact points and receivers from external Alertmanager datasources (Prometheus Alertmanager, Mimir, Cortex).

Grafana OnCall

  • List and manage schedules: View and manage on-call schedules in Grafana OnCall.
  • Get shift details: Retrieve detailed information about specific on-call shifts.
  • Get current on-call users: See which users are currently on call for a schedule.
  • List teams and users: View all OnCall teams and users.
  • List alert groups: View and filter alert groups from Grafana OnCall by various criteria including state, integration, labels, and time range.
  • Get alert group details: Retrieve detailed information about a specific alert group by its ID.

Admin

Note: Admin tools are disabled by default. To enable them, include admin in your --enabled-tools flag.

  • List teams: View all configured teams in Grafana.
  • List Users: View all users in an organization in Grafana.
  • List all roles: List all Grafana roles, with an optional filter for delegatable roles.
  • Get role details: Get details for a specific Grafana role by UID.
  • List assignments for a role: List all users, teams, and service accounts assigned to a role.
  • List roles for users: List all roles assigned to one or more users.
  • List roles for teams: List all roles assigned to one or more teams.
  • List permissions for a resource: List all permissions defined for a specific resource (dashboard, datasource, folder, etc.).
  • Describe a Grafana resource: List available permissions and assignment capabilities for a resource type.

User

  • User info: Get the current Grafana identity — login, email, name, whether it is a Grafana (server) admin, the current organization, and the organizations the credential can access (with roles). Use it to discover valid orgId values for multi-organization requests.

Navigation

  • Generate deeplinks: Create accurate deeplink URLs for Grafana resources instead of relying on LLM URL guessing.
    • Dashboard links: Generate direct links to dashboards using their UID (e.g., http://localhost:3000/d/dashboard-uid)
    • Panel links: Create links to specific panels within dashboards with viewPanel parameter (e.g., http://localhost:3000/d/dashboard-uid?viewPanel=5)
    • Explore links: Generate links to Grafana Explore with pre-configured datasources (e.g., http://localhost:3000/explore?left={"datasource":"prometheus-uid"})
    • Time range support: Add time range parameters to links (from=now-1h&to=now)
    • Custom parameters: Include additional query parameters like dashboard variables or refresh intervals

Annotations

  • Get Annotations: Query annotations with filters. Supports time range, dashboard UID, tags, and match mode.
  • Create Annotation: Create a new annotation on a dashboard or panel.
  • Create Graphite Annotation: Create annotations using Graphite format (what, when, tags, data).
  • Update Annotation: Replace all fields of an existing annotation (full update).
  • Patch Annotation: Update only specific fields of an annotation (partial update).
  • Get Annotation Tags: List available annotation tags with optional filtering.

Snapshots

  • List snapshots: List dashboard snapshots with optional query and limit filters.
  • Get snapshot: Retrieve snapshot metadata and dashboard payload by snapshot key.
  • Create snapshot: Create a dashboard snapshot from a full dashboard payload, with optional expiration and external snapshot options.
  • Delete snapshot: Delete a snapshot by snapshot key.

Rendering

  • Get panel or dashboard image: Render a Grafana dashboard panel or full dashboard as a PNG image. Returns the image as base64 encoded data for use in reports, alerts, or presentations. Supports customizing dimensions, time range, theme, scale, and dashboard variables. Also supports rendering not-yet-applied dashboards from a provisioning repository branch (e.g. a git-sync PR preview) via the optional provisioningPreview parameter.
    • Note: Requires the Grafana Image Renderer service to be installed and configured.

Provisioning

  • List provisioning repositories: List provisioning repositories configured for this Grafana instance (e.g. git-sync sources), returning each repository's slug along with its source URL, branch, path, sync state, and health.
  • Validate provisioning file: Dry-run-apply a file from a provisioning repository at a given branch or commit. Returns whether it would be accepted, the resource action (create/update), the target resource type, and any structured validation errors — the same admission surface Grafana's PR commenter uses.

The list of tools is configurable, so you can choose which tools you want to make available to the MCP client. This is useful if you don't use certain functionality or if you don't want to take up too much of the context window. To disable a category of tools, use the --disable-<category> flag when starting the server. For example, to disable the OnCall tools, use --disable-oncall, or to disable navigation deeplink generation, use --disable-navigation.

RBAC Permissions

Each tool requires specific RBAC permissions to function properly. When creating a service account for the MCP server, ensure it has the necessary permissions based on which tools you plan to use. The permissions listed are the minimum required actions - you may also need appropriate scopes (e.g., datasources:*, dashboards:*, folders:*) depending on your use case.

Tip: If you're not familiar with Grafana RBAC or you want a quicker, simpler setup instead of configuring many granular scopes, you can assign a built-in role such as Editor to the service account. The Editor role grants broad read/write access that will allow most MCP server operations; it is less granular (and therefore less restrictive) than manually-applied scopes, so use it only when convenience is more important than strict least-privilege access.

Note: Grafana Incident and Sift tools use basic Grafana roles instead of fine-grained RBAC permissions:

  • Viewer role: Required for read-only operations (list incidents, get investigations)
  • Editor role: Required for write operations (create incidents, modify investigations)

For more information about Grafana RBAC, see the official documentation.

RBAC Scopes

Scopes define the specific resources that permissions apply to. Each action requires both the appropriate permission and scope combination.

Common Scope Patterns:

  • Broad access: Use * wildcards for organization-wide access

    • datasources:* - Access to all datasources
    • dashboards:* - Access to all dashboards
    • folders:* - Access to all folders
    • teams:* - Access to all teams
  • Limited access: Use specific UIDs or IDs to restrict access to individual resources

    • datasources:uid:prometheus-uid - Access only to a specific Prometheus datasource
    • dashboards:uid:abc123 - Access only to dashboard with UID abc123
    • folders:uid:xyz789 - Access only to folder with UID xyz789
    • teams:id:5 - Access only to team with ID 5
    • global.users:id:123 - Access only to user with ID 123

Examples:

  • Full MCP server access: Grant broad permissions for all tools

    datasources:* (datasources:read, datasources:query)
    dashboards:* (dashboards:read, dashboards:create, dashboards:write)
    folders:* (for dashboard creation and alert rules)
    teams:* (teams:read)
    global.users:* (users:read)
    
  • Limited datasource access: Only query specific Prometheus and Loki instances

    datasources:uid:prometheus-prod (datasources:query)
    datasources:uid:loki-prod (datasources:query)
    
  • Dashboard-specific access: Read only specific dashboards

    dashboards:uid:monitoring-dashboard (dashboards:read)
    dashboards:uid:alerts-dashboard (dashboards:read)
    

Tools

ToolCategoryDescriptionRequired RBAC PermissionsRequired Scopes
list_teamsAdminList all teamsteams:readteams:* or teams:id:1
list_users_by_orgAdminList all users in an organizationusers:readglobal.users:* or global.users:id:123
list_all_rolesAdminList all Grafana rolesroles:readroles:*
get_role_detailsAdminGet details for a Grafana roleroles:readroles:uid:editor
get_role_assignmentsAdminList assignments for a roleroles:readroles:uid:editor
list_user_rolesAdminList roles for usersroles:readglobal.users:id:123
list_team_rolesAdminList roles for teamsroles:readteams:id:7
get_resource_permissionsAdminList permissions for a resourcepermissions:readdashboards:uid:abcd1234
get_resource_descriptionAdminDescribe a Grafana resource typepermissions:readdashboards:*
user_infoUserCurrent identity, capabilities, and accessible organizationsNone (signed-in user)—
search_dashboardsSearchSearch for dashboardsdashboards:readdashboards:* or dashboards:uid:abc123
get_dashboard_by_uidDashboardGet a dashboard by uiddashboards:readdashboards:uid:abc123
update_dashboardDashboardUpdate or create a new dashboarddashboards:create, dashboards:writedashboards:*, folders:* or folders:uid:xyz789
get_dashboard_panel_queriesDashboardGet panel title, queries, datasource UID and type from a dashboarddashboards:readdashboards:uid:abc123
run_panel_queryRunPanelQuery*Execute one or more dashboard panel queriesdashboards:read, datasources:querydashboards:uid:*, datasources:uid:*
get_dashboard_propertyDashboardExtract specific parts of a dashboard using JSONPath expressionsdashboards:readdashboards:uid:abc123
get_dashboard_summaryDashboardGet a compact summary of a dashboard without full JSONdashboards:readdashboards:uid:abc123
list_datasourcesDatasourcesList datasourcesdatasources:readdatasources:*
get_datasourceDatasourcesGet a datasource by UID or namedatasources:readdatasources:uid:prometheus-uid
get_query_examplesExamples*Get example queries for a datasource typedatasources:readdatasources:*
query_prometheusPrometheusExecute a query against a Prometheus datasourcedatasources:querydatasources:uid:prometheus-uid
list_prometheus_metric_metadataPrometheusList metric metadatadatasources:querydatasources:uid:prometheus-uid
list_prometheus_metric_namesPrometheusList available metric namesdatasources:querydatasources:uid:prometheus-uid
list_prometheus_label_namesPrometheusList label names matching a selectordatasources:querydatasources:uid:prometheus-uid
list_prometheus_label_valuesPrometheusList values for a specific labeldatasources:querydatasources:uid:prometheus-uid
query_prometheus_histogramPrometheusCalculate histogram percentile valuesdatasources:querydatasources:uid:prometheus-uid
list_incidentsIncidentList incidents in Grafana Incident, optionally with their custom field valuesViewer roleN/A
create_incidentIncidentCreate an incident in Grafana Incident, optionally setting custom fieldsEditor roleN/A
add_activity_to_incidentIncidentAdd an activity item to an incident in Grafana IncidentEditor roleN/A
update_incidentIncidentUpdate an incident in Grafana Incident (status, severity, title, or custom fields)Editor roleN/A
get_incidentIncidentGet a single incident by ID, including its custom fieldsViewer roleN/A
list_incident_custom_fieldsIncidentList the custom fields configured for incidents, with their types and select optionsViewer roleN/A
query_loki_logsLokiQuery and retrieve logs using LogQL (either log or metric queries)datasources:querydatasources:uid:loki-uid
list_loki_label_namesLokiList all available label names in logsdatasources:querydatasources:uid:loki-uid
list_loki_label_valuesLokiList values for a specific log labeldatasources:querydatasources:uid:loki-uid
query_loki_statsLokiGet statistics about log streamsdatasources:querydatasources:uid:loki-uid
query_loki_patternsLokiQuery detected log patterns to identify common structuresdatasources:querydatasources:uid:loki-uid
analyze_loki_labelsLokiAudit a Loki label strategy (live or static) and optionally diagnose query performancedatasources:querydatasources:uid:loki-uid
suggest_loki_alloy_label_configConfigGenerate an Alloy loki.process snippet enforcing approved labelsN/AN/A
query_influxdbInfluxDBQuery InfluxDB using InfluxQL (v1) or Flux (v2)datasources:querydatasources:uid:influxdb-uid
list_clickhouse_tablesClickHouse*List tables in a ClickHouse databasedatasources:querydatasources:uid:*
describe_clickhouse_tableClickHouse*Get table schema with column typesdatasources:querydatasources:uid:*
query_clickhouseClickHouse*Execute SQL queries with macro substitutiondatasources:querydatasources:uid:*
list_cloudwatch_namespacesCloudWatch*List available AWS CloudWatch namespacesdatasources:querydatasources:uid:*
list_cloudwatch_metricsCloudWatch*List metrics in a namespacedatasources:querydatasources:uid:*
list_cloudwatch_dimensionsCloudWatch*List dimensions for a metricdatasources:querydatasources:uid:*
query_cloudwatchCloudWatch*Execute CloudWatch metric queriesdatasources:querydatasources:uid:*
list_athena_catalogsAthena*List available Athena data catalogsdatasources:querydatasources:uid:*
list_athena_databasesAthena*List databases in an Athena catalogdatasources:querydatasources:uid:*
list_athena_tablesAthena*List tables in an Athena databasedatasources:querydatasources:uid:*
describe_athena_tableAthena*Get column names for an Athena tabledatasources:querydatasources:uid:*
query_athenaAthena*Execute SQL queries with macro substitutiondatasources:querydatasources:uid:*
query_elasticsearchElasticsearch/OpenSearch*Query Elasticsearch or OpenSearch using Lucene syntax or Query DSLdatasources:querydatasources:uid:datasource-uid
query_quickwitQuickwit*Query Quickwit using Lucene syntax or Query DSLdatasources:querydatasources:uid:quickwit-uid
list_snowflake_tablesSnowflake*List tables in a Snowflake database/schema via INFORMATION_SCHEMAdatasources:querydatasources:uid:*
describe_snowflake_tableSnowflake*Get table schema (column types, nullability, defaults, comments)datasources:querydatasources:uid:*
query_snowflakeSnowflake*Execute SQL queries with macro/variable substitutiondatasources:querydatasources:uid:*
alerting_manage_rulesAlertingManage alert rules (list, get, versions, create, update, delete)alert.rules:read + alert.rules:write for mutationsfolders:* or folders:uid:alerts-folder
alerting_manage_routingAlertingManage notification policies, contact points, and time intervalsalert.notifications:readGlobal scope
alerting_manage_silencesAlertingManage alerting silences (list, get, create, update, expire)alert.instances:read + alert.instances:write for mutationsGlobal scope
list_oncall_schedulesOnCallList schedules from Grafana OnCallgrafana-oncall-app.schedules:readPlugin-specific scopes
get_oncall_shiftOnCallGet details for a specific OnCall shiftgrafana-oncall-app.schedules:readPlugin-specific scopes
get_current_oncall_usersOnCallGet users currently on-call for a specific schedulegrafana-oncall-app.schedules:readPlugin-specific scopes
list_oncall_teamsOnCallList teams from Grafana OnCallgrafana-oncall-app.user-settings:readPlugin-specific scopes
list_oncall_usersOnCallList users from Grafana OnCallgrafana-oncall-app.user-settings:readPlugin-specific scopes
list_alert_groupsOnCallList alert groups from Grafana OnCall with filtering optionsgrafana-oncall-app.alert-groups:readPlugin-specific scopes
get_alert_groupOnCallGet a specific alert group from Grafana OnCall by its IDgrafana-oncall-app.alert-groups:readPlugin-specific scopes
update_alert_groupOnCallAcknowledge, unacknowledge, resolve, or unresolve an alert groupgrafana-oncall-app.alert-groups:write (and :read)Plugin-specific scopes
get_sift_investigationSiftRetrieve an existing Sift investigation by its UUIDViewer roleN/A
get_sift_analysisSiftRetrieve a specific analysis from a Sift investigationViewer roleN/A
list_sift_investigationsSiftRetrieve a list of Sift investigations with an optional limitViewer roleN/A
find_error_pattern_logsSiftFinds elevated error patterns in Loki logs.Editor roleN/A
find_slow_requestsSiftFinds slow requests from the relevant tempo datasources.Editor roleN/A
list_pyroscope_label_namesPyroscopeList label names matching a selectordatasources:querydatasources:uid:pyroscope-uid
list_pyroscope_label_valuesPyroscopeList label values matching a selector for a label namedatasources:querydatasources:uid:pyroscope-uid
list_pyroscope_profile_typesPyroscopeList available profile typesdatasources:querydatasources:uid:pyroscope-uid
query_pyroscopePyroscopeQuery profiles, metrics, or both from Pyroscopedatasources:querydatasources:uid:pyroscope-uid
get_assertionsAssertsGet assertion summary for a given entityPlugin-specific permissionsPlugin-specific scopes
agento11y_manage_conversationsAgent Observability*List, search, and fetch LLM conversations from Grafana Agent Observabilitygrafana-agento11y-app.conversations:readN/A
agento11y_manage_generationsAgent Observability*Fetch LLM generation details and evaluation scores from Grafana Agent Observabilitygrafana-agento11y-app.data:readN/A
agento11y_manage_agentsAgent Observability*Read the agent catalog: list agents, get one agent version in full, list version history, and per-version score aggregatesgrafana-agento11y-app.data:readN/A
agento11y_manage_evaluatorsAgent Observability*Manage evaluators, evaluator templates, and the judge catalog (list, get, upsert, fork, test, delete)grafana-agento11y-app.data:read + grafana-agento11y-app.eval:write for mutations and testsN/A
agento11y_manage_eval_rulesAgent Observability*Manage eval rules and guards (list, get, create, update, preview, delete)grafana-agento11y-app.data:read + grafana-agento11y-app.eval:write for mutations and previewsN/A
agento11y_manage_eval_collectionsAgent Observability*Manage saved conversations and the collections that group them (list, get, save, create, update, delete, add and remove members)grafana-agento11y-app.data:read + grafana-agento11y-app.eval:write for mutationsN/A
agento11y_manage_experimentsAgent Observability*Read offline experiments, their trials, scores, artifact metadata, and filter facets; update and cancel an experimentgrafana-agento11y-app.data:read + grafana-agento11y-app.eval:write for mutationsN/A
agento11y_manage_test_suitesAgent Observability*Manage the test suites that offline experiments run against, their versions, and their test cases (list, get, create, update, draft, publish, upsert, delete)grafana-agento11y-app.data:read + grafana-agento11y-app.eval:write for mutationsN/A
ask_assistantAssistant*Send a prompt to Grafana Assistant and return the full text reply (multi-turn via contextId)Plugin-specific permissionsPlugin-specific scopes
generate_deeplinkNavigationGenerate accurate deeplink URLs for Grafana resourcesNone (read-only URL generation)N/A
get_annotationsAnnotationsFetch annotations with filtersannotations:readannotations:* or annotations:id:123
create_annotationAnnotationsCreate a new annotation (standard or Graphite format)annotations:writeannotations:*
update_annotationAnnotationsUpdate specific fields of an annotation (partial update)annotations:writeannotations:*
get_annotation_tagsAnnotationsList annotation tags with optional filteringannotations:readannotations:*
list_snapshotsSnapshotList dashboard snapshots with optional query and limit filtersdashboards:readdashboards:* or dashboards:uid:abc123
get_snapshotSnapshotGet snapshot metadata and dashboard payload by snapshot keydashboards:readdashboards:* or dashboards:uid:abc123
create_snapshotSnapshotCreate a dashboard snapshot from a full dashboard payloaddashboards:writedashboards:* or dashboards:uid:abc123
delete_snapshotSnapshotDelete a dashboard snapshot by snapshot keydashboards:writedashboards:* or dashboards:uid:abc123
get_panel_imageRenderingRender a stored dashboard or panel — or a provisioning preview from a repository branch — as a PNG imagedashboards:readdashboards:uid:abc123
list_provisioning_repositoriesProvisioningList provisioning repositories (e.g. git-sync sources) with their source URL, branch, sync state, and healthprovisioning.repositories:readN/A
validate_provisioning_fileProvisioningDry-run-apply a file from a provisioning repository and report admission validation errorsprovisioning.repositories:readN/A
search_docsDocsSearch Grafana documentation or list product groups (omit query to list products)None (public grafana.com/docs)N/A
get_docDocsFetch a documentation page; set outline_only for headings, or section for bounded retrievalNone (public grafana.com/docs)N/A

* Disabled by default. Add category to --enabled-tools to enable.

CLI Flags Reference

The mcp-grafana binary supports various command-line flags for configuration:

Transport Options:

  • -t, --transport: Transport type (stdio, sse, or streamable-http) - default: stdio
  • --address: The host and port for SSE/streamable-http server - default: localhost:8000
  • --base-path: Base path for the SSE/streamable-http server
  • --endpoint-path: Endpoint path for the streamable-http server - default: /mcp
  • --server-name: Server name used in the MCP handshake and OTel service.name - default: mcp-grafana. Overrides GRAFANA_MCP_SERVER_NAME env var

HTTP Transport Security (SSE / streamable-http only):

Host/Origin validation is enforced on every route on the listener — /sse, /mcp, /healthz, and /metrics — so a DNS-rebinding browser cannot reach any of them. Stdio transport is unaffected.

  • --allowed-hosts: Comma-separated allowlist of Host header values. Defaults to loopback variants of --address (e.g. localhost:8000,127.0.0.1:8000,[::1]:8000). A value that parses to empty (unset, ,, ,, etc.) also falls back to the defaults so a typo cannot silently disable the check. Requests with a Host header outside the allowlist are rejected with 403. Pass * to disable the check — only safe when running behind a trusted reverse proxy that rewrites Host, or in an isolated network. K8s httpGet probes and external /metrics scrapes will need either an explicit hostname in this list, *, or a tcpSocket probe / a separate metrics port (--metrics-address).
  • --allowed-origins: Comma-separated allowlist of Origin header values. Empty by default — any request that carries an Origin header is rejected (browsers always send one for cross-origin requests, and no browser should be calling this server directly). Set to an explicit list to permit browser-based clients, or * to disable the check.

Caller Authentication (SSE / streamable-http only):

Optionally require MCP clients to authenticate to the server. This is separate from the credentials the server uses to reach Grafana. Stdio is unaffected.

  • --server-auth-token: Bearer token callers must send as Authorization: Bearer <token>. Falls back to the MCP_GRAFANA_SERVER_TOKEN environment variable. When set, requests without a valid token are rejected with 401 before any tool runs. Prefer the env var so the secret isn't visible in the process arguments.

Caller authentication is enforced only when --server-auth-token is set. When it isn't and the server binds a non-loopback address, the server starts but logs a security error — emitted at the error log level so it isn't hidden by --log-level (loopback and stdio are unaffected); a future major release will make that a startup error. Use TLS (or TLS termination) whenever caller auth is enabled on a non-loopback address. When caller auth is enabled, the validated Authorization header is stripped before requests reach Grafana; combining --server-auth-token with GRAFANA_FORWARD_HEADERS=Authorization is rejected at startup.

Debug and Logging:

  • --debug: Enable debug mode for detailed HTTP request/response logging
  • --log-level: Log level (debug, info, warn, error) - default: info

Grafana Client Options:

  • --grafana-timeout: Time limit for requests made by the Grafana client. Accepts Go duration strings (e.g., 10s, 500ms) - default: 10s
  • --include-args-in-spans: Include tool call arguments in OpenTelemetry spans. Only enable in non-production environments or when arguments are known not to contain PII - default: false

Observability:

  • --metrics: Enable Prometheus metrics endpoint at /metrics
  • --metrics-address: Separate address for metrics server (e.g., :9090). If empty, metrics are served on the main server
  • --slow-request-threshold: Log an event when any MCP request (tool invocation, list, resource read, etc.) takes longer than this duration. Accepts Go duration strings (e.g., 500ms, 5s). Default 0 disables slow-request logging. See the Slow-request logging section.
  • --slow-request-log-level: Log level for slow-request events (info or warn) - default: warn.

Session Management:

  • --session-idle-timeout-minutes: Session idle timeout in minutes. Sessions with no activity for this duration are automatically reaped - default: 30. Set to 0 to disable session reaping. Only relevant for SSE and streamable-http transports.

View the full README on GitHub

Featured
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
inference shell
inference shell
create and run specialised agents in minutes
build now →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →

Configuration

GRAFANA_URL*

URL to your Grafana instance

GRAFANA_SERVICE_ACCOUNT_TOKENsecret

Service account token used to authenticate with your Grafana instance

GRAFANA_USERNAME

Username to authenticate with your Grafana instance

GRAFANA_PASSWORDsecret

Password to authenticate with your Grafana instance

GRAFANA_ORG_ID

Organization ID for multi-org support. Can also be set via X-Grafana-Org-Id header in SSE/streamable HTTP transports.

GRAFANA_EXTRA_HEADERS

JSON object of additional HTTP headers to send with all Grafana API requests

GRAFANA_FORWARD_HEADERS

Comma-separated list of HTTP header names to forward from the incoming request to Grafana (SSE/streamable-http only). Example: Cookie,X-Session-Id

Categories
Monitoring & ObservabilityData & Analytics
Registryactive
Packagedocker.io/grafana/mcp-grafana:0.15.2
TransportSTDIO, HTTP
AuthRequired
UpdatedJun 4, 2026
View on GitHub

Related Monitoring & Observability MCP Servers

View all →
googleanalytics avatar
Analytics

googleanalytics/google-analytics-mcp

Provides access to Google Analytics data and reports via an MCP API surface.
2.1k
getsentry avatar
Sentry Mcp

getsentry/sentry-mcp

MCP server for Sentry - error monitoring, issue tracking, and debugging for AI assistants
724
pab1it0 avatar
Prometheus MCP Server

pab1it0/prometheus-mcp-server

MCP server providing Prometheus metrics access and PromQL query execution for AI assistants
457
surendranb avatar
Google Analytics Mcp

surendranb/google-analytics-mcp

An MCP server that provides [describe what your server does]
214
winor30 avatar
Datadog

winor30/mcp-server-datadog

exposes Datadog APIs for incidents, monitors, logs, dashboards, metrics, traces, hosts, and RUM via MCP tools.
142
livehybrid avatar
Splunk

livehybrid/splunk-mcp

A Model Context Protocol (MCP) implementation for Splunk Enterprise and Cloud integration with Cursor IDE or Claude
104