An MCP server giving access to Grafana dashboards, data and more.
A [Model Context Protocol][mcp] (MCP) server for Grafana.
This provides access to your Grafana instance and the surrounding ecosystem.
Requires uv. Add the following to your MCP client configuration (e.g. Claude Desktop, Cursor):
{
"mcpServers": {
"grafana": {
"command": "uvx",
"args": ["mcp-grafana"],
"env": {
"GRAFANA_URL": "http://localhost:3000",
"GRAFANA_SERVICE_ACCOUNT_TOKEN": "<your service account token>"
}
}
}
}
For Grafana Cloud, replace GRAFANA_URL with your instance URL (e.g. https://myinstance.grafana.net). See Usage for more installation options including Docker, binary, and Helm.
The following features are currently available in MCP server. This list is for informational purposes only and does not represent a roadmap or commitment to future features.
version to load a saved snapshot instead of the current dashboard. Warning: Large dashboards can consume significant context window space.$.title, $.panels[*].title) to fetch only needed data and reduce context window consumptionNote: Run panel query tools are disabled by default. To enable them, add
runpanelqueryto your--enabled-toolsflag.
The dashboard tools now include several strategies to manage context window usage effectively (issue #101):
get_dashboard_summary for dashboard overview and planning modificationsget_dashboard_property with JSONPath when you only need specific dashboard partsget_dashboard_by_uid unless you specifically need the complete dashboard JSONNote: Query examples tools are disabled by default. To enable them, add
examplesto your--enabled-toolsflag.
Note: InfluxDB tools are disabled by default. To enable them, add
influxdbto your--enabled-toolsflag.
dialect parameter.Note: SQL tools are disabled by default. To enable them, add
sqlto your--enabled-toolsflag. Back-compat aliasesclickhouse,snowflake, andathenaalso work.
Unified SQL tools support ClickHouse, Snowflake, Athena, MySQL, PostgreSQL, and MSSQL through a single set of tools. Queries go through Grafana's datasource plugins, so authentication is handled by datasource configuration — credentials are never seen by the MCP server.
$__timeFilter(col), $__from/$__to, $__interval, ${varname}), automatic limit enforcement, and template variable support.Note: CloudWatch tools are disabled by default. To enable them, add
cloudwatchto your--enabled-toolsflag.
Note: Google Cloud Logging tools are disabled by default. To enable them, add
cloudloggingto your--enabled-toolsflag. Requires the Google Cloud Logging datasource plugin (googlecloud-logging-datasource) version 1.8.0 or later, which needs Grafana 11.2+. Older plugin versions return a different response layout andquery_cloud_loggingreports an error asking for an upgrade.
resource.type="k8s_container" AND severity>=ERROR) with time range and limit; returns entries newest-first with severity, body, labels, and trace ID. GCP authentication is handled by the datasource configuration.Note: Graphite tools are disabled by default. To enable them, add
graphiteto your--enabled-toolsflag.
Note: Elasticsearch/OpenSearch tools are disabled by default. To enable them, add
elasticsearchto your--enabled-toolsflag.
Note: Quickwit tools are disabled by default. To enable them, add
quickwitto your--enabled-toolsflag.
Note: Agent Observability tools are disabled by default and work only in Grafana Cloud. To enable them, add
agento11yto your--enabled-toolsflag.
sha256: hashes that a tool change never affects; for an agent that reports no version of its own they hash the system prompt, so a prompt edit mints a new version. Catalog and version rows carry a token_estimate, which is worth checking before fetching a full prompt.preview_rule and test_evaluator operations need the grafana-agento11y-app.eval:write permission, granted by the Agento11y Admin role.grafana-agento11y-app.eval:write permission.grafana-agento11y-app.eval:write.grafana-agento11y-app.eval:write. Experiments are created by SDK runners, not by this tool.Note: Assistant tools are disabled by default and require the Grafana Assistant plugin (
grafana-assistant-app) to be installed on the target Grafana instance. They are also write tools (the assistant may mutate stack state), so they are skipped when--disable-writeis set. To enable them, addassistantto your--enabled-toolsflag.
contextId back in a follow-up call to continue the same conversation. Complex tasks can take several minutes; the call blocks until the reply is done or the request times out (5 minutes).Note: Admin tools are disabled by default. To enable them, include
adminin your--enabled-toolsflag.
orgId values for multi-organization requests.http://localhost:3000/d/dashboard-uid)http://localhost:3000/d/dashboard-uid?viewPanel=5)http://localhost:3000/explore?schemaVersion=1&panes={"a":{"datasource":"prometheus-uid"}}). Grafana below 10.2 does not understand panes, so the legacy ?left={...} format is emitted for those versions instead.from=now-1h&to=now)what, when, tags, data).provisioningPreview parameter.
The list of tools is configurable, so you can choose which tools you want to make available to the MCP client.
This is useful if you don't use certain functionality or if you don't want to take up too much of the context window.
To disable a category of tools, use the --disable-<category> flag when starting the server. For example, to disable
the OnCall tools, use --disable-oncall, or to disable navigation deeplink generation, use --disable-navigation.
Each tool requires specific RBAC permissions to function properly. When creating a service account for the MCP server, ensure it has the necessary permissions based on which tools you plan to use. The permissions listed are the minimum required actions - you may also need appropriate scopes (e.g., datasources:*, dashboards:*, folders:*) depending on your use case.
Tip: If you're not familiar with Grafana RBAC or you want a quicker, simpler setup instead of configuring many granular scopes, you can assign a built-in role such as Editor to the service account. The Editor role grants broad read/write access that will allow most MCP server operations; it is less granular (and therefore less restrictive) than manually-applied scopes, so use it only when convenience is more important than strict least-privilege access.
Note: Grafana Incident tools use basic Grafana roles instead of fine-grained RBAC permissions:
For more information about Grafana RBAC, see the official documentation.
Scopes define the specific resources that permissions apply to. Each action requires both the appropriate permission and scope combination.
Common Scope Patterns:
Broad access: Use * wildcards for organization-wide access
datasources:* - Access to all datasourcesdashboards:* - Access to all dashboardsfolders:* - Access to all foldersteams:* - Access to all teamsLimited access: Use specific UIDs or IDs to restrict access to individual resources
datasources:uid:prometheus-uid - Access only to a specific Prometheus datasourcedashboards:uid:abc123 - Access only to dashboard with UID abc123folders:uid:xyz789 - Access only to folder with UID xyz789teams:id:5 - Access only to team with ID 5global.users:id:123 - Access only to user with ID 123Examples:
Full MCP server access: Grant broad permissions for all tools
datasources:* (datasources:read, datasources:query)
dashboards:* (dashboards:read, dashboards:create, dashboards:write)
folders:* (for dashboard creation and alert rules)
teams:* (teams:read)
global.users:* (users:read)
Limited datasource access: Only query specific Prometheus and Loki instances
datasources:uid:prometheus-prod (datasources:query)
datasources:uid:loki-prod (datasources:query)
Dashboard-specific access: Read only specific dashboards
dashboards:uid:monitoring-dashboard (dashboards:read)
dashboards:uid:alerts-dashboard (dashboards:read)
| Tool | Category | Description | Required RBAC Permissions | Required Scopes |
|---|---|---|---|---|
list_teams | Admin | List all teams | teams:read | teams:* or teams:id:1 |
list_users_by_org | Admin | List all users in an organization | users:read | global.users:* or global.users:id:123 |
list_all_roles | Admin | List all Grafana roles | roles:read | roles:* |
get_role_details | Admin | Get details for a Grafana role | roles:read | roles:uid:editor |
get_role_assignments | Admin | List assignments for a role | roles:read | roles:uid:editor |
list_user_roles | Admin | List roles for users | roles:read | global.users:id:123 |
list_team_roles | Admin | List roles for teams | roles:read | teams:id:7 |
get_resource_permissions | Admin | List permissions for a resource | permissions:read | dashboards:uid:abcd1234 |
get_resource_description | Admin | Describe a Grafana resource type | permissions:read | dashboards:* |
user_info | User | Current identity, capabilities, and accessible organizations | None (signed-in user) | — |
search_dashboards | Search | Search for dashboards by query, folder UID, tag, or starred | dashboards:read | dashboards:* or dashboards:uid:abc123 |
get_dashboard_by_uid | Dashboard | Get a dashboard by uid, optionally a saved version | dashboards:read | dashboards:uid:abc123 |
list_dashboard_versions | Dashboard | List saved versions of a dashboard (version, author, time, message) | dashboards:read | dashboards:uid:abc123 |
update_dashboard | Dashboard | Update or create a new dashboard | dashboards:create, dashboards:write | dashboards:*, folders:* or folders:uid:xyz789 |
get_dashboard_panel_queries | Dashboard | Get panel title, queries, datasource UID and type from a dashboard | dashboards:read | dashboards:uid:abc123 |
run_panel_query | RunPanelQuery* | Execute one or more dashboard panel queries | dashboards:read, datasources:query | dashboards:uid:*, datasources:uid:* |
get_dashboard_property | Dashboard | Extract specific parts of a dashboard using JSONPath expressions | dashboards:read | dashboards:uid:abc123 |
get_dashboard_summary | Dashboard | Get a compact summary of a dashboard without full JSON | dashboards:read | dashboards:uid:abc123 |
list_datasources | Datasources | List datasources | datasources:read | datasources:* |
get_datasource | Datasources | Get a datasource by UID or name | datasources:read | datasources:uid:prometheus-uid |
get_query_examples | Examples* | Get example queries for a datasource type | datasources:read | datasources:* |
query_prometheus | Prometheus | Execute a query against a Prometheus datasource | datasources:query | datasources:uid:prometheus-uid |
list_prometheus_metric_metadata | Prometheus | List metric metadata | datasources:query | datasources:uid:prometheus-uid |
list_prometheus_metric_names | Prometheus | List available metric names | datasources:query | datasources:uid:prometheus-uid |
list_prometheus_label_names | Prometheus | List label names matching a selector | datasources:query | datasources:uid:prometheus-uid |
list_prometheus_label_values | Prometheus | List values for a specific label | datasources:query | datasources:uid:prometheus-uid |
query_prometheus_histogram | Prometheus | Calculate histogram percentile values | datasources:query | datasources:uid:prometheus-uid |
list_incidents | Incident | List incidents in Grafana Incident, optionally with their custom field values | Viewer role | N/A |
create_incident | Incident | Create an incident in Grafana Incident, optionally setting custom fields | Editor role | N/A |
add_activity_to_incident | Incident | Add an activity item to an incident in Grafana Incident | Editor role | N/A |
update_incident | Incident | Update an incident in Grafana Incident (status, severity, title, or custom fields) | Editor role | N/A |
get_incident | Incident | Get a single incident by ID, including its custom fields | Viewer role | N/A |
list_incident_custom_fields | Incident | List the custom fields configured for incidents, with their types and select options | Viewer role | N/A |
query_loki_logs | Loki | Query and retrieve logs using LogQL (either log or metric queries) | datasources:query | datasources:uid:loki-uid |
list_loki_label_names | Loki | List all available label names in logs | datasources:query | datasources:uid:loki-uid |
list_loki_label_values | Loki | List values for a specific log label | datasources:query | datasources:uid:loki-uid |
query_loki_stats | Loki | Get statistics about log streams | datasources:query | datasources:uid:loki-uid |
query_loki_patterns | Loki | Query detected log patterns to identify common structures | datasources:query | datasources:uid:loki-uid |
analyze_loki_labels | Loki | Audit a Loki label strategy (live or static) and optionally diagnose query performance | datasources:query | datasources:uid:loki-uid |
suggest_loki_alloy_label_config | Config | Generate an Alloy loki.process snippet enforcing approved labels | N/A | N/A |
query_influxdb | InfluxDB | Query InfluxDB using InfluxQL (v1) or Flux (v2) | datasources:query | datasources:uid:influxdb-uid |
list_sql_databases | SQL* | List databases, schemas, or catalogs from a SQL datasource | datasources:query | datasources:uid:* |
list_sql_tables | SQL* | List tables in a SQL datasource | datasources:query | datasources:uid:* |
describe_sql_table | SQL* | Get column schema for a table | datasources:query | datasources:uid:* |
query_sql | SQL* | Execute SQL queries with macro substitution | datasources:query | datasources:uid:* |
list_cloudwatch_namespaces | CloudWatch* | List available AWS CloudWatch namespaces | datasources:query | datasources:uid:* |
list_cloudwatch_metrics | CloudWatch* | List metrics in a namespace | datasources:query | datasources:uid:* |
list_cloudwatch_dimensions | CloudWatch* | List dimensions for a metric | datasources:query | datasources:uid:* |
list_cloudwatch_dimension_values | CloudWatch* | List values for a dimension key | datasources:query | datasources:uid:* |
query_cloudwatch | CloudWatch* | Execute CloudWatch metric queries | datasources:query | datasources:uid:* |
list_cloud_logging_projects | Cloud Logging* | List GCP projects readable by a Google Cloud Logging datasource | datasources:query | datasources:uid:* |
list_cloud_logging_buckets | Cloud Logging* | List log buckets in a GCP project | datasources:query | datasources:uid:* |
list_cloud_logging_views | Cloud Logging* | List log views in a log bucket | datasources:query | datasources:uid:* |
query_cloud_logging | Cloud Logging* | Query logs with the Cloud Logging query language | datasources:query | datasources:uid:* |
query_elasticsearch | Elasticsearch/OpenSearch* | Query Elasticsearch or OpenSearch using Lucene syntax or Query DSL | datasources:query | datasources:uid:datasource-uid |
query_quickwit | Quickwit* | Query Quickwit using Lucene syntax or Query DSL | datasources:query | datasources:uid:quickwit-uid |
alerting_rules_read | Alerting | List and inspect alert rules (list, get, versions) | alert.rules:read | folders:* or folders:uid:alerts-folder |
alerting_rules_write | Alerting | Create, update, and delete alert rules | alert.rules:read + alert.rules:write | folders:* or folders:uid:alerts-folder |
alerting_manage_routing | Alerting | Manage notification policies, contact points, and time intervals | alert.notifications:read | Global scope |
alerting_routing_write | Alerting | Create Grafana-managed contact points | alert.notifications.provisioning:write | Global scope |
alerting_silences_read | Alerting | List and inspect alerting silences (list, get) | alert.instances:read | Global scope |
alerting_silences_write | Alerting | Create, update, and expire alerting silences | alert.instances:read + alert.instances:write | Global scope |
list_oncall_schedules | OnCall | List schedules from Grafana OnCall | grafana-oncall-app.schedules:read | Plugin-specific scopes |
get_oncall_shift | OnCall | Get details for a specific OnCall shift | grafana-oncall-app.schedules:read | Plugin-specific scopes |
get_current_oncall_users | OnCall | Get users currently on-call for a specific schedule | grafana-oncall-app.schedules:read | Plugin-specific scopes |
list_oncall_teams | OnCall | List teams from Grafana OnCall | grafana-oncall-app.user-settings:read | Plugin-specific scopes |
list_oncall_users | OnCall | List users from Grafana OnCall | grafana-oncall-app.user-settings:read | Plugin-specific scopes |
list_alert_groups | OnCall | List alert groups from Grafana OnCall with filtering options | grafana-oncall-app.alert-groups:read | Plugin-specific scopes |
get_alert_group | OnCall | Get a specific alert group from Grafana OnCall by its ID | grafana-oncall-app.alert-groups:read | Plugin-specific scopes |
update_alert_group | OnCall | Acknowledge, unacknowledge, resolve, or unresolve an alert group | grafana-oncall-app.alert-groups:write (and :read) | Plugin-specific scopes |
list_pyroscope_label_names | Pyroscope | List label names matching a selector | datasources:query | datasources:uid:pyroscope-uid |
list_pyroscope_label_values | Pyroscope | List label values matching a selector for a label name | datasources:query | datasources:uid:pyroscope-uid |
list_pyroscope_profile_types | Pyroscope | List available profile types | datasources:query | datasources:uid:pyroscope-uid |
query_pyroscope | Pyroscope | Query profiles, metrics, or both from Pyroscope | datasources:query | datasources:uid:pyroscope-uid |
get_assertions | Asserts | Get assertion summary for a given entity | Plugin-specific permissions | Plugin-specific scopes |
agento11y_manage_conversations | Agent Observability* | List, search, and fetch LLM conversations from Grafana Agent Observability | grafana-agento11y-app.conversations:read | N/A |
agento11y_manage_generations | Agent Observability* | Fetch LLM generation details and evaluation scores from Grafana Agent Observability | grafana-agento11y-app.data:read | N/A |
agento11y_manage_agents | Agent Observability* | Read the agent catalog: list agents, get one agent version in full, list version history, and per-version score aggregates | grafana-agento11y-app.data:read | N/A |
agento11y_manage_evaluators | Agent Observability* | Manage evaluators, evaluator templates, and the judge catalog (list, get, upsert, fork, test, delete) | grafana-agento11y-app.data:read + grafana-agento11y-app.eval:write for mutations and tests | N/A |
agento11y_manage_eval_rules | Agent Observability* | Manage eval rules and guards (list, get, create, update, preview, delete) | grafana-agento11y-app.data:read + grafana-agento11y-app.eval:write for mutations and previews | N/A |
agento11y_manage_eval_collections | Agent Observability* | Manage saved conversations and the collections that group them (list, get, save, create, update, delete, add and remove members) | grafana-agento11y-app.data:read + grafana-agento11y-app.eval:write for mutations | N/A |
agento11y_manage_experiments | Agent Observability* | Read offline experiments, their trials, scores, artifact metadata, and filter facets; update and cancel an experiment | grafana-agento11y-app.data:read + grafana-agento11y-app.eval:write for mutations | N/A |
agento11y_manage_test_suites | Agent Observability* | Manage the test suites that offline experiments run against, their versions, and their test cases (list, get, create, update, draft, publish, upsert, delete) | grafana-agento11y-app.data:read + grafana-agento11y-app.eval:write for mutations | N/A |
ask_assistant | Assistant* | Send a prompt to Grafana Assistant and return the full text reply (multi-turn via contextId) | Plugin-specific permissions | Plugin-specific scopes |
generate_deeplink | Navigation | Generate accurate deeplink URLs for Grafana resources | None (read-only URL generation) | N/A |
get_annotations | Annotations | Fetch annotations with filters | annotations:read | annotations:* or annotations:id:123 |
create_annotation | Annotations | Create a new annotation (standard or Graphite format) | annotations:write | annotations:* |
update_annotation | Annotations | Update specific fields of an annotation (partial update) | annotations:write | annotations:* |
delete_annotation | Annotations | Delete an annotation by ID | annotations:delete | annotations:* |
get_annotation_tags | Annotations | List annotation tags with optional filtering | annotations:read | annotations:* |
list_snapshots | Snapshot | List dashboard snapshots with optional query and limit filters | dashboards:read | dashboards:* or dashboards:uid:abc123 |
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
docker run -i --rm docker.io/grafana/mcp-grafana:2.0.1Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-grafana-mcp-grafana": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"docker.io/grafana/mcp-grafana:2.0.1"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referencedocker.io/grafana/mcp-grafana:2.0.1dockerio.github.grafana/mcp-grafana works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.