Skip to main content
Tools Reference

Grafana Tools

Written By Christopher Scaminaci

Last updated 7 days ago

Grafana Tools

grafana_ · 309 tools · Free 137 · Pro 172 Grafana observability: dashboards, folders and search; data sources, health tests and the query endpoint; alerting provisioning and Prometheus rule import; annotations; organizations, users, teams and service accounts; reporting; licensing; query history; cloud migration; instance administration. Auth is a static service account token minted in the customer's own Grafana; its authority is that account's role, not a request scope. The tenant supplies the instance URL, and its path is preserved: a Grafana behind a reverse proxy serves every route under a sub-path. An optional organization id rides every call except /api/admin/; instance-wide tools accept none. Paging is page + limit (or perpage) from 1, no cursor, capped at 1000 (5000 on /api/search). Responses are bare JSON passed through unchanged; fifteen reads answer YAML, HCL, CSV or XML as text, and three report downloads answer a short-lived link. Sixty-four tools wrap deprecated operations; sixty-one need Enterprise or Cloud.

All connector tools · Grafana setup guide

Grafana tool groups

Dashboard snapshots

ToolPlanAccessSummary
grafana_create_dashboard_snapshotProWriteWhen creating a snapshot using the API, you have to provide the full dashboard payload including the snapshot data.
grafana_delete_dashboard_snapshotProDestructiveDESTRUCTIVE: delete Snapshot by Key.
grafana_delete_dashboard_snapshot_by_delete_keyProDestructiveDESTRUCTIVE: delete a dashboard snapshot using its delete key.
grafana_get_dashboard_snapshotFreeRead-onlyGet Snapshot by Key.
grafana_get_sharing_optionsFreeRead-onlyGet snapshot sharing settings.
grafana_search_dashboard_snapshotsFreeRead-onlyList snapshots.

[Grafana] When creating a snapshot using the API, you have to provide the full dashboard payload including the snapshot data. This endpoint is designed for the Grafana UI. POST /api/snapshots. Send the request body as JSON; Grafana documents these fields: apiVersion, dashboard, deleteKey, expires, external, key, kind, name. Required: dashboard. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: apiVersion, dashboard, deleteKey, expires, external, key, kind, name. Required: dashboard.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: delete Snapshot by Key. It deletes the resource outright, and Grafana does not undo this. DELETE /api/snapshots/. Path parameters: key. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
keystringyesRequired. The key this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: delete a dashboard snapshot using its delete key. GET /api/snapshots-delete/. Grafana serves this DELETION over a GET - that is the vendor's design, not a mistake here, and its own summary for the route is Delete Snapshot by deleteKey. The snapshot and the public link to it stop working immediately. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
deleteKeystringyesRequired. The deleteKey this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get Snapshot by Key. GET /api/snapshots/. Path parameters: key. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
keystringyesRequired. The key this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get snapshot sharing settings. GET /api/snapshot/shared-options. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] List snapshots. GET /api/dashboard/snapshots. Optional filters: query, limit. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
limitintegernonullOptional. Limit the number of returned results. Capped at 1000 by StackJack.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
querystringnonullOptional. Search Query.

Dashboard versions

ToolPlanAccessSummary
grafana_get_dashboard_version_by_uidFreeRead-onlyGet a specific dashboard version using UID.
grafana_get_dashboard_versions_by_uidFreeRead-onlyGets all existing versions for the dashboard using UID.

[Grafana] Get a specific dashboard version using UID. GET /api/dashboards/uid//versions/. Path parameters: DashboardVersionID, uid. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
dashboardVersionIDintegeryesRequired. The DashboardVersionID this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] Gets all existing versions for the dashboard using UID. GET /api/dashboards/uid//versions. Path parameters: uid. Optional filters: limit, start. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
limitintegernonullOptional. Maximum number of results to return. Capped at 1000 by StackJack.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
startintegernonullOptional. Version to start from when returning queries.
uidstringyesRequired. The uid this call targets.

Dashboards

ToolPlanAccessSummary
grafana_delete_dashboard_by_uidProDestructiveDESTRUCTIVE: delete a dashboard by uid.
grafana_get_dashboard_by_uidFreeRead-onlyRead one dashboard whole - its panels, queries, variables, annotations and version - by uid.
grafana_get_dashboard_permissions_list_by_uidFreeRead-onlyGets all existing permissions for the given dashboard.
grafana_get_dashboard_tagsFreeRead-onlyGet all dashboards tags of an organization.
grafana_get_home_dashboardFreeRead-onlyNOTE: the home dashboard is configured in preferences.
grafana_import_dashboardProWriteImport dashboard.
grafana_interpolate_dashboardProWriteInterpolate dashboard.
grafana_post_dashboardProDestructiveDESTRUCTIVE: create a dashboard, or save a new version of an existing one.
grafana_restore_dashboard_version_by_uidProWriteRestore a dashboard to a given dashboard version using UID.
grafana_update_dashboard_permissions_by_uidProDestructiveDESTRUCTIVE: updates permissions for a dashboard.

[Grafana] DESTRUCTIVE: delete a dashboard by uid. DELETE /api/dashboards/uid/. It takes the dashboard's whole version history with it, so grafana_restore_dashboard_version_by_uid cannot bring it back - the versions are gone too. Anything linking to it, including alert rules annotated onto its panels and playlists that include it, is left pointing at nothing. Get the uid from grafana_search and confirm the title before calling. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] Read one dashboard whole - its panels, queries, variables, annotations and version - by uid. GET /api/dashboards/uid/. Get the uid from grafana_search; the numeric id that also appears in Grafana responses is deprecated and should not be used to address anything. The response is {dashboard, meta}: the dashboard object is the same JSON grafana_post_dashboard takes back, so read-modify-write works. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] Gets all existing permissions for the given dashboard. GET /api/dashboards/uid//permissions. Path parameters: uid. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] Get all dashboards tags of an organization. GET /api/dashboards/tags. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] NOTE: the home dashboard is configured in preferences. This API will be removed in G13. GET /api/dashboards/home. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Import dashboard. POST /api/dashboards/import. Send the request body as JSON; Grafana documents these fields: dashboard, folderUid, inputs, overwrite, path, pluginId. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: dashboard, folderUid, inputs, overwrite, path, pluginId.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Interpolate dashboard. This is an experimental endpoint under dashboardLibrary or suggestedDashboards feature flags and is subject to change. POST /api/dashboards/interpolate. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: create a dashboard, or save a new version of an existing one. POST /api/dashboards/db. Why this is destructive: a partial object REPLACES the dashboard rather than merging into it, so every panel, query, variable and annotation you leave out is gone. Read the current one with grafana_get_dashboard_by_uid first and send its dashboard object back with your changes. Send {dashboard: , folderUid, message, overwrite}. Keep the dashboard's uid and version to save safely: Grafana refuses a save whose version is stale unless overwrite is true, and overwrite true discards whatever anyone else saved in the meantime. Every save makes a new version, so grafana_restore_dashboard_version_by_uid can put the old one back - the customer's dashboard is wrong until somebody notices and does that, which is why this asks before it runs. message is the change note that shows in the version list; write one. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: UpdatedAt, dashboard, folderUid, isFolder, message, overwrite, userId.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Restore a dashboard to a given dashboard version using UID. POST /api/dashboards/uid//restore. Path parameters: uid. Send the request body as JSON; Grafana documents these fields: version. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: version.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] DESTRUCTIVE: updates permissions for a dashboard. It changes who can see or change what. Permission changes are easy to miss and hard to trace back afterwards. POST /api/dashboards/uid//permissions. Path parameters: uid. Send the request body as JSON; Grafana documents these fields: items. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: items.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The dashboard UID.

Public dashboards

ToolPlanAccessSummary
grafana_create_public_dashboardProWriteCreate public dashboard for a dashboard.
grafana_delete_public_dashboardProDestructiveDESTRUCTIVE: delete public dashboard for a dashboard.
grafana_get_public_annotationsFreeRead-onlyGet annotations for a public dashboard.
grafana_get_public_dashboardFreeRead-onlyGet public dashboard by dashboardUid.
grafana_list_public_dashboardsFreeRead-onlyGet list of public dashboards.
grafana_query_public_dashboardProWriteGet results for a given panel on a public dashboard.
grafana_update_public_dashboardProWriteUpdate public dashboard for a dashboard.
grafana_view_public_dashboardFreeRead-onlyGet public dashboard for view.

[Grafana] Create public dashboard for a dashboard. POST /api/dashboards/uid//public-dashboards. Path parameters: dashboardUid. Send the request body as JSON; Grafana documents these fields: accessToken, annotationsEnabled, isEnabled, share, timeSelectionEnabled, uid. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: accessToken, annotationsEnabled, isEnabled, share, timeSelectionEnabled, uid.
dashboardUidstringyesRequired. The dashboardUid this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: delete public dashboard for a dashboard. It deletes the resource outright, and Grafana does not undo this. DELETE /api/dashboards/uid//public-dashboards/. Path parameters: dashboardUid, uid. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
dashboardUidstringyesRequired. The dashboardUid this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] Get annotations for a public dashboard. GET /api/public/dashboards//annotations. Path parameters: accessToken. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
accessTokenstringyesRequired. The accessToken this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get public dashboard by dashboardUid. GET /api/dashboards/uid//public-dashboards. Path parameters: dashboardUid. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
dashboardUidstringyesRequired. The dashboardUid this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get list of public dashboards. GET /api/dashboards/public-dashboards. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get results for a given panel on a public dashboard. POST /api/public/dashboards//panels//query. Path parameters: accessToken, panelId. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
accessTokenstringyesRequired. The accessToken this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
panelIdintegeryesRequired. The panelId this call targets.

[Grafana] Update public dashboard for a dashboard. PATCH /api/dashboards/uid//public-dashboards/. Path parameters: dashboardUid, uid. Send the request body as JSON; Grafana documents these fields: accessToken, annotationsEnabled, isEnabled, share, timeSelectionEnabled, uid. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: accessToken, annotationsEnabled, isEnabled, share, timeSelectionEnabled, uid.
dashboardUidstringyesRequired. The dashboardUid this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] Get public dashboard for view. GET /api/public/dashboards/. Path parameters: accessToken. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
accessTokenstringyesRequired. The accessToken this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
ToolPlanAccessSummary
grafana_list_sort_optionsFreeRead-onlyList search sorting options.
grafana_searchFreeRead-onlyFind dashboards and folders by name, tag or folder.

[Grafana] List search sorting options. GET /api/search/sorting. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Find dashboards and folders by name, tag or folder. GET /api/search. This is the entry point for almost everything else: it is where a dashboard uid comes from, and the uid is what every other dashboard tool takes. Filter with query (free text), tag (comma-separate several), type (dash-db for dashboards, dash-folder for folders), folderUIDs, starred and deleted. Paging is page plus limit, numbered from 1; Grafana caps limit at 5000 and StackJack caps it at 1000. Note the response is a BARE ARRAY, not an object with a count. Pass orgId to search inside a specific organization. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
dashboardIdsstringnonullOptional. List of dashboard id’s to search for. Comma-separate several values; each is sent as its own dashboardIds parameter.
dashboardUIDsstringnonullOptional. List of dashboard uid’s to search for. Comma-separate several values; each is sent as its own dashboardUIDs parameter.
deletedbooleannonullOptional. Flag indicating if only soft deleted Dashboards should be returned.
folderIdsstringnonullOptional. List of folder id’s to search in for dashboards. Comma-separate several values; each is sent as its own folderIds parameter.
folderUIDsstringnonullOptional. List of folder UID’s to search in for dashboards. Comma-separate several values; each is sent as its own folderUIDs parameter.
limitintegernonullOptional. Limit the number of returned results (max 5000). Capped at 1000 by StackJack.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
pageintegernonullOptional. Use this parameter to access hits beyond limit. Numbering starts at 1. limit param acts as page size. Only available in Grafana v6.2+.
permissionstringnonullOptional. Set to `Edit` to return dashboards/folders that the user can edit. One of: Edit, View.
querystringnonullOptional. Search Query.
sortstringnonullOptional. Sort method; for listing all the possible sort methods use the search sorting endpoint. One of: alpha-asc, alpha-desc.
starredbooleannonullOptional. Flag indicating if only starred Dashboards should be returned.
tagstringnonullOptional. List of tags to search for. Comma-separate several values; each is sent as its own tag parameter.
typestringnonullOptional. Type to search for, dash-folder or dash-db. One of: dash-folder, dash-db.

Folders

ToolPlanAccessSummary
grafana_create_folderProWriteCreate folder.
grafana_delete_folderProDestructiveDESTRUCTIVE: delete a folder.
grafana_get_folder_by_uidFreeRead-onlyGet folder by uid.
grafana_get_folder_descendant_countsFreeRead-onlyGets the count of each descendant of a folder by kind.
grafana_get_folder_permission_listFreeRead-onlyGets all existing permissions for the folder with the given `uid`.
grafana_get_foldersFreeRead-onlyList folders.
grafana_move_folderProWriteMove folder.
grafana_update_folderProWriteUpdate folder.
grafana_update_folder_permissionsProDestructiveDESTRUCTIVE: updates permissions for a folder.

[Grafana] Create folder. POST /api/folders. Send the request body as JSON; Grafana documents these fields: description, parentUid, title, uid. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: description, parentUid, title, uid.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: delete a folder. DELETE /api/folders/. It takes the folder's CONTENTS with it - every dashboard inside it, and every alert rule stored in it - not just the folder. Grafana refuses if the folder holds Grafana-managed alert rules unless forceDeleteRules is true, and setting that deletes those rules, which stops the alerting they provide with nothing else announcing it. Call grafana_get_folder_descendant_counts first and read what is in there. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
folderUidstringyesRequired. The folder_uid this call targets.
forceDeleteRulesbooleannonullOptional. If `true` any Grafana 8 Alerts under this folder will be deleted.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get folder by uid. GET /api/folders/. Path parameters: folder_uid. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
folderUidstringyesRequired. The folder_uid this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Gets the count of each descendant of a folder by kind. The folder is identified by UID. GET /api/folders//counts. Path parameters: folder_uid. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
folderUidstringyesRequired. The folder_uid this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Gets all existing permissions for the folder with the given `uid`. GET /api/folders//permissions. Path parameters: folder_uid. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
folderUidstringyesRequired. The folder_uid this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] List folders. GET /api/folders. Folders are how Grafana groups dashboards AND alert rules, and they are also the unit permissions are granted on, so this is usually the first call when mapping out an unfamiliar instance. Nest with parentUid; limit and page walk the list, numbered from 1 and capped at 1000 by StackJack. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
limitintegernonullOptional. Limit the maximum number of folders to return. Capped at 1000 by StackJack.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
pageintegernonullOptional. Page index for starting fetching folders.
parentUidstringnonullOptional. The parent folder UID.
permissionstringnonullOptional. Set to `Edit` to return folders that the user can edit. One of: Edit, View.

[Grafana] Move folder. POST /api/folders//move. Path parameters: folder_uid. Send the request body as JSON; Grafana documents these fields: parentUid. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: parentUid.
folderUidstringyesRequired. The folder_uid this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Update folder. PUT /api/folders/. Path parameters: folder_uid. Send the request body as JSON; Grafana documents these fields: description, overwrite, title, version. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: description, overwrite, title, version.
folderUidstringyesRequired. The folder_uid this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: updates permissions for a folder. This operation will remove existing permissions if they’re not included in the request. It changes who can see or change what. Permission changes are easy to miss and hard to trace back afterwards. POST /api/folders//permissions. Path parameters: folder_uid. Send the request body as JSON; Grafana documents these fields: items. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: items.
folderUidstringyesRequired. The folder_uid this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

Library panels

ToolPlanAccessSummary
grafana_create_library_elementProWriteCreate library element.
grafana_delete_library_element_by_uidProDestructiveDESTRUCTIVE: delete library element.
grafana_get_library_element_by_nameFreeRead-onlyGet library element by name.
grafana_get_library_element_by_uidFreeRead-onlyGet library element by UID.
grafana_get_library_element_connectionsFreeRead-onlyGet library element connections.
grafana_get_library_elementsFreeRead-onlyGet all library elements.
grafana_update_library_elementProWriteUpdate library element.

[Grafana] Create library element. POST /api/library-elements. Send the request body as JSON; Grafana documents these fields: folderUid, kind, model, name, uid. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: folderUid, kind, model, name, uid.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: delete library element. It deletes the resource outright, and Grafana does not undo this. DELETE /api/library-elements/. Path parameters: library_element_uid. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
libraryElementUidstringyesRequired. The library_element_uid this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get library element by name. GET /api/library-elements/name/. Path parameters: library_element_name. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
libraryElementNamestringyesRequired. The library_element_name this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get library element by UID. GET /api/library-elements/. Path parameters: library_element_uid. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
libraryElementUidstringyesRequired. The library_element_uid this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get library element connections. GET /api/library-elements//connections/. Path parameters: library_element_uid. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
libraryElementUidstringyesRequired. The library_element_uid this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get all library elements. GET /api/library-elements. Optional filters: searchString, kind, sortDirection, typeFilter, excludeUid, folderFilter, folderFilterUIDs, perPage, page. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
excludeUidstringnonullOptional. Element UID to exclude from search results.
folderFilterstringnonullOptional. A comma separated list of folder ID(s) to filter the elements by.
folderFilterUIDsstringnonullOptional. A comma separated list of folder UID(s) to filter the elements by.
kindintegernonullOptional. Kind of element to search for. One of: 1.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
pageintegernonullOptional. The page for a set of records, given that only perPage records are returned at a time. Numbering starts at 1.
perPageintegernonullOptional. The number of results per page. Capped at 1000 by StackJack.
searchStringstringnonullOptional. Part of the name or description searched for.
sortDirectionstringnonullOptional. Sort order of elements. One of: alpha-asc, alpha-desc.
typeFilterstringnonullOptional. A comma separated list of types to filter the elements by.

[Grafana] Update library element. PATCH /api/library-elements/. Path parameters: library_element_uid. Send the request body as JSON; Grafana documents these fields: folderUid, kind, model, name, uid, version. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: folderUid, kind, model, name, uid, version.
libraryElementUidstringyesRequired. The library_element_uid this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

Playlists

ToolPlanAccessSummary
grafana_create_playlistProWriteCreate playlist.
grafana_delete_playlistProDestructiveDESTRUCTIVE: delete playlist.
grafana_get_playlistFreeRead-onlyGet playlist.
grafana_get_playlist_itemsFreeRead-onlyGet playlist items.
grafana_search_playlistsFreeRead-onlyGet playlists.
grafana_update_playlistProWriteUpdate playlist.

[Grafana] Create playlist. POST /api/playlists. Send the request body as JSON; Grafana documents these fields: interval, items, name. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: interval, items, name.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: delete playlist. It deletes the resource outright, and Grafana does not undo this. DELETE /api/playlists/. Path parameters: uid. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] Get playlist. GET /api/playlists/. Path parameters: uid. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] Get playlist items. GET /api/playlists//items. Path parameters: uid. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] Get playlists. GET /api/playlists. Optional filters: query, limit. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
limitintegernonullOptional. The limit filter. Capped at 1000 by StackJack.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
querystringnonullOptional. The query filter.

[Grafana] Update playlist. PUT /api/playlists/. Path parameters: uid. Send the request body as JSON; Grafana documents these fields: interval, items, name, uid. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: interval, items, name, uid.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

Data source caching and access rules

ToolPlanAccessSummary
grafana_clean_data_source_cacheProWriteclean cache for a single data source.
grafana_disable_data_source_cacheProDestructiveDESTRUCTIVE: disable cache for a single data source.
grafana_enable_data_source_cacheProWriteenable cache for a single data source.
grafana_get_data_source_cache_configFreeRead-onlyget cache config for a single data source.
grafana_get_team_lbac_rulesFreeRead-onlyRetrieves LBAC rules for a team.
grafana_set_data_source_cache_configProWriteset cache config for a single data source.
grafana_update_team_lbac_rulesProDestructiveDESTRUCTIVE: updates LBAC rules for a team.

[Grafana] clean cache for a single data source. POST /api/datasources//cache/clean. Path parameters: dataSourceUID. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
dataSourceUIDstringyesRequired. The dataSourceUID this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: disable cache for a single data source. It changes or clears the data source's query cache, which affects what every dashboard reading from it sees next. POST /api/datasources//cache/disable. Path parameters: dataSourceUID. Optional filters: dataSourceType. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
dataSourceTypestringnonullOptional. Optional datasource type used to disambiguate datasource UID lookups.
dataSourceUIDstringyesRequired. The dataSourceUID this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] enable cache for a single data source. POST /api/datasources//cache/enable. Path parameters: dataSourceUID. Optional filters: dataSourceType. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
dataSourceTypestringnonullOptional. Optional datasource type used to disambiguate datasource UID lookups.
dataSourceUIDstringyesRequired. The dataSourceUID this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] get cache config for a single data source. GET /api/datasources//cache. Path parameters: dataSourceUID. Optional filters: dataSourceType. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
dataSourceTypestringnonullOptional. Optional datasource type used to disambiguate datasource UID lookups.
dataSourceUIDstringyesRequired. The dataSourceUID this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Retrieves LBAC rules for a team. GET /api/datasources/uid//lbac/teams. Path parameters: uid. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] set cache config for a single data source. POST /api/datasources//cache. Path parameters: dataSourceUID. Optional filters: dataSourceType. Send the request body as JSON; Grafana documents these fields: dataSourceID, dataSourceUID, enabled, ttlQueriesMs, ttlResourcesMs, useDefaultTTL. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: dataSourceID, dataSourceUID, enabled, ttlQueriesMs, ttlResourcesMs, useDefaultTTL.
dataSourceTypestringnonullOptional. Optional datasource type used to disambiguate datasource UID lookups.
dataSourceUIDstringyesRequired. The dataSourceUID this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: updates LBAC rules for a team. It REPLACES every team LBAC rule on the data source with the set you send, and the body is OPTIONAL - a call with no body replaces all of them with nothing. Those rules decide which rows of the underlying data each team may see, so dropping them WIDENS what a team can read rather than narrowing it. PUT /api/datasources/uid//lbac/teams. Path parameters: uid. Send the request body as JSON; Grafana documents these fields: rules. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringnonullOptional. A JSON request body. Grafana publishes no field list for this endpoint; omit it unless you know the shape.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

Data source correlations

ToolPlanAccessSummary
grafana_create_correlationProWriteAdd correlation.
grafana_delete_correlationProDestructiveDESTRUCTIVE: delete a correlation.
grafana_get_correlationFreeRead-onlyGets a correlation.
grafana_get_correlationsFreeRead-onlyGets all correlations.
grafana_get_correlations_by_source_uidFreeRead-onlyGets all correlations originating from the given data source.
grafana_update_correlationProWriteUpdates a correlation.

[Grafana] Add correlation. POST /api/datasources/uid//correlations. Path parameters: sourceUID. Send the request body as JSON; Grafana documents these fields: config, description, label, provisioned, targetUID, type. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: config, description, label, provisioned, targetUID, type.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
sourceUIDstringyesRequired. The sourceUID this call targets.

[Grafana] DESTRUCTIVE: delete a correlation. Deleting a data source breaks every dashboard, alert rule and query that reads from it, and Grafana does not warn you which ones those are. DELETE /api/datasources/uid//correlations/. Path parameters: uid, correlationUID. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
correlationUIDstringyesRequired. The correlationUID this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] Gets a correlation. GET /api/datasources/uid//correlations/. Path parameters: sourceUID, correlationUID. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
correlationUIDstringyesRequired. The correlationUID this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
sourceUIDstringyesRequired. The sourceUID this call targets.

[Grafana] Gets all correlations. GET /api/datasources/correlations. Optional filters: limit, page, sourceUID. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
limitintegernonullOptional. Limit the maximum number of correlations to return per page. Capped at 1000 by StackJack.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
pageintegernonullOptional. Page index for starting fetching correlations.
sourceUIDstringnonullOptional. Source datasource UID filter to be applied to correlations. Comma-separate several values; each is sent as its own sourceUID parameter.

[Grafana] Gets all correlations originating from the given data source. GET /api/datasources/uid//correlations. Path parameters: sourceUID. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
sourceUIDstringyesRequired. The sourceUID this call targets.

[Grafana] Updates a correlation. PATCH /api/datasources/uid//correlations/. Path parameters: sourceUID, correlationUID. Send the request body as JSON; Grafana documents these fields: config, description, label, type. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringnonullOptional. A JSON request body. Grafana publishes no field list for this endpoint; omit it unless you know the shape.
correlationUIDstringyesRequired. The correlationUID this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
sourceUIDstringyesRequired. The sourceUID this call targets.

Data source proxy

ToolPlanAccessSummary
grafana_call_datasource_resourceProDestructiveDESTRUCTIVE, OPEN WORLD: call a data source plugin's own resource endpoint through Grafana.
grafana_datasource_proxy_deleteProDestructiveDESTRUCTIVE, OPEN WORLD: forward a DELETE straight through Grafana to the upstream data source.
grafana_datasource_proxy_getProDestructiveDESTRUCTIVE, OPEN WORLD: forward a GET straight through Grafana to the upstream data source.
grafana_datasource_proxy_postProDestructiveDESTRUCTIVE, OPEN WORLD: forward a POST straight through Grafana to the upstream data source.

[Grafana] DESTRUCTIVE, OPEN WORLD: call a data source plugin's own resource endpoint through Grafana. GET /api/datasources/uid//resources/. Plugins expose their own routes here - label and metric name lookups on Prometheus, index lists on Elasticsearch, schema reads on SQL sources - and the path segment is forwarded as written, slashes and all. It is usually a read, but StackJack cannot see which route a plugin exposes or what it does, so it carries the open-world warning. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
datasourceProxyRoutestringyesRequired. The datasource_proxy_route this call targets. The value is a PATH on the upstream data source and may contain slashes; it is forwarded exactly as written.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] DESTRUCTIVE, OPEN WORLD: forward a DELETE straight through Grafana to the upstream data source. DELETE /api/datasources/proxy/uid//. The path segment is sent to that system as written, so this deletes whatever that path names on the upstream system - a Prometheus series, an Elasticsearch index, a database row - and StackJack can neither see nor bound what that is. There is no undo. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
datasourceProxyRoutestringyesRequired. The datasource_proxy_route this call targets. The value is a PATH on the upstream data source and may contain slashes; it is forwarded exactly as written.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] DESTRUCTIVE, OPEN WORLD: forward a GET straight through Grafana to the upstream data source. GET /api/datasources/proxy/uid//. Whatever you put in datasource_proxy_route is appended to that data source's own base URL and sent as written, slashes and all, so this tool reaches anything that system exposes - StackJack can neither see nor describe the effect in advance, and a GET on some data sources is not read-only. Prefer grafana_query_metrics_with_expressions, which is the supported way to query data; reach for the proxy only for a vendor endpoint that has no other route. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
datasourceProxyRoutestringyesRequired. The datasource_proxy_route this call targets. The value is a PATH on the upstream data source and may contain slashes; it is forwarded exactly as written.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] DESTRUCTIVE, OPEN WORLD: forward a POST straight through Grafana to the upstream data source. POST /api/datasources/proxy/uid//. Both the path segment and the body are sent to that system as written, so this tool can do anything that data source's API can do - including its own writes and deletes - and StackJack can neither see nor bound what that is. Prefer grafana_query_metrics_with_expressions for querying. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON, per Grafana's documented sample for this endpoint.
datasourceProxyRoutestringyesRequired. The datasource_proxy_route this call targets. The value is a PATH on the upstream data source and may contain slashes; it is forwarded exactly as written.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

Data source query

ToolPlanAccessSummary
grafana_query_metrics_with_expressionsFreeRead-onlyRun a query against any data source this Grafana has configured and get the result series back.

[Grafana] Run a query against any data source this Grafana has configured and get the result series back. This is how you ask the monitoring system a question - CPU on a host over the last hour, error rate on a service, rows from a SQL data source - rather than reading a dashboard that someone already built. POST /api/ds/query. It is a READ: it creates and changes nothing, despite the POST. The body is {queries: [...], from, to}: each query carries a datasource {uid, type}, a refId, and the fields that data source's own query language needs (expr for Prometheus, rawSql for SQL, expr plus queryType for Loki). Get a uid from grafana_get_data_sources. from and to are epoch milliseconds as strings, or relative like now-1h and now. Pass orgId to query inside a specific organization. Returns raw Grafana JSON - one frame per refId, in Grafana's dataframe shape.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: debug, from, queries, to. Required: from, queries, to.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

Data sources

ToolPlanAccessSummary
grafana_add_data_sourceProWriteCreate a data source.
grafana_check_datasource_health_with_uidFreeRead-onlyAsk Grafana to test one data source and report whether it is actually reachable and answering.
grafana_delete_data_source_by_nameProDestructiveDESTRUCTIVE: delete an existing data source by name.
grafana_delete_data_source_by_uidProDestructiveDESTRUCTIVE: delete an existing data source by UID.
grafana_get_data_source_by_nameFreeRead-onlyGet a single data source by Name.
grafana_get_data_source_by_uidFreeRead-onlyGet a single data source by UID.
grafana_get_data_source_id_by_nameFreeRead-onlyGet data source Id by Name.
grafana_get_data_sourcesFreeRead-onlyList the data sources this Grafana queries - Prometheus, Loki, Elasticsearch, SQL databases, cloud provider metrics and plugin sources.
grafana_update_data_source_by_uidProWriteUpdate an existing data source.

[Grafana] Create a data source. POST /api/datasources. Send the request body as JSON; Grafana documents these fields: access, basicAuth, basicAuthUser, database, isDefault, jsonData, name, secureJsonData, type, uid, url, user. Grafana documents 1 more field; the bodyJson parameter lists all of them. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: access, basicAuth, basicAuthUser, database, isDefault, jsonData, name, secureJsonData, type, uid, url, user, withCredentials.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Ask Grafana to test one data source and report whether it is actually reachable and answering. GET /api/datasources/uid//health. This is the read to make when dashboards are blank or an alert rule stopped firing: it tells you whether the problem is the customer's Prometheus, Loki or database rather than Grafana. Grafana runs the data source plugin's own health check, so the message field carries the upstream system's words. Get the uid from grafana_get_data_sources. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] DESTRUCTIVE: delete an existing data source by name. This function will be removed in the future. Deleting a data source breaks every dashboard, alert rule and query that reads from it, and Grafana does not warn you which ones those are. DELETE /api/datasources/name/. Path parameters: name. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
namestringyesRequired. The name this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: delete an existing data source by UID. Deleting a data source breaks every dashboard, alert rule and query that reads from it, and Grafana does not warn you which ones those are. DELETE /api/datasources/uid/. Path parameters: uid. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] Get a single data source by Name. This function will be removed in the future. GET /api/datasources/name/. Path parameters: name. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
namestringyesRequired. The name this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get a single data source by UID. GET /api/datasources/uid/. Path parameters: uid. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] Get data source Id by Name. This function will be removed in the future. GET /api/datasources/id/. Path parameters: name. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
namestringyesRequired. The name this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] List the data sources this Grafana queries - Prometheus, Loki, Elasticsearch, SQL databases, cloud provider metrics and plugin sources. GET /api/datasources. This is where a data source uid comes from, and that uid is what grafana_query_metrics_with_expressions and grafana_check_datasource_health_with_uid take. Secrets are never returned: Grafana replaces secureJsonData with a secureJsonFields map saying only which secrets are set. Pass orgId to list a specific organization's data sources. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Update an existing data source. PUT /api/datasources/uid/. Path parameters: uid. Send the request body as JSON; Grafana documents these fields: access, basicAuth, basicAuthUser, database, isDefault, jsonData, name, secureJsonData, type, uid, url, user. Grafana documents 2 more fields; the bodyJson parameter lists all of them. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: access, basicAuth, basicAuthUser, database, isDefault, jsonData, name, secureJsonData, type, uid, url, user, version, withCredentials.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

Alert rules

ToolPlanAccessSummary
grafana_delete_alert_ruleProDestructiveDESTRUCTIVE: delete a specific alert rule by UID.
grafana_delete_alert_rule_groupProDestructiveDESTRUCTIVE: delete rule group.
grafana_get_alert_ruleFreeRead-onlyGet a specific alert rule by UID.
grafana_get_alert_rule_exportFreeRead-onlyExport an alert rule in provisioning file format.
grafana_get_alert_rule_groupFreeRead-onlyGet a rule group.
grafana_get_alert_rule_group_exportFreeRead-onlyExport an alert rule group in provisioning file format.
grafana_get_alert_rulesFreeRead-onlyList every Grafana-managed alert rule in the organization.
grafana_get_alert_rules_exportFreeRead-onlyExport all alert rules in provisioning file format.
grafana_post_alert_ruleProWriteCreate a new alert rule.
grafana_put_alert_ruleProWriteUpdate an existing alert rule.
grafana_put_alert_rule_groupProWriteCreate or update alert rule group.

[Grafana] DESTRUCTIVE: delete a specific alert rule by UID. It deletes the resource outright, and Grafana does not undo this. DELETE /api/v1/provisioning/alert-rules/. Path parameters: UID. Optional import hints: X-Disable-Provenance. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. Alert rule UID.
xDisableProvenancestringnonullOptional. The X-Disable-Provenance import hint, sent as a request header. Sent as the X-Disable-Provenance request header.

[Grafana] DESTRUCTIVE: delete rule group. It deletes the resource outright, and Grafana does not undo this. DELETE /api/v1/provisioning/folder//rule-groups/. Path parameters: FolderUID, Group. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
folderUIDstringyesRequired. The FolderUID this call targets.
groupstringyesRequired. The Group this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get a specific alert rule by UID. GET /api/v1/provisioning/alert-rules/. Path parameters: UID. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. Alert rule UID.

[Grafana] Export an alert rule in provisioning file format. GET /api/v1/provisioning/alert-rules//export. Path parameters: UID. Optional filters: download, format. Pass orgId to act on a specific Grafana organization inside the instance. Returns the document Grafana answers with, verbatim - YAML by default on this route, not JSON.

ParamTypeRequiredDefaultDescription
downloadbooleannonullOptional. Whether to initiate a download of the file or not.
formatstringnonullOptional. Format of the downloaded file. Supported yaml, json or hcl. Accept header can also be used, but the query parameter will take precedence. One of: yaml, json, hcl.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. Alert rule UID.

[Grafana] Get a rule group. GET /api/v1/provisioning/folder//rule-groups/. Path parameters: FolderUID, Group. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
folderUIDstringyesRequired. The FolderUID this call targets.
groupstringyesRequired. The Group this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Export an alert rule group in provisioning file format. GET /api/v1/provisioning/folder//rule-groups//export. Path parameters: FolderUID, Group. Optional filters: download, format. Pass orgId to act on a specific Grafana organization inside the instance. Returns the document Grafana answers with, verbatim - YAML by default on this route, not JSON.

ParamTypeRequiredDefaultDescription
downloadbooleannonullOptional. Whether to initiate a download of the file or not.
folderUIDstringyesRequired. The FolderUID this call targets.
formatstringnonullOptional. Format of the downloaded file. Supported yaml, json or hcl. Accept header can also be used, but the query parameter will take precedence. One of: yaml, json, hcl.
groupstringyesRequired. The Group this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] List every Grafana-managed alert rule in the organization. GET /api/v1/provisioning/alert-rules. Each rule carries its uid, title, folderUID, ruleGroup, condition, the queries it evaluates, its for duration, its labels and annotations, and whether it is paused. This is the inventory read for an alerting review - what is armed, what is paused, and what is silent because nobody built a rule for it. Silences and the Alertmanager configuration are NOT reachable through this API at all; Grafana publishes no machine-readable document for them. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Export all alert rules in provisioning file format. GET /api/v1/provisioning/alert-rules/export. Optional filters: download, format, folderUid, group, ruleUid. Pass orgId to act on a specific Grafana organization inside the instance. Returns the document Grafana answers with, verbatim - YAML by default on this route, not JSON.

ParamTypeRequiredDefaultDescription
downloadbooleannonullOptional. Whether to initiate a download of the file or not.
folderUidstringnonullOptional. UIDs of folders from which to export rules. Comma-separate several values; each is sent as its own folderUid parameter.
formatstringnonullOptional. Format of the downloaded file. Supported yaml, json or hcl. Accept header can also be used, but the query parameter will take precedence. One of: yaml, json, hcl.
groupstringnonullOptional. Name of group of rules to export. Must be specified only together with a single folder UID.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
ruleUidstringnonullOptional. UID of alert rule to export. If specified, parameters folderUid and group must be empty.

[Grafana] Create a new alert rule. POST /api/v1/provisioning/alert-rules. Optional import hints: X-Disable-Provenance. Send the request body as JSON; Grafana documents these fields: annotations, condition, data, execErrState, folderUID, for, id, isPaused, keep_firing_for, labels, missingSeriesEvalsToResolve, noDataState. Grafana documents 8 more fields; the bodyJson parameter lists all of them. Required: condition, data, execErrState, folderUID, for, noDataState, orgID, ruleGroup, title. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringnonullOptional. A JSON request body. Grafana publishes no field list for this endpoint; omit it unless you know the shape.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
xDisableProvenancestringnonullOptional. The X-Disable-Provenance import hint, sent as a request header. Sent as the X-Disable-Provenance request header.

[Grafana] Update an existing alert rule. PUT /api/v1/provisioning/alert-rules/. Path parameters: UID. Optional import hints: X-Disable-Provenance. Send the request body as JSON; Grafana documents these fields: annotations, condition, data, execErrState, folderUID, for, id, isPaused, keep_firing_for, labels, missingSeriesEvalsToResolve, noDataState. Grafana documents 8 more fields; the bodyJson parameter lists all of them. Required: condition, data, execErrState, folderUID, for, noDataState, orgID, ruleGroup, title. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringnonullOptional. A JSON request body. Grafana publishes no field list for this endpoint; omit it unless you know the shape.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. Alert rule UID.
xDisableProvenancestringnonullOptional. The X-Disable-Provenance import hint, sent as a request header. Sent as the X-Disable-Provenance request header.

[Grafana] Create or update alert rule group. PUT /api/v1/provisioning/folder//rule-groups/. Path parameters: FolderUID, Group. Optional import hints: X-Disable-Provenance. Send the request body as JSON; Grafana documents these fields: folderUid, interval, rules, title. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringnonullOptional. A JSON request body. Grafana publishes no field list for this endpoint; omit it unless you know the shape.
folderUIDstringyesRequired. The FolderUID this call targets.
groupstringyesRequired. The Group this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
xDisableProvenancestringnonullOptional. The X-Disable-Provenance import hint, sent as a request header. Sent as the X-Disable-Provenance request header.

Contact points

ToolPlanAccessSummary
grafana_delete_contactpointsProDestructiveDESTRUCTIVE: delete a contact point.
grafana_get_contactpointsFreeRead-onlyGet all the contact points.
grafana_get_contactpoints_exportFreeRead-onlyExport all contact points in provisioning file format.
grafana_post_contactpointsProWriteCreate a contact point.
grafana_put_contactpointProWriteUpdate an existing contact point.

[Grafana] DESTRUCTIVE: delete a contact point. It deletes the resource outright, and Grafana does not undo this. DELETE /api/v1/provisioning/contact-points/. Path parameters: UID. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. UID is the contact point unique identifier.

[Grafana] Get all the contact points. GET /api/v1/provisioning/contact-points. Optional filters: name. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
namestringnonullOptional. Filter by name.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Export all contact points in provisioning file format. GET /api/v1/provisioning/contact-points/export. Optional filters: download, format, decrypt, name. Pass orgId to act on a specific Grafana organization inside the instance. Returns the document Grafana answers with, verbatim - YAML by default on this route, not JSON.

ParamTypeRequiredDefaultDescription
decryptbooleannonullOptional. Whether any contained secure settings should be decrypted or left redacted. Redacted settings will contain RedactedValue instead. Currently, only org admin can view decrypted secure settings.
downloadbooleannonullOptional. Whether to initiate a download of the file or not.
formatstringnonullOptional. Format of the downloaded file. Supported yaml, json or hcl. Accept header can also be used, but the query parameter will take precedence. One of: yaml, json, hcl.
namestringnonullOptional. Filter by name.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Create a contact point. POST /api/v1/provisioning/contact-points. Optional import hints: X-Disable-Provenance. Send the request body as JSON; Grafana documents these fields: disableResolveMessage, name, provenance, settings, type, uid. Required: settings, type. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringnonullOptional. A JSON request body. Grafana publishes no field list for this endpoint; omit it unless you know the shape.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
xDisableProvenancestringnonullOptional. The X-Disable-Provenance import hint, sent as a request header. Sent as the X-Disable-Provenance request header.

[Grafana] Update an existing contact point. PUT /api/v1/provisioning/contact-points/. Path parameters: UID. Optional import hints: X-Disable-Provenance. Send the request body as JSON; Grafana documents these fields: disableResolveMessage, name, provenance, settings, type, uid. Required: settings, type. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringnonullOptional. A JSON request body. Grafana publishes no field list for this endpoint; omit it unless you know the shape.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. UID is the contact point unique identifier.
xDisableProvenancestringnonullOptional. The X-Disable-Provenance import hint, sent as a request header. Sent as the X-Disable-Provenance request header.

Mute timings

ToolPlanAccessSummary
grafana_delete_mute_timingProDestructiveDESTRUCTIVE: delete a mute timing.
grafana_export_mute_timingFreeRead-onlyExport a mute timing in provisioning format.
grafana_export_mute_timingsFreeRead-onlyExport all mute timings in provisioning format.
grafana_get_mute_timingFreeRead-onlyGet a mute timing.
grafana_get_mute_timingsFreeRead-onlyGet all the mute timings.
grafana_post_mute_timingProWriteCreate a new mute timing.
grafana_put_mute_timingProWriteReplace an existing mute timing.

[Grafana] DESTRUCTIVE: delete a mute timing. It deletes the resource outright, and Grafana does not undo this. DELETE /api/v1/provisioning/mute-timings/. Path parameters: name. Optional filters: version. Optional import hints: X-Disable-Provenance. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
namestringyesRequired. Mute timing name.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
versionstringnonullOptional. Version of mute timing to use for optimistic concurrency. Leave empty to disable validation.
xDisableProvenancestringnonullOptional. The X-Disable-Provenance import hint, sent as a request header. Sent as the X-Disable-Provenance request header.

[Grafana] Export a mute timing in provisioning format. GET /api/v1/provisioning/mute-timings//export. Path parameters: name. Optional filters: download, format. Pass orgId to act on a specific Grafana organization inside the instance. Returns the document Grafana answers with, verbatim - YAML by default on this route, not JSON.

ParamTypeRequiredDefaultDescription
downloadbooleannonullOptional. Whether to initiate a download of the file or not.
formatstringnonullOptional. Format of the downloaded file. Supported yaml, json or hcl. Accept header can also be used, but the query parameter will take precedence. One of: yaml, json, hcl.
namestringyesRequired. Mute timing name.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Export all mute timings in provisioning format. GET /api/v1/provisioning/mute-timings/export. Optional filters: download, format. Pass orgId to act on a specific Grafana organization inside the instance. Returns the document Grafana answers with, verbatim - YAML by default on this route, not JSON.

ParamTypeRequiredDefaultDescription
downloadbooleannonullOptional. Whether to initiate a download of the file or not.
formatstringnonullOptional. Format of the downloaded file. Supported yaml, json or hcl. Accept header can also be used, but the query parameter will take precedence. One of: yaml, json, hcl.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get a mute timing. GET /api/v1/provisioning/mute-timings/. Path parameters: name. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
namestringyesRequired. Mute timing name.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get all the mute timings. GET /api/v1/provisioning/mute-timings. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Create a new mute timing. POST /api/v1/provisioning/mute-timings. Optional import hints: X-Disable-Provenance. Send the request body as JSON; Grafana documents these fields: name, time_intervals. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringnonullOptional. A JSON request body. Grafana publishes no field list for this endpoint; omit it unless you know the shape.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
xDisableProvenancestringnonullOptional. The X-Disable-Provenance import hint, sent as a request header. Sent as the X-Disable-Provenance request header.

[Grafana] Replace an existing mute timing. PUT /api/v1/provisioning/mute-timings/. Path parameters: name. Optional import hints: X-Disable-Provenance. Send the request body as JSON; Grafana documents these fields: name, time_intervals. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringnonullOptional. A JSON request body. Grafana publishes no field list for this endpoint; omit it unless you know the shape.
namestringyesRequired. Mute timing name.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
xDisableProvenancestringnonullOptional. The X-Disable-Provenance import hint, sent as a request header. Sent as the X-Disable-Provenance request header.

Notification policies

ToolPlanAccessSummary
grafana_get_policy_treeFreeRead-onlyGet the notification policy tree.
grafana_get_policy_tree_exportFreeRead-onlyExport the notification policy tree in provisioning file format.
grafana_put_policy_treeProDestructiveDESTRUCTIVE: replace the organization's WHOLE notification policy tree.
grafana_reset_policy_treeProDestructiveDESTRUCTIVE: reset the organization's notification policy tree to Grafana's default.

[Grafana] Get the notification policy tree. GET /api/v1/provisioning/policies. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Export the notification policy tree in provisioning file format. GET /api/v1/provisioning/policies/export. Pass orgId to act on a specific Grafana organization inside the instance. Returns the document Grafana answers with, verbatim - YAML by default on this route, not JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: replace the organization's WHOLE notification policy tree. PUT /api/v1/provisioning/policies. The policy tree is what decides which contact point each firing alert reaches; this call replaces it outright rather than merging into it, so anything not in the body you send is gone. Getting it wrong silently stops alert notifications reaching anyone and nothing announces that - the alerts still fire, they just go nowhere. Read the current tree with grafana_get_policy_tree, change that object, and send it back. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringnonullOptional. A JSON request body. Grafana publishes no field list for this endpoint; omit it unless you know the shape.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
xDisableProvenancestringnonullOptional. The X-Disable-Provenance import hint, sent as a request header. Sent as the X-Disable-Provenance request header.

[Grafana] DESTRUCTIVE: reset the organization's notification policy tree to Grafana's default. DELETE /api/v1/provisioning/policies. Every routing rule anyone built is discarded and every alert falls back to the default contact point. If that default is unset or wrong, alert notifications stop reaching anyone while the alerts keep firing, and nothing announces it. Save the current tree with grafana_get_policy_tree_export first. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

Notification templates

ToolPlanAccessSummary
grafana_delete_templateProDestructiveDESTRUCTIVE: delete a notification template group.
grafana_get_templateFreeRead-onlyGet a notification template group.
grafana_get_templatesFreeRead-onlyGet all notification template groups.
grafana_put_templateProWriteUpdates an existing notification template group.

[Grafana] DESTRUCTIVE: delete a notification template group. It deletes the resource outright, and Grafana does not undo this. DELETE /api/v1/provisioning/templates/. Path parameters: name. Optional filters: version. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
namestringyesRequired. Template group name.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
versionstringnonullOptional. Version of template to use for optimistic concurrency. Leave empty to disable validation.

[Grafana] Get a notification template group. GET /api/v1/provisioning/templates/. Path parameters: name. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
namestringyesRequired. Template group name.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get all notification template groups. GET /api/v1/provisioning/templates. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Updates an existing notification template group. PUT /api/v1/provisioning/templates/. Path parameters: name. Optional import hints: X-Disable-Provenance. Send the request body as JSON; Grafana documents these fields: template, version. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringnonullOptional. A JSON request body. Grafana publishes no field list for this endpoint; omit it unless you know the shape.
namestringyesRequired. Template group name.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
xDisableProvenancestringnonullOptional. The X-Disable-Provenance import hint, sent as a request header. Sent as the X-Disable-Provenance request header.

Prometheus rule conversion

ToolPlanAccessSummary
grafana_convert_prometheus_cortex_delete_namespaceProDestructiveDESTRUCTIVE: deletes all rule groups that were imported from Prometheus-compatible sources within the specified namespace.
grafana_convert_prometheus_cortex_delete_rule_groupProDestructiveDESTRUCTIVE: deletes a specific rule group if it was imported from a Prometheus-compatible source.
grafana_convert_prometheus_cortex_get_namespaceFreeRead-onlyGets Grafana-managed alert rules that were imported from Prometheus-compatible sources for a specified namespace (folder).
grafana_convert_prometheus_cortex_get_rule_groupFreeRead-onlyGets a single rule group in Prometheus-compatible format if it was imported from a Prometheus-compatible source.
grafana_convert_prometheus_cortex_get_rulesFreeRead-onlyGets all Grafana-managed alert rules that were imported from Prometheus-compatible sources, grouped by namespace.
grafana_convert_prometheus_cortex_post_rule_groupProWriteConverts a Prometheus rule group into a Grafana rule group and creates or updates it within the specified namespace.
grafana_convert_prometheus_cortex_post_rule_groupsProWriteConverts the submitted rule groups into Grafana-Managed Rules.
grafana_convert_prometheus_delete_namespaceProDestructiveDESTRUCTIVE: deletes all rule groups that were imported from Prometheus-compatible sources within the specified namespace.
grafana_convert_prometheus_delete_rule_groupProDestructiveDESTRUCTIVE: deletes a specific rule group if it was imported from a Prometheus-compatible source.
grafana_convert_prometheus_get_namespaceFreeRead-onlyGets Grafana-managed alert rules that were imported from Prometheus-compatible sources for a specified namespace (folder).
grafana_convert_prometheus_get_rule_groupFreeRead-onlyGets a single rule group in Prometheus-compatible format if it was imported from a Prometheus-compatible source.
grafana_convert_prometheus_get_rulesFreeRead-onlyGets all Grafana-managed alert rules that were imported from Prometheus-compatible sources, grouped by namespace.
grafana_convert_prometheus_post_rule_groupProWriteConverts a Prometheus rule group into a Grafana rule group and creates or updates it within the specified namespace.
grafana_convert_prometheus_post_rule_groupsProWriteConverts the submitted rule groups into Grafana-Managed Rules.

[Grafana] DESTRUCTIVE: deletes all rule groups that were imported from Prometheus-compatible sources within the specified namespace. It deletes every Grafana alert rule that was imported from a Prometheus rule file under this namespace or group, so the alerting they provide stops. DELETE /api/convert/api/prom/rules/. Path parameters: NamespaceTitle. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
namespaceTitlestringyesRequired. The NamespaceTitle this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: deletes a specific rule group if it was imported from a Prometheus-compatible source. It deletes every Grafana alert rule that was imported from a Prometheus rule file under this namespace or group, so the alerting they provide stops. DELETE /api/convert/api/prom/rules//. Path parameters: NamespaceTitle, Group. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
groupstringyesRequired. The Group this call targets.
namespaceTitlestringyesRequired. The NamespaceTitle this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Gets Grafana-managed alert rules that were imported from Prometheus-compatible sources for a specified namespace (folder). GET /api/convert/api/prom/rules/. Path parameters: NamespaceTitle. Pass orgId to act on a specific Grafana organization inside the instance. Returns the document Grafana answers with, verbatim - YAML by default on this route, not JSON.

ParamTypeRequiredDefaultDescription
namespaceTitlestringyesRequired. The NamespaceTitle this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Gets a single rule group in Prometheus-compatible format if it was imported from a Prometheus-compatible source. GET /api/convert/api/prom/rules//. Path parameters: NamespaceTitle, Group. Pass orgId to act on a specific Grafana organization inside the instance. Returns the document Grafana answers with, verbatim - YAML by default on this route, not JSON.

ParamTypeRequiredDefaultDescription
groupstringyesRequired. The Group this call targets.
namespaceTitlestringyesRequired. The NamespaceTitle this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Gets all Grafana-managed alert rules that were imported from Prometheus-compatible sources, grouped by namespace. GET /api/convert/api/prom/rules. Pass orgId to act on a specific Grafana organization inside the instance. Returns the document Grafana answers with, verbatim - YAML by default on this route, not JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Converts a Prometheus rule group into a Grafana rule group and creates or updates it within the specified namespace. POST /api/convert/api/prom/rules/. Path parameters: NamespaceTitle. Optional import hints: x-grafana-alerting-datasource-uid, x-grafana-alerting-recording-rules-paused, x-grafana-alerting-alert-rules-paused, x-grafana-alerting-target-datasource-uid, x-grafana-alerting-folder-uid, x-grafana-alerting-notification-settings. Send the rule group as a Prometheus-format YAML document; it is passed to Grafana verbatim. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
namespaceTitlestringyesRequired. The NamespaceTitle this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
xGrafanaAlertingAlertRulesPausedbooleannonullOptional. The x-grafana-alerting-alert-rules-paused import hint, sent as a request header. Sent as the x-grafana-alerting-alert-rules-paused request header.
xGrafanaAlertingDatasourceUidstringnonullOptional. The x-grafana-alerting-datasource-uid import hint, sent as a request header. Sent as the x-grafana-alerting-datasource-uid request header.
xGrafanaAlertingFolderUidstringnonullOptional. The x-grafana-alerting-folder-uid import hint, sent as a request header. Sent as the x-grafana-alerting-folder-uid request header.
xGrafanaAlertingNotificationSettingsstringnonullOptional. The x-grafana-alerting-notification-settings import hint, sent as a request header. Sent as the x-grafana-alerting-notification-settings request header.
xGrafanaAlertingRecordingRulesPausedbooleannonullOptional. The x-grafana-alerting-recording-rules-paused import hint, sent as a request header. Sent as the x-grafana-alerting-recording-rules-paused request header.
xGrafanaAlertingTargetDatasourceUidstringnonullOptional. The x-grafana-alerting-target-datasource-uid import hint, sent as a request header. Sent as the x-grafana-alerting-target-datasource-uid request header.
yamlstringyesRequired. The rule group as a Prometheus-format YAML document, exactly as it would appear in a Prometheus rules file. It is sent to Grafana verbatim.

[Grafana] Converts the submitted rule groups into Grafana-Managed Rules. POST /api/convert/api/prom/rules. Send the rule groups as a YAML document. Grafana's specification declares no request body for this route even though its own summary describes submitted rule groups, so StackJack forwards exactly what you send and claims no shape for it. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
yamlstringyesRequired. The rule groups as a YAML document. Grafana publishes no schema for this route's body, so it is sent verbatim and StackJack cannot validate it for you.

[Grafana] DESTRUCTIVE: deletes all rule groups that were imported from Prometheus-compatible sources within the specified namespace. It deletes every Grafana alert rule that was imported from a Prometheus rule file under this namespace or group, so the alerting they provide stops. DELETE /api/convert/prometheus/config/v1/rules/. Path parameters: NamespaceTitle. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
namespaceTitlestringyesRequired. The NamespaceTitle this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: deletes a specific rule group if it was imported from a Prometheus-compatible source. It deletes every Grafana alert rule that was imported from a Prometheus rule file under this namespace or group, so the alerting they provide stops. DELETE /api/convert/prometheus/config/v1/rules//. Path parameters: NamespaceTitle, Group. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
groupstringyesRequired. The Group this call targets.
namespaceTitlestringyesRequired. The NamespaceTitle this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Gets Grafana-managed alert rules that were imported from Prometheus-compatible sources for a specified namespace (folder). GET /api/convert/prometheus/config/v1/rules/. Path parameters: NamespaceTitle. Pass orgId to act on a specific Grafana organization inside the instance. Returns the document Grafana answers with, verbatim - YAML by default on this route, not JSON.

ParamTypeRequiredDefaultDescription
namespaceTitlestringyesRequired. The NamespaceTitle this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Gets a single rule group in Prometheus-compatible format if it was imported from a Prometheus-compatible source. GET /api/convert/prometheus/config/v1/rules//. Path parameters: NamespaceTitle, Group. Pass orgId to act on a specific Grafana organization inside the instance. Returns the document Grafana answers with, verbatim - YAML by default on this route, not JSON.

ParamTypeRequiredDefaultDescription
groupstringyesRequired. The Group this call targets.
namespaceTitlestringyesRequired. The NamespaceTitle this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Gets all Grafana-managed alert rules that were imported from Prometheus-compatible sources, grouped by namespace. GET /api/convert/prometheus/config/v1/rules. Pass orgId to act on a specific Grafana organization inside the instance. Returns the document Grafana answers with, verbatim - YAML by default on this route, not JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Converts a Prometheus rule group into a Grafana rule group and creates or updates it within the specified namespace. POST /api/convert/prometheus/config/v1/rules/. Path parameters: NamespaceTitle. Optional import hints: x-grafana-alerting-datasource-uid, x-grafana-alerting-recording-rules-paused, x-grafana-alerting-alert-rules-paused, x-grafana-alerting-target-datasource-uid, x-grafana-alerting-folder-uid, x-grafana-alerting-notification-settings. Send the rule group as a Prometheus-format YAML document; it is passed to Grafana verbatim. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
namespaceTitlestringyesRequired. The NamespaceTitle this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
xGrafanaAlertingAlertRulesPausedbooleannonullOptional. The x-grafana-alerting-alert-rules-paused import hint, sent as a request header. Sent as the x-grafana-alerting-alert-rules-paused request header.
xGrafanaAlertingDatasourceUidstringnonullOptional. The x-grafana-alerting-datasource-uid import hint, sent as a request header. Sent as the x-grafana-alerting-datasource-uid request header.
xGrafanaAlertingFolderUidstringnonullOptional. The x-grafana-alerting-folder-uid import hint, sent as a request header. Sent as the x-grafana-alerting-folder-uid request header.
xGrafanaAlertingNotificationSettingsstringnonullOptional. The x-grafana-alerting-notification-settings import hint, sent as a request header. Sent as the x-grafana-alerting-notification-settings request header.
xGrafanaAlertingRecordingRulesPausedbooleannonullOptional. The x-grafana-alerting-recording-rules-paused import hint, sent as a request header. Sent as the x-grafana-alerting-recording-rules-paused request header.
xGrafanaAlertingTargetDatasourceUidstringnonullOptional. The x-grafana-alerting-target-datasource-uid import hint, sent as a request header. Sent as the x-grafana-alerting-target-datasource-uid request header.
yamlstringyesRequired. The rule group as a Prometheus-format YAML document, exactly as it would appear in a Prometheus rules file. It is sent to Grafana verbatim.

[Grafana] Converts the submitted rule groups into Grafana-Managed Rules. POST /api/convert/prometheus/config/v1/rules. Send the rule groups as a YAML document. Grafana's specification declares no request body for this route even though its own summary describes submitted rule groups, so StackJack forwards exactly what you send and claims no shape for it. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
yamlstringyesRequired. The rule groups as a YAML document. Grafana publishes no schema for this route's body, so it is sent verbatim and StackJack cannot validate it for you.

Recording rules

ToolPlanAccessSummary
grafana_create_recording_ruleProWriteCreate a recording rule that is then registered and started.
grafana_create_recording_rule_write_targetProWriteCreate a remote write target.
grafana_delete_recording_ruleProDestructiveDESTRUCTIVE: delete removes the rule from the registry and stops it.
grafana_delete_recording_rule_write_targetProDestructiveDESTRUCTIVE: delete the remote write target.
grafana_get_recording_rule_write_targetFreeRead-onlyReturn the prometheus remote write target.
grafana_list_recording_rulesFreeRead-onlyLists all rules in the database: active or deleted.
grafana_test_create_recording_ruleProWriteTest a recording rule.
grafana_update_recording_ruleProWriteUpdate the active status of a rule.

[Grafana] Create a recording rule that is then registered and started. POST /api/recording-rules. Send the request body as JSON; Grafana documents these fields: active, count, description, dest_data_source_uid, id, interval, name, prom_name, queries, range, target_ref_id. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: active, count, description, dest_data_source_uid, id, interval, name, prom_name, queries, range, target_ref_id.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Create a remote write target. POST /api/recording-rules/writer. Send the request body as JSON; Grafana documents these fields: data_source_uid, id, remote_write_path. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: data_source_uid, id, remote_write_path.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: delete removes the rule from the registry and stops it. It deletes the recording rule, so the series it was writing stop being produced and anything querying them goes empty. DELETE /api/recording-rules/. Path parameters: recordingRuleID. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
recordingRuleIDintegeryesRequired. The recordingRuleID this call targets.

[Grafana] DESTRUCTIVE: delete the remote write target. It deletes the recording rule, so the series it was writing stop being produced and anything querying them goes empty. DELETE /api/recording-rules/writer. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Return the prometheus remote write target. GET /api/recording-rules/writer. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Lists all rules in the database: active or deleted. GET /api/recording-rules. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Test a recording rule. POST /api/recording-rules/test. Send the request body as JSON; Grafana documents these fields: active, count, description, dest_data_source_uid, id, interval, name, prom_name, queries, range, target_ref_id. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: active, count, description, dest_data_source_uid, id, interval, name, prom_name, queries, range, target_ref_id.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Update the active status of a rule. PUT /api/recording-rules. Send the request body as JSON; Grafana documents these fields: active, count, description, dest_data_source_uid, id, interval, name, prom_name, queries, range, target_ref_id. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: active, count, description, dest_data_source_uid, id, interval, name, prom_name, queries, range, target_ref_id.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

Annotations

ToolPlanAccessSummary
grafana_delete_annotation_by_idProDestructiveDESTRUCTIVE: delete Annotation By ID.
grafana_get_annotation_by_idFreeRead-onlyGet Annotation by ID.
grafana_get_annotation_tagsFreeRead-onlyFind Annotations Tags.
grafana_get_annotationsFreeRead-onlyFind Annotations.
grafana_mass_delete_annotationsProDestructiveDESTRUCTIVE: delete annotations in bulk.
grafana_patch_annotationProWritePatch Annotation.
grafana_post_annotationProWriteWrite an annotation - a timestamped marker that appears on every dashboard panel covering that moment.
grafana_post_graphite_annotationProWriteCreate Annotation in Graphite format.
grafana_update_annotationProWriteUpdate Annotation.

[Grafana] DESTRUCTIVE: delete Annotation By ID. It deletes the resource outright, and Grafana does not undo this. DELETE /api/annotations/. Path parameters: annotation_id. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
annotationIdstringyesRequired. The annotation_id this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get Annotation by ID. GET /api/annotations/. Path parameters: annotation_id. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
annotationIdstringyesRequired. The annotation_id this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Find Annotations Tags. GET /api/annotations/tags. Optional filters: tag, limit. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
limitstringnonullOptional. Max limit for results returned. Capped at 1000 by StackJack.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
tagstringnonullOptional. Tag is a string that you can use to filter tags.

[Grafana] Find Annotations. GET /api/annotations. Optional filters: from, to, userId, userUID, alertId, alertUID, dashboardId, dashboardUID, panelId, limit, tags, type, matchAny. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
alertIdintegernonullOptional. Find annotations for a specified alert rule by its ID.
alertUIDstringnonullOptional. Find annotations for a specified alert rule by its UID.
dashboardIdintegernonullOptional. Find annotations that are scoped to a specific dashboard.
dashboardUIDstringnonullOptional. Find annotations that are scoped to a specific dashboard.
fromintegernonullOptional. Find annotations created after specific epoch datetime in milliseconds.
limitintegernonullOptional. Max limit for results returned. Capped at 1000 by StackJack.
matchAnybooleannonullOptional. Match any or all tags.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
panelIdintegernonullOptional. Find annotations that are scoped to a specific panel.
tagsstringnonullOptional. Use this to filter organization annotations. Organization annotations are annotations from an annotation data source that are not connected specifically to a dashboard or panel. You can filter by multiple tags. Comma-separate several values; each is sent as its own tags parameter.
tointegernonullOptional. Find annotations created before specific epoch datetime in milliseconds.
typestringnonullOptional. Return alerts or user created annotations. One of: alert, annotation.
userIdintegernonullOptional. Limit response to annotations created by specific user.
userUIDstringnonullOptional. Limit response to annotations created by a specific user, identified by UID.

[Grafana] DESTRUCTIVE: delete annotations in bulk. POST /api/annotations/mass-delete. It deletes by dashboard or panel rather than by id, so a wrong dashboardUID erases the entire change history for that dashboard - every deployment and maintenance marker anyone ever wrote on it. Send {dashboardUID, panelId} or {dashboardId, panelId}. There is no undo and no dry run; read them first with grafana_get_annotations for the same dashboard. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: annotationId, dashboardId, dashboardUID, panelId.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Patch Annotation. PATCH /api/annotations/. Path parameters: annotation_id. Send the request body as JSON; Grafana documents these fields: data, id, tags, text, time, timeEnd. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
annotationIdstringyesRequired. The annotation_id this call targets.
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: data, id, tags, text, time, timeEnd.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Write an annotation - a timestamped marker that appears on every dashboard panel covering that moment. POST /api/annotations. This is the highest-value small write in the connector: put a marker down for a deployment, a maintenance window, a failover or a config change and every graph afterwards shows what happened when. Send {time, timeEnd, tags, text}, with times as epoch MILLISECONDS; add dashboardUID and panelId to pin it to one panel, or leave both off for an organization-wide marker. timeEnd makes it a region rather than a point. Tag it so grafana_get_annotations can find it again. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: dashboardId, dashboardUID, data, panelId, tags, text, time, timeEnd. Required: text.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Create Annotation in Graphite format. POST /api/annotations/graphite. Send the request body as JSON; Grafana documents these fields: data, tags, what, when. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: data, tags, what, when.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Update Annotation. PUT /api/annotations/. Path parameters: annotation_id. Send the request body as JSON; Grafana documents these fields: data, id, tags, text, time, timeEnd. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
annotationIdstringyesRequired. The annotation_id this call targets.
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: data, id, tags, text, time, timeEnd.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

All organizations

ToolPlanAccessSummary
grafana_add_org_userProWriteAdd a new user to the current organization.
grafana_create_orgProWriteCreate Organization.
grafana_delete_org_by_idProDestructiveDESTRUCTIVE: delete Organization.
grafana_get_org_by_idFreeRead-onlyGet Organization by ID.
grafana_get_org_by_nameFreeRead-onlyGet Organization by Name.
grafana_get_org_usersFreeRead-onlyGet Users in Organization.
grafana_remove_org_userProDestructiveDESTRUCTIVE: delete user in current organization.
grafana_search_org_usersFreeRead-onlySearch Users in Organization.
grafana_search_orgsFreeRead-onlyList every organization in the instance.
grafana_update_orgProWriteUpdate Organization.
grafana_update_org_addressProWriteUpdate Organization's address.
grafana_update_org_userProWriteUpdate Users in Organization.

[Grafana] Add a new user to the current organization. POST /api/orgs//users. Path parameters: org_id. Send the request body as JSON; Grafana documents these fields: loginOrEmail, role. Returns raw Grafana JSON. Grafana's own documentation marks this route as Basic-authentication only - its API specification omits the marking, and the vendor's Admin Organizations guide states it outright - so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: loginOrEmail, role.
orgIdintegeryesRequired. The org_id this call targets.

[Grafana] Create Organization. POST /api/orgs. Send the request body as JSON; Grafana documents these fields: name. Returns raw Grafana JSON. Grafana's own documentation marks this route as Basic-authentication only - its API specification omits the marking, and the vendor's Admin Organizations guide states it outright - so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: name.

[Grafana] DESTRUCTIVE: delete Organization. It deletes a whole Grafana organization - its dashboards, data sources, alert rules and members - which for an MSP running one organization per customer is that customer's entire Grafana. DELETE /api/orgs/. Path parameters: org_id. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
orgIdintegeryesRequired. The org_id this call targets.

[Grafana] Get Organization by ID. GET /api/orgs/. Path parameters: org_id. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
orgIdintegeryesRequired. The org_id this call targets.

[Grafana] Get Organization by Name. GET /api/orgs/name/. Path parameters: org_name. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
orgNamestringyesRequired. The org_name this call targets.

[Grafana] Get Users in Organization. GET /api/orgs//users. Path parameters: org_id. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
orgIdintegeryesRequired. The org_id this call targets.

[Grafana] DESTRUCTIVE: delete user in current organization. It deletes the resource outright, and Grafana does not undo this. DELETE /api/orgs//users/. Path parameters: org_id, user_id. Returns raw Grafana JSON. Grafana's own documentation marks this route as Basic-authentication only - its API specification omits the marking, and the vendor's Admin Organizations guide states it outright - so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
orgIdintegeryesRequired. The org_id this call targets.
userIdintegeryesRequired. The user_id this call targets.

[Grafana] Search Users in Organization. GET /api/orgs//users/search. Path parameters: org_id. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
orgIdintegeryesRequired. The org_id this call targets.

[Grafana] List every organization in the instance. GET /api/orgs. For an MSP running one Grafana with one organization per customer, this is the customer list, and the ids it returns are what the orgId argument on every other tool takes. Use grafana_get_current_org for the organization this connection is already working in. Paging is page plus perpage, numbered from 1 and capped at 1000 by StackJack. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
namestringnonullOptional. The name filter.
pageintegernonullOptional. The page filter.
perpageintegernonullOptional. Number of items per page. Capped at 1000 by StackJack.
querystringnonullOptional. If set it will return results where the query value is contained in the name field. Query values with spaces need to be URL encoded.

[Grafana] Update Organization. PUT /api/orgs/. Path parameters: org_id. Send the request body as JSON; Grafana documents these fields: name. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: name.
orgIdintegeryesRequired. The org_id this call targets.

[Grafana] Update Organization's address. PUT /api/orgs//address. Path parameters: org_id. Send the request body as JSON; Grafana documents these fields: address1, address2, city, country, state, zipcode. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: address1, address2, city, country, state, zipcode.
orgIdintegeryesRequired. The org_id this call targets.

[Grafana] Update Users in Organization. PATCH /api/orgs//users/. Path parameters: org_id, user_id. Send the request body as JSON; Grafana documents these fields: role. Returns raw Grafana JSON. Grafana's own documentation marks this route as Basic-authentication only - its API specification omits the marking, and the vendor's Admin Organizations guide states it outright - so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: role.
orgIdintegeryesRequired. The org_id this call targets.
userIdintegeryesRequired. The user_id this call targets.

Current organization

ToolPlanAccessSummary
grafana_add_org_inviteProWriteAdd invite.
grafana_add_org_user_to_current_orgProWriteAdd a new user to the current organization.
grafana_get_current_orgFreeRead-onlyRead the organization this connection is working in - its id and name.
grafana_get_org_preferencesFreeRead-onlyGet Current Org Prefs.
grafana_get_org_users_for_current_orgFreeRead-onlyGet all users within the current organization.
grafana_get_org_users_for_current_org_lookupFreeRead-onlyGet all users within the current organization (lookup).
grafana_get_pending_org_invitesFreeRead-onlyGet pending invites.
grafana_patch_org_preferencesProWritePatch Current Org Prefs.
grafana_remove_org_user_for_current_orgProDestructiveDESTRUCTIVE: delete user in current organization.
grafana_revoke_inviteProDestructiveDESTRUCTIVE: revoke invite.
grafana_update_current_orgProWriteUpdate current Organization.
grafana_update_current_org_addressProWriteUpdate current Organization's address.
grafana_update_org_preferencesProWriteUpdate Current Org Prefs.
grafana_update_org_user_for_current_orgProWriteUpdates the given user.

[Grafana] Add invite. POST /api/org/invites. Send the request body as JSON; Grafana documents these fields: loginOrEmail, name, role, sendEmail. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: loginOrEmail, name, role, sendEmail.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Add a new user to the current organization. POST /api/org/users. Send the request body as JSON; Grafana documents these fields: loginOrEmail, role. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: loginOrEmail, role.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Read the organization this connection is working in - its id and name. GET /api/org. Cheap, takes no parameters, and it is the call to make first when you want to know what this credential can actually see: it is also what StackJack uses to check the connection is alive. For an instance holding several customer organizations, grafana_search_orgs would list them all but Grafana refuses service account tokens on that route, while this one works for any token. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get Current Org Prefs. GET /api/org/preferences. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get all users within the current organization. GET /api/org/users. Optional filters: query, limit. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
limitintegernonullOptional. The limit filter. Capped at 1000 by StackJack.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
querystringnonullOptional. The query filter.

[Grafana] Get all users within the current organization (lookup). GET /api/org/users/lookup. Optional filters: query, limit. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
limitintegernonullOptional. The limit filter. Capped at 1000 by StackJack.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
querystringnonullOptional. The query filter.

[Grafana] Get pending invites. GET /api/org/invites. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Patch Current Org Prefs. PATCH /api/org/preferences. Send the request body as JSON; Grafana documents these fields: homeDashboardId, homeDashboardUID, language, navbar, queryHistory, theme, timezone, weekStart. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: homeDashboardId, homeDashboardUID, language, navbar, queryHistory, theme, timezone, weekStart.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: delete user in current organization. It deletes the resource outright, and Grafana does not undo this. DELETE /api/org/users/. Path parameters: user_id. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
userIdintegeryesRequired. The user_id this call targets.

[Grafana] DESTRUCTIVE: revoke invite. It deletes the resource outright, and Grafana does not undo this. DELETE /api/org/invites//revoke. Path parameters: invitation_code. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
invitationCodestringyesRequired. The invitation_code this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Update current Organization. PUT /api/org. Send the request body as JSON; Grafana documents these fields: name. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: name.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Update current Organization's address. PUT /api/org/address. Send the request body as JSON; Grafana documents these fields: address1, address2, city, country, state, zipcode. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: address1, address2, city, country, state, zipcode.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Update Current Org Prefs. PUT /api/org/preferences. Send the request body as JSON; Grafana documents these fields: homeDashboardId, homeDashboardUID, language, navbar, queryHistory, theme, timezone, weekStart. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: homeDashboardId, homeDashboardUID, language, navbar, queryHistory, theme, timezone, weekStart.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Updates the given user. PATCH /api/org/users/. Path parameters: user_id. Send the request body as JSON; Grafana documents these fields: role. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: role.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
userIdintegeryesRequired. The user_id this call targets.

Quotas

ToolPlanAccessSummary
grafana_get_current_org_quotaFreeRead-onlyFetch Organization quota.
grafana_get_org_quotaFreeRead-onlyFetch Organization quota.
grafana_get_user_quotaFreeRead-onlyFetch user quota.
grafana_get_user_quotasFreeRead-onlyFetch user quota.
grafana_update_org_quotaProDestructiveDESTRUCTIVE: update user quota.
grafana_update_user_quotaProDestructiveDESTRUCTIVE: update user quota.

[Grafana] Fetch Organization quota. GET /api/org/quotas. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Fetch Organization quota. GET /api/orgs//quotas. Path parameters: org_id. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdintegeryesRequired. The org_id this call targets.

[Grafana] Fetch user quota. GET /api/admin/users//quotas. Path parameters: user_id. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
userIdintegeryesRequired. The user_id this call targets.

[Grafana] Fetch user quota. GET /api/user/quotas. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: update user quota. It changes a resource quota, which can stop the organization or the user creating dashboards, data sources or alert rules with no other warning. PUT /api/orgs//quotas/. Path parameters: quota_target, org_id. Send the request body as JSON; Grafana documents these fields: limit, target. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: limit, target.
orgIdintegeryesRequired. The org_id this call targets.
quotaTargetstringyesRequired. The quota_target this call targets.

[Grafana] DESTRUCTIVE: update user quota. It changes a resource quota, which can stop the organization or the user creating dashboards, data sources or alert rules with no other warning. PUT /api/admin/users//quotas/. Path parameters: quota_target, user_id. Send the request body as JSON; Grafana documents these fields: limit, target. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: limit, target.
quotaTargetstringyesRequired. The quota_target this call targets.
userIdintegeryesRequired. The user_id this call targets.

Signed-in user

ToolPlanAccessSummary
grafana_change_user_passwordProDestructiveDESTRUCTIVE: change Password.
grafana_get_signed_in_userFreeRead-onlyGet (current authenticated user).
grafana_get_signed_in_user_org_listFreeRead-onlyOrganizations of the actual User.
grafana_get_signed_in_user_team_listFreeRead-onlyTeams that the actual User is member of.
grafana_get_user_auth_tokensFreeRead-onlyAuth tokens of the actual User.
grafana_get_user_preferencesFreeRead-onlyGet user preferences.
grafana_patch_user_preferencesProWritePatch user preferences.
grafana_revoke_user_auth_tokenProDestructiveDESTRUCTIVE: revoke an auth token of the actual User.
grafana_star_dashboard_by_uidProWriteStar a dashboard.
grafana_unstar_dashboard_by_uidProDestructiveDESTRUCTIVE: unstar a dashboard.
grafana_update_signed_in_userProWriteUpdate signed in User.
grafana_update_user_preferencesProWriteUpdate user preferences.
grafana_user_set_using_orgProWriteSwitch user context for signed in user.

[Grafana] DESTRUCTIVE: change Password. It replaces the password of the SERVER-ADMINISTRATOR ACCOUNT THIS CONNECTION SIGNS IN WITH, not another person's: Grafana resolves this route against the signed-in user, and this route travels on the username and password stored on the connection. The stored pair stops working the moment Grafana accepts the change, so every Basic-only Grafana tool fails until somebody re-enters the new password in Configure. Use grafana_admin_update_user_password to change anybody else's password. PUT /api/user/password. Send the request body as JSON; Grafana documents these fields: newPassword, oldPassword. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: newPassword, oldPassword.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get (current authenticated user). GET /api/user. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Organizations of the actual User. GET /api/user/orgs. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Teams that the actual User is member of. GET /api/user/teams. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Auth tokens of the actual User. GET /api/user/auth-tokens. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get user preferences. GET /api/user/preferences. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Patch user preferences. PATCH /api/user/preferences. Send the request body as JSON; Grafana documents these fields: homeDashboardId, homeDashboardUID, language, navbar, queryHistory, theme, timezone, weekStart. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: homeDashboardId, homeDashboardUID, language, navbar, queryHistory, theme, timezone, weekStart.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: revoke an auth token of the actual User. It ends one of the signed-in user's own live Grafana sessions immediately - which, on a service account token, can be the session StackJack itself is using. POST /api/user/revoke-auth-token. Send the request body as JSON; Grafana documents these fields: authTokenId. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: authTokenId.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Star a dashboard. POST /api/user/stars/dashboard/uid/. Path parameters: dashboard_uid. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
dashboardUidstringyesRequired. The dashboard_uid this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: unstar a dashboard. It deletes the resource outright, and Grafana does not undo this. DELETE /api/user/stars/dashboard/uid/. Path parameters: dashboard_uid. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
dashboardUidstringyesRequired. The dashboard_uid this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Update signed in User. PUT /api/user. Send the request body as JSON; Grafana documents these fields: email, login, name, theme. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: email, login, name, theme.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Update user preferences. PUT /api/user/preferences. Send the request body as JSON; Grafana documents these fields: homeDashboardId, homeDashboardUID, language, navbar, queryHistory, theme, timezone, weekStart. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: homeDashboardId, homeDashboardUID, language, navbar, queryHistory, theme, timezone, weekStart.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Switch user context for signed in user. POST /api/user/using/. Path parameters: org_id. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdintegeryesRequired. The org_id this call targets.

Team sync

ToolPlanAccessSummary
grafana_add_team_groupProWriteAdd External Group.
grafana_get_team_groupsFreeRead-onlyGet External Groups.
grafana_remove_team_groupProDestructiveDESTRUCTIVE: remove External Group.
grafana_search_team_groupsFreeRead-onlySearch for team groups with optional filtering and pagination.

[Grafana] Add External Group. POST /api/teams//groups. Path parameters: teamId. Send the request body as JSON; Grafana documents these fields: groupId. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: groupId.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
teamIdstringyesRequired. The teamId this call targets.

[Grafana] Get External Groups. GET /api/teams//groups. Path parameters: teamId. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
teamIdstringyesRequired. The teamId this call targets.

[Grafana] DESTRUCTIVE: remove External Group. It deletes the resource outright, and Grafana does not undo this. DELETE /api/teams//groups. Path parameters: teamId. Optional filters: groupId. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
groupIdstringnonullOptional. The groupId filter.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
teamIdstringyesRequired. The teamId this call targets.

[Grafana] Search for team groups with optional filtering and pagination. GET /api/teams//groups/search. Path parameters: teamId. Optional filters: page, perpage, query, name. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
namestringnonullOptional. Filter by exact name match.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
pageintegernonullOptional. The page filter.
perpageintegernonullOptional. Number of items per page. Capped at 1000 by StackJack.
querystringnonullOptional. If set it will return results where the query value is contained in the name field. Query values with spaces need to be URL encoded.
teamIdintegeryesRequired. The teamId this call targets.

Teams

ToolPlanAccessSummary
grafana_add_team_memberProWriteAdd Team Member.
grafana_create_teamProWriteAdd Team.
grafana_delete_team_by_idProDestructiveDESTRUCTIVE: delete Team By ID.
grafana_get_team_by_idFreeRead-onlyGet Team By ID.
grafana_get_team_membersFreeRead-onlyGet Team Members.
grafana_get_team_preferencesFreeRead-onlyGet Team Preferences.
grafana_remove_team_memberProDestructiveDESTRUCTIVE: remove Member From Team.
grafana_search_teamsFreeRead-onlyTeam Search With Paging.
grafana_set_team_membershipsProDestructiveDESTRUCTIVE: set team memberships.
grafana_update_teamProWriteUpdate Team.
grafana_update_team_memberProWriteUpdate Team Member.
grafana_update_team_preferencesProWriteUpdate Team Preferences.

[Grafana] Add Team Member. POST /api/teams//members. Path parameters: team_id. Send the request body as JSON; Grafana documents these fields: userId. Required: userId. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: userId. Required: userId.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
teamIdstringyesRequired. The team_id this call targets.

[Grafana] Add Team. POST /api/teams. Send the request body as JSON; Grafana documents these fields: email, name. Required: name. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: email, name. Required: name.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: delete Team By ID. It deletes the resource outright, and Grafana does not undo this. DELETE /api/teams/. Path parameters: team_id. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
teamIdstringyesRequired. The team_id this call targets.

[Grafana] Get Team By ID. GET /api/teams/. Path parameters: team_id. Optional filters: accesscontrol. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
accesscontrolbooleannonullOptional. The accesscontrol filter.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
teamIdstringyesRequired. The team_id this call targets.

[Grafana] Get Team Members. GET /api/teams//members. Path parameters: team_id. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
teamIdstringyesRequired. The team_id this call targets.

[Grafana] Get Team Preferences. GET /api/teams//preferences. Path parameters: team_id. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
teamIdstringyesRequired. The team_id this call targets.

[Grafana] DESTRUCTIVE: remove Member From Team. It deletes the resource outright, and Grafana does not undo this. DELETE /api/teams//members/. Path parameters: team_id, user_id. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
teamIdstringyesRequired. The team_id this call targets.
userIdintegeryesRequired. The user_id this call targets.

[Grafana] Team Search With Paging. GET /api/teams/search. Optional filters: page, perpage, name, query, accesscontrol, sort. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
accesscontrolbooleannonullOptional. The accesscontrol filter.
namestringnonullOptional. The name filter.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
pageintegernonullOptional. The page filter.
perpageintegernonullOptional. Number of items per page. Capped at 1000 by StackJack.
querystringnonullOptional. If set it will return results where the query value is contained in the name field. Query values with spaces need to be URL encoded.
sortstringnonullOptional. The sort filter.

[Grafana] DESTRUCTIVE: set team memberships. It REPLACES the team's whole membership list with the one you send. Every member you leave out is removed from the team, and loses whatever dashboards, folders and data sources that team's permissions granted them. To add one person, read the current members first and send them all back. PUT /api/teams//members. Path parameters: team_id. Send the request body as JSON; Grafana documents these fields: admins, members. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: admins, members.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
teamIdstringyesRequired. The team_id this call targets.

[Grafana] Update Team. PUT /api/teams/. Path parameters: team_id. Send the request body as JSON; Grafana documents these fields: email, name. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: email, name.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
teamIdstringyesRequired. The team_id this call targets.

[Grafana] Update Team Member. PUT /api/teams//members/. Path parameters: team_id, user_id. Send the request body as JSON; Grafana documents these fields: permission. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: permission.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
teamIdstringyesRequired. The team_id this call targets.
userIdintegeryesRequired. The user_id this call targets.

[Grafana] Update Team Preferences. PUT /api/teams//preferences. Path parameters: team_id. Send the request body as JSON; Grafana documents these fields: homeDashboardId, homeDashboardUID, language, navbar, queryHistory, theme, timezone, weekStart. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: homeDashboardId, homeDashboardUID, language, navbar, queryHistory, theme, timezone, weekStart.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
teamIdstringyesRequired. The team_id this call targets.

Users

ToolPlanAccessSummary
grafana_get_user_by_idFreeRead-onlyGet user by id.
grafana_get_user_by_login_or_emailFreeRead-onlyGet user by login or email.
grafana_get_user_org_listFreeRead-onlyGet organizations for user.
grafana_get_user_teamsFreeRead-onlyGet teams for user.
grafana_search_usersFreeRead-onlyGet users.
grafana_search_users_with_pagingFreeRead-onlyGet users with paging.
grafana_update_userProWriteUpdate user.

[Grafana] Get user by id. GET /api/users/. Path parameters: user_id. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
userIdintegeryesRequired. The user_id this call targets.

[Grafana] Get user by login or email. GET /api/users/lookup. Optional filters: loginOrEmail. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
loginOrEmailstringnonullOptional. loginOrEmail of the user.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get organizations for user. GET /api/users//orgs. Path parameters: user_id. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
userIdintegeryesRequired. The user_id this call targets.

[Grafana] Get teams for user. GET /api/users//teams. Path parameters: user_id. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
userIdintegeryesRequired. The user_id this call targets.

[Grafana] Get users. GET /api/users. Optional filters: perpage, page. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
pageintegernonullOptional. Page index for starting fetching users.
perpageintegernonullOptional. Limit the maximum number of users to return per page. Capped at 1000 by StackJack.

[Grafana] Get users with paging. GET /api/users/search. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Update user. PUT /api/users/. Path parameters: user_id. Send the request body as JSON; Grafana documents these fields: email, login, name, theme. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: email, login, name, theme.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
userIdintegeryesRequired. The user_id this call targets.

Service accounts

ToolPlanAccessSummary
grafana_create_service_accountProWriteCreate service account.
grafana_create_tokenProDestructiveDESTRUCTIVE: mint a new service account token.
grafana_delete_service_accountProDestructiveDESTRUCTIVE: delete service account.
grafana_delete_tokenProDestructiveDESTRUCTIVE: revoke a service account token.
grafana_list_tokensFreeRead-onlyGet service account tokens.
grafana_retrieve_service_accountFreeRead-onlyGet single serviceaccount by Id.
grafana_search_service_accountsFreeRead-onlySearch service accounts with paging.
grafana_update_service_accountProWriteUpdate service account.

[Grafana] Create service account. POST /api/serviceaccounts. Send the request body as JSON; Grafana documents these fields: isDisabled, name, role. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringnonullOptional. A JSON request body. Grafana publishes no field list for this endpoint; omit it unless you know the shape.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: mint a new service account token. POST /api/serviceaccounts//tokens. The token that comes back is a LIVE Grafana credential with the full authority of that service account's role, it keeps working long after this conversation ends, and Grafana shows it exactly once - it cannot be retrieved again. Send {name, secondsToLive}; omit secondsToLive and the token never expires. Treat the response as a secret: it is one. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringnonullOptional. A JSON request body. Grafana publishes no field list for this endpoint; omit it unless you know the shape.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
serviceAccountIdintegeryesRequired. The serviceAccountId this call targets.

[Grafana] DESTRUCTIVE: delete service account. It deletes the service account AND every token under it, so anything authenticating with one of those tokens stops working immediately. DELETE /api/serviceaccounts/. Path parameters: serviceAccountId. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
serviceAccountIdintegeryesRequired. The serviceAccountId this call targets.

[Grafana] DESTRUCTIVE: revoke a service account token. DELETE /api/serviceaccounts//tokens/. Anything still authenticating with that token stops working immediately and with no warning - which may include StackJack's own connection to this Grafana. List them with grafana_list_tokens and check what the token is named before revoking it. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
serviceAccountIdintegeryesRequired. The serviceAccountId this call targets.
tokenIdintegeryesRequired. The tokenId this call targets.

[Grafana] Get service account tokens. GET /api/serviceaccounts//tokens. Path parameters: serviceAccountId. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
serviceAccountIdintegeryesRequired. The serviceAccountId this call targets.

[Grafana] Get single serviceaccount by Id. GET /api/serviceaccounts/. Path parameters: serviceAccountId. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
serviceAccountIdintegeryesRequired. The serviceAccountId this call targets.

[Grafana] Search service accounts with paging. GET /api/serviceaccounts/search. Optional filters: Disabled, expiredTokens, query, perpage, page. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
disabledbooleannonullOptional. The Disabled filter.
expiredTokensbooleannonullOptional. The expiredTokens filter.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
pageintegernonullOptional. The default value is 1.
perpageintegernonullOptional. The default value is 1000. Capped at 1000 by StackJack.
querystringnonullOptional. It will return results where the query value is contained in one of the name.

[Grafana] Update service account. PATCH /api/serviceaccounts/. Path parameters: serviceAccountId. Send the request body as JSON; Grafana documents these fields: isDisabled, name, role, serviceAccountId. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringnonullOptional. A JSON request body. Grafana publishes no field list for this endpoint; omit it unless you know the shape.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
serviceAccountIdintegeryesRequired. The serviceAccountId this call targets.

Resource permissions

ToolPlanAccessSummary
grafana_get_resource_descriptionFreeRead-onlyGet a description of a resource's access control properties.
grafana_get_resource_permissionsFreeRead-onlyGet permissions for a resource.
grafana_set_resource_permissionsProDestructiveDESTRUCTIVE: set resource permissions.
grafana_set_resource_permissions_for_built_in_roleProWriteSet resource permissions for a built-in role.
grafana_set_resource_permissions_for_teamProWriteSet resource permissions for a team.
grafana_set_resource_permissions_for_userProWriteSet resource permissions for a user.

[Grafana] Get a description of a resource's access control properties. GET /api/access-control//description. Path parameters: resource. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
resourcestringyesRequired. The resource this call targets.

[Grafana] Get permissions for a resource. GET /api/access-control//. Path parameters: resource, resourceID. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
resourcestringyesRequired. The resource this call targets.
resourceIDstringyesRequired. The resourceID this call targets.

[Grafana] DESTRUCTIVE: set resource permissions. It REPLACES every permission on that dashboard, folder, data source or service account with the set you send. Any user, team or built-in role you leave out loses its access, which on a folder means the dashboards and alert rules inside it too. Read the current permissions with grafana_get_resource_permissions first and send them all back. POST /api/access-control//. Path parameters: resource, resourceID. Send the request body as JSON; Grafana documents these fields: permissions. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: permissions.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
resourcestringyesRequired. The resource this call targets.
resourceIDstringyesRequired. The resourceID this call targets.

[Grafana] Set resource permissions for a built-in role. POST /api/access-control///builtInRoles/. Path parameters: resource, resourceID, builtInRole. Send the request body as JSON; Grafana documents these fields: permission. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: permission.
builtInRolestringyesRequired. The builtInRole this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
resourcestringyesRequired. The resource this call targets.
resourceIDstringyesRequired. The resourceID this call targets.

[Grafana] Set resource permissions for a team. POST /api/access-control///teams/. Path parameters: resource, resourceID, teamID. Send the request body as JSON; Grafana documents these fields: permission. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: permission.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
resourcestringyesRequired. The resource this call targets.
resourceIDstringyesRequired. The resourceID this call targets.
teamIDintegeryesRequired. The teamID this call targets.

[Grafana] Set resource permissions for a user. POST /api/access-control///users/. Path parameters: resource, resourceID, userID. Send the request body as JSON; Grafana documents these fields: permission. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: permission.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
resourcestringyesRequired. The resource this call targets.
resourceIDstringyesRequired. The resourceID this call targets.
userIDintegeryesRequired. The userID this call targets.

Role assignments

ToolPlanAccessSummary
grafana_add_team_roleProWriteAdd team role.
grafana_add_user_roleProWriteAdd a user role assignment.
grafana_list_team_rolesFreeRead-onlyGet team roles.
grafana_list_teams_rolesFreeRead-onlyList roles assigned to multiple teams.
grafana_list_user_rolesFreeRead-onlyList roles assigned to a user.
grafana_list_users_rolesFreeRead-onlyList roles assigned to multiple users.
grafana_remove_team_roleProDestructiveDESTRUCTIVE: remove team role.
grafana_remove_user_roleProDestructiveDESTRUCTIVE: remove a user role assignment.
grafana_set_team_rolesProDestructiveDESTRUCTIVE: update team role.
grafana_set_user_rolesProDestructiveDESTRUCTIVE: set user role assignments.

[Grafana] Add team role. POST /api/access-control/teams//roles. Path parameters: teamId. Send the request body as JSON; Grafana documents these fields: roleUid. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: roleUid.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
teamIdintegeryesRequired. The teamId this call targets.

[Grafana] Add a user role assignment. POST /api/access-control/users//roles. Path parameters: userId. Send the request body as JSON; Grafana documents these fields: global, roleUid. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: global, roleUid.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
userIdintegeryesRequired. The userId this call targets.

[Grafana] Get team roles. GET /api/access-control/teams//roles. Path parameters: teamId. Optional filters: targetOrgId. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
targetOrgIdintegernonullOptional. The targetOrgId filter.
teamIdintegeryesRequired. The teamId this call targets.

[Grafana] List roles assigned to multiple teams. POST /api/access-control/teams/roles/search. Send the request body as JSON; Grafana documents these fields: includeHidden, orgId, teamIds, userIds. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: includeHidden, orgId, teamIds, userIds.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] List roles assigned to a user. GET /api/access-control/users//roles. Path parameters: userId. Optional filters: includeHidden, targetOrgId. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
includeHiddenbooleannonullOptional. The includeHidden filter.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
targetOrgIdintegernonullOptional. The targetOrgId filter.
userIdintegeryesRequired. The userId this call targets.

[Grafana] List roles assigned to multiple users. POST /api/access-control/users/roles/search. Send the request body as JSON; Grafana documents these fields: includeHidden, orgId, teamIds, userIds. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: includeHidden, orgId, teamIds, userIds.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: remove team role. It changes who can see or change what. Permission changes are easy to miss and hard to trace back afterwards. DELETE /api/access-control/teams//roles/. Path parameters: roleUID, teamId. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
roleUIDstringyesRequired. The roleUID this call targets.
teamIdintegeryesRequired. The teamId this call targets.

[Grafana] DESTRUCTIVE: remove a user role assignment. It changes who can see or change what. Permission changes are easy to miss and hard to trace back afterwards. DELETE /api/access-control/users//roles/. Path parameters: roleUID, userId. Optional filters: global. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
globalbooleannonullOptional. A flag indicating if the assignment is global or not. If set to false, the default org ID of the authenticated user will be used from the request to remove assignment.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
roleUIDstringyesRequired. The roleUID this call targets.
userIdintegeryesRequired. The userId this call targets.

[Grafana] DESTRUCTIVE: update team role. It REPLACES the team's whole role assignment list with the one you send. Every role you leave out is unassigned from the team, so everyone in it loses what that role granted. Read the current roles first and send them all back. PUT /api/access-control/teams//roles. Path parameters: teamId. Optional filters: targetOrgId. Send the request body as JSON; Grafana documents these fields: includeHidden, roleUids. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: includeHidden, roleUids.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
targetOrgIdintegernonullOptional. The targetOrgId filter.
teamIdintegeryesRequired. The teamId this call targets.

[Grafana] DESTRUCTIVE: set user role assignments. It REPLACES the user's whole role assignment list with the one you send. Every role you leave out is unassigned, so the same call that grants one role can take away access to dashboards, folders and data sources. Read the current roles first and send them all back. PUT /api/access-control/users//roles. Path parameters: userId. Optional filters: targetOrgId. Send the request body as JSON; Grafana documents these fields: global, includeHidden, roleUids. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: global, includeHidden, roleUids.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
targetOrgIdintegernonullOptional. The targetOrgId filter.
userIdintegeryesRequired. The userId this call targets.

Roles

ToolPlanAccessSummary
grafana_create_roleProWriteCreate a new custom role.
grafana_delete_roleProDestructiveDESTRUCTIVE: delete a custom role.
grafana_get_access_control_statusFreeRead-onlyGet status.
grafana_get_roleFreeRead-onlyGet a role.
grafana_get_role_assignmentsFreeRead-onlyGet role assignments.
grafana_list_rolesFreeRead-onlyGet all roles.
grafana_set_role_assignmentsProDestructiveDESTRUCTIVE: set role assignments.
grafana_update_roleProWriteUpdate a custom role.

[Grafana] Create a new custom role. POST /api/access-control/roles. Send the request body as JSON; Grafana documents these fields: description, displayName, global, group, hidden, name, permissions, uid. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: description, displayName, global, group, hidden, name, permissions, uid.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: delete a custom role. It changes who can see or change what. Permission changes are easy to miss and hard to trace back afterwards. DELETE /api/access-control/roles/. Path parameters: roleUID. Optional filters: force, global. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
forcebooleannonullOptional. The force filter.
globalbooleannonullOptional. The global filter.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
roleUIDstringyesRequired. The roleUID this call targets.

[Grafana] Get status. GET /api/access-control/status. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get a role. GET /api/access-control/roles/. Path parameters: roleUID. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
roleUIDstringyesRequired. The roleUID this call targets.

[Grafana] Get role assignments. GET /api/access-control/roles//assignments. Path parameters: roleUID. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
roleUIDstringyesRequired. The roleUID this call targets.

[Grafana] Get all roles. GET /api/access-control/roles. Optional filters: delegatable, includeHidden, targetOrgId. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
delegatablebooleannonullOptional. The delegatable filter.
includeHiddenbooleannonullOptional. The includeHidden filter.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
targetOrgIdintegernonullOptional. The targetOrgId filter.

[Grafana] DESTRUCTIVE: set role assignments. It REPLACES the whole set of users and teams this role is assigned to. Anyone you leave out loses the role, and with it everything the role granted them. Read the current assignments first and send them all back. PUT /api/access-control/roles//assignments. Path parameters: roleUID. Send the request body as JSON; Grafana documents these fields: service_accounts, teams, users. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: service_accounts, teams, users.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
roleUIDstringyesRequired. The roleUID this call targets.

[Grafana] Update a custom role. PUT /api/access-control/roles/. Path parameters: roleUID. Send the request body as JSON; Grafana documents these fields: description, displayName, global, group, hidden, name, permissions. Required: description, displayName, group. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: description, displayName, global, group, hidden, name, permissions. Required: description, displayName, group.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
roleUIDstringyesRequired. The roleUID this call targets.

Reporting

ToolPlanAccessSummary
grafana_create_reportProWriteCreate a report.
grafana_delete_reportProDestructiveDESTRUCTIVE: delete a report.
grafana_get_reportFreeRead-onlyGet a report.
grafana_get_report_branding_imageProRead-onlyDownload a branding image stored for reports - the logo that appears on a rendered report or in the email that carries it.
grafana_get_report_settingsFreeRead-onlyGet report settings.
grafana_get_reportsFreeRead-onlyList reports.
grafana_get_reports_by_dashboard_uidFreeRead-onlyList reports by dashboard uid.
grafana_render_report_csvsProRead-onlyRender the table panels of one or more dashboards as CSV and get a download link back.
grafana_render_report_pdfsProRead-onlyRender one or more dashboards as a PDF report and get a download link back.
grafana_save_report_settingsProWriteSave settings.
grafana_send_reportProWriteSend a report.
grafana_send_test_emailProWriteSend test report via email.
grafana_update_reportProWriteUpdate a report.

[Grafana] Create a report. POST /api/reports. Send the request body as JSON; Grafana documents these fields: dashboards, enableCsv, enableDashboardUrl, formats, message, name, options, recipients, replyTo, scaleFactor, schedule, state. Grafana documents 2 more fields; the bodyJson parameter lists all of them. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: dashboards, enableCsv, enableDashboardUrl, formats, message, name, options, recipients, replyTo, scaleFactor, schedule, state, subject, urls.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: delete a report. It deletes the resource outright, and Grafana does not undo this. DELETE /api/reports/. Path parameters: id. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
idintegeryesRequired. The id this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get a report. GET /api/reports/. Path parameters: id. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
idintegeryesRequired. The id this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Download a branding image stored for reports - the logo that appears on a rendered report or in the email that carries it. GET /api/reports/images/:image. The image value comes from the report settings: grafana_get_report_settings returns branding.reportLogoUrl and branding.emailLogoUrl, and it is sent as one path segment exactly as given. Grafana's own specification does not declare this placeholder, so whether it wants a bare file name, a relative path or the whole URL is unverified against a live instance - if one form is refused, try the value as the settings gave it and then its last segment. StackJack uploads whatever Grafana answers with and returns a short-lived read-only download link valid for 30 minutes, with its content type, size and exact expiry; if this deployment has no blob storage configured the call fails loudly rather than handing back a dead link. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance.

ParamTypeRequiredDefaultDescription
imagestringyesRequired. The stored branding image to fetch, taken from the report settings: Grafana's ReportSettings.branding declares reportLogoUrl and emailLogoUrl, which grafana_get_report_settings returns. The value is sent as ONE path segment exactly as given. Grafana's specification does not declare this placeholder, so whether it wants a bare file name, a relative path or the whole URL is unverified against a live instance.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Get report settings. GET /api/reports/settings. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] List reports. GET /api/reports. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] List reports by dashboard uid. GET /api/reports/dashboards/. Path parameters: uid. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
uidstringyesRequired. The uid this call targets.

[Grafana] Render the table panels of one or more dashboards as CSV and get a download link back. GET /api/reports/render/csvs. Name the dashboards with the dashboards filter and the report with title. The file Grafana returns is a ZIP archive holding one CSV per panel, not a single CSV. StackJack uploads it and returns a short-lived read-only download link valid for 30 minutes, with its content type, size and exact expiry - the file itself is never inlined. If no dashboard in the request holds a table panel with rows, Grafana answers with nothing at all and this tool tells you so rather than handing back a link to an empty file. If this StackJack deployment has no blob storage configured the call fails loudly. It is a paid-tier tool although it only reads, because the render is real work for the instance. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance.

ParamTypeRequiredDefaultDescription
dashboardsstringnonullOptional. The dashboards filter.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
titlestringnonullOptional. The title filter.

[Grafana] Render one or more dashboards as a PDF report and get a download link back. GET /api/reports/render/pdfs. Name the dashboards with the dashboards filter and shape the output with orientation, layout, title, scaleFactor and includeTables. Grafana answers this route with a FILE rather than JSON, so StackJack uploads it and returns a short-lived read-only download link valid for 30 minutes, with its content type, size and exact expiry - the PDF itself is never inlined. If this StackJack deployment has no blob storage configured the call fails loudly rather than handing back a dead link. It is a paid-tier tool although it only reads: a render drives Grafana's image renderer across every panel of every dashboard named, which is the most expensive thing this API can be asked to do. Grafana Enterprise or Grafana Cloud only, and the image renderer must be installed; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance.

ParamTypeRequiredDefaultDescription
dashboardsstringnonullOptional. The dashboards filter.
includeTablesstringnonullOptional. The includeTables filter.
layoutstringnonullOptional. The layout filter.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
orientationstringnonullOptional. The orientation filter.
scaleFactorstringnonullOptional. The scaleFactor filter.
titlestringnonullOptional. The title filter.

[Grafana] Save settings. POST /api/reports/settings. Send the request body as JSON; Grafana documents these fields: branding, embeddedImageTheme, footerFontFamily, footerItems, id, orgId, pdfDashboardTitleEnabled, pdfHeaderEnabled, pdfTheme, pdfTimeRangeEnabled, userId. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: branding, embeddedImageTheme, footerFontFamily, footerItems, id, orgId, pdfDashboardTitleEnabled, pdfHeaderEnabled, pdfTheme, pdfTimeRangeEnabled, userId.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Send a report. POST /api/reports/email. Send the request body as JSON; Grafana documents these fields: emails, id, useEmailsFromReport. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: emails, id, useEmailsFromReport.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Send test report via email. POST /api/reports/test-email. Send the request body as JSON; Grafana documents these fields: dashboards, enableCsv, enableDashboardUrl, formats, message, name, options, recipients, replyTo, scaleFactor, schedule, state. Grafana documents 2 more fields; the bodyJson parameter lists all of them. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: dashboards, enableCsv, enableDashboardUrl, formats, message, name, options, recipients, replyTo, scaleFactor, schedule, state, subject, urls.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Update a report. PUT /api/reports/. Path parameters: id. Send the request body as JSON; Grafana documents these fields: dashboards, enableCsv, enableDashboardUrl, formats, message, name, options, recipients, replyTo, scaleFactor, schedule, state. Grafana documents 2 more fields; the bodyJson parameter lists all of them. DEPRECATED from Grafana 13 by the vendor's own spec, and still the only documented way to do this - Grafana says legacy routes are not being switched off yet and any removal will be announced in advance. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: dashboards, enableCsv, enableDashboardUrl, formats, message, name, options, recipients, replyTo, scaleFactor, schedule, state, subject, urls.
idintegeryesRequired. The id this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

Anonymous devices

ToolPlanAccessSummary
grafana_list_anonymous_devicesFreeRead-onlyList the devices that viewed this Grafana WITHOUT signing in, over the last 30 days.
grafana_search_anonymous_devicesFreeRead-onlySearch the anonymous devices that viewed this Grafana in the last 30 days.

[Grafana] List the devices that viewed this Grafana WITHOUT signing in, over the last 30 days. GET /api/anonymous/devices. Grafana counts an anonymous viewer as a device (a browser on a machine), and this is how you see how much of your traffic is unauthenticated - which is what Grafana Cloud bills anonymous usage on. The vendor declares NO paging parameters on this route, so the whole 30-day collection comes back in one response and a busy public instance can make that large. Returns raw Grafana JSON.

[Grafana] Search the anonymous devices that viewed this Grafana in the last 30 days. GET /api/anonymous/search. Grafana gives this route and grafana_list_anonymous_devices the same one-line summary and declares no parameters on either, so they differ only in the response envelope the vendor builds - call the list first and use this one if you need what it adds. There are NO paging parameters here either: the whole collection comes back. Returns raw Grafana JSON.

Instance health

ToolPlanAccessSummary
grafana_get_healthFreeRead-onlyRead the instance's health - its version, commit and whether its own database is reachable.

[Grafana] Read the instance's health - its version, commit and whether its own database is reachable. GET /api/health. Grafana answers this route WITHOUT authentication, so a success here proves only that something is listening at the address, NOT that the service account token is any good. To check the credential, call grafana_get_current_org instead; that is also what StackJack's own connection test uses, for exactly this reason. Returns raw Grafana JSON.

Instance settings

ToolPlanAccessSummary
grafana_admin_get_settingsFreeRead-onlyFetch settings.
grafana_admin_get_statsFreeRead-onlyFetch Grafana Stats.
grafana_retrieve_jwksFreeRead-onlyRead the instance's JSON Web Key Set - the PUBLIC keys anything verifying a Grafana-minted token needs.

[Grafana] Fetch settings. GET /api/admin/settings. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

[Grafana] Fetch Grafana Stats. GET /api/admin/stats. Returns raw Grafana JSON.

[Grafana] Read the instance's JSON Web Key Set - the PUBLIC keys anything verifying a Grafana-minted token needs. GET /api/signing-keys/keys. These are verification keys, not credentials: no private key is ever in this body, and Grafana documents the route's required permissions as None. Use it when something outside Grafana has to check that a token Grafana issued is genuine. Returns raw Grafana JSON.

Instance users

ToolPlanAccessSummary
grafana_admin_create_userProDestructiveDESTRUCTIVE: create new user.
grafana_admin_delete_userProDestructiveDESTRUCTIVE: delete a Grafana user outright.
grafana_admin_disable_userProDestructiveDESTRUCTIVE: disable user.
grafana_admin_enable_userProDestructiveDESTRUCTIVE: enable user.
grafana_admin_get_user_auth_tokensFreeRead-onlyReturn a list of all auth tokens (devices) that the user currently have logged in from.
grafana_admin_logout_userProDestructiveDESTRUCTIVE: logout user revokes all auth tokens (devices) for the user.
grafana_admin_revoke_user_auth_tokenProDestructiveDESTRUCTIVE: revoke auth token for user.
grafana_admin_update_user_passwordProDestructiveDESTRUCTIVE: set password for user.
grafana_admin_update_user_permissionsProDestructiveDESTRUCTIVE: set permissions for user.

[Grafana] DESTRUCTIVE: create new user. It creates a Grafana user with a password you supply, which is a credential mint: whoever holds that password can sign in as them. POST /api/admin/users. Send the request body as JSON; Grafana documents these fields: email, login, name, orgId, password. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: email, login, name, orgId, password.

[Grafana] DESTRUCTIVE: delete a Grafana user outright. DELETE /api/admin/users/. This is a real person's account: their dashboards, their starred items, their API history and their membership of every organization go with it, and Grafana does not undo it. If the intent is offboarding rather than erasure, grafana_admin_disable_user keeps the account and its content while stopping sign-in, and grafana_remove_org_user takes them out of one organization only. The header that picks an organization is ignored on this route by design - it acts on the whole instance. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
userIdintegeryesRequired. The user_id this call targets.

[Grafana] DESTRUCTIVE: disable user. It turns a real person's access to Grafana off or on. A disabled user cannot sign in and their sessions end. POST /api/admin/users//disable. Path parameters: user_id. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
userIdintegeryesRequired. The user_id this call targets.

[Grafana] DESTRUCTIVE: enable user. It turns a real person's access to Grafana off or on. A disabled user cannot sign in and their sessions end. POST /api/admin/users//enable. Path parameters: user_id. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
userIdintegeryesRequired. The user_id this call targets.

[Grafana] Return a list of all auth tokens (devices) that the user currently have logged in from. GET /api/admin/users//auth-tokens. Path parameters: user_id. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
userIdintegeryesRequired. The user_id this call targets.

[Grafana] DESTRUCTIVE: logout user revokes all auth tokens (devices) for the user. User of issued auth tokens (devices) will no longer be logged in and will be required to authenticate again upon next activity. It ends a real person's live Grafana sessions immediately. They are signed out wherever they are working. POST /api/admin/users//logout. Path parameters: user_id. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
userIdintegeryesRequired. The user_id this call targets.

[Grafana] DESTRUCTIVE: revoke auth token for user. It ends a real person's live Grafana sessions immediately. They are signed out wherever they are working. POST /api/admin/users//revoke-auth-token. Path parameters: user_id. Send the request body as JSON; Grafana documents these fields: authTokenId. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: authTokenId.
userIdintegeryesRequired. The user_id this call targets.

[Grafana] DESTRUCTIVE: set password for user. It replaces a real person's sign-in password. They are not told, and their old password stops working immediately. PUT /api/admin/users//password. Path parameters: user_id. Send the request body as JSON; Grafana documents these fields: password. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: password.
userIdintegeryesRequired. The user_id this call targets.

[Grafana] DESTRUCTIVE: set permissions for user. It grants or removes INSTANCE ADMINISTRATOR authority over the whole Grafana, every organization in it included. PUT /api/admin/users//permissions. Path parameters: user_id. Send the request body as JSON; Grafana documents these fields: isGrafanaAdmin. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: isGrafanaAdmin.
userIdintegeryesRequired. The user_id this call targets.

LDAP

ToolPlanAccessSummary
grafana_get_ldap_statusFreeRead-onlyAttempts to connect to all the configured LDAP servers and returns information on whenever they're available or not.
grafana_get_sync_statusFreeRead-onlyReturns the current state of the LDAP background sync integration.
grafana_get_user_from_ldapFreeRead-onlyFinds an user based on a username in LDAP.
grafana_post_sync_user_with_ldapProDestructiveDESTRUCTIVE: enables a single Grafana user to be synchronized against LDAP.
grafana_reload_ldap_cfgProDestructiveDESTRUCTIVE: reloads the LDAP configuration.

[Grafana] Attempts to connect to all the configured LDAP servers and returns information on whenever they're available or not. GET /api/admin/ldap/status. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

[Grafana] Returns the current state of the LDAP background sync integration. GET /api/admin/ldap-sync-status. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Returns raw Grafana JSON.

[Grafana] Finds an user based on a username in LDAP. This helps illustrate how would the particular user be mapped in Grafana when synced. GET /api/admin/ldap/. Path parameters: user_name. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
userNamestringyesRequired. The user_name this call targets.

[Grafana] DESTRUCTIVE: enables a single Grafana user to be synchronized against LDAP. It re-synchronizes a real person's account from LDAP, which can change their organization membership, their role, and whether they can sign in at all. POST /api/admin/ldap/sync/. Path parameters: user_id. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

ParamTypeRequiredDefaultDescription
userIdintegeryesRequired. The user_id this call targets.

[Grafana] DESTRUCTIVE: reloads the LDAP configuration. It reloads the instance's LDAP configuration, which changes how everyone authenticates. POST /api/admin/ldap/reload. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

Provisioning reload

ToolPlanAccessSummary
grafana_admin_provisioning_reload_access_controlProDestructiveDESTRUCTIVE: you need to have a permission with action `provisioning:reload` with scope `provisioners:accesscontrol`.
grafana_admin_provisioning_reload_dashboardsProDestructiveDESTRUCTIVE: reload dashboard provisioning configurations.
grafana_admin_provisioning_reload_datasourcesProDestructiveDESTRUCTIVE: reload datasource provisioning configurations.
grafana_admin_provisioning_reload_pluginsProDestructiveDESTRUCTIVE: reload plugin provisioning configurations.

[Grafana] DESTRUCTIVE: you need to have a permission with action `provisioning:reload` with scope `provisioners:accesscontrol`. It makes Grafana re-read provisioned configuration from disk, DISCARDING any in-instance change anyone made to a provisioned dashboard, data source, plugin or notifier. POST /api/admin/provisioning/access-control/reload. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Returns raw Grafana JSON.

[Grafana] DESTRUCTIVE: reload dashboard provisioning configurations. It makes Grafana re-read provisioned configuration from disk, DISCARDING any in-instance change anyone made to a provisioned dashboard, data source, plugin or notifier. POST /api/admin/provisioning/dashboards/reload. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

[Grafana] DESTRUCTIVE: reload datasource provisioning configurations. It makes Grafana re-read provisioned configuration from disk, DISCARDING any in-instance change anyone made to a provisioned dashboard, data source, plugin or notifier. POST /api/admin/provisioning/datasources/reload. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

[Grafana] DESTRUCTIVE: reload plugin provisioning configurations. It makes Grafana re-read provisioned configuration from disk, DISCARDING any in-instance change anyone made to a provisioned dashboard, data source, plugin or notifier. POST /api/admin/provisioning/plugins/reload. Returns raw Grafana JSON. Grafana's own API specification marks this route as Basic-authentication only, so it needs the Grafana server administrator's username and password saved on the connection - the two optional fields in the connector's Configure dialog; the service account token cannot call it and no service account role changes that. Without that pair StackJack refuses this call before anything is sent to Grafana.

SSO settings

ToolPlanAccessSummary
grafana_get_provider_settingsFreeRead-onlyGet an SSO Settings entry by Key.
grafana_get_saml_metadataFreeRead-onlyRead this Grafana's SAML service-provider metadata - the XML an identity provider needs to trust it.
grafana_list_all_providers_settingsFreeRead-onlyList all SSO Settings entries.
grafana_patch_provider_settingsProWritePatch SSO Settings.
grafana_remove_provider_settingsProDestructiveDESTRUCTIVE: remove SSO Settings.
grafana_update_provider_settingsProWriteUpdate SSO Settings.

[Grafana] Get an SSO Settings entry by Key. GET /api/v1/sso-settings/. Path parameters: key. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
keystringyesRequired. The key this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Read this Grafana's SAML service-provider metadata - the XML an identity provider needs to trust it. GET /api/saml/metadata. This is the document you hand to Entra ID, Okta or ADFS when you register Grafana as an application: it carries the entity id, the assertion consumer service URL and the signing certificate. It is a configuration READ; the SAML callbacks themselves are browser redirects and are not tools. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Returns the XML document Grafana answers with, verbatim - not JSON.

[Grafana] List all SSO Settings entries. GET /api/v1/sso-settings. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Patch SSO Settings. PATCH /api/v1/sso-settings/. Path parameters: key. Send the request body as JSON; Grafana documents these fields: settings. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: settings.
keystringyesRequired. The key this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: remove SSO Settings. It changes how people sign in to Grafana. A wrong value can lock every user out of the instance. DELETE /api/v1/sso-settings/. Path parameters: key. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
keystringyesRequired. The key this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] Update SSO Settings. PUT /api/v1/sso-settings/. Path parameters: key. Send the request body as JSON; Grafana documents these fields: id, provider, settings. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: id, provider, settings.
keystringyesRequired. The key this call targets.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

Cloud migration

ToolPlanAccessSummary
grafana_cancel_cloud_migration_snapshotProWriteCancel a migration snapshot wherever it is in its processing chain.
grafana_create_cloud_migration_sessionProWriteStart a Grafana Cloud migration session on this instance.
grafana_create_cloud_migration_snapshotProWriteTake a snapshot of this instance's migratable content for a migration session.
grafana_create_cloud_migration_tokenProDestructiveDESTRUCTIVE: mint a Grafana Cloud access token on this instance.
grafana_delete_cloud_migration_sessionProDestructiveDESTRUCTIVE: delete a Grafana Cloud migration session.
grafana_delete_cloud_migration_tokenProDestructiveDESTRUCTIVE: revoke a Grafana Cloud migration token.
grafana_get_cloud_migration_dependenciesFreeRead-onlyRead the dependency graph of everything this instance could migrate to Grafana Cloud.
grafana_get_cloud_migration_sessionFreeRead-onlyRead one Grafana Cloud migration session by its uid.
grafana_get_cloud_migration_sessionsFreeRead-onlyList the Grafana Cloud migration sessions on this instance.
grafana_get_cloud_migration_snapshotFreeRead-onlyRead one migration snapshot - where it is in its processing chain and what it found.
grafana_get_cloud_migration_snapshotsFreeRead-onlyList the snapshots taken under one migration session.
grafana_get_cloud_migration_tokenFreeRead-onlyRead the Grafana Cloud migration token stored on this instance, if one exists.
grafana_upload_cloud_migration_snapshotProDestructiveDESTRUCTIVE: send a snapshot of this Grafana to Grafana Cloud.

[Grafana] Cancel a migration snapshot wherever it is in its processing chain. POST /api/cloudmigration/migration//snapshot//cancel. Use it to stop a snapshot that is still building or still uploading; anything already delivered to Grafana Cloud stays delivered, so cancelling mid-upload leaves a partial migration rather than undoing one. Needs Grafana's onPremToCloudMigrations feature toggle. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
snapshotUidstringyesRequired. UID of a snapshot.
uidstringyesRequired. Session UID of a session.

[Grafana] Start a Grafana Cloud migration session on this instance. POST /api/cloudmigration/migration. Send : that value is a Grafana Cloud MIGRATION TOKEN generated in the destination cloud stack (Administration, then Migrate to Grafana Cloud), and it is a live credential for that stack - treat it the way you treat the Grafana token this connection uses, and do not paste one into a conversation you would not paste a password into. Creating the session moves nothing on its own: it records where a migration would go. Needs Grafana's onPremToCloudMigrations feature toggle. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: authToken.

[Grafana] Take a snapshot of this instance's migratable content for a migration session. POST /api/cloudmigration/migration//snapshot. Send to limit what is captured; omit it for everything Grafana knows how to move. The snapshot is built and held ON THIS INSTANCE - nothing leaves until grafana_upload_cloud_migration_snapshot sends it - so this is the safe half of the move and the place to check what would be shipped. Get the session uid from grafana_get_cloud_migration_sessions. Needs Grafana's onPremToCloudMigrations feature toggle. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: resourceTypes.
uidstringyesRequired. UID of a session.

[Grafana] DESTRUCTIVE: mint a Grafana Cloud access token on this instance. POST /api/cloudmigration/token. Grafana generates the token and returns it, which makes this a CREDENTIAL MINT: the value that comes back is live, it keeps working long after this conversation ends, and anything holding it can move this instance's dashboards, data sources and users into the cloud stack it belongs to. Treat the response as a secret - it is one. Needs Grafana's onPremToCloudMigrations feature toggle. Returns raw Grafana JSON.

[Grafana] DESTRUCTIVE: delete a Grafana Cloud migration session. DELETE /api/cloudmigration/migration/. It takes the session's snapshots with it, so the record of what was migrated and any snapshot not yet uploaded are gone, and Grafana does not undo this. It does NOT remove anything already uploaded into the cloud stack - that has to be dealt with in the stack itself. Needs Grafana's onPremToCloudMigrations feature toggle. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
uidstringyesRequired. UID of a migration session.

[Grafana] DESTRUCTIVE: revoke a Grafana Cloud migration token. DELETE /api/cloudmigration/token/. Any migration still using that token stops working immediately and with no warning, and Grafana cannot bring the same token back - a new one has to be minted and configured. Needs Grafana's onPremToCloudMigrations feature toggle. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
uidstringyesRequired. UID of a cloud migration token.

[Grafana] Read the dependency graph of everything this instance could migrate to Grafana Cloud. GET /api/cloudmigration/resources/dependencies. It is what tells you that moving a dashboard means moving the data source it queries, so it is the read to make before deciding what a snapshot should contain. The vendor declares NO parameters and NO paging, so the whole graph comes back in one response and a large instance makes that large. Needs Grafana's onPremToCloudMigrations feature toggle. Returns raw Grafana JSON.

[Grafana] Read one Grafana Cloud migration session by its uid. GET /api/cloudmigration/migration/. It tells you where the migration points and what state it is in; the snapshots taken under it are listed by grafana_get_cloud_migration_snapshots. Get the uid from grafana_get_cloud_migration_sessions. Needs Grafana's onPremToCloudMigrations feature toggle. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
uidstringyesRequired. UID of a migration session.

[Grafana] List the Grafana Cloud migration sessions on this instance. GET /api/cloudmigration/migration. A session is one configured move of this self-hosted Grafana's content into a Grafana Cloud stack; its uid is what every other cloud-migration tool takes. The vendor declares NO paging parameters, so every session comes back in one response. The whole family sits behind Grafana's onPremToCloudMigrations feature toggle, so a 404 on an instance that has it switched off is a configuration fact, not a bad address. Returns raw Grafana JSON.

[Grafana] Read one migration snapshot - where it is in its processing chain and what it found. GET /api/cloudmigration/migration//snapshot/. This is the read that tells you WHAT WOULD BE SENT before an upload, and what happened after one. Its result rows page with resultPage plus resultLimit rather than the usual page plus limit, numbered from 1 and capped at 1000 by StackJack; errorsOnly narrows it to the resources that failed. Needs Grafana's onPremToCloudMigrations feature toggle. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
errorsOnlybooleannonullOptional. ErrorsOnly is used to only return resources with error statuses.
resultLimitintegernonullOptional. Max limit for snapshot results returned. Capped at 1000 by StackJack.
resultPageintegernonullOptional. ResultPage is used for pagination with ResultLimit.
resultSortColumnstringnonullOptional. ResultSortColumn can be used to override the default system sort. Valid values are "name", "resource_type", and "status".
resultSortOrderstringnonullOptional. ResultSortOrder is used with ResultSortColumn. Valid values are ASC and DESC.
snapshotUidstringyesRequired. UID of a snapshot.
uidstringyesRequired. Session UID of a session.

[Grafana] List the snapshots taken under one migration session. GET /api/cloudmigration/migration//snapshots. Paging is page plus limit, numbered from 1 and capped at 1000 by StackJack. Get the session uid from grafana_get_cloud_migration_sessions, then read one snapshot in full with grafana_get_cloud_migration_snapshot. Needs Grafana's onPremToCloudMigrations feature toggle. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
limitintegernonullOptional. Max limit for results returned. Capped at 1000 by StackJack.
pageintegernonullOptional. Page is used for pagination with limit.
sortstringnonullOptional. Sort with value latest to return results sorted in descending order.
uidstringyesRequired. Session UID of a session.

[Grafana] Read the Grafana Cloud migration token stored on this instance, if one exists. GET /api/cloudmigration/token. TREAT THE RESPONSE AS A CREDENTIAL: the body carries the access token itself, not a description of one, and anything holding it can pull this instance's content into the cloud stack that issued it. Do not echo it into a ticket, a chat message or a document. Needs Grafana's onPremToCloudMigrations feature toggle. Returns raw Grafana JSON.

[Grafana] DESTRUCTIVE: send a snapshot of this Grafana to Grafana Cloud. POST /api/cloudmigration/migration//snapshot//upload. The snapshot is a copy of the instance's dashboards, its data sources (their names and settings) and its users, and the upload moves that content out of the customer's own Grafana onto Grafana's infrastructure over the link the migration token authorizes. Nothing in Grafana un-sends it, and the receiving stack is not this connection's to clean up. Check what is in the snapshot with grafana_get_cloud_migration_snapshot before uploading. Needs Grafana's onPremToCloudMigrations feature toggle. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
snapshotUidstringyesRequired. UID of a snapshot.
uidstringyesRequired. Session UID of a session.

Licensing

ToolPlanAccessSummary
grafana_delete_license_tokenProDestructiveDESTRUCTIVE: remove the Enterprise license from this Grafana's database.
grafana_get_custom_permissions_csvFreeRead-onlyRead the custom permissions report as a CSV file's worth of text.
grafana_get_custom_permissions_reportFreeRead-onlyRead the custom permissions report - where role-based access control permissions on this instance differ from Grafana's built-in roles.
grafana_get_license_statusFreeRead-onlyCheck whether this Grafana has a valid Enterprise license and what it allows.
grafana_get_license_tokenFreeRead-onlyRead the Enterprise license token installed on this Grafana.
grafana_post_license_tokenProDestructiveDESTRUCTIVE: install an Enterprise license token on this Grafana.
grafana_post_renew_license_tokenProDestructiveDESTRUCTIVE: force this Grafana to renew its Enterprise license token now.
grafana_refresh_license_statsFreeWriteRefresh and read this instance's license usage statistics - the seat and user counts Grafana measures an Enterprise license against.

[Grafana] DESTRUCTIVE: remove the Enterprise license from this Grafana's database. DELETE /api/licensing/token. The instance drops to open-source behaviour: reporting, recording rules, role-based access control, team sync and data source caching stop for every organization on it, and the only way back is installing a license token again. Grafana documents a request body on this DELETE - send it as JSON with the field instance. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: instance.

[Grafana] Read the custom permissions report as a CSV file's worth of text. GET /api/licensing/custom-permissions-csv. Same content as grafana_get_custom_permissions_report, in the shape a spreadsheet opens. Needs a role carrying the licensing.reports:read action. DEPRECATED by Grafana with NO replacement; the vendor asks anyone relying on it to contact Grafana support. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Returns the report as CSV text, verbatim - not JSON.

[Grafana] Read the custom permissions report - where role-based access control permissions on this instance differ from Grafana's built-in roles. GET /api/licensing/custom-permissions. Needs a role carrying the licensing.reports:read action. DEPRECATED by Grafana with NO replacement; the vendor asks anyone relying on it to contact Grafana support. Grafana's specification declares only a 500 response for this route and documents no success body at all, so what a working instance actually answers is unverified - a failure here is as likely to be the vendor's own gap as a broken connection. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Returns raw Grafana JSON.

[Grafana] Check whether this Grafana has a valid Enterprise license and what it allows. GET /api/licensing/check. Cheap, takes no parameters, and it is the read to make first when an Enterprise-only tool - reporting, recording rules, role-based access control, team sync, data source caching - is refusing calls: it tells you whether the license or the role is the problem. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Returns raw Grafana JSON.

[Grafana] Read the Enterprise license token installed on this Grafana. GET /api/licensing/token. TREAT THE RESPONSE AS A CREDENTIAL: the body carries the license token itself, which is the material that licenses the instance, not a description of it. Use it to confirm which license is installed; do not echo it into a ticket, a chat message or a document. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Returns raw Grafana JSON.

[Grafana] DESTRUCTIVE: install an Enterprise license token on this Grafana. POST /api/licensing/token. Send the body as JSON; Grafana documents one field, instance. This REPLACES whatever license the instance is running on, which changes what every organization on it may use - reporting, recording rules, role-based access control and team sync all stop when the license does - and the response carries the resulting token, so treat it as a secret. There is no undo beyond installing the previous token again. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: instance.

[Grafana] DESTRUCTIVE: force this Grafana to renew its Enterprise license token now. POST /api/licensing/token/renew. Grafana re-fetches the token from its licensing service and replaces the stored one, so a renewal that fails can leave the instance without a working license until it is fixed, and the response carries the refreshed token - treat it as a secret. Grafana declares a request body for this route whose schema has no fields at all, so StackJack sends none; if your instance refuses the call, send an empty object, . Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringnonullOptional. A JSON request body. Grafana publishes no field list for this endpoint; omit it unless you know the shape.

[Grafana] Refresh and read this instance's license usage statistics - the seat and user counts Grafana measures an Enterprise license against. GET /api/licensing/refresh-stats. Grafana RECOMPUTES the numbers as it answers, so despite the GET this tool is NOT marked read-only: a harness restricted to read-only tools should not be able to trigger a recount. Nothing else about it moves. It is explicitly NOT destructive - the recount is idempotent, it changes no customer data and it deletes nothing - and it stays on the Free plan with the vendor's own required permission, licensing:read, because the only thing it rewrites is Grafana's own cached counters. Grafana Enterprise or Grafana Cloud only; an open-source instance refuses this with a 403 or 404 however good the token is. Returns raw Grafana JSON.

Query history

ToolPlanAccessSummary
grafana_add_query_to_historyProWriteSave a query into the signed-in user's query history.
grafana_delete_query_history_entryProDestructiveDESTRUCTIVE: delete a saved query from query history.
grafana_patch_query_commentProWriteChange the comment on a saved query in query history.
grafana_search_queriesFreeRead-onlySearch the signed-in user's query history - the queries run against data sources, with their comments and stars.
grafana_star_queryProWriteStar a saved query in query history so it can be found with the onlyStarred filter.
grafana_unstar_queryProDestructiveDESTRUCTIVE: remove the star from a saved query in query history.

[Grafana] Save a query into the signed-in user's query history. POST /api/query-history. Send the body as JSON with datasourceUid and queries; queries is required and holds the data source's own query objects, the same shape grafana_query_metrics_with_expressions takes. This records a query for later - it does NOT run one. Grafana states that this API will not be migrated to its new APIs and that the functionality is being deprecated. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: datasourceUid, queries. Required: queries.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.

[Grafana] DESTRUCTIVE: delete a saved query from query history. DELETE /api/query-history/. The vendor states plainly that this operation cannot be reverted: the query text, the data source it named and any comment on it go together. To stop a query showing in the starred list without losing it, use grafana_unstar_query instead. Grafana states that this API will not be migrated to its new APIs and that the functionality is being deprecated. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
queryHistoryUidstringyesRequired. The query_history_uid this call targets.

[Grafana] Change the comment on a saved query in query history. PATCH /api/query-history/. Send the body as JSON with one field, comment; it replaces whatever comment is there. Nothing about the query itself changes. Grafana states that this API will not be migrated to its new APIs and that the functionality is being deprecated. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
bodyJsonstringyesRequired. The request body as JSON. Grafana documents these fields: comment.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
queryHistoryUidstringyesRequired. The query_history_uid this call targets.

[Grafana] Search the signed-in user's query history - the queries run against data sources, with their comments and stars. GET /api/query-history. Filter with datasourceUid (comma-separate several), searchString, onlyStarred, sort and a from/to window in epoch seconds; paging is page plus limit, numbered from 1 and capped at 1000 by StackJack. History is PER USER, so this returns what the service account itself has run, not what people did in the Grafana UI. Grafana states that this API will not be migrated to its new APIs and that the functionality is being deprecated - it works today, but do not build anything long-lived on it. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
datasourceUidstringnonullOptional. List of data source UIDs to search for. Comma-separate several values; each is sent as its own datasourceUid parameter.
fromintegernonullOptional. From range for the query history search.
limitintegernonullOptional. Limit the number of returned results. Capped at 1000 by StackJack.
onlyStarredbooleannonullOptional. Flag indicating if only starred queries should be returned.
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
pageintegernonullOptional. Use this parameter to access hits beyond limit. Numbering starts at 1. limit param acts as page size.
searchStringstringnonullOptional. Text inside query or comments that is searched for.
sortstringnonullOptional. Sort method. One of: time-desc, time-asc.
tointegernonullOptional. To range for the query history search.

[Grafana] Star a saved query in query history so it can be found with the onlyStarred filter. POST /api/query-history/star/. Reversible with grafana_unstar_query. Grafana states that this API will not be migrated to its new APIs and that the functionality is being deprecated. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
queryHistoryUidstringyesRequired. The query_history_uid this call targets.

[Grafana] DESTRUCTIVE: remove the star from a saved query in query history. DELETE /api/query-history/star/. The query itself stays in the history and can be starred again with grafana_star_query, so this one IS reversible - it carries the destructive flag because every DELETE in this connector does, which is the same rule that already covers grafana_unstar_dashboard_by_uid. Grafana states that this API will not be migrated to its new APIs and that the functionality is being deprecated. Pass orgId to act on a specific Grafana organization inside the instance. Returns raw Grafana JSON.

ParamTypeRequiredDefaultDescription
orgIdstringnonullOptional. The Grafana ORGANIZATION this call applies to, as its numeric id. One Grafana instance can hold several organizations, each with its own dashboards, data sources, users and alert rules. Omit it to use the organization set on this connection, or the one the token itself belongs to. grafana_get_current_org returns the id this connection is already working in; listing every organization needs Basic authentication as a Grafana server administrator, which a service account token cannot do.
queryHistoryUidstringyesRequired. The query_history_uid this call targets.