Connect Grafana
Grafana is the dashboard and alerting layer over everything else you monitor. It queries Prometheus, Loki, Elasticsearch, SQL databases, cloud provider metrics and hundreds of plugin data sources, and…
Written By Christopher Scaminaci
Last updated 6 days ago
Grafana is the dashboard and alerting layer over everything else you monitor. It queries Prometheus, Loki, Elasticsearch, SQL databases, cloud provider metrics and hundreds of plugin data sources, and renders dashboards, alert rules and reports over them. StackJack talks to your own Grafana — a stack you run for a customer, or a Grafana Cloud stack they own — through Grafana's own HTTP API.
Connecting Grafana to StackJack gives your AI assistant a family of grafana_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Ask the monitoring system a question — run a query against any data source the customer has connected and get the series back, rather than reading a dashboard somebody already built
- Find and read dashboards — search by name, tag or folder, read a dashboard whole with its panels and queries, walk its version history, and see who can open it
- Check the plumbing — inventory the data sources behind every dashboard and ask Grafana to health-test one, which answers "is the customer's Prometheus actually reachable" without anyone opening a console
- Review alerting — list alert rules with their conditions, contact points, notification policies, mute timings and message templates, and import alert rules from Prometheus rule files
- Mark what changed — write a deployment or maintenance annotation that appears on every dashboard panel covering that moment, which is what turns "the graph went strange around four" into "the graph went strange when we deployed"
- Report on access — organizations, users, teams, service accounts, roles and resource permissions
- Pull a report out (on Pro plans) — render dashboards to a PDF, or their table panels to CSV, and get a download link back
- Look back at what was asked — search the saved query history, star the queries worth keeping and comment on them
- Check the licence (Grafana Enterprise and Grafana Cloud) — whether the instance has a valid licence, what it allows and how much of it is being used
- Build and change (on Pro plans) — create and version dashboards, organize folders, add and update data sources, arm and pause alert rules, manage teams and organization membership, administer the instance, and set up a move to Grafana Cloud
How StackJack authenticates to Grafana
Grafana uses a service account token — one value, created inside the instance itself. There is no client ID and nothing to renew on a schedule.
There is one optional second credential, and it only matters if you want the instance-administration routes Grafana marks Basic-only — instance users, LDAP, provisioning reload, the instance-wide organizations family and quotas. Grafana keeps those operations behind a server administrator signing in with a username and password, and it states plainly that a service account can never hold that permission. If you fill in the optional Server admin username and Server admin password, StackJack uses that pair for those tools and the token for everything else. Leave them empty and they refuse with a message saying what to add; nothing else changes.
The important part is not the token. It is the role you give the service account you create it on, because that role is the only thing that limits what StackJack can do. Grafana has no per-token permissions to narrow afterwards:
- Viewer — StackJack can read dashboards, alert rules, data sources and queries, and nothing else.
- Editor — StackJack can also create and change dashboards, folders and alert rules.
- Admin — StackJack can also manage users, teams, data sources and organizations.
Choose the lowest role that does the job. It is a decision you make once, and it is enforced by Grafana rather than by us.
Steps
- Decide the role first. See above. Changing your mind later means a new service account, not a new token.
- Create a service account. In Grafana, go to Administration, then Users and access, then Service accounts. Add one, name it something that says what it is for, and assign the role you chose.
- Add a token to it. On the service account, choose Add service account token. Leave the expiry unset if you want it to keep working. If you do set one, put a reminder in your calendar — Grafana cannot renew a token, and an expired one simply stops working.
- Copy the token immediately. Grafana shows it exactly once and it starts with
glsa_. Treat it as a password. - Enter the address and the token in StackJack. Open Connectors, choose Grafana, paste the address you sign in to Grafana at, and paste the token.
- Optional: add a server admin sign-in. Only if you want the instance-administration tools. Fill in Server admin username and Server admin password with a Grafana account whose user record has the Grafana server administrator flag set. You can add this later without touching the token.
- Run a Test Connection. A failure here is almost always the token truncated on copy, or a missing path in the address — see the next section. If you saved a server admin sign-in, the test checks that too, and it says which of the two Grafana refused.
Changing these later
Open Configure on the Grafana connector and change what you need. Two boxes keep what is stored when you leave them blank: the Service Account Token and the Server admin password. Both say so on the form. The address, the Organization ID and the Server admin username are written exactly as the form shows them, so an empty box clears the stored value — clearing the Server admin username removes the whole sign-in, password included.
Two cases are refused rather than guessed. Changing the address while leaving the token or the server admin password blank: a credential created for one Grafana must not be carried to a different one, so StackJack asks you to enter the ones the new instance issued. And changing the Server admin username while leaving its password blank: the stored password belongs to the previous account, so StackJack asks for the new account's password rather than pairing the two and letting Grafana reject them later.
Getting the address right
This is the one field worth checking twice, because a wrong address fails in a way that looks exactly like a wrong token.
- Grafana Cloud gives each customer their own stack, so the address looks like
https://acme.grafana.net. - A Grafana you host uses whatever address you published it at, including the port if it is not the standard one.
- If you reach Grafana at a path — for example
https://example.com/grafanabecause it sits behind a reverse proxy — that path is part of the address and must be entered with it. Leave it off and every request misses.
Do not add /api to the end. StackJack adds whatever it needs.
StackJack has to reach the instance from the internet, so a Grafana that is only reachable inside your network cannot be connected. Publish it at a public address with a valid certificate.
If one Grafana holds several customers
Grafana nests. An instance holds organizations, and each organization has its own dashboards, data sources, users and alert rules. MSPs use one of two arrangements, and StackJack supports both:
- One Grafana per customer — the common arrangement, and especially so on Grafana Cloud. Add one StackJack connection per instance. This is what named connections are for.
- One Grafana, one organization per customer — fill in the optional Organization ID as well. Every call on that connection then runs against that organization, and your AI can still name a different one on a single call when it needs to.
Leave the Organization ID empty when each customer has their own Grafana. Note that instance administration always acts on the whole instance: Grafana ignores the organization setting for those actions by design.
What to know before your AI uses this connector
Some writes reach further than they look
Whether your AI application asks you to confirm before running a marked tool depends on that application's own settings — see Destructive tools and confirmation. Review that setting before you grant the Pro tools, and read these seven first:
- Deleting a folder takes its contents with it — the dashboards inside it, and the alert rules stored in it. Grafana refuses if alert rules are in the way unless the call forces it, and forcing it deletes those rules and the alerting they provide.
- Deleting a data source breaks every dashboard that queries it, and nothing tells you which ones those were.
- Replacing or resetting the notification policy tree can silently stop every alert notification in the organization. The alerts still fire; they just go nowhere, and nothing announces it.
- Creating a service account token mints a live credential that keeps working long after the conversation ends, and Grafana shows it only once.
- The instance administration tools act on real people — they can disable a user, end their live sessions, reset their password, grant them instance-administrator rights, or delete their account outright.
- Setting a team's members, a role's assignments or a resource's permissions replaces the whole list. These tools do not add one person to a list; they make the list exactly what they are given. Anyone left out is removed, and loses whatever that membership or role gave them. The safe pattern is the same one as for a dashboard: read the current list, change it, send it all back.
- Changing your own password changes the one this connection signs in with. Grafana's change-password tool acts on the signed-in account, and on this connector that is the Grafana server administrator whose username and password you saved on the connection. A successful change stops those saved credentials working, and the twenty-eight tools that need them fail until you enter the new password in Configure. To change somebody else's password, use the instance administration tool that names the user.
Reports come back as a download link, not as a file
Rendering dashboards to PDF, or their table panels to CSV, gives your AI a link rather than the file itself. The link works for thirty minutes — open it or save it inside that window and it is the real file, with its name and its size. After that it stops working and the report has to be rendered again.
Two things follow from that. A render is real work for the instance: Grafana draws every panel of every dashboard you name, so these are Pro tools even though they only read, and a wide render is slow rather than free. And if your StackJack deployment has no file storage configured, these tools fail with a clear message rather than handing back a link that would not work.
If nothing in the dashboards you named has table rows to export, the CSV render reports that nothing was produced rather than handing you an empty file.
Moving a Grafana into Grafana Cloud sends a copy of it
Grafana has its own tools for moving a self-hosted instance into a Grafana Cloud stack, and StackJack exposes them. They work in stages, and the stages are not equally consequential:
- Setting up the move records where it would go. You supply a migration token generated in the destination cloud stack — treat that value the way you treat the Grafana token itself, because it authorizes moving your content.
- Taking a snapshot captures what would move, and it stays on your own instance. This is the safe step, and the one to read before going further.
- Uploading the snapshot sends it. A copy of the instance's dashboards, its data sources and its users goes to the Grafana Cloud stack, and nothing in Grafana un-sends it. That tool is marked, so your AI application can ask you to confirm it.
These tools only work when your Grafana has the cloud-migration feature switched on. If it does not, they report that the instance does not offer them — that is a Grafana setting rather than a problem with your connection.
Saving a dashboard replaces it rather than merging into it
A dashboard save sends the whole dashboard. Anything left out of the object you send is gone, so the safe pattern is read it, change it, send it back. A save is marked, so your AI application can ask you to confirm it. Grafana does keep a version per save and a version can be restored — but your dashboard is wrong until somebody notices and restores it, which is why the marking is there. A delete takes the version history with it, so a deleted dashboard cannot be restored at all.
A few reads send data, and a couple of writes look like reads
Grafana's most valuable read — running a query against a data source — sends the query in a request body rather than in a web address. It still creates nothing and changes nothing, so StackJack classifies it by what it does rather than by how it travels: it is a Free-tier read and is not marked. The same is true of two role searches.
The reverse happens twice. Grafana deletes a dashboard snapshot through what looks like an ordinary read — StackJack classifies that one as a write and marks it, so an assistant cannot delete a snapshot without the tier and the marking that a deletion deserves. And refreshing the licence usage statistics recalculates them as it answers, so StackJack does not label it read-only: an assistant you have restricted to read-only tools will not run it. It stays a Free-tier tool and it is not marked, because it changes nothing of yours — only Grafana's own counters.
Four tools reach past Grafana entirely
Grafana can forward a request straight through to an upstream data source. The four tools that do this are genuinely open-ended: whatever path they are given goes to that system as written, so they can do anything that system's own API can do, and StackJack cannot describe the effect in advance. All four need the Pro tier, all four are marked, and all four are flagged as open-ended so an assistant knows it is leaving known ground. For getting data out, use the query tool instead — it is the supported route and it is a Free-tier read.
Twenty-eight tools need a Grafana server administrator, which a service account is not
Grafana keeps a small set of instance-wide operations behind a Grafana server administrator signing in with a username and password, and it states plainly that a service account can never hold that permission. A service account token cannot call them however the account is set up, so raising its role does nothing here.
Those tools are the instance-wide organization ones (listing every organization, reading or changing one by id, its users and its quotas), the instance-wide user ones (creating, deleting, enabling, disabling or logging out a Grafana user, setting their password or their quotas), the LDAP ones, the three provisioning reloads and the instance settings read. Each says so in its own description.
To use them, save a server admin sign-in on the connection. Fill in the optional Server admin username and Server admin password on the Grafana connector's Configure dialog with an account that holds the Grafana server administrator flag. StackJack then signs those calls in as that person and everything else as the service account, so Grafana's own audit trail shows which did what. Leave the pair empty and they stop before anything is sent, with a message naming the two boxes — they do not quietly fail, and they never fall back to the token, which Grafana would refuse anyway.
Everything scoped to an organization is unaffected either way — dashboards, folders, data sources, queries, alerting, annotations, and that organization's own members, teams and service accounts all work normally on the token alone. To see which organization a connection is working in, use the current-organization read rather than the list-every-organization one.
Some features need Grafana Enterprise or Grafana Cloud
Reporting, recording rules, role-based access control, single sign-on synchronization for teams, and data source query caching are paid features. On open-source Grafana those tools are refused by Grafana itself. That is normal, it is not a broken connection, and it does not affect anything else — the tools that need a paid edition say so in their own descriptions.
Part of this API is on its way out
Grafana marks a number of dashboard, folder and alerting operations as deprecated from Grafana 13, and says plainly that it is not switching them off yet and that any removal will be announced in advance. It also says separately that the saved-query-history part of the API will not be carried forward, and that two of the licence reports have been withdrawn with nothing to replace them. They are all still the documented way to do that work, so StackJack uses them, and every tool that does says so in its own description. Nothing you build on this connector stops working today.
Query history is per service account
The saved query history belongs to whoever ran the queries. StackJack signs in as the service account you created, so the history it can search is the history of queries run through StackJack — not what people typed in the Grafana interface. An empty result there means nobody has run a query through this connection yet, not that the customer's Grafana is idle.
Plans and limits
Read tools are available on the Free tier. Everything that creates, changes, deletes or administers is Pro. Business reaches the same tools as Pro and differs by monthly call quota.
See the generated Grafana tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Grafana publishes no rate limit for this API, so StackJack paces requests conservatively and backs off on its own if it is throttled, which usually makes a large report slower rather than failed. Pacing smooths a burst; it does not guarantee that every call arrives. Retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honor any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Large listings are paged. Grafana numbers pages from one and lets you set a page size; StackJack caps that page size so a single call cannot pull an unbounded amount out of a customer's instance. Ask for the next page rather than a bigger one.
Several customers
Every Grafana instance you manage gets its own connection. Add one per customer from the connector's card, name it after the customer, and your AI names it on each call. Omit the name and the call runs against your default connection. Pin an endpoint to one connection when an AI should never reach past a single customer. See Several connections of one connector.
You can also hold several connections to the same Grafana with different service account roles — a Viewer connection for everyday questions and an Editor connection for change work. Grafana has no per-user attribution on the API, so its own audit trail records whichever service account was used; separate connections are how you keep read work and change work apart.
Troubleshooting
"Grafana rejected the service account token" — the token was deleted, or it reached the expiry chosen when it was created. Grafana cannot renew one: create a new token on the same service account and paste it in. Copy it immediately, because Grafana shows it once.
"Grafana allowed the token but not this action" — check the tool's own description first. If it says the action needs a Grafana server administrator, the token is not the credential it used: fill in the Server admin username and password on the connection, or check that the account you saved still holds the Grafana server administrator flag. No role on the service account helps there. If it says the action needs Grafana Enterprise or Grafana Cloud, no credential will make it work on open-source Grafana. Otherwise the service account's role is too low — raise it from Viewer to Editor or Admin, or grant the matching permission.
"This operation needs the Grafana server-admin username and password" — one of the instance-administration tools was called on a connection that has no server admin sign-in saved. Nothing was sent to Grafana. Open Configure on the Grafana connector and fill in the two optional boxes, or leave them empty and do not use those tools.
"Grafana rejected the server-admin username and password" — the connection holds a server admin sign-in that Grafana refuses. The service account token is fine; it passed its own check moments earlier. Check that the account can still sign in to Grafana and that its user record still has the Grafana server administrator flag, then re-enter the pair. If you do not need the instance-wide tools, clear both boxes instead. The connection keeps working either way: only the instance-administration tools are affected, and a refused server admin sign-in never switches the connector off.
Everything fails and it looks like a bad token — check the address before you touch the credential. A Grafana published at a path, for example https://example.com/grafana, must be entered with that path. Without it every request misses and Grafana answers as though nothing is there.
Something answered, but not Grafana — a sign-in page, a firewall or a reverse proxy replied instead. StackJack reports that as a failure rather than as success, so a connection test cannot pass against a login screen. Enter the exact address you reach the Grafana sign-in page at, including the port and any path, and check the certificate is valid.
A dashboard save was refused as out of date — somebody else saved that dashboard since you read it. Read it again, reapply the change and save that. Forcing the save discards their work.
An assistant asks about silencing an alert — Grafana does not publish an interface for silences or for the Alertmanager configuration, so there are no tools for them. Pausing an alert rule is available and is the nearest equivalent.
Grafana tools
grafana_ · 309 tools · Free 137 · Pro 172
Dashboard snapshots
Dashboard versions
Dashboards
Public dashboards
Search
Folders
Library panels
Playlists
Data source caching and access rules
Data source correlations
Data source proxy
Data source query
Data sources
Alert rules
Contact points
Mute timings
Notification policies
Notification templates
Prometheus rule conversion
Recording rules
Annotations
All organizations
Current organization
Quotas
Signed-in user
Team sync
Teams
Users
Service accounts
Resource permissions
Role assignments
Roles
Reporting
Anonymous devices
Instance health
Instance settings
Instance users
LDAP
Provisioning reload
SSO settings
Cloud migration
Licensing
Query history
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team