Skip to main content
Connector guides

Connect Grafana

Grafana is the dashboard and alerting layer over everything else you monitor. It queries Prometheus, Loki, Elasticsearch, SQL databases, cloud provider metrics and hundreds of plugin data sources, and…

Written By Christopher Scaminaci

Last updated 6 days ago

Grafana is the dashboard and alerting layer over everything else you monitor. It queries Prometheus, Loki, Elasticsearch, SQL databases, cloud provider metrics and hundreds of plugin data sources, and renders dashboards, alert rules and reports over them. StackJack talks to your own Grafana — a stack you run for a customer, or a Grafana Cloud stack they own — through Grafana's own HTTP API.

Connecting Grafana to StackJack gives your AI assistant a family of grafana_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Ask the monitoring system a question — run a query against any data source the customer has connected and get the series back, rather than reading a dashboard somebody already built
  • Find and read dashboards — search by name, tag or folder, read a dashboard whole with its panels and queries, walk its version history, and see who can open it
  • Check the plumbing — inventory the data sources behind every dashboard and ask Grafana to health-test one, which answers "is the customer's Prometheus actually reachable" without anyone opening a console
  • Review alerting — list alert rules with their conditions, contact points, notification policies, mute timings and message templates, and import alert rules from Prometheus rule files
  • Mark what changed — write a deployment or maintenance annotation that appears on every dashboard panel covering that moment, which is what turns "the graph went strange around four" into "the graph went strange when we deployed"
  • Report on access — organizations, users, teams, service accounts, roles and resource permissions
  • Pull a report out (on Pro plans) — render dashboards to a PDF, or their table panels to CSV, and get a download link back
  • Look back at what was asked — search the saved query history, star the queries worth keeping and comment on them
  • Check the licence (Grafana Enterprise and Grafana Cloud) — whether the instance has a valid licence, what it allows and how much of it is being used
  • Build and change (on Pro plans) — create and version dashboards, organize folders, add and update data sources, arm and pause alert rules, manage teams and organization membership, administer the instance, and set up a move to Grafana Cloud

How StackJack authenticates to Grafana

Grafana uses a service account token — one value, created inside the instance itself. There is no client ID and nothing to renew on a schedule.

There is one optional second credential, and it only matters if you want the instance-administration routes Grafana marks Basic-only — instance users, LDAP, provisioning reload, the instance-wide organizations family and quotas. Grafana keeps those operations behind a server administrator signing in with a username and password, and it states plainly that a service account can never hold that permission. If you fill in the optional Server admin username and Server admin password, StackJack uses that pair for those tools and the token for everything else. Leave them empty and they refuse with a message saying what to add; nothing else changes.

The important part is not the token. It is the role you give the service account you create it on, because that role is the only thing that limits what StackJack can do. Grafana has no per-token permissions to narrow afterwards:

  • Viewer — StackJack can read dashboards, alert rules, data sources and queries, and nothing else.
  • Editor — StackJack can also create and change dashboards, folders and alert rules.
  • Admin — StackJack can also manage users, teams, data sources and organizations.

Choose the lowest role that does the job. It is a decision you make once, and it is enforced by Grafana rather than by us.

Steps

  1. Decide the role first. See above. Changing your mind later means a new service account, not a new token.
  2. Create a service account. In Grafana, go to Administration, then Users and access, then Service accounts. Add one, name it something that says what it is for, and assign the role you chose.
  3. Add a token to it. On the service account, choose Add service account token. Leave the expiry unset if you want it to keep working. If you do set one, put a reminder in your calendar — Grafana cannot renew a token, and an expired one simply stops working.
  4. Copy the token immediately. Grafana shows it exactly once and it starts with glsa_. Treat it as a password.
  5. Enter the address and the token in StackJack. Open Connectors, choose Grafana, paste the address you sign in to Grafana at, and paste the token.
  6. Optional: add a server admin sign-in. Only if you want the instance-administration tools. Fill in Server admin username and Server admin password with a Grafana account whose user record has the Grafana server administrator flag set. You can add this later without touching the token.
  7. Run a Test Connection. A failure here is almost always the token truncated on copy, or a missing path in the address — see the next section. If you saved a server admin sign-in, the test checks that too, and it says which of the two Grafana refused.

Changing these later

Open Configure on the Grafana connector and change what you need. Two boxes keep what is stored when you leave them blank: the Service Account Token and the Server admin password. Both say so on the form. The address, the Organization ID and the Server admin username are written exactly as the form shows them, so an empty box clears the stored value — clearing the Server admin username removes the whole sign-in, password included.

Two cases are refused rather than guessed. Changing the address while leaving the token or the server admin password blank: a credential created for one Grafana must not be carried to a different one, so StackJack asks you to enter the ones the new instance issued. And changing the Server admin username while leaving its password blank: the stored password belongs to the previous account, so StackJack asks for the new account's password rather than pairing the two and letting Grafana reject them later.

Getting the address right

This is the one field worth checking twice, because a wrong address fails in a way that looks exactly like a wrong token.

  • Grafana Cloud gives each customer their own stack, so the address looks like https://acme.grafana.net.
  • A Grafana you host uses whatever address you published it at, including the port if it is not the standard one.
  • If you reach Grafana at a path — for example https://example.com/grafana because it sits behind a reverse proxy — that path is part of the address and must be entered with it. Leave it off and every request misses.

Do not add /api to the end. StackJack adds whatever it needs.

StackJack has to reach the instance from the internet, so a Grafana that is only reachable inside your network cannot be connected. Publish it at a public address with a valid certificate.

If one Grafana holds several customers

Grafana nests. An instance holds organizations, and each organization has its own dashboards, data sources, users and alert rules. MSPs use one of two arrangements, and StackJack supports both:

  • One Grafana per customer — the common arrangement, and especially so on Grafana Cloud. Add one StackJack connection per instance. This is what named connections are for.
  • One Grafana, one organization per customer — fill in the optional Organization ID as well. Every call on that connection then runs against that organization, and your AI can still name a different one on a single call when it needs to.

Leave the Organization ID empty when each customer has their own Grafana. Note that instance administration always acts on the whole instance: Grafana ignores the organization setting for those actions by design.

What to know before your AI uses this connector

Some writes reach further than they look

Whether your AI application asks you to confirm before running a marked tool depends on that application's own settings — see Destructive tools and confirmation. Review that setting before you grant the Pro tools, and read these seven first:

  • Deleting a folder takes its contents with it — the dashboards inside it, and the alert rules stored in it. Grafana refuses if alert rules are in the way unless the call forces it, and forcing it deletes those rules and the alerting they provide.
  • Deleting a data source breaks every dashboard that queries it, and nothing tells you which ones those were.
  • Replacing or resetting the notification policy tree can silently stop every alert notification in the organization. The alerts still fire; they just go nowhere, and nothing announces it.
  • Creating a service account token mints a live credential that keeps working long after the conversation ends, and Grafana shows it only once.
  • The instance administration tools act on real people — they can disable a user, end their live sessions, reset their password, grant them instance-administrator rights, or delete their account outright.
  • Setting a team's members, a role's assignments or a resource's permissions replaces the whole list. These tools do not add one person to a list; they make the list exactly what they are given. Anyone left out is removed, and loses whatever that membership or role gave them. The safe pattern is the same one as for a dashboard: read the current list, change it, send it all back.
  • Changing your own password changes the one this connection signs in with. Grafana's change-password tool acts on the signed-in account, and on this connector that is the Grafana server administrator whose username and password you saved on the connection. A successful change stops those saved credentials working, and the twenty-eight tools that need them fail until you enter the new password in Configure. To change somebody else's password, use the instance administration tool that names the user.

Rendering dashboards to PDF, or their table panels to CSV, gives your AI a link rather than the file itself. The link works for thirty minutes — open it or save it inside that window and it is the real file, with its name and its size. After that it stops working and the report has to be rendered again.

Two things follow from that. A render is real work for the instance: Grafana draws every panel of every dashboard you name, so these are Pro tools even though they only read, and a wide render is slow rather than free. And if your StackJack deployment has no file storage configured, these tools fail with a clear message rather than handing back a link that would not work.

If nothing in the dashboards you named has table rows to export, the CSV render reports that nothing was produced rather than handing you an empty file.

Moving a Grafana into Grafana Cloud sends a copy of it

Grafana has its own tools for moving a self-hosted instance into a Grafana Cloud stack, and StackJack exposes them. They work in stages, and the stages are not equally consequential:

  • Setting up the move records where it would go. You supply a migration token generated in the destination cloud stack — treat that value the way you treat the Grafana token itself, because it authorizes moving your content.
  • Taking a snapshot captures what would move, and it stays on your own instance. This is the safe step, and the one to read before going further.
  • Uploading the snapshot sends it. A copy of the instance's dashboards, its data sources and its users goes to the Grafana Cloud stack, and nothing in Grafana un-sends it. That tool is marked, so your AI application can ask you to confirm it.

These tools only work when your Grafana has the cloud-migration feature switched on. If it does not, they report that the instance does not offer them — that is a Grafana setting rather than a problem with your connection.

Saving a dashboard replaces it rather than merging into it

A dashboard save sends the whole dashboard. Anything left out of the object you send is gone, so the safe pattern is read it, change it, send it back. A save is marked, so your AI application can ask you to confirm it. Grafana does keep a version per save and a version can be restored — but your dashboard is wrong until somebody notices and restores it, which is why the marking is there. A delete takes the version history with it, so a deleted dashboard cannot be restored at all.

A few reads send data, and a couple of writes look like reads

Grafana's most valuable read — running a query against a data source — sends the query in a request body rather than in a web address. It still creates nothing and changes nothing, so StackJack classifies it by what it does rather than by how it travels: it is a Free-tier read and is not marked. The same is true of two role searches.

The reverse happens twice. Grafana deletes a dashboard snapshot through what looks like an ordinary read — StackJack classifies that one as a write and marks it, so an assistant cannot delete a snapshot without the tier and the marking that a deletion deserves. And refreshing the licence usage statistics recalculates them as it answers, so StackJack does not label it read-only: an assistant you have restricted to read-only tools will not run it. It stays a Free-tier tool and it is not marked, because it changes nothing of yours — only Grafana's own counters.

Four tools reach past Grafana entirely

Grafana can forward a request straight through to an upstream data source. The four tools that do this are genuinely open-ended: whatever path they are given goes to that system as written, so they can do anything that system's own API can do, and StackJack cannot describe the effect in advance. All four need the Pro tier, all four are marked, and all four are flagged as open-ended so an assistant knows it is leaving known ground. For getting data out, use the query tool instead — it is the supported route and it is a Free-tier read.

Twenty-eight tools need a Grafana server administrator, which a service account is not

Grafana keeps a small set of instance-wide operations behind a Grafana server administrator signing in with a username and password, and it states plainly that a service account can never hold that permission. A service account token cannot call them however the account is set up, so raising its role does nothing here.

Those tools are the instance-wide organization ones (listing every organization, reading or changing one by id, its users and its quotas), the instance-wide user ones (creating, deleting, enabling, disabling or logging out a Grafana user, setting their password or their quotas), the LDAP ones, the three provisioning reloads and the instance settings read. Each says so in its own description.

To use them, save a server admin sign-in on the connection. Fill in the optional Server admin username and Server admin password on the Grafana connector's Configure dialog with an account that holds the Grafana server administrator flag. StackJack then signs those calls in as that person and everything else as the service account, so Grafana's own audit trail shows which did what. Leave the pair empty and they stop before anything is sent, with a message naming the two boxes — they do not quietly fail, and they never fall back to the token, which Grafana would refuse anyway.

Everything scoped to an organization is unaffected either way — dashboards, folders, data sources, queries, alerting, annotations, and that organization's own members, teams and service accounts all work normally on the token alone. To see which organization a connection is working in, use the current-organization read rather than the list-every-organization one.

Some features need Grafana Enterprise or Grafana Cloud

Reporting, recording rules, role-based access control, single sign-on synchronization for teams, and data source query caching are paid features. On open-source Grafana those tools are refused by Grafana itself. That is normal, it is not a broken connection, and it does not affect anything else — the tools that need a paid edition say so in their own descriptions.

Part of this API is on its way out

Grafana marks a number of dashboard, folder and alerting operations as deprecated from Grafana 13, and says plainly that it is not switching them off yet and that any removal will be announced in advance. It also says separately that the saved-query-history part of the API will not be carried forward, and that two of the licence reports have been withdrawn with nothing to replace them. They are all still the documented way to do that work, so StackJack uses them, and every tool that does says so in its own description. Nothing you build on this connector stops working today.

Query history is per service account

The saved query history belongs to whoever ran the queries. StackJack signs in as the service account you created, so the history it can search is the history of queries run through StackJack — not what people typed in the Grafana interface. An empty result there means nobody has run a query through this connection yet, not that the customer's Grafana is idle.

Plans and limits

Read tools are available on the Free tier. Everything that creates, changes, deletes or administers is Pro. Business reaches the same tools as Pro and differs by monthly call quota.

See the generated Grafana tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

Grafana publishes no rate limit for this API, so StackJack paces requests conservatively and backs off on its own if it is throttled, which usually makes a large report slower rather than failed. Pacing smooths a burst; it does not guarantee that every call arrives. Retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honor any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.

Large listings are paged. Grafana numbers pages from one and lets you set a page size; StackJack caps that page size so a single call cannot pull an unbounded amount out of a customer's instance. Ask for the next page rather than a bigger one.

Several customers

Every Grafana instance you manage gets its own connection. Add one per customer from the connector's card, name it after the customer, and your AI names it on each call. Omit the name and the call runs against your default connection. Pin an endpoint to one connection when an AI should never reach past a single customer. See Several connections of one connector.

You can also hold several connections to the same Grafana with different service account roles — a Viewer connection for everyday questions and an Editor connection for change work. Grafana has no per-user attribution on the API, so its own audit trail records whichever service account was used; separate connections are how you keep read work and change work apart.

Troubleshooting

"Grafana rejected the service account token" — the token was deleted, or it reached the expiry chosen when it was created. Grafana cannot renew one: create a new token on the same service account and paste it in. Copy it immediately, because Grafana shows it once.

"Grafana allowed the token but not this action" — check the tool's own description first. If it says the action needs a Grafana server administrator, the token is not the credential it used: fill in the Server admin username and password on the connection, or check that the account you saved still holds the Grafana server administrator flag. No role on the service account helps there. If it says the action needs Grafana Enterprise or Grafana Cloud, no credential will make it work on open-source Grafana. Otherwise the service account's role is too low — raise it from Viewer to Editor or Admin, or grant the matching permission.

"This operation needs the Grafana server-admin username and password" — one of the instance-administration tools was called on a connection that has no server admin sign-in saved. Nothing was sent to Grafana. Open Configure on the Grafana connector and fill in the two optional boxes, or leave them empty and do not use those tools.

"Grafana rejected the server-admin username and password" — the connection holds a server admin sign-in that Grafana refuses. The service account token is fine; it passed its own check moments earlier. Check that the account can still sign in to Grafana and that its user record still has the Grafana server administrator flag, then re-enter the pair. If you do not need the instance-wide tools, clear both boxes instead. The connection keeps working either way: only the instance-administration tools are affected, and a refused server admin sign-in never switches the connector off.

Everything fails and it looks like a bad token — check the address before you touch the credential. A Grafana published at a path, for example https://example.com/grafana, must be entered with that path. Without it every request misses and Grafana answers as though nothing is there.

Something answered, but not Grafana — a sign-in page, a firewall or a reverse proxy replied instead. StackJack reports that as a failure rather than as success, so a connection test cannot pass against a login screen. Enter the exact address you reach the Grafana sign-in page at, including the port and any path, and check the certificate is valid.

A dashboard save was refused as out of date — somebody else saved that dashboard since you read it. Read it again, reapply the change and save that. Forcing the save discards their work.

An assistant asks about silencing an alert — Grafana does not publish an interface for silences or for the Alertmanager configuration, so there are no tools for them. Pausing an alert rule is available and is the nearest equivalent.

Grafana tools

grafana_ · 309 tools · Free 137 · Pro 172

Dashboard snapshots

ToolWhat it does
grafana_create_dashboard_snapshot
Pro · Write
When creating a snapshot using the API, you have to provide the full dashboard payload including the snapshot data.
grafana_delete_dashboard_snapshot
Pro · Destructive
DESTRUCTIVE: delete Snapshot by Key.
grafana_delete_dashboard_snapshot_by_delete_key
Pro · Destructive
DESTRUCTIVE: delete a dashboard snapshot using its delete key.
grafana_get_dashboard_snapshot
Free · Read-only
Get Snapshot by Key.
grafana_get_sharing_options
Free · Read-only
Get snapshot sharing settings.
grafana_search_dashboard_snapshots
Free · Read-only
List snapshots.

Dashboard versions

ToolWhat it does
grafana_get_dashboard_version_by_uid
Free · Read-only
Get a specific dashboard version using UID.
grafana_get_dashboard_versions_by_uid
Free · Read-only
Gets all existing versions for the dashboard using UID.

Dashboards

ToolWhat it does
grafana_delete_dashboard_by_uid
Pro · Destructive
DESTRUCTIVE: delete a dashboard by uid.
grafana_get_dashboard_by_uid
Free · Read-only
Read one dashboard whole - its panels, queries, variables, annotations and version - by uid.
grafana_get_dashboard_permissions_list_by_uid
Free · Read-only
Gets all existing permissions for the given dashboard.
grafana_get_dashboard_tags
Free · Read-only
Get all dashboards tags of an organization.
grafana_get_home_dashboard
Free · Read-only
NOTE: the home dashboard is configured in preferences.
grafana_import_dashboard
Pro · Write
Import dashboard.
grafana_interpolate_dashboard
Pro · Write
Interpolate dashboard.
grafana_post_dashboard
Pro · Destructive
DESTRUCTIVE: create a dashboard, or save a new version of an existing one.
grafana_restore_dashboard_version_by_uid
Pro · Write
Restore a dashboard to a given dashboard version using UID.
grafana_update_dashboard_permissions_by_uid
Pro · Destructive
DESTRUCTIVE: updates permissions for a dashboard.

Public dashboards

ToolWhat it does
grafana_create_public_dashboard
Pro · Write
Create public dashboard for a dashboard.
grafana_delete_public_dashboard
Pro · Destructive
DESTRUCTIVE: delete public dashboard for a dashboard.
grafana_get_public_annotations
Free · Read-only
Get annotations for a public dashboard.
grafana_get_public_dashboard
Free · Read-only
Get public dashboard by dashboardUid.
grafana_list_public_dashboards
Free · Read-only
Get list of public dashboards.
grafana_query_public_dashboard
Pro · Write
Get results for a given panel on a public dashboard.
grafana_update_public_dashboard
Pro · Write
Update public dashboard for a dashboard.
grafana_view_public_dashboard
Free · Read-only
Get public dashboard for view.
ToolWhat it does
grafana_list_sort_options
Free · Read-only
List search sorting options.
grafana_search
Free · Read-only
Find dashboards and folders by name, tag or folder.

Folders

ToolWhat it does
grafana_create_folder
Pro · Write
Create folder.
grafana_delete_folder
Pro · Destructive
DESTRUCTIVE: delete a folder.
grafana_get_folder_by_uid
Free · Read-only
Get folder by uid.
grafana_get_folder_descendant_counts
Free · Read-only
Gets the count of each descendant of a folder by kind.
grafana_get_folder_permission_list
Free · Read-only
Gets all existing permissions for the folder with the given `uid`.
grafana_get_folders
Free · Read-only
List folders.
grafana_move_folder
Pro · Write
Move folder.
grafana_update_folder
Pro · Write
Update folder.
grafana_update_folder_permissions
Pro · Destructive
DESTRUCTIVE: updates permissions for a folder.

Library panels

ToolWhat it does
grafana_create_library_element
Pro · Write
Create library element.
grafana_delete_library_element_by_uid
Pro · Destructive
DESTRUCTIVE: delete library element.
grafana_get_library_element_by_name
Free · Read-only
Get library element by name.
grafana_get_library_element_by_uid
Free · Read-only
Get library element by UID.
grafana_get_library_element_connections
Free · Read-only
Get library element connections.
grafana_get_library_elements
Free · Read-only
Get all library elements.
grafana_update_library_element
Pro · Write
Update library element.

Playlists

ToolWhat it does
grafana_create_playlist
Pro · Write
Create playlist.
grafana_delete_playlist
Pro · Destructive
DESTRUCTIVE: delete playlist.
grafana_get_playlist
Free · Read-only
Get playlist.
grafana_get_playlist_items
Free · Read-only
Get playlist items.
grafana_search_playlists
Free · Read-only
Get playlists.
grafana_update_playlist
Pro · Write
Update playlist.

Data source caching and access rules

ToolWhat it does
grafana_clean_data_source_cache
Pro · Write
clean cache for a single data source.
grafana_disable_data_source_cache
Pro · Destructive
DESTRUCTIVE: disable cache for a single data source.
grafana_enable_data_source_cache
Pro · Write
enable cache for a single data source.
grafana_get_data_source_cache_config
Free · Read-only
get cache config for a single data source.
grafana_get_team_lbac_rules
Free · Read-only
Retrieves LBAC rules for a team.
grafana_set_data_source_cache_config
Pro · Write
set cache config for a single data source.
grafana_update_team_lbac_rules
Pro · Destructive
DESTRUCTIVE: updates LBAC rules for a team.

Data source correlations

ToolWhat it does
grafana_create_correlation
Pro · Write
Add correlation.
grafana_delete_correlation
Pro · Destructive
DESTRUCTIVE: delete a correlation.
grafana_get_correlation
Free · Read-only
Gets a correlation.
grafana_get_correlations
Free · Read-only
Gets all correlations.
grafana_get_correlations_by_source_uid
Free · Read-only
Gets all correlations originating from the given data source.
grafana_update_correlation
Pro · Write
Updates a correlation.

Data source proxy

ToolWhat it does
grafana_call_datasource_resource
Pro · Destructive
DESTRUCTIVE, OPEN WORLD: call a data source plugin's own resource endpoint through Grafana.
grafana_datasource_proxy_delete
Pro · Destructive
DESTRUCTIVE, OPEN WORLD: forward a DELETE straight through Grafana to the upstream data source.
grafana_datasource_proxy_get
Pro · Destructive
DESTRUCTIVE, OPEN WORLD: forward a GET straight through Grafana to the upstream data source.
grafana_datasource_proxy_post
Pro · Destructive
DESTRUCTIVE, OPEN WORLD: forward a POST straight through Grafana to the upstream data source.

Data source query

ToolWhat it does
grafana_query_metrics_with_expressions
Free · Read-only
Run a query against any data source this Grafana has configured and get the result series back.

Data sources

ToolWhat it does
grafana_add_data_source
Pro · Write
Create a data source.
grafana_check_datasource_health_with_uid
Free · Read-only
Ask Grafana to test one data source and report whether it is actually reachable and answering.
grafana_delete_data_source_by_name
Pro · Destructive
DESTRUCTIVE: delete an existing data source by name.
grafana_delete_data_source_by_uid
Pro · Destructive
DESTRUCTIVE: delete an existing data source by UID.
grafana_get_data_source_by_name
Free · Read-only
Get a single data source by Name.
grafana_get_data_source_by_uid
Free · Read-only
Get a single data source by UID.
grafana_get_data_source_id_by_name
Free · Read-only
Get data source Id by Name.
grafana_get_data_sources
Free · Read-only
List the data sources this Grafana queries - Prometheus, Loki, Elasticsearch, SQL databases, cloud provider metrics and plugin sources.
grafana_update_data_source_by_uid
Pro · Write
Update an existing data source.

Alert rules

ToolWhat it does
grafana_delete_alert_rule
Pro · Destructive
DESTRUCTIVE: delete a specific alert rule by UID.
grafana_delete_alert_rule_group
Pro · Destructive
DESTRUCTIVE: delete rule group.
grafana_get_alert_rule
Free · Read-only
Get a specific alert rule by UID.
grafana_get_alert_rule_export
Free · Read-only
Export an alert rule in provisioning file format.
grafana_get_alert_rule_group
Free · Read-only
Get a rule group.
grafana_get_alert_rule_group_export
Free · Read-only
Export an alert rule group in provisioning file format.
grafana_get_alert_rules
Free · Read-only
List every Grafana-managed alert rule in the organization.
grafana_get_alert_rules_export
Free · Read-only
Export all alert rules in provisioning file format.
grafana_post_alert_rule
Pro · Write
Create a new alert rule.
grafana_put_alert_rule
Pro · Write
Update an existing alert rule.
grafana_put_alert_rule_group
Pro · Write
Create or update alert rule group.

Contact points

ToolWhat it does
grafana_delete_contactpoints
Pro · Destructive
DESTRUCTIVE: delete a contact point.
grafana_get_contactpoints
Free · Read-only
Get all the contact points.
grafana_get_contactpoints_export
Free · Read-only
Export all contact points in provisioning file format.
grafana_post_contactpoints
Pro · Write
Create a contact point.
grafana_put_contactpoint
Pro · Write
Update an existing contact point.

Mute timings

ToolWhat it does
grafana_delete_mute_timing
Pro · Destructive
DESTRUCTIVE: delete a mute timing.
grafana_export_mute_timing
Free · Read-only
Export a mute timing in provisioning format.
grafana_export_mute_timings
Free · Read-only
Export all mute timings in provisioning format.
grafana_get_mute_timing
Free · Read-only
Get a mute timing.
grafana_get_mute_timings
Free · Read-only
Get all the mute timings.
grafana_post_mute_timing
Pro · Write
Create a new mute timing.
grafana_put_mute_timing
Pro · Write
Replace an existing mute timing.

Notification policies

ToolWhat it does
grafana_get_policy_tree
Free · Read-only
Get the notification policy tree.
grafana_get_policy_tree_export
Free · Read-only
Export the notification policy tree in provisioning file format.
grafana_put_policy_tree
Pro · Destructive
DESTRUCTIVE: replace the organization's WHOLE notification policy tree.
grafana_reset_policy_tree
Pro · Destructive
DESTRUCTIVE: reset the organization's notification policy tree to Grafana's default.

Notification templates

ToolWhat it does
grafana_delete_template
Pro · Destructive
DESTRUCTIVE: delete a notification template group.
grafana_get_template
Free · Read-only
Get a notification template group.
grafana_get_templates
Free · Read-only
Get all notification template groups.
grafana_put_template
Pro · Write
Updates an existing notification template group.

Prometheus rule conversion

ToolWhat it does
grafana_convert_prometheus_cortex_delete_namespace
Pro · Destructive
DESTRUCTIVE: deletes all rule groups that were imported from Prometheus-compatible sources within the specified namespace.
grafana_convert_prometheus_cortex_delete_rule_group
Pro · Destructive
DESTRUCTIVE: deletes a specific rule group if it was imported from a Prometheus-compatible source.
grafana_convert_prometheus_cortex_get_namespace
Free · Read-only
Gets Grafana-managed alert rules that were imported from Prometheus-compatible sources for a specified namespace (folder).
grafana_convert_prometheus_cortex_get_rule_group
Free · Read-only
Gets a single rule group in Prometheus-compatible format if it was imported from a Prometheus-compatible source.
grafana_convert_prometheus_cortex_get_rules
Free · Read-only
Gets all Grafana-managed alert rules that were imported from Prometheus-compatible sources, grouped by namespace.
grafana_convert_prometheus_cortex_post_rule_group
Pro · Write
Converts a Prometheus rule group into a Grafana rule group and creates or updates it within the specified namespace.
grafana_convert_prometheus_cortex_post_rule_groups
Pro · Write
Converts the submitted rule groups into Grafana-Managed Rules.
grafana_convert_prometheus_delete_namespace
Pro · Destructive
DESTRUCTIVE: deletes all rule groups that were imported from Prometheus-compatible sources within the specified namespace.
grafana_convert_prometheus_delete_rule_group
Pro · Destructive
DESTRUCTIVE: deletes a specific rule group if it was imported from a Prometheus-compatible source.
grafana_convert_prometheus_get_namespace
Free · Read-only
Gets Grafana-managed alert rules that were imported from Prometheus-compatible sources for a specified namespace (folder).
grafana_convert_prometheus_get_rule_group
Free · Read-only
Gets a single rule group in Prometheus-compatible format if it was imported from a Prometheus-compatible source.
grafana_convert_prometheus_get_rules
Free · Read-only
Gets all Grafana-managed alert rules that were imported from Prometheus-compatible sources, grouped by namespace.
grafana_convert_prometheus_post_rule_group
Pro · Write
Converts a Prometheus rule group into a Grafana rule group and creates or updates it within the specified namespace.
grafana_convert_prometheus_post_rule_groups
Pro · Write
Converts the submitted rule groups into Grafana-Managed Rules.

Recording rules

ToolWhat it does
grafana_create_recording_rule
Pro · Write
Create a recording rule that is then registered and started.
grafana_create_recording_rule_write_target
Pro · Write
Create a remote write target.
grafana_delete_recording_rule
Pro · Destructive
DESTRUCTIVE: delete removes the rule from the registry and stops it.
grafana_delete_recording_rule_write_target
Pro · Destructive
DESTRUCTIVE: delete the remote write target.
grafana_get_recording_rule_write_target
Free · Read-only
Return the prometheus remote write target.
grafana_list_recording_rules
Free · Read-only
Lists all rules in the database: active or deleted.
grafana_test_create_recording_rule
Pro · Write
Test a recording rule.
grafana_update_recording_rule
Pro · Write
Update the active status of a rule.

Annotations

ToolWhat it does
grafana_delete_annotation_by_id
Pro · Destructive
DESTRUCTIVE: delete Annotation By ID.
grafana_get_annotation_by_id
Free · Read-only
Get Annotation by ID.
grafana_get_annotation_tags
Free · Read-only
Find Annotations Tags.
grafana_get_annotations
Free · Read-only
Find Annotations.
grafana_mass_delete_annotations
Pro · Destructive
DESTRUCTIVE: delete annotations in bulk.
grafana_patch_annotation
Pro · Write
Patch Annotation.
grafana_post_annotation
Pro · Write
Write an annotation - a timestamped marker that appears on every dashboard panel covering that moment.
grafana_post_graphite_annotation
Pro · Write
Create Annotation in Graphite format.
grafana_update_annotation
Pro · Write
Update Annotation.

All organizations

ToolWhat it does
grafana_add_org_user
Pro · Write
Add a new user to the current organization.
grafana_create_org
Pro · Write
Create Organization.
grafana_delete_org_by_id
Pro · Destructive
DESTRUCTIVE: delete Organization.
grafana_get_org_by_id
Free · Read-only
Get Organization by ID.
grafana_get_org_by_name
Free · Read-only
Get Organization by Name.
grafana_get_org_users
Free · Read-only
Get Users in Organization.
grafana_remove_org_user
Pro · Destructive
DESTRUCTIVE: delete user in current organization.
grafana_search_org_users
Free · Read-only
Search Users in Organization.
grafana_search_orgs
Free · Read-only
List every organization in the instance.
grafana_update_org
Pro · Write
Update Organization.
grafana_update_org_address
Pro · Write
Update Organization's address.
grafana_update_org_user
Pro · Write
Update Users in Organization.

Current organization

ToolWhat it does
grafana_add_org_invite
Pro · Write
Add invite.
grafana_add_org_user_to_current_org
Pro · Write
Add a new user to the current organization.
grafana_get_current_org
Free · Read-only
Read the organization this connection is working in - its id and name.
grafana_get_org_preferences
Free · Read-only
Get Current Org Prefs.
grafana_get_org_users_for_current_org
Free · Read-only
Get all users within the current organization.
grafana_get_org_users_for_current_org_lookup
Free · Read-only
Get all users within the current organization (lookup).
grafana_get_pending_org_invites
Free · Read-only
Get pending invites.
grafana_patch_org_preferences
Pro · Write
Patch Current Org Prefs.
grafana_remove_org_user_for_current_org
Pro · Destructive
DESTRUCTIVE: delete user in current organization.
grafana_revoke_invite
Pro · Destructive
DESTRUCTIVE: revoke invite.
grafana_update_current_org
Pro · Write
Update current Organization.
grafana_update_current_org_address
Pro · Write
Update current Organization's address.
grafana_update_org_preferences
Pro · Write
Update Current Org Prefs.
grafana_update_org_user_for_current_org
Pro · Write
Updates the given user.

Quotas

ToolWhat it does
grafana_get_current_org_quota
Free · Read-only
Fetch Organization quota.
grafana_get_org_quota
Free · Read-only
Fetch Organization quota.
grafana_get_user_quota
Free · Read-only
Fetch user quota.
grafana_get_user_quotas
Free · Read-only
Fetch user quota.
grafana_update_org_quota
Pro · Destructive
DESTRUCTIVE: update user quota.
grafana_update_user_quota
Pro · Destructive
DESTRUCTIVE: update user quota.

Signed-in user

ToolWhat it does
grafana_change_user_password
Pro · Destructive
DESTRUCTIVE: change Password.
grafana_get_signed_in_user
Free · Read-only
Get (current authenticated user).
grafana_get_signed_in_user_org_list
Free · Read-only
Organizations of the actual User.
grafana_get_signed_in_user_team_list
Free · Read-only
Teams that the actual User is member of.
grafana_get_user_auth_tokens
Free · Read-only
Auth tokens of the actual User.
grafana_get_user_preferences
Free · Read-only
Get user preferences.
grafana_patch_user_preferences
Pro · Write
Patch user preferences.
grafana_revoke_user_auth_token
Pro · Destructive
DESTRUCTIVE: revoke an auth token of the actual User.
grafana_star_dashboard_by_uid
Pro · Write
Star a dashboard.
grafana_unstar_dashboard_by_uid
Pro · Destructive
DESTRUCTIVE: unstar a dashboard.
grafana_update_signed_in_user
Pro · Write
Update signed in User.
grafana_update_user_preferences
Pro · Write
Update user preferences.
grafana_user_set_using_org
Pro · Write
Switch user context for signed in user.

Team sync

ToolWhat it does
grafana_add_team_group
Pro · Write
Add External Group.
grafana_get_team_groups
Free · Read-only
Get External Groups.
grafana_remove_team_group
Pro · Destructive
DESTRUCTIVE: remove External Group.
grafana_search_team_groups
Free · Read-only
Search for team groups with optional filtering and pagination.

Teams

ToolWhat it does
grafana_add_team_member
Pro · Write
Add Team Member.
grafana_create_team
Pro · Write
Add Team.
grafana_delete_team_by_id
Pro · Destructive
DESTRUCTIVE: delete Team By ID.
grafana_get_team_by_id
Free · Read-only
Get Team By ID.
grafana_get_team_members
Free · Read-only
Get Team Members.
grafana_get_team_preferences
Free · Read-only
Get Team Preferences.
grafana_remove_team_member
Pro · Destructive
DESTRUCTIVE: remove Member From Team.
grafana_search_teams
Free · Read-only
Team Search With Paging.
grafana_set_team_memberships
Pro · Destructive
DESTRUCTIVE: set team memberships.
grafana_update_team
Pro · Write
Update Team.
grafana_update_team_member
Pro · Write
Update Team Member.
grafana_update_team_preferences
Pro · Write
Update Team Preferences.

Users

ToolWhat it does
grafana_get_user_by_id
Free · Read-only
Get user by id.
grafana_get_user_by_login_or_email
Free · Read-only
Get user by login or email.
grafana_get_user_org_list
Free · Read-only
Get organizations for user.
grafana_get_user_teams
Free · Read-only
Get teams for user.
grafana_search_users
Free · Read-only
Get users.
grafana_search_users_with_paging
Free · Read-only
Get users with paging.
grafana_update_user
Pro · Write
Update user.

Service accounts

ToolWhat it does
grafana_create_service_account
Pro · Write
Create service account.
grafana_create_token
Pro · Destructive
DESTRUCTIVE: mint a new service account token.
grafana_delete_service_account
Pro · Destructive
DESTRUCTIVE: delete service account.
grafana_delete_token
Pro · Destructive
DESTRUCTIVE: revoke a service account token.
grafana_list_tokens
Free · Read-only
Get service account tokens.
grafana_retrieve_service_account
Free · Read-only
Get single serviceaccount by Id.
grafana_search_service_accounts
Free · Read-only
Search service accounts with paging.
grafana_update_service_account
Pro · Write
Update service account.

Resource permissions

ToolWhat it does
grafana_get_resource_description
Free · Read-only
Get a description of a resource's access control properties.
grafana_get_resource_permissions
Free · Read-only
Get permissions for a resource.
grafana_set_resource_permissions
Pro · Destructive
DESTRUCTIVE: set resource permissions.
grafana_set_resource_permissions_for_built_in_role
Pro · Write
Set resource permissions for a built-in role.
grafana_set_resource_permissions_for_team
Pro · Write
Set resource permissions for a team.
grafana_set_resource_permissions_for_user
Pro · Write
Set resource permissions for a user.

Role assignments

ToolWhat it does
grafana_add_team_role
Pro · Write
Add team role.
grafana_add_user_role
Pro · Write
Add a user role assignment.
grafana_list_team_roles
Free · Read-only
Get team roles.
grafana_list_teams_roles
Free · Read-only
List roles assigned to multiple teams.
grafana_list_user_roles
Free · Read-only
List roles assigned to a user.
grafana_list_users_roles
Free · Read-only
List roles assigned to multiple users.
grafana_remove_team_role
Pro · Destructive
DESTRUCTIVE: remove team role.
grafana_remove_user_role
Pro · Destructive
DESTRUCTIVE: remove a user role assignment.
grafana_set_team_roles
Pro · Destructive
DESTRUCTIVE: update team role.
grafana_set_user_roles
Pro · Destructive
DESTRUCTIVE: set user role assignments.

Roles

ToolWhat it does
grafana_create_role
Pro · Write
Create a new custom role.
grafana_delete_role
Pro · Destructive
DESTRUCTIVE: delete a custom role.
grafana_get_access_control_status
Free · Read-only
Get status.
grafana_get_role
Free · Read-only
Get a role.
grafana_get_role_assignments
Free · Read-only
Get role assignments.
grafana_list_roles
Free · Read-only
Get all roles.
grafana_set_role_assignments
Pro · Destructive
DESTRUCTIVE: set role assignments.
grafana_update_role
Pro · Write
Update a custom role.

Reporting

ToolWhat it does
grafana_create_report
Pro · Write
Create a report.
grafana_delete_report
Pro · Destructive
DESTRUCTIVE: delete a report.
grafana_get_report
Free · Read-only
Get a report.
grafana_get_report_branding_image
Pro · Read-only
Download a branding image stored for reports - the logo that appears on a rendered report or in the email that carries it.
grafana_get_report_settings
Free · Read-only
Get report settings.
grafana_get_reports
Free · Read-only
List reports.
grafana_get_reports_by_dashboard_uid
Free · Read-only
List reports by dashboard uid.
grafana_render_report_csvs
Pro · Read-only
Render the table panels of one or more dashboards as CSV and get a download link back.
grafana_render_report_pdfs
Pro · Read-only
Render one or more dashboards as a PDF report and get a download link back.
grafana_save_report_settings
Pro · Write
Save settings.
grafana_send_report
Pro · Write
Send a report.
grafana_send_test_email
Pro · Write
Send test report via email.
grafana_update_report
Pro · Write
Update a report.

Anonymous devices

ToolWhat it does
grafana_list_anonymous_devices
Free · Read-only
List the devices that viewed this Grafana WITHOUT signing in, over the last 30 days.
grafana_search_anonymous_devices
Free · Read-only
Search the anonymous devices that viewed this Grafana in the last 30 days.

Instance health

ToolWhat it does
grafana_get_health
Free · Read-only
Read the instance's health - its version, commit and whether its own database is reachable.

Instance settings

ToolWhat it does
grafana_admin_get_settings
Free · Read-only
Fetch settings.
grafana_admin_get_stats
Free · Read-only
Fetch Grafana Stats.
grafana_retrieve_jwks
Free · Read-only
Read the instance's JSON Web Key Set - the PUBLIC keys anything verifying a Grafana-minted token needs.

Instance users

ToolWhat it does
grafana_admin_create_user
Pro · Destructive
DESTRUCTIVE: create new user.
grafana_admin_delete_user
Pro · Destructive
DESTRUCTIVE: delete a Grafana user outright.
grafana_admin_disable_user
Pro · Destructive
DESTRUCTIVE: disable user.
grafana_admin_enable_user
Pro · Destructive
DESTRUCTIVE: enable user.
grafana_admin_get_user_auth_tokens
Free · Read-only
Return a list of all auth tokens (devices) that the user currently have logged in from.
grafana_admin_logout_user
Pro · Destructive
DESTRUCTIVE: logout user revokes all auth tokens (devices) for the user.
grafana_admin_revoke_user_auth_token
Pro · Destructive
DESTRUCTIVE: revoke auth token for user.
grafana_admin_update_user_password
Pro · Destructive
DESTRUCTIVE: set password for user.
grafana_admin_update_user_permissions
Pro · Destructive
DESTRUCTIVE: set permissions for user.

LDAP

ToolWhat it does
grafana_get_ldap_status
Free · Read-only
Attempts to connect to all the configured LDAP servers and returns information on whenever they're available or not.
grafana_get_sync_status
Free · Read-only
Returns the current state of the LDAP background sync integration.
grafana_get_user_from_ldap
Free · Read-only
Finds an user based on a username in LDAP.
grafana_post_sync_user_with_ldap
Pro · Destructive
DESTRUCTIVE: enables a single Grafana user to be synchronized against LDAP.
grafana_reload_ldap_cfg
Pro · Destructive
DESTRUCTIVE: reloads the LDAP configuration.

Provisioning reload

ToolWhat it does
grafana_admin_provisioning_reload_access_control
Pro · Destructive
DESTRUCTIVE: you need to have a permission with action `provisioning:reload` with scope `provisioners:accesscontrol`.
grafana_admin_provisioning_reload_dashboards
Pro · Destructive
DESTRUCTIVE: reload dashboard provisioning configurations.
grafana_admin_provisioning_reload_datasources
Pro · Destructive
DESTRUCTIVE: reload datasource provisioning configurations.
grafana_admin_provisioning_reload_plugins
Pro · Destructive
DESTRUCTIVE: reload plugin provisioning configurations.

SSO settings

ToolWhat it does
grafana_get_provider_settings
Free · Read-only
Get an SSO Settings entry by Key.
grafana_get_saml_metadata
Free · Read-only
Read this Grafana's SAML service-provider metadata - the XML an identity provider needs to trust it.
grafana_list_all_providers_settings
Free · Read-only
List all SSO Settings entries.
grafana_patch_provider_settings
Pro · Write
Patch SSO Settings.
grafana_remove_provider_settings
Pro · Destructive
DESTRUCTIVE: remove SSO Settings.
grafana_update_provider_settings
Pro · Write
Update SSO Settings.

Cloud migration

ToolWhat it does
grafana_cancel_cloud_migration_snapshot
Pro · Write
Cancel a migration snapshot wherever it is in its processing chain.
grafana_create_cloud_migration_session
Pro · Write
Start a Grafana Cloud migration session on this instance.
grafana_create_cloud_migration_snapshot
Pro · Write
Take a snapshot of this instance's migratable content for a migration session.
grafana_create_cloud_migration_token
Pro · Destructive
DESTRUCTIVE: mint a Grafana Cloud access token on this instance.
grafana_delete_cloud_migration_session
Pro · Destructive
DESTRUCTIVE: delete a Grafana Cloud migration session.
grafana_delete_cloud_migration_token
Pro · Destructive
DESTRUCTIVE: revoke a Grafana Cloud migration token.
grafana_get_cloud_migration_dependencies
Free · Read-only
Read the dependency graph of everything this instance could migrate to Grafana Cloud.
grafana_get_cloud_migration_session
Free · Read-only
Read one Grafana Cloud migration session by its uid.
grafana_get_cloud_migration_sessions
Free · Read-only
List the Grafana Cloud migration sessions on this instance.
grafana_get_cloud_migration_snapshot
Free · Read-only
Read one migration snapshot - where it is in its processing chain and what it found.
grafana_get_cloud_migration_snapshots
Free · Read-only
List the snapshots taken under one migration session.
grafana_get_cloud_migration_token
Free · Read-only
Read the Grafana Cloud migration token stored on this instance, if one exists.
grafana_upload_cloud_migration_snapshot
Pro · Destructive
DESTRUCTIVE: send a snapshot of this Grafana to Grafana Cloud.

Licensing

ToolWhat it does
grafana_delete_license_token
Pro · Destructive
DESTRUCTIVE: remove the Enterprise license from this Grafana's database.
grafana_get_custom_permissions_csv
Free · Read-only
Read the custom permissions report as a CSV file's worth of text.
grafana_get_custom_permissions_report
Free · Read-only
Read the custom permissions report - where role-based access control permissions on this instance differ from Grafana's built-in roles.
grafana_get_license_status
Free · Read-only
Check whether this Grafana has a valid Enterprise license and what it allows.
grafana_get_license_token
Free · Read-only
Read the Enterprise license token installed on this Grafana.
grafana_post_license_token
Pro · Destructive
DESTRUCTIVE: install an Enterprise license token on this Grafana.
grafana_post_renew_license_token
Pro · Destructive
DESTRUCTIVE: force this Grafana to renew its Enterprise license token now.
grafana_refresh_license_stats
Free · Write
Refresh and read this instance's license usage statistics - the seat and user counts Grafana measures an Enterprise license against.

Query history

ToolWhat it does
grafana_add_query_to_history
Pro · Write
Save a query into the signed-in user's query history.
grafana_delete_query_history_entry
Pro · Destructive
DESTRUCTIVE: delete a saved query from query history.
grafana_patch_query_comment
Pro · Write
Change the comment on a saved query in query history.
grafana_search_queries
Free · Read-only
Search the signed-in user's query history - the queries run against data sources, with their comments and stars.
grafana_star_query
Pro · Write
Star a saved query in query history so it can be found with the onlyStarred filter.
grafana_unstar_query
Pro · Destructive
DESTRUCTIVE: remove the star from a saved query in query history.