Overview
What Grafana MCP Server does
Grafana's MCP server spans dashboards, Prometheus and Loki queries, alerting, incidents, OnCall, Sift, navigation, and related observability workflows. Users can self-host the open-source server against Grafana Cloud or a managed Grafana instance, or use Grafana Cloud's hosted OAuth service. Tool categories and writes can be disabled so the exposed surface matches an operational role.
Best for
- Investigating metrics and logs alongside application code
- Summarizing dashboards without returning their full JSON
- Assisted alert, incident, and on-call workflows
Not ideal for
- Grafana deployments older than version 9 for full datasource support
- Production agents with broadly privileged service accounts
- Replacing alerting policy, runbooks, or human incident command
Capabilities
What an agent can do
- 01
Dashboard search, summaries, and updates
- 02
Prometheus metrics and Loki log queries
- 03
Datasource and alert-rule inspection
- 04
Incident, OnCall, and Sift workflows
- 05
Grafana resource deeplinks
- 06
Read-only and category-level tool controls
Representative tools and operations
search_dashboardsget_dashboard_summaryquery_prometheusquery_loki_logslist_alert_rulescreate_incidentlist_oncall_schedulesgenerate_deeplink
Installation
Connect Grafana MCP Server
Use the publisher’s current instructions as the source of truth. The examples below were checked on .
Claude DesktopLaunch with uvx
uvx mcp-grafana
{"command":"uvx","args":["mcp-grafana"],"env":{"GRAFANA_URL":"https://myinstance.grafana.net","GRAFANA_SERVICE_ACCOUNT_TOKEN":"${GRAFANA_SERVICE_ACCOUNT_TOKEN}"}}
Generic MCP clientRun the Docker image over stdio
docker run --rm -i -e GRAFANA_URL -e GRAFANA_SERVICE_ACCOUNT_TOKEN grafana/mcp-grafana -t stdio
Set the two environment variables outside committed client configuration.
Trust and access
Authentication and security notes
Authentication: Self-hosted mode recommends a Grafana service-account token and supports username/password. Grafana Cloud's hosted MCP service uses OAuth 2.1 scoped to the signed-in user.
Review before connecting
- Grant the service account only the RBAC actions and resource scopes needed by enabled tools.
- Combine --disable-write with a read-only service account for investigation-only workflows.
- Secure HTTP transports with TLS and bind them to an appropriate interface.
- Limit returned log volume and treat log text as untrusted data.
Known limitations
- Grafana 9 or newer is required for full functionality.
- Large dashboards can consume substantial model context; prefer summary or property tools.
- Some Incident and Sift operations use broader built-in roles rather than fine-grained RBAC.
Evidence
Sources used for this guide
Facts were checked against primary publisher material. Descriptions and guidance are original Graphify summaries.
FAQ
Questions about Grafana MCP Server
Can Grafana MCP be read-only?
Yes. Disable write tools and use credentials whose Grafana RBAC permissions are also read-only.
Does it work with self-managed Grafana?
Yes. Run the open-source server and point GRAFANA_URL at a compatible Grafana 9+ instance.