The Grafana connector.
Dashboards, datasources and alert rules. Connect once with your own key. Every agent your team runs reads the same 5 tools under one permission model.
How access is governed
5
Read tools
Open by default. They run when called, and every call is logged with the endpoint, tool and capability.
0
Write tools
Grafana exposes no write tools. Nothing it does mutates external state.
0
Destructive tools
Grafana defines no destructive tools. Nothing here deletes data.
Defaults come from the capability on each tool definition, and an admin can tighten or open any tool individually. The endpoint's capability ceiling can only tighten that policy. An endpoint scoped to read never surfaces a write tool.
Every Grafana tool
5 tools, named as the agent sees them.
- search_dashboardsread
Search dashboards by title or tag. Start here: the `uid` each hit returns is what get_dashboard takes. Narrow to a folder with a `folderUID` from list_folders.
- get_dashboardread
Get one dashboard by UID: its metadata plus a panel-by-panel summary (id, type, title). Takes a `uid` from search_dashboards. Use it to see what a dashboard actually measures without pulling the whole JSON model.
- list_datasourcesread
List the datasources configured on this Grafana (Prometheus, Loki, Postgres, CloudWatch, and so on). Use it to see where a dashboard's data actually comes from; the returned `uid` is what dashboard panels and alert rules reference.
- list_alert_rulesread
List the Grafana-managed alert rules, with their folder, rule group, pending period and paused state. Use it to audit alerting coverage or to find the rule behind an alert. Filter by folder using a `folderUID` from list_folders.
- list_foldersread
List dashboard folders. Use it to get the `uid` that search_dashboards and list_alert_rules take as `folderUID`.
Use it from any agent
The same Grafana tools reach Claude Code, Cursor, Claude Desktop or your own agent through one MCP endpoint. The endpoint is scoped to a group, the token is issued per group and revocable from the dashboard, and an allowed-tool list and capability ceiling limit what it exposes. Reads run. Gated writes refuse unless an admin opens them. Destructive tools remain unavailable over MCP.
{
"mcpServers": {
"growth": {
"type": "http",
"url": "https://app.notara.ai/mcp/g/acme/growth",
"headers": {
"Authorization": "Bearer ntr_mcp_xxxxxxxxxxxxxxxxxxxx"
}
}
}
}The URL and token are placeholders. Real endpoints are issued per group from the dashboard.
Setup
- 01
Create a Grafana Service Account Token in your Grafana account (where to find it). The key is yours: Notara stores it encrypted and never sees a bill.
- 02
Paste it into the Notara dashboard. Credentials can be scoped to the workspace or to one person.
- 03
The tools appear with their capability defaults already set. Tighten or open any of them per tool, then invite the agent to a channel or issue an MCP token.
Connect Grafana once. Use it everywhere.
Use Notara directly, or bring us the workflow that needs to be redesigned and built.
