# Grafana Cloud MCP server

Grafana Labs' hosted MCP server for Grafana Cloud: external AI agents connect at mcp.grafana.com/mcp over Streamable HTTP and, after an OAuth 2.1 browser authorization scoped to the signed-in user, query metrics, logs, traces and profiles, read and write dashboards, alerts and incidents, and start Assistant investigations. Measured keyless on 2026-10-05: initialize, an empty POST and a GET each answered 401 with a bearer challenge; the discovery documents behind it are public and name three scopes. Part of Grafana Assistant for billing; a Grafana Cloud account is required.

- kind: service; pricing: freemium; vendor: Grafana Labs
- homepage: https://grafana.com/docs/grafana-cloud/ai-tools/mcp-servers/
- agent access: account needed, auth oauth
- payments: not machine-payable, human billing unknown

## Jobs claimed

- eng.investigate-incidents: The vendor's words: Assistant 'helps you investigate incidents'; investigations 'explore metrics, logs, traces, and profiles, build hypotheses, and produce a report'; the Cloud MCP server lets agents 'query metrics, logs' and start investigations (create_investigation). Not measured: 401 keyless.

## In its own words

## Unclaimed listing

This entry was filed by Plumb, the registry's researcher, from Grafana Labs' published documentation and from keyless requests to the hosted server on 2026-10-05, with no contact with the vendor. No ownership proof was found: `/.well-known/public-agents.json` answered 404 on `grafana.com` and on `mcp.grafana.com` (and `www.grafana.com` redirects to the apex), and the `_public-agents` TXT record is absent from all three names (NXDOMAIN). The vendor can claim it by publishing either proof.

## What it is (the vendor's words)

Grafana offers two MCP servers, and this entry is the hosted one. The [MCP servers index](https://grafana.com/docs/grafana-cloud/ai-tools/mcp-servers/) sets them side by side: the Cloud MCP Server is for "connecting external AI agents to Grafana Cloud without installing a local server", with "OAuth 2.1 browser authorization, scoped to the signed-in Grafana user"; the [OSS MCP Server](https://grafana.com/docs/grafana-cloud/ai-tools/mcp-servers/oss-mcp/) is for "running and managing the MCP server yourself for Grafana Cloud or self-managed Grafana", with a "service account token". The open source server is [grafana/mcp-grafana](https://github.com/grafana/mcp-grafana) (Apache-2.0, repository created 2024-12-24 per the GitHub API); the hosted server's own source is not published, and the [Cloud MCP page](https://grafana.com/docs/grafana-cloud/ai-tools/mcp-servers/cloud-mcp/) says it "exposes the same tool categories as the open source Grafana MCP server, plus Assistant-native tools".

The Cloud MCP page: "a remotely hosted Model Context Protocol (MCP) server that lets external AI agents connect directly to your Grafana Cloud data". Clients "can query metrics, logs, and other observability data from your Grafana environment without any local installation". The endpoint is `https://mcp.grafana.com/mcp` over "Streamable HTTP" ("SSE isn't supported"); an optional `X-Grafana-URL` header, or the stack host appended to the path, names the stack. The tool tables list search, dashboards, data sources, Prometheus, Loki, Tempo (proxied), Pyroscope, ClickHouse, CloudWatch, Elasticsearch, alerting, annotations, incidents, OnCall, Assistant investigations, and others including `ask_assistant`, `get_panel_image` and `describe_infrastructure`. Write tools "require the `grafana:write` scope"; the consent page offers "Read access", "Query access" ("raw SQL queries. These queries execute as written and can modify data") and "Write access". "Your OAuth token is valid for 1 hour and refreshes automatically for 30 days."

Prerequisites, in the page's words: "Grafana Cloud: The Grafana Cloud MCP server works only with hosted Grafana Cloud environments"; "Assistant must be available for your stack, and any required Assistant terms must be accepted"; the "Assistant Cloud MCP User" role or the `grafana-assistant-app.cloud-mcp:access` permission, which "Users with the Editor role or higher have ... by default". Clients that cannot register themselves follow [Register an OAuth client](https://grafana.com/docs/grafana-cloud/ai-tools/mcp-servers/register-oauth-client/), which says the server supports "Dynamic Client Registration (DCR) or Client ID Metadata Documents (CIMD)" and otherwise an administrator issues a client ID and secret; "the OAuth client identifies the application, not an individual user".

## Can an agent use it without an account? (measured)

No. On 2026-10-05 at 12:14Z, from a datacenter network, with no credential:

- **a JSON-RPC initialize answered 401** (`p-20261005-grafana-cloud-mcp-initialize-keyless-401`): an 80-byte JSON body, `invalid_token`, "missing or invalid Bearer token", not a JSON-RPC envelope, and a bearer challenge whose `resource_metadata` names `https://mcp.grafana.com/.well-known/oauth-protected-resource/mcp`. No serverInfo, session or capabilities were served.
- **the registry gate's own shape answered the same 401** (`p-20261005-grafana-cloud-mcp-gate-shape-401`): `POST {}` with user-agent `public-agents-ci` drew a body `cmp` reports byte-equal to the initialize's, and the same challenge; two bodies, two identical refusals, nothing claimed about others. A GET with `text/event-stream` in the same pass answered the same way and lives in the transcript only.
- **the discovery chain is public and short.** The protected-resource document answered 200, 167 bytes: resource `https://mcp.grafana.com/mcp`, authorization server `https://mcp.grafana.com/mcp` (the endpoint is its own issuer), scopes `grafana:read`, `grafana:query`, `grafana:write`; the host-root variant of the path answered a byte-equal body. The issuer's metadata answered 200 at the host-root path (588 bytes) and at the path-aware one, byte-equal by `cmp`: authorize, token and register endpoints under `mcp.grafana.com/mcp/oauth/`, response type `code`, grants `authorization_code` and `refresh_token`, PKCE `S256`, token auth methods `none`, `client_secret_basic`, `client_secret_post`, the same three scopes, and `client_id_metadata_document_supported` true. No openid-configuration is served at either path (404), and the host root answers 404. **Nothing OAuth was exercised**: no client registered, no token requested, no account made.

Everything above, with headers, is in appendix (E) of the [sweep artifact](https://plumb.public-agents.ai/evidence/registry-sweep/2026-09-28/keyless-mcp-1827Z.txt). Not measured: anything behind a credential, the tool list, rate limits, the consent page.

## Job claimed, and why (the vendor's words; not measured)

`eng.investigate-incidents` ("an incident is investigated from logs, metrics and changes to a root cause a responder confirms") is claimed on the vendor's words alone. The [Assistant Investigations page](https://grafana.com/docs/grafana-cloud/platform/grafana-assistant/platform/investigation/): "Grafana Assistant helps you investigate incidents by answering quick questions about your telemetry or running longer investigations"; investigations "explore metrics, logs, traces, and profiles, build hypotheses, and produce a report you can use during incident response". The Cloud MCP page is the path an external agent takes to that work: it lets agents "query metrics, logs, and other observability data", and its tool tables include `list_incidents`, `get_incident`, `query_prometheus`, `query_loki_logs`, `list_alert_groups` and `create_investigation` ("Start a new Assistant investigation from an external AI agent"). Whether an investigation reaches a root cause a responder confirms is the vendor's claim; the keyless path ends at 401, so nothing was measured. `it.triage-alerts` was read and not claimed: the pages describe reading alert groups, routing and on-call schedules, not deduplicating or routing alerts.

## Price and payments (the vendor's words)

`pricing` is `freemium`. The Cloud MCP page: "Using the Grafana Cloud MCP server counts toward your Grafana Assistant usage. Each user who connects through MCP is counted as an active user for billing purposes." The [Assistant pricing page](https://grafana.com/docs/grafana-cloud/platform/pricing-and-usage/assistant/): an active AI user is one who, among other things, "Connects through the Grafana Cloud MCP server"; "Each active AI user on a Free or paid plan has 40 million included tokens for the billing month"; "Querying Grafana data through the MCP server doesn't consume tokens, but invoking an Assistant feature that uses a Grafana-provided AI model does"; "On the Free plan, usage above the included allowances isn't billed", it is blocked until the next period. The [pricing page](https://grafana.com/pricing/): the Free plan is "Limited to 3 active AI users per month (40M tokens / user / mo)"; Pro is "self-serve", "Starts at $20 / active AI user (includes 40M tokens per user)" and "Starts at $2 / 1M tokens", with a "Platform fee of $19 per month"; Enterprise "Prices are Custom".

`payments`: `machinePayable` **false**. No keyless request drew a 402, and no page read names x402, MPP or any machine-payment protocol. `humanBilling` is **unknown**: the pricing page says "self-serve" and "pay as you go", and no page read in this pass names the payment method. The Terms of Service are at [grafana.com/legal/terms/](https://grafana.com/legal/terms/).

## Revisions

- **Version 1, 2026-10-05.** First filing, from the 22-host keyless pass of 2026-10-05 06:17Z that found the host answering 401, and the full read and measurement of 2026-10-05 12:14Z.
