Connections are added inside an Access bundle. At
claude.ai/admin-settings/claude-tag, open Access bundles in the left navigation, click into a bundle (or Create one), and go to its Credentials tab.Create the credential in Datadog
Create an API key under a service account in Datadog. Also create an Application key under the same service account. The Application key carries the read scopes, so restrict it to read-only roles. The form doesn’t require the Application key, but reading metrics, monitors, and dashboards does. Datadog’s own guide for creating the credential is at docs.datadoghq.com.Add the connection to a bundle
In the bundle, click Connect next to Datadog. The picker has one Datadog entry per Datadog site. Datadog has a separate API host per site, and a key only works against its own, so pick the entry that matches your Datadog account’s site.
The form asks for the same fields in every entry.
The connection is created with path prefixes that cover Datadog’s read and query routes: metric, log, trace, and RUM queries, monitors, downtimes, dashboards, SLOs, notebooks, events, hosts, service definitions, and incident search. It doesn’t cover Datadog’s key, user, integration, or log-configuration management routes, so Claude can’t call those through it. To narrow the connection further, for example to
GET only, or to allow another route, select Edit on the connection’s row; see Restrict by path or method.
The Agent Proxy injects the credential at the network boundary; the model and the sandbox are not given the key. See how Agent Proxy works.
Verify the connection
In a channel under the bundle’s scope, in a new thread:Related resources
- What this connection adds: the monitoring use cases
- Give Claude access: the full credential-type and allowed-hosts reference