Explore documentation
MCP server
Connect AI assistants to your Incidents and Telemetry data through the Model Context Protocol.
Getting started
If this is your first time working with MCP servers, check out our MCP explained guide to understand the basics.
Step 1: Install the MCP server
The Better Stack MCP server runs as a remote HTTP server. Add one of the following configurations to your MCP client:
OAuth (recommended)
If your client supports OAuth, use this minimal configuration and sign in through the browser when prompted:
If you're using Claude Code, install the Better Stack plugin:
API token
For clients that support HTTP servers but not OAuth, pass your API token via the Authorization header:
Proxy (mcp-remote)
If your MCP client doesn't support remote HTTP servers, you can use the mcp-remote proxy instead:
Claude web, desktop, and mobile apps
- In Claude, go to Customize → Plugins → Discover.
- Search for Better Stack and click Add.
- On the plugin's Connectors tab, click Connect and sign in with Better Stack.
Claude Tag in Slack
An admin sets it up once in an Access bundle at claude.ai/admin-settings/claude-tag
- On the bundle's Plugins tab, turn on Better Stack.
- On the Credentials tab, click Connect next to Custom tool and choose Bearer.
- Paste a Better Stack API token and set Allowed websites to
mcp.betterstack.com. - In a covered channel, ask
@Claude list open Better Stack incidents and the errors from the last hour.
Step 2: Test your connection
Your AI assistant can now access Better Stack data. Try these:
- "Show me the current status of all monitors"
- "What's the availability of my website monitor?"
- "What incidents occurred yesterday?"
- "What metrics are available for my source?"
- "Build an explore query to find HTTP 500 errors"
- "Create a dashboard showing error rates for my API service"
- "Who has access to my team?"
Limiting available tools
By default, the Better Stack MCP server exposes all available tools to your AI assistant. You can restrict which tools are available by passing a custom header in your MCP configuration.
X-MCP-Tools-Only: Allowlist - only the specified tools will be availableX-MCP-Tools-Except: Blocklist - all tools except the specified ones will be available
Include only specific tools
Exclude specific tools
This is useful when you want to give your AI assistant read-only access, limit it to a specific workflow, or reduce the initial context size when you only need a subset of tools.
Documentation tools
Your AI assistant can search Better Stack documentation and pull relevant articles directly into the conversation:
Search documentation: Searches Better Stack documentation and returns the contents of relevant articles
Example queries
- "How do I forward logs from Kubernetes to Better Stack?"
- "Look up the Better Stack docs for the Terraform provider"
Incidents tools
Your AI assistant can manage monitoring infrastructure and incidents through natural language. Ask questions like:
- "Show me all monitors that are currently down"
- "What's the availability of my website this month?"
- "Create an incident for the payment service outage"
- "Who's on-call right now?"
- "Acknowledge incident #1234 and add a comment about the fix"
On-call scheduling and alerting
Find who's on-call and understand escalation policies.
On-call scheduling
Get on-call details: Shows who's on-call for a calendar, right now or at a given timeList on-call calendars: Provides information about on-call calendars and rotationsList on-call events: Lists upcoming shifts and schedule changesGet on-call event details: Fetches details for specific on-call eventsGet on-call rotation details: Explains how rotations are configured
Example queries
- "Who's on-call right now?"
- "Show me the on-call schedule for next week"
- "What are the rotation details for our main on-call calendar?"
Escalation policies
Get available incident escalation policies: Shows available escalation targets for incidentsList escalation policies: Lists configured escalation rules and stepsGet escalation policy details: Provides detailed policy informationList severities: Shows incident severity levels and configurationsGet severity details: Explains specific severity settings
Example queries
- "Show me escalation options for incident #5678"
- "List all escalation policies and their steps"
- "What are the notification settings for critical severity incidents?"
Incidents
Create, manage, and collaborate on incidents from start to resolution.
Create incident: Reports new issues with context and metadataList incidents: Finds incidents by date, status, monitor, or other criteriaGet incident details: Shows full incident information including error messages and screenshotsGet incident timeline: Displays complete incident historyGet incident comments: Retrieves incident commentsCreate incident comment: Adds team collaboration commentsAcknowledge incident: Takes ownership of incidents to stop escalationsEscalate incident: Routes incidents to users, teams, schedules, or policiesResolve incident: Marks incidents as fixedReopen incident: Reopens a resolved incident within 24 hours of resolution
Example queries
- "List all unacknowledged incidents from today"
- "Create an incident for the payment service outage with high severity"
- "Acknowledge incident #1234 and add a comment about the database fix"
- "Show me the timeline for the last critical incident"
- "Reopen incident #1234, the issue is happening again"
Monitoring
Check service health through monitors and heartbeats.
Monitors
List monitors: Shows all monitors with filtering optionsGet monitor details: Provides monitor configuration, status, and settingsCreate monitor: Creates a new monitor to track the availability of a website, host, or serviceGet monitor availability: Calculates SLA summaries and uptime percentagesGet monitor response times: Analyzes performance metrics and trends
Example queries
- "Show me all monitors that are currently down"
- "What's the availability of my website monitor this month?"
- "List monitors with response times above 5 seconds"
- "Create a monitor for https://example.com and check it every 30 seconds"
Heartbeats
List heartbeats: Shows all heartbeat monitors and their statusGet heartbeat details: Provides heartbeat configuration and recent activityCreate heartbeat: Creates a new heartbeat that alerts when a cron job or background task stops reportingGet heartbeat availability: Tracks uptime for scheduled tasks
Example queries
- "List all heartbeats that are currently down"
- "Show me the status of my database backup heartbeat"
- "What's the uptime of my daily cleanup job this week?"
- "Create a heartbeat for my nightly database backup job"
Status pages
Communicate service status and maintenance to users.
List status pages: Shows all your status pagesGet status page details: Provides status page configuration and current statusUpdate status page: Updates status page settings like company name, theme, layout, or custom domainGet status page resources: Lists monitors and heartbeats displayed on each pageAdd status page resource: Adds a monitor, heartbeat, or group to a status pageUpdate status page resource: Changes a resource's public name, description, widget type, or placementRemove status page resource: Removes a resource from a status pageGet status page sections: Lists the sections of a status pageCreate status page section: Creates a section to group status page resources under a headingUpdate status page section: Renames a section or moves it to a new positionRemove status page section: Removes a section and its resources from a status pageCreate status page report: Creates incident reports or maintenance announcementsCreate status page report update: Adds updates to ongoing reportsList status page reports: Shows status reports for a specific pageList status page report updates: Lists updates for a specific reportGet status page report update details: Provides details for specific updates
Example queries
- "Show me all status pages and their current status"
- "Create a status page report for scheduled database maintenance tomorrow"
- "List all recent reports on our main status page"
- "Update the maintenance report with completion status"
- "Add my API monitor to the status page under a new 'Core services' section"
- "Switch my status page to the dark theme"
Telemetry tools
Your AI assistant can analyze logs, query metrics, and manage observability infrastructure through natural language. Ask questions like:
- "Show me all error logs from the past hour"
- "Create a new log source for my Node.js application"
- "What metrics are available for my production source?"
- "Build a query to find HTTP 500 errors in my API logs"
- "Get field details for my application logs"
Query your logs, traces, errors & metrics
You can execute ClickHouse queries directly against your Better Stack data. Use the instruction tools (Get query instructions, Get metric query instructions, Get errors query instructions, Get replays query instructions) to learn how to write queries for each data type, then run them with Execute query.
Execute query: Executes a ClickHouse SQL query against your telemetry data, including logs, spans, metrics, exceptions, and replaysRender chart: Executes a ClickHouse SQL query and renders the result as a line, bar, or pie chart, useful for visualizing trends over time directly in the conversationPlan query windows: Estimates how many rows a long-range query reads and, when it's too much for one call, splits the time range into windows to run one by one
Example queries
- "Run a query to get the top 10 error messages from today"
- "Execute this ClickHouse query against my production logs"
- "Query my metrics source for average response times over the last hour"
- "Run a query to find exception counts grouped by release version"
- "Show me a chart of error rates per minute for the last 24 hours"
- "Visualize HTTP 500 error counts over time as a chart"
- "Count errors per service over the last 30 days"
Sources
Manage log sources and explore data structure.
Source management
List sources: Shows all log sources with status and configurationGet source details: Provides detailed source configuration and settingsCreate source: Creates new log sources with integration guidesGet source fields: Discovers available fields for querying logs and spans
Example queries
- "List all my log sources and their current status"
- "Create a new Docker log source in the US East region"
- "Show me all available fields for my application source"
- "Get details for source #1234 including ingestion settings"
Dashboards
Manage and interact with your observability dashboards.
Dashboard management
List dashboards: Lists all dashboards with their ID, name, creation, and update datesList dashboard groups: Lists the groups your dashboards are organized into and how many dashboards each one holdsGet dashboard details: Shows detailed dashboard information including charts, sections, layout, and configurationList dashboard templates: Lists all available dashboard templates, including ID, name, description, and platformCreate dashboard: Creates a new dashboard, optionally from a template or with a specific sourceConfigure dashboard: Updates a dashboard's name or source eligibilitySet dashboard variable: Creates or updates a dashboard variable, a filter in the dashboard toolbar referenced as{{name}}in chart queriesRemove dashboard variable: Removes a dashboard variable by nameExport dashboard: Exports a dashboard's full configuration, including charts, sections, and settings, as JSONImport dashboard: Imports a new dashboard from a JSON configuration, creating a new dashboard with the provided data structureRemove dashboard: Permanently removes a dashboard and all its associated charts
Example queries
- "List all my dashboards"
- "Show me the details for dashboard #1234"
- "Create a new dashboard from the Nginx template in the Production group"
- "Rename dashboard #1234 to 'Production Overview'"
- "Add a host dropdown variable to dashboard #1234"
- "Export dashboard #1234 as JSON"
- "Import a new dashboard using the provided JSON data"
- "Remove dashboard #5678"
Charts
Get chart details: Shows chart configuration, SQL queries, and settingsGet chart building instructions: Provides guidance on chart types, units, axis settings, and best practicesGet dashboard query instructions: Provides instructions for writing ClickHouse queries used inside dashboard chartsAdd chart to dashboard: Adds a new chart with a SQL query to a dashboardConfigure chart: Updates a chart's name, type, query, or settingsRemove chart: Permanently removes a chart from its dashboardAdd dashboard section: Adds a section divider to organize charts into groupsConfigure dashboard section: Updates a section's title, description, or collapsed stateRemove dashboard section: Removes a section divider from a dashboardMove charts: Rearranges chart positions on the dashboard grid
Example queries
- "Show me the details for chart #456 on my dashboard"
- "What chart types and settings are available?"
- "Add a line chart showing error rates per minute to dashboard #1234"
- "Change chart #456 to a bar chart"
- "Remove chart #789 from the dashboard"
- "Add a 'Performance Metrics' section to dashboard #1234"
- "Move chart #456 to the top-left position"
Alerts
List chart alerts: Lists chart alerts with their ID, name, chart, and statusGet chart alert details: Shows configuration of a specific alert including its configuration, SQL queries, and current incident infoGet chart alert instructions: Provides instructions for creating and configuring chart alerts, including alert types and operatorsCreate chart alert: Creates a new alert on an existing chart with support for threshold, relative, and anomaly detection alert typesConfigure chart alert: Updates an existing chart alert's configurationRemove chart alert: Permanently removes a chart alertPause or resume chart alert: Pauses or unpauses a chart alert
Example queries
- "List all chart alerts on my Nginx dashboard"
- "Create a threshold alert on my CPU usage chart that triggers when it exceeds 90%"
- "Change the confirmation period on alert #1234 to 5 minutes"
- "Delete the traffic drop alert, we no longer need it"
Explorations
Inspect and adjust explorations, your saved Explore queries.
List explorations: Lists saved explorations with their ID, name, chart type, sources, and groupGet exploration details: Shows an exploration's sources, chart type, variables, saved time range, and querySet exploration variable: Creates or updates an exploration variable, most often to change which sources the exploration queriesRemove exploration variable: Removes an exploration variable by name
Example queries
- "List my saved explorations"
- "Point the checkout errors exploration at my staging source"
- "Remove the region variable from exploration #1234"
Logs & spans
Query and explore logs and distributed traces.
Query building
Get query instructions: Provides instructions for building logs and spans queries to run directly via the query toolsGet explore logs query instructions: Provides instructions for writing queries for the Explore logs page and live-tail charts
Example queries
- "Build a query to find all ERROR level logs from my API service"
- "Show me how to query logs with response times above 1 second"
- "Find all HTTP 500 errors in the last 24 hours"
Metrics
Build dashboards and analyze performance trends.
Metrics catalog
Get metrics schema: Shows available metrics with data points and series countGet metric details: Explains how to query and use specific metrics with examplesGet metric query instructions: Provides instructions for building metrics queries to run directly via the query tools
Example queries
- "Show me all available metrics for my production source"
- "Get details for the response_time metric including example queries"
- "Build a dashboard query for average CPU usage over time"
- "What aggregation functions are available for memory metrics?"
Metric expressions
Extract metrics and labels from your logs.
List metric expressions: Lists the extract-metrics-from-logs rules on a sourceCreate metric expression: Creates a new metric or label extracted from log fieldsUpdate metric expression: Updates an existing metric expression's name, SQL expression, type, or aggregationsRemove metric expression: Deletes a metric expression from a source
Example queries
- "Extract the HTTP status code from my logs as a metric"
- "List all metric expressions on my production source"
- "Change the request_duration metric to also track the average"
Infrastructure
Manage data regions, clusters, and secure connections.
Data regions and clusters
List data regions: Shows available regions for storing dataList clusters: Lists storage clusters for direct data accessList teams: Shows teams with telemetry platform access
Cloud connections
Create cloud connection: Creates temporary credentials for direct ClickHouse access
Example queries
- "List all available data regions for creating a new source"
- "Show me storage clusters in the Europe region"
- "Create a cloud connection for direct access to my logs data"
- "What teams have access to the telemetry platform?"
Error tools
Your AI assistant can manage error tracking applications, analyze exceptions, and query error data through natural language. Ask questions like:
- "Show me all error tracking applications"
- "Create a new Python error tracking application"
- "What errors occurred in production this week?"
- "Show me all releases for my application"
- "Build a query to find the most frequent exceptions"
Applications
Manage error tracking applications and their configuration.
Application management
List applications: Shows all error tracking applications with status and configurationGet application details: Provides detailed configuration, ingestion settings, and available data tablesCreate application: Creates new error tracking applications with platform-specific integration guidesEdit application: Renames an application, pauses or resumes ingestion, or sets its VRL transformations, including the exception grouping program
Example queries
- "List all my error tracking applications"
- "Create a new JavaScript application for error tracking in the US East region"
- "Get details for application #1234 including the DSN and collection names"
- "Show me all applications that are currently paused"
- "Pause ingestion for application #1234"
Releases
Track application releases and their error patterns.
List releases: Shows all releases for an application with first and last seen timestampsCreate release: Registers a release so it appears as soon as it deploys, before its first error arrivesRemove release: Permanently removes a release. A release that still receives errors is detected again with its next event
Example queries
- "Show me all releases for my production application"
- "List releases deployed in the last week"
- "What environments is release v2.1.0 running in?"
- "Register release v2.2.0 in production for my API application"
- "Remove release v2.0.0-rc1, it was never deployed"
Error details and management
View detailed error information and manage error states for triage and resolution tracking.
List errors: Lists error patterns for an application with occurrence counts, affected users, and current state. Supports filtering by state, release, environment, or time rangeGet error details: Shows comprehensive error information including type, message, call site, first occurrence, and current state (unhandled, unresolved, ignored, resolved, or reoccurred)Update error state: Changes error state to mark errors as resolved, ignored, or unresolved with optional notification settingsLink error to issue: Links an error to an existing Linear issue or Jira work item, then posts every error state change as a comment on it. Accepts a Linear identifier, a Jira key, or the issue URLCreate issue for error: Creates a Linear issue or Jira work item for an error through the team's integration and links the two, using Better Stack's standard issue body and the integration's configured defaultsUnlink error from issue: Removes the link between an error and a Linear, Jira, or GitLab issue, leaving the issue itself untouchedGet error comments: Reads the conversation on an error, including comments left in Better Stack, replies in the error's Slack thread, and comments synced from a linked Linear issueCreate error comment: Posts a comment on an error, marked as posted via MCP. When the error is linked to a Linear issue that syncs comments, the comment is posted there too
Example queries
- "List all unresolved errors from the last 3 days in production"
- "Get details for error pattern abc123 in application #1234"
- "Show me the current state and call site information for this error"
- "Mark error pattern xyz789 as resolved"
- "Ignore error pattern abc123 for the next 100 occurrences"
- "Mark this error as unresolved and notify on every exception"
- "Create a Linear issue for error pattern abc123 in application #1234"
- "Link error pattern abc123 to ENG-4242"
- "Unlink PROJ-45 from this error"
- "Summarize what the team has said about error pattern abc123"
- "Add a comment to this error with the root cause you found"
Replays
Query session replay data linked to errors and user sessions.
Get replays query instructions: Provides instructions for querying session replay data, including data structure, fields, and query patterns for finding replays linked to errors or specific users
Example queries
- "Show me how to query session replays for my application"
- "Find replays linked to error pattern abc123"
- "Get instructions for finding replays from a specific user"
Error queries
Build and execute ClickHouse queries to analyze error patterns and individual exceptions.
Query building
Get errors query instructions: Provides comprehensive documentation for querying error data including the two-layer architecture (errors and exceptions), available columns, query patterns, and best practices
Example queries
- "Show me how to query error patterns for my application"
- "Get instructions for building queries to analyze individual exception occurrences"
- "What's the difference between the metrics and exceptions sources?"
- "How do I query errors by release version?"
Team management tools
Your AI assistant can audit who has access to your teams and manage members and their roles:
List team members: Shows members of a team, including pending invitations, with each member's e-mail, name, and roleList organization roles: Lists the roles in your organization with their IDs, including custom rolesInvite team member: Invites someone to a team by e-mail address with an optional roleChange team member role: Changes an existing team member's roleRemove team member: Removes a member from a team or cancels a pending invitation
Example queries
- "Who has access to my team?"
- "Invite jane@example.com to the SRE team as a responder"
- "Change John's role to team lead"
- "Remove bob@example.com from the team"
- "Cancel the pending invitation for alex@example.com"
Next steps 🚀
- Get started with Uptime monitoring to set up monitors and alerting that your AI assistant can manage.
- Explore Telemetry to build comprehensive observability with your AI assistant analyzing your data.
Have any questions?
Please feel free to message us at hello@betterstack.com. We'll get back to you as soon as we can, typically within a few hours. 🙏 Thank you!