Grafana logoClaude logo
Grafana · Claude

Connect Grafana to Claude. For your whole team.

The official Grafana MCP runs with one service account token, org-wide, and its README recommends the Editor role. Loopthink holds a Viewer token, gives every Claude user in your team their own login, and lets SRE, Developers and Management query the dashboards, alerts and logs their role allows.

Free for your own server · Team from €99 · EU-hosted

The problem

Grafana in a chat client, today.

Today a team that wants Grafana in an AI client creates one service account token and passes it around. Even a Viewer token can query every data source in the organisation, so a chat can pull production logs with IP addresses in them. If the token was Editor, as the official server suggests, a chat can also silence alerts, and Grafana logs the service account, not the person.

Who may do what

One matrix for Grafana. Roles across, tools down.

ToolSREDevelopersManagement
Dashboards SRE may use DashboardsDevelopers may use DashboardsManagement may use Dashboards
Data source queries SRE may use Data source queriesDevelopers may use Data source queriesManagement may not use Data source queries
Alerts & incidents SRE may use Alerts & incidentsDevelopers may use Alerts & incidentsManagement may use Alerts & incidents
Logs (Loki) SRE may use Logs (Loki)Developers may use Logs (Loki)Management may not use Logs (Loki)
OnCall schedule SRE may use OnCall scheduleDevelopers may not use OnCall scheduleManagement may not use OnCall schedule
Write actions off by defaultSRE may not use Write actionsDevelopers may not use Write actionsManagement may not use Write actions

Masked for every role: IP addresses in log lines, user emails in annotations, contact point addresses.

You set this once. Every Claude user in your team gets exactly this.

How to connect

Once on the Grafana side, once in Claude.

Grafana logo

On the Grafana side

Service account token, Viewer role

  1. 1

    Grafana → Administration → Users and access → Service accounts → Add service account. Role: Viewer.

  2. 2

    Open the account → Add service account token. Set an expiration date; Loopthink tells you before it runs out.

  3. 3

    Paste the token and your Grafana URL into Loopthink. Nobody on the team handles it again.

Claude logo

In Claude

Custom connector, OAuth

  1. 1

    An Owner opens Organization settings → Connectors → Add and pastes your Loopthink connector URL. On Free, Pro and Max: Customize → Connectors → + → Add custom connector.

  2. 2

    Each team member opens Customize → Connectors, clicks Connect on Loopthink and signs in once with their own account.

  3. 3

    In a chat, the + menu lists the connector. Toggle it on, ask away. No key, no config file.

Custom connectors are available on Free, Pro, Max, Team and Enterprise. On Team and Enterprise only Owners can add one; every member still connects individually, which is exactly what gives each call its own identity.

Steps checked against the vendor documentation on 17 September 2026: Service accounts · Data source permissions · Grafana MCP server · Get started with custom connectors using remote MCP · Use connectors to extend Claude's capabilities

Loopthink sits in between: it holds the key, shows Claude a normal login, and applies your roles on every call.

What you get

Four checks between Claude and Grafana.

  1. 01

    Identify

    OIDC/SSO against your own IdP, including Microsoft Entra. The call runs as the person who made it, never as a shared service account.

  2. 02

    Authorize

    Per-role, per-tool, read or write. Anything not explicitly granted never shows up in the tool list in the first place.

  3. 03

    Mask

    Field-level masking and pseudonymization applied on your side, before the result travels. The model never sees the raw field. Composio, AnythingMCP and both provider tunnels have no field-level masking at all.

  4. 04

    Log

    Who asked, which tool, which records, which fields were masked. One audit trail across every AI client, exportable for review.

Use cases

What people actually ask Claude about Grafana.

  • SRE

    “Which alerts fired in the last 24 hours, and are any of them still firing?”

  • Developers

    “Show me the p95 latency of checkout-api over the last seven days.”

  • Management

    “Uptime of the customer portal this month, against the 99.9 target?”

Each question runs as the person who asked it, with that person's role. A Developers colleague asking the SRE question gets the tools their own role allows, not an error, not more.

Compare

Four ways to put Grafana into Claude.

Native Grafana connectorBuild it yourselfEnterprise gateways1Loopthink
Per-user identityOne personal login, all its rightsOnly if you build itYesYes, every call runs as the person who asked
Tool-level rolesNoYour codeYesYes, write off by default
Field maskingNoYour codeNot documentedYes, before the model sees the data
Published priceIncluded in your Grafana planYour engineers' timeContact salesFree, Team from €99
EU companyNoWhatever you areMostly USYes, Germany

Native Grafana connector: Official Grafana MCP server with one service account token. Org-wide Viewer or Editor, shared by everyone who copies the config.

1 MintMCP, MCP Manager, Pomerium

Coming from one of them? Composio alternative · MintMCP alternative · MCP Manager alternative · AnythingMCP alternative

FAQ

Before you connect.

Does every team member need their own Grafana account?
No. Loopthink holds one key or token for Grafana. Your people sign in to Loopthink with their own identity, and every call to Grafana is logged under their name. Seats in Grafana stay where they are today.
Who has to add the connector in Claude?
One person with the right to add connectors in your Claude workspace, once. After that every team member enables it for themselves. Nobody pastes a key, nobody edits a config file.
Where does the Grafana key live?
In Loopthink, encrypted, in the EU. It never reaches Claude and never reaches the people using the connector. Rotate it in Grafana whenever you like and paste the new one once.
Can somebody write to Grafana from the chat?
Not unless you switch it on. Write actions are a separate row in the permission matrix and are off for every role by default. If a role needs one write tool, you grant that one tool to that one role.
What does the model see?
The result of the tool call, after masking. Fields you mark as personal, such as emails, names or card details, are masked before the answer travels to Claude. The model gets the numbers, not the people.
Is there an audit trail?
Yes. Who asked, which tool, which parameters, which fields were masked, when. One log across every client your team uses, exportable for review.
What does it cost?
Free for one person and your own MCP server, forever. Team starts at €99 per month and covers the built connector, per-person identity, roles, masking and audit for the whole team. Prices are on the pricing page, no call needed.
We already run our own MCP server for Grafana. Does it still work?
Yes. Point it at Loopthink and it inherits the same login, roles, masking and audit. Nothing on the server has to change.

Grafana in Claude, with rules.

One key in Loopthink, one login per person, one matrix that decides who may do what.

Free for your own server · Team from €99 · EU-hosted