Skip to content

Blog

Grafana MCP setup: dashboards and read access

Start with a known dashboard. Check the instance, permissions and data source before running broader queries.

Published on · by tracevero · Reading time 3 minutes (554 words)

A useful first test answers one small question: can this connection read the dashboard you prepared? Record its UID, folder and expected data source. A request to inspect the whole environment makes troubleshooting harder because account access, query scope and expected output are all uncertain. This guide provides a configuration and a test plan to carry out in your own environment.

Prepare the instance and service account

Grafana documents a local server launched with uvx mcp-grafana. Set the instance address in GRAFANA_URL and pass the token through GRAFANA_SERVICE_ACCOUNT_TOKEN. Use a dedicated service account with appropriate permissions. Its token inherits those permissions. Check the expiry and organisation before placing a configuration in a shared project.

VS Code example with write tools disabled

Replace the instance address and merge this configuration into .vscode/mcp.json. The client prompts for the token. Install uv first and check that VS Code can find uvx. The --disable-write flag removes write tools. It does not replace restricted account permissions. The exact tools available also depend on the server version you run.

{
  "servers": {
    "grafana": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "mcp-grafana",
        "--disable-write"
      ],
      "env": {
        "GRAFANA_URL": "https://YOUR_STACK.grafana.net",
        "GRAFANA_SERVICE_ACCOUNT_TOKEN": "${input:grafana-token}"
      }
    }
  },
  "inputs": [
    {
      "id": "grafana-token",
      "type": "promptString",
      "description": "Grafana service account token",
      "password": true
    }
  ]
}

The VS Code guide explains file selection and startup. When editing an existing file, merge the server entry into its current structure instead of appending another root object. Record the package version after a successful test so that a later failure can be compared against both configuration and server changes.

From dashboard to the intended data source

Three choices for a reproducible request 1. Instance Check organisation 2. Dashboard Select the UID 3. Data source Limit the time range
Suggested checks for your own environment.
  1. Open the prepared dashboard directly in Grafana. Record its UID, data source and a fixed time range containing an expected value.

  2. Start the MCP server and inspect the tool list. Retrieve details for the known dashboard before running a data query.

  3. Compare the UID and data source against your notes. Query only the prepared time range if your permissions allow it.

  4. Record the time range, time zone and output. Repeat that same request after changing the token or server version.

Locate the failing step

Choose the next check
ObservationNext step
Server does not startCheck the uvx path and process log.
Dashboard is missingCheck organisation, UID and folder permissions.
Dashboard loads without dataCheck the data source, query permissions and time range.

A dashboard title alone does not establish that you reached the right environment. Use its UID and compare a known value. For empty time series, check the time range before widening permissions. Use the permission planner to define scope and the troubleshooting navigator to separate startup and connection problems. The Grafana registry search provides further entries.

Does --disable-write make the token read-only?
No. It limits the exposed tools. Check the token permissions on its service account separately.
What goes in GRAFANA_URL?
Your own Grafana instance address, such as your Cloud stack URL. Replace the placeholder in the example.
Why does a dashboard show no data?
Check the data source, permissions, time range and time zone separately. Reading dashboard metadata does not prove that a data query succeeded.
Has this guide tested my account?
No. It uses vendor documentation. You need to perform the proposed first request in your own environment.

Vendor documentation checked on 2 October 2026. No authenticated account test.

  1. Grafana: MCP server
    Show retrieval commandcurl -s https://github.com/grafana/mcp-grafana
  2. Grafana: Service accounts
    Show retrieval commandcurl -s https://grafana.com/docs/grafana/latest/administration/service-accounts/

Put it into practice

All posts

tracevero · https://tracevero.com/blog/grafana-mcp-setup