Best of · Developer & infrastructure
Best observability and incident tools for AI agents
All 7 ranked observability and incident tools on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change.
- 7 ranked
- 2 agent-ready
- 6 hosted endpoints
- Updated 9 October 2026
Top three
Picks by need
Worked out from the scores, prices and facts, so they change when the research does.
Schema & documentation
88/100 on schema & documentation, against 81 for the overall leader.
Transparency & trust
Sentry MCP BB
81/100 on transparency & trust, against 79 for the overall leader.
The shortlist
| # | Tool | Grade | Best for | Price | Where |
|---|---|---|---|---|---|
| 1 | Grafana MCP Server Grafana Labs |
BB 74.5 | Teams on Grafana, self-managed or Cloud, that want an agent to read dashboards and query Prometheus, Loki, Tempo and Pyroscope, and to work with alert rules, incidents and OnCall. | Free · OSS | local |
| 2 | Sentry MCP Sentry |
BB 70.2 | Coding agents that triage and fix production errors from Sentry. datadog-mcp covers wider observability data, pagerduty-mcp on-call and incidents. | Your plan | hosted and local |
| 3 | incident.io API Pineapple Technology Ltd. (incident.io) |
B 68.9 | Agents that declare and update incidents, page people, read on-call schedules and post status page incidents in an organisation that already pays for incident.io. | $19 / seat-mo | hosted |
| 4 | Rootly MCP Server Rootly Inc. |
C 59.7 | Incident and on-call agents in teams that already run Rootly. | $20 / seat-mo | hosted and local |
| 5 | Honeycomb MCP Honeycomb |
C 58.3 | Agents that investigate latency and error spikes in a team already sending traces and events to Honeycomb, and that record findings as Boards, Triggers or SLOs. | Your plan | hosted |
| 6 | Datadog MCP Server Datadog |
C 56.6 | Agents that triage production issues across metrics, logs, traces and monitors in a Datadog org. sentry-mcp is narrower and deeper on errors, pagerduty-mcp covers on-call. | Your plan | hosted and local |
| 7 | PagerDuty MCP Server PagerDuty |
D 48.4 | Incident and on-call agents in PagerDuty shops. | Your plan | hosted |
How to choose
- Signal coverage and on-call dataCheck which of errors, metrics, logs, traces and on-call data the tool exposes, since an agent debugging an incident can only reason over the signals it can query.
- Idempotency of incident writesCheck whether incident and on-call writes are idempotent, because an agent that retries after a timeout could otherwise open duplicate incidents or page the same person twice.
- Limits on large time rangesCheck the rate limits and pagination on log and metric queries, since an agent scanning a long time range can hit a limit and miss data.
- Freshness of returned stateCheck how current returned metrics and incident states are and whether responses report the time they were last changed, so an agent does not reason from stale state.
Each one in detail
Grafana MCP Server
BB 74.5/100Grafana Labs' open-source MCP server for Grafana. It runs locally or self-hosted and gives agents dashboards, datasource queries (Prometheus, Loki, Tempo, Pyroscope and others), alerting, incidents and OnCall on a self-managed Grafana or Grafana Cloud.
Verdict Every default tool declares typed inputs and read-only and destructive annotations in source, and --disable-write cuts the default 79 tools to 62. Writes and a general grafana_api_request tool are on by default, the default list is long at 79 tools, and usage statistics have been sent to Grafana Labs by default since 2.0.0.
Choose it for Teams on Grafana, self-managed or Cloud, that want an agent to read dashboards and query Prometheus, Loki, Tempo and Pyroscope, and to work with alert rules, incidents and OnCall.
Strengths
- All 79 default tools in 2.0.2 build typed JSON Schema inputs from Go parameter structs and set
readOnlyHintanddestructiveHint, and 73 also setidempotentHint, read from source at tag v2.0.2 --disable-write,--disable-query, per-category flags and Loki enforced matchers narrow what the server can do, with a per-tool table of required RBAC permissions- 17 tagged releases between 13 July and 7 October 2026, with a Keep a Changelog file that labels breaking changes
Weaknesses
- The default set is 79 tools, and 119 with every category on, counted from the registration code in source
- Write tools and
grafana_api_request, which can call any Grafana API path, are enabled unless the operator turns them off - Anonymous usage statistics went from off by default in 1.5.0 (17 September 2026) to on by default in 2.0.0
Price Free · OSSAuth OAuth or keyx402 nolocal
Sentry MCP
BB 70.2/100Sentry's MCP for searching errors and traces, triaging issues, reading docs and managing projects, with agent-embedded natural-language search tools.
Verdict OAuth with skills chosen at consent, Inspect and Seer (read-only) by default. No MCP component on status.sentry.io and no SLA.
Choose it for Coding agents that triage and fix production errors from Sentry. datadog-mcp covers wider observability data, pagerduty-mcp on-call and incidents.
Strengths
- OAuth with skills chosen at consent, Inspect and Seer (read-only) by default
- Nine top-level tools with on-demand loading of 59 more, plus org and project scoping in the URL
- Descriptions with usage guidance, examples and hints, and typed errors with recovery advice
Weaknesses
- No MCP component on status.sentry.io and no SLA
- The upstream Sentry token always holds project, team, event and alert write scopes
execute_sentry_toolwraps every catalogue tool, which breaks per-tool approval (issue #1254)
Price Your planAuth OAuthx402 nohosted and local
incident.io API
B 68.9/100incident.io is an incident response, on-call, alerting and status page service. Agents reach it through a REST API at api.incident.io with an OpenAPI description and seven SDKs, a hosted MCP server and the inc CLI.
Verdict The REST API has a public OpenAPI description with 284 operations, numeric rate limits, Retry-After on 429 and required idempotency keys on seven create calls. API and MCP access need the Team plan or higher, so the free Basic plan cannot be used by an agent, and audit logs are Enterprise only.
Choose it for Agents that declare and update incidents, page people, read on-call schedules and post status page incidents in an organisation that already pays for incident.io.
Strengths
- OpenAPI 3.0.3 description with 284 operations, per-resource description files, llms.txt and Markdown twins of every docs page
- API keys carry chosen permissions, 13 of the 36 scopable to named teams, and user keys take the owner's role
- Default limit of 1,200 requests a minute per key,
X-RateLimit-*headers on every response andRetry-Afteron 429
Weaknesses
- The pricing page marks API, webhooks and MCP as not included in the free Basic plan. Team starts at $19 per user a month
- Audit logs are Enterprise only and reach the customer by CSV export or log stream, with no API to read them
- Alert event and heartbeat endpoints accept the alert source token in a
tokenquery parameter
Price $19 / seat-moAuth OAuth or keyx402 nohosted
Rootly MCP Server
C 59.7/100Rootly's MCP server for its incident management and on-call platform. Agents list, search and update incidents, alerts, schedules and escalation policies through a hosted endpoint at mcp.rootly.com with OAuth or an API key, or run the Apache-2.0 package themselves.
Verdict The server is open source under Apache-2.0, ships a dated release about every two weeks, and has a slim profile and a Code Mode endpoint that cut the 218-tool list. Hosted connections expose write tools by default, and the 2.3.21 changelog records telemetry changes that broke tool calls for clients with cached schemas in late September 2026.
Choose it for Incident and on-call agents in teams that already run Rootly.
Strengths
- Apache-2.0 source for the same server Rootly hosts, with six dated releases between 23 July and 5 October 2026
- A slim profile of about 70 tools and a Code Mode endpoint with five meta-tools reduce the full list of about 218
- Every tool sets
readOnlyHint,destructiveHintandopenWorldHintsince 2.3.19 of 9 September 2026
Weaknesses
- Hosted connections expose write tools by default, and the docs describe the read-only switch only for servers the owner runs
- The 2.3.21 changelog records two hosted regressions in late September 2026, one failing fifteen tools for clients with cached schemas and one failing every tool call
- Hosted telemetry records tool arguments and responses through AgentCat per the README. AgentCat isn't named on Rootly's subprocessor list
Price $20 / seat-moAuth OAuth or keyx402 nohosted and local
Honeycomb MCP
C 58.3/100Honeycomb's hosted MCP server lets AI agents query a team's traces, metrics and events, run BubbleUp analysis, and create or update Boards, Triggers and SLOs. It uses OAuth or a Management API key and has US and EU endpoints.
Verdict OAuth with mcp:read and mcp:write scopes keeps the 34 tools read-only until write access is granted, and per-tool rate limits are published. Tool input schemas are visible only after sign-in, and no injection guidance was found for telemetry content. The product changelogs disallow unnamed crawlers, so release history went unread.
Choose it for Agents that investigate latency and error spikes in a team already sending traces and events to Honeycomb, and that record findings as Boards, Triggers or SLOs.
Strengths
- OAuth with PKCE, dynamic client registration and two scopes. Write tools need
mcp:write, granted at consent or on the API key - Per-tool rate limits are published, from 10 calls a minute for
get_service_mapto 300 for semantic-convention lookups - Listed in the official MCP registry as
io.honeycomb/mcp1.0.0, under the vendor's own domain namespace
Weaknesses
- Tool input schemas and annotations are visible only through
tools/listafter sign-in. The public reference gives descriptions, not parameters - No guidance on prompt injection was found, although trace and log content returned to the agent is untrusted text
- The status page has no MCP component. US1 queries over older data failed for 67 minutes on 10 August 2026
Price Your planAuth OAuth or keyx402 nohosted
Datadog MCP Server
C 56.6/100Datadog's hosted MCP server for querying monitors, logs, metrics, traces, dashboards, incidents and more, with 30-plus toolsets, a sandboxed code-execution toolset, OAuth 2.0 or key auth, and per-call permission checks on writes.
Verdict OAuth read-only grants, mcp_read and mcp_write permissions and an organisation-level block on MCP writes. Tools and parameters are removed the day they're announced, with no notice period.
Choose it for Agents that triage production issues across metrics, logs, traces and monitors in a Datadog org. sentry-mcp is narrower and deeper on errors, pagerduty-mcp covers on-call.
Strengths
- OAuth read-only grants,
mcp_readandmcp_writepermissions and an organisation-level block on MCP writes - Toolsets, a sandboxed
execute_codetoolset andwhoamiandtoolsetsresources keep the schema in proportion - Dated public changelog with 42 entries since 3 July 2026
Weaknesses
- Tools and parameters are removed the day they're announced, with no notice period
- Not in the official MCP registry and no MCP component on the status page
- Tool schemas and descriptions aren't readable without an account
Price Your planAuth OAuth or keyx402 nohosted and local
PagerDuty MCP Server
D 48.4/100PagerDuty's hosted MCP server at mcp.pagerduty.com (EU at mcp.eu.pagerduty.com) for incidents, services, schedules, on-call, escalation policies, alerts and analytics, with OAuth or API-key auth.
Verdict Scoped OAuth with per-resource scopes and mandatory PKCE, or an API key in a header. No read-only mode on the hosted server, where the local one was read-only by default.
Choose it for Incident and on-call agents in PagerDuty shops.
Strengths
- Scoped OAuth with per-resource scopes and mandatory PKCE, or an API key in a header
- US and EU endpoints documented
- REST limits published at 960 requests a minute with ratelimit-reset headers
Weaknesses
- No read-only mode on the hosted server, where the local one was read-only by default
- Hosted tool list, schemas and changelog aren't published
- No native tool filtering, so the full list loads whatever the OAuth scopes allow
Price Your planAuth OAuth or keyx402 nohosted
Head to head
- Grafana MCP Server vs Sentry MCP BB 74.5 vs BB 70.2
- Grafana MCP Server vs incident.io API BB 74.5 vs B 68.9
- Grafana MCP Server vs Rootly MCP Server BB 74.5 vs C 59.7
- Grafana MCP Server vs Honeycomb MCP BB 74.5 vs C 58.3
- Honeycomb MCP vs Sentry MCP C 58.3 vs BB 70.2
- incident.io API vs Rootly MCP Server B 68.9 vs C 59.7
Questions
What are the highest-rated observability and incident tools for AI agents?
Grafana MCP Server has the highest benchmark score of the 7 ranked observability and incident tools, 74.5 (BB). Sentry MCP is second with 70.2 (BB).
How many observability and incident tools are agent-ready?
2 of the 7 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.
Which observability and incident tools accept x402 payments?
None of the ranked listings here accepts x402 for its main call yet.
How is this list ranked?
By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 9 October 2026.
How this list is made
The order is the Anchor benchmark score, the same number as on each listing and in the top list. Each listing is graded from public evidence against the benchmark checklist, and the picks above are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.
Full ranked table · 15 head-to-head comparisons · Best tools in every category