# Rootly MCP Server (slim) > Rootly's MCP server for its incident management and on-call platform. Agents list, search and update incidents, alerts, schedules and escalation policies through a hosted endpoint at mcp.rootly.com with OAuth or an API key, or run the Apache-2.0 package themselves. - Full: https://www.anchorterminal.com/tools/rootly-mcp.md (~8,050 tokens) · this version ~1,780 tokens · JSON https://www.anchorterminal.com/tools/rootly-mcp.json · canonical https://www.anchorterminal.com/tools/rootly-mcp - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-10 **C · 59.7/100 · rank #541 of 950 · #4 in Observability & incidents · not agent-ready · confidence medium** Assessment: The server is open source under Apache-2.0, ships a dated release about every two weeks, and has a slim profile and a Code Mode endpoint that cut the 218-tool list. Hosted connections expose write tools by default, and the 2.3.21 changelog records telemetry changes that broke tool calls for clients with cached schemas in late September 2026. ## Facts - Kind: MCP server · vendor: Rootly Inc. · category: Observability & incidents · legal entity: Rootly Inc. · provenance 95/100 - Endpoint: `https://mcp.rootly.com/mcp` (Streamable HTTP, SSE (legacy), stdio) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Apache-2.0 for the server. The hosted service runs under Rootly's Terms of Use - Probe metrics: not measured yet (probes haven't run) - Endpoints: `https://mcp.rootly.com/mcp` (streamable HTTP), `https://mcp.rootly.com/sse` and `https://mcp.rootly.com/mcp-codemode`. An unauthenticated `initialize` answers 401 with an OAuth resource metadata header - Tools: About 218 on the default endpoint and about 70 on the slim profile per the README at v2.3.21. Curated tools cover incidents, on-call, alerts and audits, and the rest are generated from Rootly's OpenAPI description - Code Mode: Five meta-tools (`list_tools`, `tool_search`, `get_schema`, `tags`, `execute`). The model writes a short async Python block that chains tool calls on the server. The README calls it experimental and the docs recommend it - Writes: Create and update tools are on by default. `ROOTLY_MCP_ENABLE_WRITE_TOOLS=false` or `--no-enable-write-tools` makes a server the owner runs read-only. Deletes are off by default - Credentials: OAuth 2 with dynamic client registration, PKCE, one-hour tokens and rotating refresh tokens, or a bearer API key (global with a role, team, or personal) - Rate limits: REST API limits of 3,000 reads and 3,000 writes a minute per API key and 50 alert creations a minute, with X-RateLimit headers. No limit specific to the MCP endpoint was found - Annotations: `readOnlyHint`, `destructiveHint` and `openWorldHint` on every tool since 2.3.19, with `idempotentHint` on writes - Telemetry: Hosted deployments send tool-call telemetry to AgentCat, with credential scrubbing and an optional Sentry export. PostHog analytics is opt-in and off wherever AgentCat is active - Local server: Python 3.12 or later, run with `uvx --from rootly-mcp-server rootly-mcp-server` and `ROOTLY_API_TOKEN`. A Dockerfile is in the repository - Releases: v2.3.21 on 5 October 2026. Six dated releases between 23 July and 5 October 2026, under semantic versioning - Security programme: security.txt valid to 1 September 2027, a disclosure policy with safe harbour that names the MCP server in scope, no paid bounty, and SOC 2 Type II stated on the pricing page - Subprocessors: About 30 listed with purpose, data and location, nearly all in the United States, with AWS as primary hosting. AgentCat isn't on the list - Prices: Essentials plan, incident response $20 per seat per month; Essentials plan, on-call $20 per seat per month - Scores: Reliability 48, Performance pending, Schema & documentation 78, Agent ergonomics 77, Security & auth 65, Payments & pricing 20, Task success pending, Maintenance & community 81, Transparency & trust 80 · negative events -3 · total over the 7 assessed categories - Why: Reliability, Scored as a hosted MCP server, the path the docs recommend. · Schema & documentation, Read from the source at v2.3.21. Curated tools declare typed pydantic inputs and the rest are generated from Rootly's OpenAPI 3.0.1 descript… · Agent ergonomics, The default endpoint lists about 218 tools per the README, which the checklist scores at 5. A slim profile (77 names in the source, about 70… · Security & auth, OAuth 2 with dynamic client registration, PKCE with S256, one-hour access tokens, rotating refresh tokens, a revocation endpoint and `:read`… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, v2.3.21 was tagged on 5 October 2026, four days before this check (30). · Transparency & trust, The server is Apache-2.0 and the hosted service runs under Rootly's Terms of Use of July 2026 (27). - Sources: 19, open questions: 12, both in the full twin - Capabilities: observability.incidents, work.oncall - JSON: https://www.anchorterminal.com/api/v1/tools/rootly-mcp.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/rootly-mcp.svg` or a link to https://www.anchorterminal.com/tools/rootly-mcp from a page on rootly.com or one of its subdomains, or the README of github.com/rootlyhq/rootly-mcp-server, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Connect to `https://mcp.rootly.com/mcp-codemode` or add `?tool_profile=slim` to `/mcp`. The default endpoint loads about 218 tool definitions 2. Connect Code Mode in place of the classic endpoint, not beside it. The docs say models skip `execute` when both are present 3. Use a Global API key for `get_oncall_handoff_summary` and `get_oncall_shift_metrics`. Team and personal keys return partial results 4. Refetch the tool list after a server release. Curated tools reject undeclared arguments, which failed calls from cached schemas in September 2026 5. Treat a 404 from a generated tool as a possible plan limit or missing parent record, and read the hint in the response ## Connect ```bash uvx --from rootly-mcp-server rootly-mcp-server ``` ```bash claude mcp add --transport http rootly https://mcp.rootly.com/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/rootly-mcp ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Grafana MCP Server | BB | 74.5 | observability.incidents, work.oncall | https://www.anchorterminal.com/tools/grafana-mcp-server.min.md | | incident.io API | B | 68.9 | observability.incidents, work.oncall | https://www.anchorterminal.com/tools/incident-io.min.md | | PagerDuty MCP Server | D | 48.4 | observability.incidents, work.oncall | https://www.anchorterminal.com/tools/pagerduty-mcp.min.md | | Datadog MCP Server | C | 56.6 | observability.incidents | https://www.anchorterminal.com/tools/datadog-mcp.min.md | | Sentry MCP | BB | 70.2 | same category | https://www.anchorterminal.com/tools/sentry-mcp.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)