Skip to main content

MCP tool reference

All 74 tools across 13 toolsets with parameters, and which are read versus write.

The /mcp endpoint is on by default and exposes the tools from n9e-mcp-server. This page is the full list.

How to connect and authenticate is in Enable the MCP endpoint; the permission boundary is in Permission inheritance.

Two switches​

[HTTP.A2A]
# read-only tools are registered by default; write tools (create/update/delete) are an opt-in
MCPEnableWriteTools = false
# empty = all default toolsets; unknown names are ignored, so the list never widens by accident
# MCPToolsets = ["alerts", "dashboards"]

Tools marked "write" below are not registered at all under the default configuration. That is deliberate: an MCP client holds exactly its token owner's permissions, so enabling write tools lets a model genuinely change your alerting configuration.

The list​

74 tools across 13 toolsets, 32 of them write tools.

Write tools are not registered by default — set MCPEnableWriteTools = true under [HTTP.A2A] to expose them.

alert_subscribes​

Alert subscription management tools for event handling

ToolAccessWhat it does
list_alert_subscribesreadList alert subscriptions for a business group
list_alert_subscribes_by_gidsreadList alert subscriptions across multiple business groups
get_alert_subscribereadGet details of a specific alert subscription by ID

This toolset is read-only.

alerts​

Alert management tools for viewing and managing alerts

ToolAccessWhat it does
list_active_alertsreadList active alert events with optional filters. Use this to view currently firing alerts.
get_active_alertreadGet details of a specific active alert event by ID
list_history_alertsreadList historical alert events with optional filters
get_history_alertreadGet details of a specific historical alert event by ID
list_alert_rulesreadList alert rules for a business group
get_alert_rulereadGet details of a specific alert rule by ID
create_alert_rulewriteCreate a new alert rule in a business group. Pass the full rule body in 'rule' (mirror the structure returned by get_alert_rule, omit id/create_at/update_at).
update_alert_rulewriteUpdate an existing alert rule. Pass the full rule body (typically: get_alert_rule, modify fields, then submit).
import_alert_ruleswriteBulk import alert rules into a business group from a JSON array (matches the n9e import format).
import_prom_ruleswriteImport Prometheus alerting rules (YAML or JSON) into a business group. Wraps n9e's /alert-rules/import-prom-rule endpoint.
clone_alert_rules_to_bgswriteClone the given alert rules into one or more target business groups.
toggle_alert_ruleswriteEnable or disable a batch of alert rules. Uses n9e's PUT .../alert-rules/fields with {disabled:0|1}.

busi_groups​

Business group management tools

ToolAccessWhat it does
list_busi_groupsreadList all business groups that the current user has access to

This toolset is read-only.

dashboards​

Dashboard (board) management: list/get/create/update/clone

ToolAccessWhat it does
list_dashboardsreadList dashboards. Pass group_id for a single business group, or gids (comma-separated) to query multiple.
get_dashboardreadGet a dashboard's metadata by ID. Use get_dashboard_pure if you also need the panel configs.
get_dashboard_purereadGet a dashboard including its full panel JSON. Uses an extended response size cap (64MB) — large boards return their entire layout.
create_dashboardwriteCreate a new dashboard inside a business group.
update_dashboard_metawriteUpdate a dashboard's name and tags (PUT /board/{bid}). Use update_dashboard_panels to change the panel JSON.
update_dashboard_panelswriteReplace a dashboard's panel JSON (PUT /board/{bid}/configs). 'configs' must be a JSON string.
set_dashboard_publicwriteToggle a dashboard's public visibility (PUT /board/{bid}/public).
clone_dashboardwriteClone a dashboard into the same business group (POST /busi-group/{gid}/board/{bid}/clone).

datasource​

Datasource management tools (Prometheus/VictoriaMetrics/Loki/ES/...)

ToolAccessWhat it does
list_datasourcesreadList all available datasources (sanitized brief view — no auth secrets)
list_datasources_fullreadList datasources with full configuration including auth (admin perspective). Pass an optional filter body matching n9e's /datasource/list payload.
get_datasourcereadGet full configuration of a single datasource by ID (POST /datasource/desc).
list_datasource_pluginsreadList supported datasource plugin types (Prometheus, Loki, ES, Tencent CLS, ...).
upsert_datasourcewriteCreate or update a datasource. n9e runs a connectivity check as part of upsert — a successful response implies the datasource is reachable. Omit 'id' to create.
set_datasource_statuswriteEnable or disable one or more datasources (POST /datasource/status/update).

event_pipelines​

Event pipeline/workflow management tools for event processing

ToolAccessWhat it does
list_event_pipelinesreadList all event pipelines/workflows that the current user has access to
get_event_pipelinereadGet details of a specific event pipeline/workflow by ID
list_event_pipeline_executionsreadList execution records for a specific event pipeline
list_all_event_pipeline_executionsreadList all event pipeline execution records across all pipelines
get_event_pipeline_executionreadGet details of a specific pipeline execution by execution ID

This toolset is read-only.

logs​

Logs query tools (Loki/Elasticsearch/OpenSearch) via n9e logs-query

ToolAccessWhat it does
query_logsreadQuery logs from a datasource (Loki/ES/OS) via n9e's plugin-dispatched /logs-query endpoint. Pass 'body' as the n9e query payload (must include datasource_id and the engine-specific query). Time range > 7 days is rejected.
list_log_indicesreadList indices for an Elasticsearch (default) or OpenSearch datasource. Body must include datasource_id.
list_log_fieldsreadList fields for an Elasticsearch (default) or OpenSearch index. Body must include datasource_id and the index name.

This toolset is read-only.

metrics​

Metrics query tools (PromQL instant/range) via n9e query APIs

ToolAccessWhat it does
query_instantreadRun a PromQL instant query against a Prometheus-compatible datasource. Returns the result series array (each item: metric labels + [timestamp, value]).
query_rangereadRun a PromQL range query against a Prometheus-compatible datasource. The 'step' is auto-adjusted upward when the result would exceed max_points (default 1000) per series, and 'truncated' is set in the response.

This toolset is read-only.

mutes​

Alert mute/silence management tools

ToolAccessWhat it does
list_mutesreadList alert mutes/silences for a business group
get_mutereadGet details of a specific alert mute by ID
create_mutewriteCreate a new alert mute/silence rule. Use mute_time_type=0 for time range mode (btime/etime), or mute_time_type=1 for periodic mode (periodic_mutes).
update_mutewriteUpdate an existing alert mute/silence rule

notify_rules​

Notification rule, channel and template management

ToolAccessWhat it does
list_notify_rulesreadList all notification rules that the current user has access to
get_notify_rulereadGet details of a specific notification rule by ID
list_notify_channelsreadList all notification channel configurations (full payload — admin perspective)
get_notify_channelreadGet a single notification channel configuration by ID
list_notify_templatesreadList all notification templates
create_notify_ruleswriteCreate one or more notification rules (n9e endpoint accepts an array)
update_notify_rulewriteUpdate an existing notification rule by ID
test_notify_rulewriteSend a test notification using the supplied notify-rule body without persisting it.
create_notify_channelwriteCreate a notification channel configuration (e.g. webhook, dingtalk, feishu).
update_notify_channelwriteUpdate an existing notification channel configuration
create_notify_templatewriteCreate a notification template
update_notify_templatewriteUpdate a notification template (full body)
update_notify_template_contentwriteUpdate only the rendered content of a notification template (lighter than update_notify_template).

roles​

Role and permission management (n9e RBAC)

ToolAccessWhat it does
list_rolesreadList all roles defined in the system.
list_operationsreadList every operation (permission) the system understands.
list_role_operationsreadList operations bound to a specific role.
create_rolewriteCreate a new role.
update_rolewriteUpdate a role's metadata (PUT /roles).
bind_role_operationswriteReplace the operations bound to a role (PUT /role/{id}/ops). Send the full ops list, not a delta.

targets​

Target/Host management tools for viewing monitored objects

ToolAccessWhat it does
list_targetsreadList monitored targets/hosts with optional filters

This toolset is read-only.

users​

User and user group management tools

ToolAccessWhat it does
list_usersreadList users with optional filters
get_userreadGet details of a specific user by ID
list_user_groupsreadList user groups/teams that the current user has access to
get_user_groupreadGet details of a specific user group including its members
create_userwriteCreate a new user. The body should at minimum include username, password, and roles.
update_user_profilewriteUpdate a user's profile. The 'roles' field on the body assigns roles to the user (n9e v8 stores roles on the user row, no dedicated assign endpoint).
reset_user_passwordwriteReset a user's password. Requires admin privileges on the n9e side.
create_user_groupwriteCreate a new user group (team).
update_user_groupwriteUpdate a user group's metadata (name, note).
add_user_group_memberswriteAdd user(s) to a user group.