Honeycomb MCP

Live

OAUTH 2.1

OBSERVABILITY

Monitoring

Honeycomb MCP gives your agent observability data: run queries and BubbleUp on your datasets, pull traces and spans, and manage boards, triggers, and markers in each user's Honeycomb environments.

  • Per-user credentials: each call uses the actual user's token, never a shared bot.
  • Encrypted per-tenant vault: AES-256, resolved at request time, never in LLM context.
  • Scoped before every call: pre-call scope check, 90-day SIEM-exportable audit chain.
Honeycomb MCP
agent · Acme Q3
Run
Why did checkout latency spike in production over the last hour?
S
honeycombmcp_run_bubbleup
212ms
Observability agent
BubbleUp shows 92% of the slow checkout spans come from build 4812 in eu-west-1. Latency there is 3x the baseline.
Sources: Honeycomb, production checkout dataset
honeycombmcp
1 BubbleUp run
18:29
Message Claude...

Tools your observability agent reaches for on Honeycomb, scoped per user.

CALL ANY TOOL
31 tools for observability in Honeycomb: run queries and BubbleUp, read traces, spans, and datasets, review Anomaly Signals, and create boards, triggers, recipients, and markers.
honeycombmcp_canvas_agent_invoke
Invoke canvas agent
Kick off a single-turn run of the Honeycomb Canvas agent. Pass investigation_id to extend an existing investigation visible to the caller's team. Omit investigation_id to create a new investigation for this prompt; the new ID is returned in the response so the caller can reuse it on follow-up calls. Returns one of: status='running' with a session_id (call canvas_agent_poll_response next); status='busy' with a message (the user is mid-turn, wait at least 30 seconds, then retry, do NOT loop). Both responses also include investigation_url, a direct browser link to the canvas. On 'running', poll repeatedly until poll returns status='completed' or 'error'. Each poll waits up to 50 seconds. Best for asking the agent to summarize findings, run additional analysis, or kick off a new investigation.
Parameters
Name
Type
Required
Description
prompt
string
Required
Prompt to send to the canvas agent. Will be wrapped in <instructions> tags before delivery.
investigation_id
string
Optional
ID of an existing investigation (e.g. 'hcciv_…'). Omit to create a new investigation for this prompt.
team
string
Optional
Team to run this tool against; only needed when your authorization covers multiple teams
title
string
Optional
Optional title for a newly-created investigation. Ignored when investigation_id is provided. Defaults to an auto-generated title.
honeycombmcp_canvas_agent_poll_response
Canvas agent poll response
honeycombmcp_create_board
Create board
honeycombmcp_create_marker
Create marker
honeycombmcp_create_recipient
Create recipient
honeycombmcp_create_trigger
Trigger create
honeycombmcp_feedback
Feedback
honeycombmcp_find_columns
Find columns
honeycombmcp_find_queries
Find queries
honeycombmcp_get_aiconversation
Get aiconversation
honeycombmcp_get_dataset
Get dataset
honeycombmcp_get_dataset_columns
Get dataset columns
honeycombmcp_get_environment
Get environment
honeycombmcp_get_query_results
Get query results
honeycombmcp_get_signals
Get signals
honeycombmcp_get_span_details
Get span details
honeycombmcp_get_trace
Get trace
honeycombmcp_get_triggers
Get triggers
honeycombmcp_list_aiconversations
List aiconversations
honeycombmcp_list_boards
List boards
honeycombmcp_list_recipients
List recipients
honeycombmcp_list_spans
List spans
honeycombmcp_migration_guide
Migration guide
honeycombmcp_record_onboarding_state
Record onboarding state
honeycombmcp_refinery_docs
Refinery docs
honeycombmcp_run_bubbleup
Run bubbleup
honeycombmcp_run_query
Query run
honeycombmcp_semconv
Semconv
honeycombmcp_update_board
Update board
honeycombmcp_update_trigger
Trigger update

For more tools, view docs.

Build your Agent
Same auth pattern across LangChain, OpenAI, Anthropic, and Google ADK.
Python · LlamaIndex
import { ScalekitClient } from "@scalekit-sdk/node";
import { createReactAgent } from "@langchain/langgraph/prebuilt";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

// Honeycomb MCP tools scoped to this user
const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["honeycombmcp"], toolNames: [
    "honeycombmcp_get_workspace_context",
    "honeycombmcp_run_query",
    "honeycombmcp_get_trace"] },
  pageSize: 100,
});

const agent = createReactAgent({ llm, tools });
await agent.invoke({ messages: [{ role: "user", content: "Why did checkout latency spike in production over the last hour?" }] });
import OpenAI from "openai";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
const openai = new OpenAI();

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["honeycombmcp"] }, pageSize: 100,
});

const res = await openai.chat.completions.create({
  model: "gpt-5",
  messages: [{ role: "user", content: "Why did checkout latency spike in production over the last hour?" }],
  tools,
});

// Execute the tool call with the user's vaulted Honeycomb token
await sk.tools.executeTool(res.choices[0].message.tool_calls[0], "user_123");
import Anthropic from "@anthropic-ai/sdk";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
const anthropic = new Anthropic();

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["honeycombmcp"] }, pageSize: 100,
});

const msg = await anthropic.messages.create({
  model: "claude-sonnet-5",
  max_tokens: 1024,
  messages: [{ role: "user", content: "Why did checkout latency spike in production over the last hour?" }],
  tools,
});

// Tool call runs with the user's vaulted Honeycomb token
await sk.tools.executeTool(msg.content, "user_123");
import { Agent } from "@google/adk/agents";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["honeycombmcp"] }, pageSize: 100,
});

const agent = new Agent({
  name: "observability_agent",
  model: "gemini-2.5-pro",
  instruction: "Honeycomb MCP tools scoped to this user",
  tools,
});

await agent.run("Why did checkout latency spike in production over the last hour?");
Try these prompts
Copy any prompt into your agent. Each maps directly to a Honeycomb MCP tool. Click to copy, paste into your agent, done.
Queries and analysis
Copy the prompt
Copied
Run a P99 latency query on the checkout dataset for the last 6 hours.
Copy the prompt
Copied
Run BubbleUp on slow requests to find what makes them different.
Copy the prompt
Copied
Find saved queries about error rates.
Traces and spans
Copy the prompt
Copied
Show the waterfall for this trace ID.
Copy the prompt
Copied
List the most common span names in production.
Copy the prompt
Copied
Summarize the attributes on spans named POST /checkout.
Alerts and boards
Copy the prompt
Copied
Create a trigger that alerts when errors exceed 50 in 5 minutes.
Copy the prompt
Copied
Add a deploy marker for build 4812 to production.
Copy the prompt
Copied
Create a board with latency and error rate panels.
SEE HOW AUTH WORKS
Each user signs in to Honeycomb once; Scalekit stores and refreshes their tokens. Credentials stay vaulted, every call is scope checked, and every action is logged.
1
Authorize
Your user connects
Honeycomb MCP
once. We tie it to their identity and the meetings they approved — no shared bot account, no org-wide access
Who:
user ‘A’
when:
Once per user
access:
Limited to user
2
Store
Their
Honeycomb MCP
token lives in a vault scoped to them. User A's meetings are never reachable by an agent acting for user B, even on the same connection
vault:
encrypted
scope:
per-user
tokens:
auto-refreshed
3
Resolve
When your agent calls a
Honeycomb MCP
tool, we fetch the right token server-side. It never touches your agent, never appears in the LLM context, never shows up in your logs
speed:
~40ms
check:
before every call
seen by:
nobody
4
Audit
Every
Honeycomb MCP
tool call is logged — who triggered it, which meeting was fetched, what came back. 90 days of history, tied to the user who authorized it
history:
90 days
export:
SIEM-ready
logged:
every call
Test other agents
See the same per-user auth pattern across other monitoring and developer tool connectors.
Engineering Teams
DevOps assistant agent
Polls GitHub for failing checks and stale PRs, opens Linear issues for the ones that need work, and posts a daily digest to Slack. It acts as the engineer, not a shared service account.
Engineering Teams
Engineering standup agent
Pulls commits from GitHub and GitLab, tracks issue movement in Jira, and posts a per-engineer standup brief to Slack. Each engineer's activity is read on their own delegated OAuth.
Engineering Teams
Auto release notes agent
Reads merged GitHub PRs, groups them into structured release notes, publishes the page to Notion, and announces the release in Slack. Every call runs on the engineer's own delegated OAuth.
Support and Ops Teams
Support triage agent
Fetches new Zendesk tickets, classifies them by type and urgency, searches the Notion knowledge base for an answer, and routes what it cannot resolve to Slack. Every call runs on the support agent's own delegated OAuth.
Test other agents
See the same per-user auth pattern across other monitoring and developer tool connectors.
ENGINEERING
DevOps assistant agent
Poll GitHub for failing checks and stale pull requests, open Linear issues for the ones that need work, and digest to Slack.
ENGINEERING
Engineering standup agent
Pull commits from GitHub and GitLab, track Jira issue movement, and post a per-engineer standup brief to Slack.
ENGINEERING
Auto-release notes agent
Group merged GitHub PRs into structured release notes, publish the page to Notion, and announce the release in Slack.
SUPPORT
Support triage agent
Classify new Zendesk tickets, search the Notion knowledge base for an answer, and route what it cannot resolve to Slack.
Why Scalekit
Secure your agent's access. Connectors ship in minutes
01.
Shared tokens break per-user analytics
A shared Honeycomb token looks fine in a demo. In production every query and trigger change looks like one service account, and you cannot tell which user triggered it. Scalekit resolves the credential of the actual user who triggered the agent, never a shared bot.
// shared token
audit → bot_service_account

// scalekit
audit → user_abc ✓
02.
Authentication is not authorization
03.
Multi-tenancy is architectural
04.
Honeycomb today. Ten connectors tomorrow.
“Our agents act across Salesforce, Gong, Google Drive, and more, on behalf of every customer. Scalekit behind the scenes meant we can keep adding tools without ever rebuilding how credentials or tool calling work.”
Venu Madhav Kattagoni
Head of Engineering / Von
FAQs
Frequently Asked Questions
Does the agent access Honeycomb as the user or through a shared service account?
As the user. Each user signs in to Honeycomb once, and Scalekit stores and refreshes their tokens. Every query and trigger change in your audit trail is attributed to that user, not a shared service account.
Where is the Honeycomb OAuth token stored?
In Scalekit's managed AES-256 token vault, namespaced per tenant. Refresh is automatic. Revocation is a single dashboard action. Credentials never appear in prompts, logs, or LLM context.
Can I limit what the agent does in Honeycomb?
Yes. Filter by tool name in listScopedTools to expose only what you want, for example the 23 read-only tools without the board and trigger write tools. Scalekit also enforces scope checks before every API call.
What happens when a user revokes Honeycomb access?
The connection is invalidated on the next tool call. Subsequent requests for that user fail closed with a clear error. Other users in the tenant remain unaffected. The event is logged for audit.
Can the agent change alerts and dashboards in Honeycomb?
Yes, if you expose the write tools. Most of the 31 tools are read-only. The write tools create boards, triggers, recipients, and markers, and honeycombmcp_update_board and honeycombmcp_update_trigger edit existing ones in place. Leave those out of toolNames to keep the agent read-only.
Start in your coding agent
Up and running in one command
Install the Scalekit skill in your editor of choice. Connector, auth, tools, prompt, all wired up
Claude Code REPL
/plugin marketplace add scalekit-inc/claude-code-authstack
/plugin install agentkit@scalekit-auth-stack
Cursor Code REPL
# ~/.cursor/mcp.json
{
""mcpServers"": {
""honeycombmcp"": {
""url"": ""https://mcp.scalekit.com/honeycombmcp"",
""headers"": { ""Authorization"": ""Bearer $SCALEKIT_TOKEN"" }
}
}
}
Codex Code REPL
# ~/.codex/config.toml
[mcp_servers.honeycombmcp]
url = ""https://mcp.scalekit.com/honeycombmcp""
auth_env = ""SCALEKIT_TOKEN""
Copilot Code REPL
# .vscode/mcp.json
{
""servers"": {
""honeycombmcp"": {
""url"": ""https://mcp.scalekit.com/honeycombmcp"",
""type"": ""http""
}
}
}