Skip to content
Development
Skill

/dd-pup

Datadog CLI (pup). OAuth2 auth with token refresh.

From plugin
pup
97511 skills49 agents
Install
$ npx -y skills add DataDog/pup --skill dd-pup --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/dd-pup

Context preview

The summary Claude sees to decide when to auto-load this skill.

Datadog CLI (pup). OAuth2 auth with token refresh.

SKILL.md

dd-pup.SKILL.md
name: dd-pup
description: Datadog CLI (pup). OAuth2 auth with token refresh.
metadata:
  version: "1.0.0"
  author: datadog-labs
  repository: https://github.com/datadog-labs/agent-skills
  tags: datadog,cli,dd-pup,pup
  alwaysApply: "false"

pup (Datadog CLI)

Pup CLI for Datadog API operations. Supports OAuth2 and API key auth.

Quick Reference

| Task | Command | |------|---------| | Search error logs | `pup logs search --query "status:error" --from 1h` | | List monitors | `pup monitors list` | | Create downtime | `pup downtime create --file downtime.json` | | Find slow traces | `pup traces search --query="@duration:>500000000" --from="1h"` | | List incidents | `pup incidents list` | | Query metrics | `pup metrics query --query "avg:system.cpu.user{*}"` | | List hosts | `pup infrastructure hosts list` | | Check SLOs | `pup slos list` | | On-call teams | `pup on-call teams list` | | Security signals | `pup security signals list --query "*" --from 24h` | | Inspect runtime values | `pup debugger probes create --service my-svc --env prod --probe-location "com.example.MyClass:myMethod"` or `"com.example.MyClass:myMethod(String, int)"` | | Find probe-able methods | `pup symdb search --service my-svc --query MyController --view probe-locations` | | Check auth | `pup auth status` | | Refresh token | `pup auth refresh` |

Prerequisites

# Install pup via Homebrew (recommended)
brew tap datadog-labs/pack
brew install pup

Auth

pup auth login          # OAuth2 browser flow (recommended)
pup auth status         # Check token validity
pup auth refresh        # Refresh expired token (no browser)
pup auth logout         # Clear credentials

**⚠️ Tokens expire (~1 hour)**. If a command fails with 401/403 mid-conversation:

pup auth refresh        # Try refresh first
pup auth login          # If refresh fails, full re-auth

Headless/CI (no browser)

# Use env vars or:
export DD_API_KEY=your-api-key
export DD_APP_KEY=your-app-key
export DD_SITE=datadoghq.com    # or datadoghq.eu, etc.

Command Reference

Monitors

pup monitors list --limit 10
pup monitors list --tags "env:prod"
pup monitors get 12345
pup monitors search --query "High CPU"
pup monitors create --file monitor.json
pup monitors update 12345 --file monitor.json
pup monitors delete 12345

Logs

pup logs search --query "status:error" --from 1h
pup logs search --query "service:payment-api" --from 1h --limit 100
pup logs search --query "@http.status_code:5*" --from 24h
pup logs aggregate --query "service:api" --compute count --from 1h

Metrics

pup metrics query --query "avg:system.cpu.user{*}" --from 1h
pup metrics query --query "sum:trace.express.request.hits{service:api}" --from 1h
pup metrics list --filter "system.*"

APM / Services

pup apm services list --env production
pup apm services stats --env production
pup apm services operations --env production --service my-service
pup apm services resources --env production --service my-service --name http.request
pup apm dependencies list --env production

Traces

# Search traces (duration in nanoseconds: 1s = 1000000000)
pup traces search --query="service:api-gateway" --from="1h"
pup traces search --query="service:api @duration:>1000000000" --from="1h"
pup traces search --query="service:api status:error" --from="1h"
pup traces aggregate --query="service:api" --compute="avg(@duration)" --group-by="resource_name" --from="1h"

Incidents

pup incidents list
pup incidents list --limit 20
pup incidents get <incident-id>

Dashboards

pup dashboards list
pup dashboards get abc-123
pup dashboards create --file dashboard.json
pup dashboards update abc-123 --file dashboard.json
pup dashboards delete abc-123

SLOs

pup slos list
pup slos get slo-123
pup slos status slo-123 --from 30d --to now
pup slos create --file slo.json

Synthetics

pup synthetics tests list
pup synthetics tests get abc-123
pup synthetics tests search --text "login"
pup synthetics locations list

Downtimes

pup downtime list
pup downtime get abc-123-def
pup downtime create --file downtime.json
pup downtime cancel abc-123-def

Infrastructure / Hosts

pup infrastructure hosts list
pup infrastructure hosts list --filter "env:prod"
pup infrastructure hosts list --count 100
pup infrastructure hosts get <host-id>

Events

pup events list --from 24h
pup events list --tags "source:deploy" --from 24h
pup events search --query "deploy" --from 24h
pup events get <event-id>

Users / Teams

pup users list
pup users get <user-id>
pup on-call teams list
pup on-call teams get <team-id>

Security

pup security signals list --query "*" --from 24h
pup security signals list --query "severity:critical" --from 24h
pup security rules list

Live Debugger

# Check service context (verify env has active instances)
pup debugger context my-svc
pup debugger context my-svc --env prod

# Find probe-able methods in a service
pup symdb search --service my-svc --query MyController --view probe-locations

# Place a log probe with capture expressions
# --probe-location accepts TYPE:METHOD or TYPE:METHOD(arg1, arg2, ...) with optional signature
pup debugger probes create --service my-svc --env prod \
  --probe-location "com.example.MyController:handleRequest" \
  --capture "request.id" --capture "request.headers" \
  --ttl 1h

# With method signature (useful when the method is overloaded)
pup debugger probes create --service my-svc --env prod \
  --probe-location "com.example.MyController:handleRequest(String, HttpHeaders)" \
  --capture "request.id" --ttl 1h

# Watch probe events — compact output
pup debugger probes watch <PROBE_ID> --fields "message,captures,timestamp" --timeout 60 --limit 10 --wait 5

# Watch — template message only
pup debugger probes watch <PROBE_ID> --fields
Read more
Ships withpup

Every AI agent needs a loyal companion. Meet Pup — the CLI that gives your agents full access to Datadog's observability platform (because even autonomous agents need good tooling, not just tricks).

Get the whole plugin