/dd-pup
Datadog CLI (pup). OAuth2 auth with token refresh.
$ npx -y skills add DataDog/pup --skill dd-pup --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/dd-pup
Context preview
The summary Claude sees to decide when to auto-load this skill.
Datadog CLI (pup). OAuth2 auth with token refresh.
SKILL.md
dd-pup.SKILL.mdname: dd-pup
description: Datadog CLI (pup). OAuth2 auth with token refresh.
metadata:
version: "1.0.0"
author: datadog-labs
repository: https://github.com/datadog-labs/agent-skills
tags: datadog,cli,dd-pup,pup
alwaysApply: "false"
pup (Datadog CLI)
Pup CLI for Datadog API operations. Supports OAuth2 and API key auth.
Quick Reference
| Task | Command | |------|---------| | Search error logs | `pup logs search --query "status:error" --from 1h` | | List monitors | `pup monitors list` | | Create downtime | `pup downtime create --file downtime.json` | | Find slow traces | `pup traces search --query="@duration:>500000000" --from="1h"` | | List incidents | `pup incidents list` | | Query metrics | `pup metrics query --query "avg:system.cpu.user{*}"` | | List hosts | `pup infrastructure hosts list` | | Check SLOs | `pup slos list` | | On-call teams | `pup on-call teams list` | | Security signals | `pup security signals list --query "*" --from 24h` | | Inspect runtime values | `pup debugger probes create --service my-svc --env prod --probe-location "com.example.MyClass:myMethod"` or `"com.example.MyClass:myMethod(String, int)"` | | Find probe-able methods | `pup symdb search --service my-svc --query MyController --view probe-locations` | | Check auth | `pup auth status` | | Refresh token | `pup auth refresh` |
Prerequisites
# Install pup via Homebrew (recommended)
brew tap datadog-labs/pack
brew install pup
Auth
pup auth login # OAuth2 browser flow (recommended)
pup auth status # Check token validity
pup auth refresh # Refresh expired token (no browser)
pup auth logout # Clear credentials
**⚠️ Tokens expire (~1 hour)**. If a command fails with 401/403 mid-conversation:
pup auth refresh # Try refresh first
pup auth login # If refresh fails, full re-auth
Headless/CI (no browser)
# Use env vars or:
export DD_API_KEY=your-api-key
export DD_APP_KEY=your-app-key
export DD_SITE=datadoghq.com # or datadoghq.eu, etc.
Command Reference
Monitors
pup monitors list --limit 10
pup monitors list --tags "env:prod"
pup monitors get 12345
pup monitors search --query "High CPU"
pup monitors create --file monitor.json
pup monitors update 12345 --file monitor.json
pup monitors delete 12345
Logs
pup logs search --query "status:error" --from 1h
pup logs search --query "service:payment-api" --from 1h --limit 100
pup logs search --query "@http.status_code:5*" --from 24h
pup logs aggregate --query "service:api" --compute count --from 1h
Metrics
pup metrics query --query "avg:system.cpu.user{*}" --from 1h
pup metrics query --query "sum:trace.express.request.hits{service:api}" --from 1h
pup metrics list --filter "system.*"APM / Services
pup apm services list --env production
pup apm services stats --env production
pup apm services operations --env production --service my-service
pup apm services resources --env production --service my-service --name http.request
pup apm dependencies list --env production
Traces
# Search traces (duration in nanoseconds: 1s = 1000000000)
pup traces search --query="service:api-gateway" --from="1h"
pup traces search --query="service:api @duration:>1000000000" --from="1h"
pup traces search --query="service:api status:error" --from="1h"
pup traces aggregate --query="service:api" --compute="avg(@duration)" --group-by="resource_name" --from="1h"
Incidents
pup incidents list
pup incidents list --limit 20
pup incidents get <incident-id>
Dashboards
pup dashboards list
pup dashboards get abc-123
pup dashboards create --file dashboard.json
pup dashboards update abc-123 --file dashboard.json
pup dashboards delete abc-123
SLOs
pup slos list
pup slos get slo-123
pup slos status slo-123 --from 30d --to now
pup slos create --file slo.json
Synthetics
pup synthetics tests list
pup synthetics tests get abc-123
pup synthetics tests search --text "login"
pup synthetics locations list
Downtimes
pup downtime list
pup downtime get abc-123-def
pup downtime create --file downtime.json
pup downtime cancel abc-123-def
Infrastructure / Hosts
pup infrastructure hosts list
pup infrastructure hosts list --filter "env:prod"
pup infrastructure hosts list --count 100
pup infrastructure hosts get <host-id>
Events
pup events list --from 24h
pup events list --tags "source:deploy" --from 24h
pup events search --query "deploy" --from 24h
pup events get <event-id>
Users / Teams
pup users list
pup users get <user-id>
pup on-call teams list
pup on-call teams get <team-id>
Security
pup security signals list --query "*" --from 24h
pup security signals list --query "severity:critical" --from 24h
pup security rules list
Live Debugger
# Check service context (verify env has active instances)
pup debugger context my-svc
pup debugger context my-svc --env prod
# Find probe-able methods in a service
pup symdb search --service my-svc --query MyController --view probe-locations
# Place a log probe with capture expressions
# --probe-location accepts TYPE:METHOD or TYPE:METHOD(arg1, arg2, ...) with optional signature
pup debugger probes create --service my-svc --env prod \
--probe-location "com.example.MyController:handleRequest" \
--capture "request.id" --capture "request.headers" \
--ttl 1h
# With method signature (useful when the method is overloaded)
pup debugger probes create --service my-svc --env prod \
--probe-location "com.example.MyController:handleRequest(String, HttpHeaders)" \
--capture "request.id" --ttl 1h
# Watch probe events — compact output
pup debugger probes watch <PROBE_ID> --fields "message,captures,timestamp" --timeout 60 --limit 10 --wait 5
# Watch — template message only
pup debugger probes watch <PROBE_ID> --fields
Read more
name: dd-pup description: Datadog CLI (pup). OAuth2 auth with token refresh. metadata: version: "1.0.0" author: datadog-labs repository: https://github.com/datadog-labs/agent-skills tags: datadog,cli,dd-pup,pup alwaysApply: "false"
pup (Datadog CLI)
Pup CLI for Datadog API operations. Supports OAuth2 and API key auth.
Quick Reference
| Task | Command | |------|---------| | Search error logs | `pup logs search --query "status:error" --from 1h` | | List monitors | `pup monitors list` | | Create downtime | `pup downtime create --file downtime.json` | | Find slow traces | `pup traces search --query="@duration:>500000000" --from="1h"` | | List incidents | `pup incidents list` | | Query metrics | `pup metrics query --query "avg:system.cpu.user{*}"` | | List hosts | `pup infrastructure hosts list` | | Check SLOs | `pup slos list` | | On-call teams | `pup on-call teams list` | | Security signals | `pup security signals list --query "*" --from 24h` | | Inspect runtime values | `pup debugger probes create --service my-svc --env prod --probe-location "com.example.MyClass:myMethod"` or `"com.example.MyClass:myMethod(String, int)"` | | Find probe-able methods | `pup symdb search --service my-svc --query MyController --view probe-locations` | | Check auth | `pup auth status` | | Refresh token | `pup auth refresh` |
Prerequisites
# Install pup via Homebrew (recommended) brew tap datadog-labs/pack brew install pup
Auth
pup auth login # OAuth2 browser flow (recommended) pup auth status # Check token validity pup auth refresh # Refresh expired token (no browser) pup auth logout # Clear credentials
**⚠️ Tokens expire (~1 hour)**. If a command fails with 401/403 mid-conversation:
pup auth refresh # Try refresh first pup auth login # If refresh fails, full re-auth
Headless/CI (no browser)
# Use env vars or: export DD_API_KEY=your-api-key export DD_APP_KEY=your-app-key export DD_SITE=datadoghq.com # or datadoghq.eu, etc.
Command Reference
Monitors
pup monitors list --limit 10 pup monitors list --tags "env:prod" pup monitors get 12345 pup monitors search --query "High CPU" pup monitors create --file monitor.json pup monitors update 12345 --file monitor.json pup monitors delete 12345
Logs
pup logs search --query "status:error" --from 1h pup logs search --query "service:payment-api" --from 1h --limit 100 pup logs search --query "@http.status_code:5*" --from 24h pup logs aggregate --query "service:api" --compute count --from 1h
Metrics
pup metrics query --query "avg:system.cpu.user{*}" --from 1h
pup metrics query --query "sum:trace.express.request.hits{service:api}" --from 1h
pup metrics list --filter "system.*"APM / Services
pup apm services list --env production pup apm services stats --env production pup apm services operations --env production --service my-service pup apm services resources --env production --service my-service --name http.request pup apm dependencies list --env production
Traces
# Search traces (duration in nanoseconds: 1s = 1000000000) pup traces search --query="service:api-gateway" --from="1h" pup traces search --query="service:api @duration:>1000000000" --from="1h" pup traces search --query="service:api status:error" --from="1h" pup traces aggregate --query="service:api" --compute="avg(@duration)" --group-by="resource_name" --from="1h"
Incidents
pup incidents list pup incidents list --limit 20 pup incidents get <incident-id>
Dashboards
pup dashboards list pup dashboards get abc-123 pup dashboards create --file dashboard.json pup dashboards update abc-123 --file dashboard.json pup dashboards delete abc-123
SLOs
pup slos list pup slos get slo-123 pup slos status slo-123 --from 30d --to now pup slos create --file slo.json
Synthetics
pup synthetics tests list pup synthetics tests get abc-123 pup synthetics tests search --text "login" pup synthetics locations list
Downtimes
pup downtime list pup downtime get abc-123-def pup downtime create --file downtime.json pup downtime cancel abc-123-def
Infrastructure / Hosts
pup infrastructure hosts list pup infrastructure hosts list --filter "env:prod" pup infrastructure hosts list --count 100 pup infrastructure hosts get <host-id>
Events
pup events list --from 24h pup events list --tags "source:deploy" --from 24h pup events search --query "deploy" --from 24h pup events get <event-id>
Users / Teams
pup users list pup users get <user-id> pup on-call teams list pup on-call teams get <team-id>
Security
pup security signals list --query "*" --from 24h pup security signals list --query "severity:critical" --from 24h pup security rules list
Live Debugger
# Check service context (verify env has active instances) pup debugger context my-svc pup debugger context my-svc --env prod # Find probe-able methods in a service pup symdb search --service my-svc --query MyController --view probe-locations # Place a log probe with capture expressions # --probe-location accepts TYPE:METHOD or TYPE:METHOD(arg1, arg2, ...) with optional signature pup debugger probes create --service my-svc --env prod \ --probe-location "com.example.MyController:handleRequest" \ --capture "request.id" --capture "request.headers" \ --ttl 1h # With method signature (useful when the method is overloaded) pup debugger probes create --service my-svc --env prod \ --probe-location "com.example.MyController:handleRequest(String, HttpHeaders)" \ --capture "request.id" --ttl 1h # Watch probe events — compact output pup debugger probes watch <PROBE_ID> --fields "message,captures,timestamp" --timeout 60 --limit 10 --wait 5 # Watch — template message only pup debugger probes watch <PROBE_ID> --fields
Every AI agent needs a loyal companion. Meet Pup — the CLI that gives your agents full access to Datadog's observability platform (because even autonomous agents need good tooling, not just tricks).
Repo: DataDog/pup
Other skills on pup.
- /dd-apm
APM - traces, services, dependencies, performance analysis.
Open skill - /dd-code-generation
Use pup CLI for immediate Datadog operations or generate code for integration into applications
Open skill - /dd-debugger
Live Debugger - inspect runtime argument/variable values in production by placing log probes on methods. Use when asked what values a function receives, what parameters look like at runtime, or to capture live data from running services without redeploying.
Open skill - /dd-docs
Datadog docs lookup using docs.datadoghq.com/llms.txt and linked Markdown pages.
Open skill - /dd-file-issue
File GitHub issues to the right repository (pup CLI or plugin)
Open skill - /dd-logs
Log management - search, pipelines, archives, and cost control.
Open skill

