Skip to main content

newrelic-mcp-nerdgraph

CI PyPI Python License

An open source MCP server that connects AI agents to New Relic through the public NerdGraph GraphQL API.

It runs locally over stdio with a standard User API key. There is no hosted bridge in the path, so every query is one you can read, reproduce in the NerdGraph GraphiQL explorer, and audit.

Why this exists

New Relic ships its own hosted MCP server. It is a good product, but it is a remote service gated behind account previews, and several of its tools require OAuth rather than an API key. This project targets a different set of constraints:

  • Local and self-hosted. Runs as a subprocess of your editor; telemetry never transits a third-party bridge.
  • Explicit NRQL instead of opaque translation. Tools either take NRQL you can read or generate NRQL that is returned alongside the results.
  • Read-only by default. Anything that changes New Relic configuration is behind an opt-in flag.
  • No extra cost. Only the New Relic account you already pay for.

See docs/comparison.md for a feature-by-feature comparison, and docs/architecture.md for the design.

Install

uv tool install newrelic-mcp-nerdgraph
# or
pipx install newrelic-mcp-nerdgraph

Configure

You need a New Relic User API key (NRAK-...) and your account id.

Variable Required Default Purpose
NEW_RELIC_API_KEY yes — User API key
NEW_RELIC_ACCOUNT_IDS recommended — Comma-separated defaults, e.g. 123,456
NEW_RELIC_REGION no US US or EU
NEW_RELIC_DEFAULT_SINCE no 30 MINUTES AGO Time window added to NRQL without one
NEW_RELIC_MAX_RESULT_ROWS no 200 LIMIT added to NRQL without one
NEW_RELIC_MAX_RESPONSE_CHARS no 100000 Byte budget per tool response
NEW_RELIC_QUERY_TIMEOUT_SECONDS no 30 Server-side NRQL timeout
NEW_RELIC_MAX_RETRIES no 3 Retries on 429/5xx
NEW_RELIC_REDACT_SENSITIVE_VALUES no true Mask credential-shaped strings in output
NEW_RELIC_ENABLE_RAW_NERDGRAPH no false Expose the arbitrary-GraphQL tool
NEW_RELIC_ENABLE_MUTATIONS no false Allow write operations

Cursor

~/.cursor/mcp.json:

{
  "mcpServers": {
    "newrelic": {
      "command": "newrelic-mcp",
      "env": {
        "NEW_RELIC_API_KEY": "NRAK-your-key",
        "NEW_RELIC_ACCOUNT_IDS": "1234567"
      }
    }
  }
}

Claude Desktop

claude_desktop_config.json uses the same shape. Run without installing:

{
  "mcpServers": {
    "newrelic": {
      "command": "uvx",
      "args": ["newrelic-mcp-nerdgraph"],
      "env": { "NEW_RELIC_API_KEY": "NRAK-your-key", "NEW_RELIC_ACCOUNT_IDS": "1234567" }
    }
  }
}

Tools

Tool What it answers
run_nrql Any NRQL query, one or many accounts
run_nrql_async Long-running query, polled to completion
validate_nrql_query Check NRQL and see the clauses the server adds
search_entities Find services, hosts and lambdas by name, type or tag
get_entity Tags, golden metrics and relationships for one GUID
list_open_issues Currently firing alert issues
list_alert_policies Alert policies in an account
list_nrql_conditions Condition queries and thresholds
search_logs Logs by service, level, trace id or message
summarize_log_errors Error logs grouped by message pattern
get_trace Spans of one distributed trace
get_recent_errors Transaction errors grouped by class
list_deployments Recent deploys, for change correlation
compare_metric_windows An aggregate against the same window in the past
nerdgraph_query Arbitrary GraphQL (opt-in)

Full input schemas: docs/tools.md.

Resources and prompts

  • newrelic://nrql/cheatsheet — event types, query patterns, common pitfalls.
  • newrelic://playbook/investigation — the incident flow these tools are built for.
  • newrelic://config — active configuration, API key excluded.
  • Prompts: investigate_incident, write_nrql.

Example session

"The checkout service is alerting. What happened in the last hour?"

The agent walks list_open_issues → get_entity → list_deployments → get_recent_errors → get_trace → search_logs, each step narrowing the next. docs/recipes.md has five worked examples.

Security

  • The API key lives in a SecretStr, is attached per request, and never appears in logs, repr output or the config resource.
  • Every NRQL string is validated: no stacked statements, no comment markers, read-only verbs only. All interpolated values are escaped.
  • Credential-shaped strings in results (JWTs, bearer tokens, cloud keys) are masked before they reach the model.
  • Responses are size-capped so a wide query degrades into a truncated result rather than an unusable context.

Note that NRQL guardrails are a correctness and cost control, not an authorization boundary. The server can only read what the API key can read, so scope the key to the accounts the agent should see. Report vulnerabilities via SECURITY.md.

Development

uv sync --all-extras
uv run pytest
uv run ruff check . && uv run ruff format --check .
uv run mypy

Tests mock NerdGraph with respx; no account or network access is needed. See CONTRIBUTING.md.

License

Apache-2.0. Not affiliated with or endorsed by New Relic, Inc.

Metadata

Release files for newrelic-mcp-nerdgraph 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for newrelic-mcp-nerdgraph 0.1.0
File Size Uploaded
newrelic_mcp_nerdgraph-0.1.0.tar.gz 34.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for newrelic-mcp-nerdgraph 0.1.0
File Interpreter ABI Platform
newrelic_mcp_nerdgraph-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 74.5 kB

Release files / newrelic_mcp_nerdgraph-0.1.0.tar.gz

Download URL newrelic_mcp_nerdgraph-0.1.0.tar.gz
Size 34.2 kB
Tags Source
SHA-256 checksum
How to use checksums
6b86a751ffb134e4d1b356d16d2bd0ae5314907cda6f14bb61291c9f0391cf94
BLAKE2b-256 checksum
How to use checksums
2d1a2a1c8f2f44c8afbcf408541d351d6e2b02c7008398c62fa7137e3088af5f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.

Transparency log

Release files / newrelic_mcp_nerdgraph-0.1.0-py3-none-any.whl

Download URL newrelic_mcp_nerdgraph-0.1.0-py3-none-any.whl
Size 40.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
47be48b46ec509002b4eec54922d1b981254a2b736d585287a307bfa3edae062
BLAKE2b-256 checksum
How to use checksums
24076589553832441f575496bbae2ce3916ace1f6ce68640766565609932310a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page