OnboardingConnect Providers

Datadog

Prerequisites

  • Datadog Pro or Enterprise.
  • The parent organization. Datadog's cost endpoints only work from a parent-level org: a sub-organization key is refused.
  • A Datadog admin, to create an application key scoped to usage and billing reads.

Connect

Create an API key and a scoped application key in Datadog

In your Datadog parent organization, copy your organization API key from Organization Settings > API Keys.

Then create a service account and an application key for it, scoped to usage_read and billing_read. Both scopes are required: either alone is refused.

Add it to LevelFour

Open Connect Providers, select Datadog, and paste the API key, the application key, and your Datadog site (for example datadoghq.com or datadoghq.eu). Click Add API key.

Confirming it worked

The connection moves to Connected. Your first data appears within a day.

Rotating or removing access

Rotating the credential

Create a new application key in Datadog, paste it into Connect Providers, then revoke the old key.

Removing access

Disconnect Datadog under Connect Providers, then revoke the application key from Datadog's Organization Settings.

Troubleshooting

SymptomWhat to do
The connection is refused with a permissions errorConfirm the application key has both usage_read and billing_read. Either alone is not enough
The connection is refused even with both scopesDatadog's cost endpoints only work from the parent-level organization. A key created in a sub-organization will not work; create it from the parent org
Recent days keep changingExpected for products Datadog bills on peak (p95/p99) usage. A month is not final until about 17 days after it closes

Next