How can we help?

Datadog Integration

Netanel Hugi
Netanel Hugi
  • Updated
Torii SMP
Torii Identity

Setup your Datadog integration and get all the insights in Torii's dashboard

Overview

Torii integrates with Datadog and syncs users' names, emails, statuses, roles, and licenses.

Note that Torii can sync multiple Datadog accounts.

API Key vs. Application Key

Datadog has two different key types, and the Torii integration needs both. They are created on two separate pages, and they are not interchangeable.

API Key Application Key
What it is Identifies your Datadog organization. Identifies who is calling the API and what they are allowed to do.
Where to create it Organization Settings > API Keys Organization Settings > Application Keys
Belongs to The organization. The user who created it. If that user is disabled in Datadog, the key stops working and the Torii sync fails.
Has permission scopes? No. Yes — optional. With no scopes selected, the key inherits all the permissions of the user who created it.
How it looks 32 characters. 40 characters.

Quick check: if both values you copied are the same length, you most likely copied the same key twice. The API Key is the shorter one.

Tip: create the Application Key from a Datadog service account rather than from a personal user account. Datadog cannot transfer an application key between users, so a key owned by an employee who later leaves will break the integration.

Prerequisites

The integration requires the following from your account:

  1. Datadog API URL
    Your Datadog API URL is based on the Datadog site you are hosted on.

    For example: for site US1 the URL is https://api.datadoghq.com.
    If you are unsure, this is usually the correct one.
    mceclip4.png
  2. API Key
    In Datadog, go to Organization Settings > API Keys, create a new API key (or reuse an existing one), and copy its value.
    API keys have no scopes — there is nothing to configure here.
    mceclip2.png mceclip9.png
  3. Application Key
    In Datadog, go to Organization Settings > Application Keys, create a new application key, and copy its value. The full value is shown only once, at creation time.
    mceclip3.png

    Scopes: leaving the key unscoped is the simplest option — it then inherits the permissions of the user who created it. If your security policy requires a scoped key, select:
    For a read-only integration: user_access_read.
    For a read and take action integration, add: user_access_invite and user_access_manage.

    The org_management scope is optional. Provide it to let Torii detect your organization name automatically; otherwise enter the organization name manually (see below).
  4. Organization Name (optional)
    If you prefer not to provide the org_management scope, you can instead manually enter your Datadog organization name.
    This field is optional, but if used, make sure to enter the organization name exactly as it appears in your Datadog account.

Connect Datadog integration to Torii

  1. Go to the Integrations page and select the Datadog tile.
  2. Click Connect to Datadog
    mceclip5.png
  3. In the Connect Datadog window, enter your Datadog API URL, API Key, and Application Key. Make sure each key goes into its matching field — swapping them is the most common cause of a failed connection.
    If you are not providing the org_management scope, please fill in the Organization Name field manually.
    mceclip7.png
  4. Click Connect
    mceclip6.png
  5. Once the integration is connected and synced, it will display a green checkbox.
    mceclip10.png

Troubleshooting

Error What to do
The provided "API key" or "Application key" are invalid One of the two values is wrong, or the two were swapped between the fields. Re-copy both from Datadog: the API Key from Organization Settings > API Keys and the Application Key from Organization Settings > Application Keys.
The provided "Application key" is invalid The Application Key was deleted, or the Datadog user who owns it was disabled. Create a new Application Key (preferably from a service account) and reconnect.
Insufficient permissions (HTTP error 403) / Missing scopes The Application Key is scoped, but is missing a scope the integration needs. Either remove all scopes from the key, or create a new Application Key with the scopes listed in the Prerequisites section above.

Application Capabilities

You can constantly be updated with application information from our Integrations page >> Integration Capabilities button >> Integration Capabilities table.
mceclip11.png

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request