Appendix K - Creating Datadog API and Application Keys

Playblocks uses three Datadog assets:
  • API key - An organization-level key that you generate under Organization Settings > API Keys. It identifies your Datadog organization on every request.

  • Application key - A key that you generate under Organization Settings > Application Keys, scoped to the On-Call permissions.

    Datadog sends both keys together on every request:

    • API key identifies the organization.

    • Application key carries the permissions that authorize the action.

  • API base URL - The regional Datadog endpoint that hosts your organization.

Procedure:
  1. Generate an API key:
    1. Sign in to Datadog as an account administrator.
    2. Go to Organization Settings > Access > API Keys.

    3. Click New Key.

      The New API Key window appears.

    4. In the Name field, enter a name, for example Playblocks.

      This helps you identify the key if you need to rotate or revoke it.

    5. Click Create Key.

    6. Click Copy to copy the key.
      Important:
      The key appears only once. Copy and save it immediately. You cannot retrieve it later.
    7. Click Finish.
  2. Generate an application key with On-Call scopes:
    1. Go to Organization Settings > Access > Application Keys.
    2. Click New Key.

      The New Key window appears.

    3. In the Name field, enter a name. For example, Playblocks.

    4. Click Create Key.

    5. In the Scope section, click Edit.

      The Edit Key Scope window appears.

    6. In the search field, search and select these scopes:
      • on_call_page - Authorizes Playblocks to open a page.
      • on_call_respond - Authorizes Playblocks to acknowledge and resolve a page
        Note:
        To support Datadog paging requests, Playblocks requires both scopes. Requests fail if either scope is missing, even when the API key is valid.
    7. Click Save.
    8. Click Copy to copy the key.
      Important:
      The key appears only once. Copy and save it immediately. You cannot retrieve it later.
    9. Click Finish.
  3. Identify the correct API base URL.
  4. Verify that Datadog On-Call is configured:
    1. Playblocks pages a Datadog On-Call team or user. Before you configure the connector, confirm that your Datadog account has an On-Call team with an escalation policy and routing rules.

      To create an escalation policy:

      1. Go to Incident Response > Teams.
      2. From the Add Team to On-Call list, select New team.

      3. In the Team Name field, enter a name for the team.

      4. Click Create Team.
      5. In the How do you want to manage Incoming alerts section, select All alerts to escalation policy.

      6. Click Next.
      7. In the Set targets section, from the Escalation Policy list, select New Escalation Policy.

      8. In the Name field, enter a name for the policy.

      9. Click Create Escalation Policy.
    2. Check the URL of the Datadog team page in your browser’s address bar and note the team ID for the team you want Playblocks to page.

      Note:

      If On-Call is not configured, the connector still connects, but the Trigger Alert step cannot deliver a page.