Connect Dynatrace
Last updated: September 4, 2026
The Dynatrace connector lets Rhythms read operational, reliability and observability data from your Dynatrace environment as context in chat and documents. Dynatrace's MCP server lives in your own environment, so a Rhythms Admin adds it once with OAuth client credentials created in Dynatrace, and then each person connects their own Dynatrace account.
Rhythms uses Dynatrace's recommended approach for MCP integrations: a confidential OAuth client with the Authorization Code grant. Tokens refresh automatically and each user's access stays scoped to their own Dynatrace permissions. For Dynatrace's own reference, see the Dynatrace MCP server documentation.
Step 1: Create an OAuth client in Dynatrace (admin)
- In Dynatrace, go to Account Management › Identity & Access Management › OAuth clients.
- Create a confidential OAuth client with the Authorization Code grant type.
- Add
https://app.rhythms.ai/mcp/auth/callbackas a redirect URI (Rhythms shows the exact callback URL for your environment in the connector dialog). - Set the logout URL to
https://rhythms.ai. - Grant the client the scopes Rhythms requests (listed under Permissions below).
- Copy the Client ID and Client Secret.
- Note your environment's MCP URL. It follows this pattern:
https://<environment-name>.apps.dynatrace.com/platform-reserved/mcp-gateway/v0.1/servers/dynatrace-mcp/mcp
Step 2: Add the connector in Rhythms (admin)
- Go to Settings › Workspace › Connectors and select the Dynatrace tile. The Add Dynatrace connector dialog opens.
- Give the connector a name and paste your environment's MCP URL into Dynatrace MCP URL.
- Expand Advanced settings and enter the Client ID and Client Secret from Dynatrace. Both are required for Dynatrace.
- Click Connect and sign in to Dynatrace to authorize.
By default only Rhythms Admins can add connectors of this kind; an admin can allow all members to do so from the Connectors settings page.
Step 3: Individual users connect
Once the connector exists, each person opens My connectors, finds Dynatrace, clicks Connect and signs in to Dynatrace with their own account. Nobody else needs the client secret.
Permissions
Rhythms requests these scopes, so the OAuth client must be allowed to issue them:
mcp-gateway:servers:invoke, mcp-gateway:servers:read, ai:operator:execute, davis-copilot:conversations:execute, davis-copilot:nl2dql:execute, davis-copilot:dql2nl:execute, davis-copilot:document-search:execute, davis:analyzers:read, davis:analyzers:execute, document:documents:read, storage:bizevents:read, storage:buckets:read, storage:system:read, storage:spans:read, storage:entities:read, storage:user.events:read, storage:user.sessions:read, storage:user.replays:read, storage:smartscape:read
A user's effective access is the intersection of these scopes and that user's own Dynatrace permissions.
Troubleshooting
- If the connection fails, first check that the OAuth client allows every scope above and that the redirect URI matches exactly.
- Then check that the Client ID and Client Secret entered under Advanced settings are correct. Wrong scopes and wrong credentials are the two most common causes.