Skip to main content

Grafana

Grafana is an open-source observability platform for visualizing metrics, logs, and traces from many data sources. Its HTTP API exposes administrative resources such as role-based access control (RBAC) roles, role assignments, and resource permissions, allowing you to read and manage access configuration programmatically. This connector uses the Grafana HTTP API to move that access-control data into and out of Nexla.

Grafana icon

Power end-to-end data operations for your Grafana API with Nexla. Our bi-directional Grafana connector is purpose-built for Grafana, making it simple to ingest data, sync it across systems, and deliver it anywhere — all with no coding required. Nexla turns API-sourced data into ready-to-use, reusable data products and makes it easy to send data to Grafana or any other destination. With comprehensive monitoring, lineage tracking, and access controls, Nexla keeps your Grafana workflows fast, secure, and fully governed.

Features

Type: API

SourceDestination

  • Seamless API Integration: Connect to any endpoint as source or destination without coding, with automatic data product creation
  • Visual Composition & Chaining: Build complex integrations using visual templates, chain API calls, and compose workflows with data validation and filtering
  • API Proxy: Expose curated slices of your data securely with a secure and customizable API proxy that validates and transforms data on the fly
  • Request optimization with intelligent batching, retry, and caching to minimize API calls and costs

Prerequisites

Before creating a Grafana credential, you need the base URL of your Grafana instance and an authentication token. Grafana supports two authentication methods for its HTTP API: a service account token (recommended, sent as a bearer token in the Authorization header) and basic authentication using a username and password.

To obtain a service account token, follow these steps:

  1. Sign in to your Grafana instance with an account that has administrator privileges.

  2. Navigate to Administration > Users and access > Service accounts in the Grafana navigation menu.

  3. Click Add service account, enter a name for the service account, and assign a role that grants the permissions required for your use case.

  4. Open the newly created service account and click Add service account token.

  5. Enter a token name, optionally set an expiration date, and click Generate token.

  6. Copy the token immediately and store it securely. The token value is shown only once and cannot be retrieved again after you leave the page.

Note your Grafana Base URL as well (for example, https://your-org.grafana.net for Grafana Cloud, or the address of your self-hosted instance). The base URL is combined with each API path to form the full request URL. Service account tokens are not tied to an individual user, so applications continue to authenticate even if a user is removed. For complete information about authentication and available endpoints, see the Grafana HTTP API documentation and Grafana service accounts documentation.

Authenticate

Credentials required

An authentication method that requires sending a unique secret token with each API request

FieldRequiredSecretDescription
Base URLYesNoThe base URL of your Grafana instance (e.g. https://your-org.grafana.net)
API Key ValueYesYesAn encoded string value used as a secret token to authenticate API requests

Create a credential in Nexla

  1. After selecting the data source/destination type, click the Add Credential tile to open the Add New Credential overlay.

  2. Enter a name for the credential in the Credential Name field and a short, meaningful description in the Credential Description field.

  3. Select the authentication method you want to use. For Api Key, enter the base URL of your Grafana instance in the Base URL field and your service account token in the API Key Value field. For Basic Authentication, enter the Base URL, your Username Or API Key, and your Password.

  4. Enter your Grafana instance address in the Base URL field (for example, https://your-org.grafana.net). This value is combined with each API path to form the full request URL.

    Treat the API Key Value and Password as sensitive information. If a service account token is compromised, revoke it in Grafana under Administration > Users and access > Service accounts and generate a new one.

    For detailed information about authentication methods and available endpoints, see the Grafana HTTP API documentation.

  5. Click the Save button at the bottom of the overlay. The newly added credential will now appear in a tile on the Authenticate screen during data source/destination creation.

Use as a data source

To create a new data flow, navigate to the Integrate section, and click the New Data Flow button. Select the Grafana connector tile, then select the credential that will be used to connect to the Grafana instance, and click Next; or, create a new Grafana credential for use in this flow.

Endpoint templates

Nexla provides pre-built templates that can be used to rapidly configure data sources to ingest data from common Grafana endpoints. Select the endpoint from which this source will fetch data from the Endpoint pulldown menu. Available endpoint templates are listed in the expandable boxes below.

[Rest API] Get all roles

This endpoint template retrieves all RBAC roles defined in your Grafana instance. Use it to inventory the fixed and custom roles that control access to Grafana resources.

  • Optional query parameters let you filter the results, including Delegatable, Includehidden, and Targetorgid.

[Rest API] Create a new custom role

This endpoint template creates a new custom RBAC role in your Grafana instance. Use it when you need to define a role with a specific set of permissions.

  • The role definition is supplied through parameters such as Name, Displayname, Description, Group, Global, Hidden, Uid, and Permissions.

[Rest API] Get a role

This endpoint template retrieves a single RBAC role by its unique identifier, including the permissions assigned to it.

  • Specify the target role using the Roleuid parameter.

[Rest API] Update a custom role

This endpoint template updates an existing custom RBAC role, replacing its definition and permissions with the values you provide.

  • Identify the role with the Roleuid parameter, and supply the updated definition through fields such as Name, Displayname, Description, Group, Global, Hidden, and Permissions.

[Rest API] Get role assignments

This endpoint template retrieves the assignments for a given RBAC role, showing the users, teams, and service accounts the role is assigned to.

  • Specify the target role using the Roleuid parameter.

[Rest API] Set role assignments

This endpoint template sets the complete list of assignments for an RBAC role, replacing any existing assignments for that role.

  • Identify the role with the Roleuid parameter, and provide the assignees through the Users, Teams, and Service Accounts parameters.

[Rest API] Get status

This endpoint template returns the status of the access control (RBAC) system, indicating whether role-based access control is enabled for your Grafana instance.

  • This endpoint requires no additional parameters.

[Rest API] List roles assigned to multiple teams

This endpoint template searches for the roles assigned to multiple teams at once, returning the role assignments for the teams you specify.

  • Scope the search using parameters such as Teamids, Userids, Orgid, and Includehidden.

[Rest API] Get team roles

This endpoint template retrieves the RBAC roles assigned to a specific team.

  • Identify the team with the Teamid parameter, and optionally scope the request with Targetorgid.

[Rest API] List roles assigned to multiple users

This endpoint template searches for the roles assigned to multiple users at once, returning the role assignments for the users you specify.

  • Scope the search using parameters such as Userids, Teamids, Orgid, and Includehidden.

Once the selected endpoint template has been configured, click the Test button to the right of the endpoint selection menu to retrieve a sample of the data that will be fetched. Sample data will be displayed in the Endpoint Test Result panel on the right, allowing you to verify that the source is configured correctly before saving.

Manual configuration

Grafana data sources can also be manually configured to ingest data from any valid Grafana HTTP API endpoint, including endpoints not covered by the pre-built templates, chained API calls, or custom request parameters. Select the Advanced tab at the top of the configuration screen, and follow the instructions in Connect to Any API to configure the API method, endpoint URL, date/time and lookup macros, path to data, metadata, and request headers.

Once all of the relevant settings have been configured, click the Create button in the upper right corner of the screen to save and create the new Grafana data source. Nexla will now begin ingesting data from the configured endpoint and will organize any data that it finds into one or more Nexsets.

Use as a destination

Click the + icon on the Nexset that will be sent to the Grafana destination, and select the Send to Destination option from the menu. Select the Grafana connector from the list of available destination connectors, then select the credential that will be used to connect to the Grafana instance, and click Next; or, create a new Grafana credential for use in this flow.

Endpoint templates

Nexla provides pre-built templates that can be used to rapidly configure destinations to send data to common Grafana endpoints. Select the endpoint to which data will be sent from the Endpoint pulldown menu. Then, click on the template in the list below to expand it, and follow the instructions to configure additional endpoint settings.

[Rest API] Delete a custom role

This endpoint template deletes a custom RBAC role from your Grafana instance using records from a Nexset.

  • Identify the role with the Roleuid parameter, and optionally control the operation with the Force and Global parameters.

[Rest API] Add team role

This endpoint template assigns an RBAC role to a team using records from a Nexset.

  • Identify the team with the Teamid parameter and the role with the Roleuid parameter.

[Rest API] Update team role

This endpoint template updates the full set of RBAC roles assigned to a team, replacing the existing assignments.

  • Identify the team with the Teamid parameter, and provide the roles through Roleuids, along with optional Targetorgid and Includehidden parameters.

[Rest API] Remove team role

This endpoint template removes an RBAC role assignment from a team using records from a Nexset.

  • Identify the team with the Teamid parameter and the role with the Roleuid parameter.

[Rest API] Add a user role assignment

This endpoint template assigns an RBAC role to a user using records from a Nexset.

  • Identify the user with the Userid parameter and the role with the Roleuid parameter, and optionally set the Global parameter.

[Rest API] Set user role assignments

This endpoint template sets the full list of RBAC roles assigned to a user, replacing the existing assignments.

  • Identify the user with the Userid parameter, and provide the roles through Roleuids, along with optional Targetorgid, Global, and Includehidden parameters.

[Rest API] Remove a user role assignment

This endpoint template removes an RBAC role assignment from a user using records from a Nexset.

  • Identify the user with the Userid parameter and the role with the Roleuid parameter, and optionally set the Global parameter.

[Rest API] Set resource permissions

This endpoint template sets the permissions on a specific Grafana resource using records from a Nexset.

  • Identify the target with the Resource and Resourceid parameters, and supply the access rules through the Permissions parameter.

[Rest API] Set resource permissions for a built-in role

This endpoint template sets the permission a built-in role has on a specific Grafana resource using records from a Nexset.

  • Identify the target with the Resource and Resourceid parameters, specify the Builtinrole, and provide the access level through the Permission parameter.

[Rest API] Set resource permissions for a team

This endpoint template sets the permission a team has on a specific Grafana resource using records from a Nexset.

  • Identify the target with the Resource and Resourceid parameters, specify the Teamid, and provide the access level through the Permission parameter.

Manual configuration

Grafana destinations can also be manually configured to send data to any valid Grafana HTTP API endpoint. Select the Advanced tab at the top of the configuration screen, and follow the instructions in Connect to Any API to configure the API method, data format, endpoint URL, request headers, attribute exclusions, record batching, and response webhooks.

Grafana HTTP APIs typically expect JSON format for most operations. For update or delete operations, include the identifier of the target object in the endpoint URL.

Save & activate

Once all endpoint settings have been configured, click the Done button in the upper right corner of the screen to save and create the destination. To send the data to the configured Grafana endpoint, open the destination resource menu, and select Activate.

The Nexset data will not be sent to the Grafana endpoint until the destination is activated. Destinations can be activated immediately or at a later time, providing full control over data movement.