Skip to Content

PagerDuty

The PagerDuty enables tools and to call PagerDuty APIs  on behalf of a using OAuth 2.0 authentication.

The Arcade PagerDuty MCP server requests granular PagerDuty scopes, so register a Scoped OAuth app and grant it the scopes listed under Permissions. See the PagerDuty OAuth documentation .

Want to quickly get started with PagerDuty in your or AI app? The pre-built Arcade PagerDuty MCP Server is what you want!

What’s documented here

This page describes how to use and configure PagerDuty auth with Arcade.

This is used by:

Configuring PagerDuty auth

When using your own app credentials, make sure you configure your to use a custom user verifier. Without this, your end-users will not be able to use your app or in production.

In a production environment, you will most likely want to use your own PagerDuty app credentials. This way, your will see your application’s name requesting permission.

Before showing how to configure your PagerDuty app credentials, let’s go through the steps to create a PagerDuty app.

Create a PagerDuty app

To integrate with PagerDuty’s API using OAuth 2.0, register an app in your PagerDuty . App Registration requires a base role of Manager, Global Admin, or Account Owner.

Open App Registration

  1. Log in to your PagerDuty .
  2. From the top menu, select Integrations → Developer → App Registration.

Create a new app

  1. On the My Apps page, click New App.
  2. Enter a name and a brief description, and complete the rest of the wizard.

Add Scoped OAuth

  1. Select your app on the My Apps page to open its configuration page.
  2. In the Functionality section, click Add on the OAuth 2.0 card.
  3. On the Configure OAuth 2.0 screen, choose Scoped OAuth and select the scopes listed under Permissions, plus any scopes your custom need.
  4. Add the Redirect URI generated by Arcade (see configuration section below) to your app’s redirect URLs.
  5. Click Save.

Save your credentials

  1. Copy the Client ID and Client Secret that PagerDuty issues.
  2. Important: Save these credentials immediately, as the Client Secret won’t be accessible again.

Arcade doesn’t use the separate Events Integration functionality, so you can skip it.

Scoped OAuth apps are confidential clients: PagerDuty requires the client secret and PKCE on every authorization. Arcade’s included PagerDuty provider sends both.

A Scoped OAuth app works right away on the PagerDuty that registered it. To authorize on other PagerDuty accounts, PagerDuty must publish the app, and an administrator on each of those accounts must install it.

For details, refer to PagerDuty’s Register an App  and OAuth Functionality  guides.

Next, add the PagerDuty app to Arcade.

Configuring your own PagerDuty Auth Provider in Arcade

Configure PagerDuty Auth Using the Arcade Dashboard GUI

Access the Arcade Dashboard

To access the Arcade Cloud dashboard, go to api.arcade.dev/dashboard . If you are self-hosting, by default the dashboard will be available at http://localhost:9099/dashboard . Adjust the host and port number to match your environment.

  • Under the Connections section of the Arcade Dashboard left-side menu, click Connected apps.
  • Click Add OAuth Provider in the top right corner.
  • Select the Included Providers tab at the top.
  • In the Provider dropdown, select PagerDuty.

Enter the provider details

  • Choose a unique ID for your provider (e.g. “my-pagerduty-provider”).
  • Optionally enter a Description.
  • Enter the Client ID and Client Secret from your PagerDuty app.
  • Note the Redirect URI generated by Arcade. This must be set as one of your PagerDuty app’s Redirect URLs.

Create the provider

Hit the Create button and the provider will be ready to be used.

When you use tools that require PagerDuty auth using your Arcade credentials, Arcade will automatically use this PagerDuty OAuth provider. If you have multiple PagerDuty providers, see using multiple auth providers of the same type for more information.

Using PagerDuty auth in app code

Use the PagerDuty in your own and AI apps to get a token for the PagerDuty API. See authorizing agents with Arcade to understand how this works.

Use client.auth.start() to get a token for the PagerDuty API:

Python
from arcadepy import Arcade client = Arcade() # Automatically finds the `ARCADE_API_KEY` env variable user_id = "{arcade_user_id}" # Start the authorization process auth_response = client.auth.start( user_id=user_id, provider="pagerduty", scopes=["users.read"], ) if auth_response.status != "completed": print("Please complete the authorization challenge in your browser:") print(auth_response.url) # Wait for the authorization to complete auth_response = client.auth.wait_for_completion(auth_response) token = auth_response.context.token # Do something interesting with the token...

Using PagerDuty auth in custom tools

You can use the pre-built Arcade PagerDuty MCP Server to quickly build and AI apps that interact with PagerDuty.

If the pre-built tools in the PagerDuty Server don’t meet your needs, you can author your own custom tools that interact with the PagerDuty API.

Use the PagerDuty() auth class to specify that a requires authorization with PagerDuty. The context.authorization.token field will be automatically populated with the ’s PagerDuty token:

Python
from typing import Annotated import httpx from arcade_mcp_server import Context, tool from arcade_mcp_server.auth import PagerDuty @tool( requires_auth=PagerDuty( scopes=["users.read"], ) ) async def get_current_user( context: Context, ) -> Annotated[dict, "The current user information."]: """ Retrieve information about the authenticated user from PagerDuty. """ url = "https://api.pagerduty.com/users/me" headers = { "Authorization": f"Bearer {context.authorization.token}", "Accept": "application/vnd.pagerduty+json;version=2", } async with httpx.AsyncClient() as client: response = await client.get(url, headers=headers) response.raise_for_status() return dict(response.json())

Permissions

The Arcade PagerDuty server requests these PagerDuty scopes:

  • escalation_policies.read
  • incidents.read
  • incidents.write
  • oncalls.read
  • schedules.read
  • services.read
  • teams.read
  • users.read
  • users:contact_methods.read

The PagerDuty API reference  lists the scope each endpoint requires. For more details, refer to PagerDuty’s Private Apps  guide.

Troubleshooting

  • Arcade asks the to authorize again after every sign-in: PagerDuty doesn’t reject a scope the app isn’t registered for. It issues a token with only the openid scope instead, so Arcade keeps prompting. Check that the app uses Scoped OAuth, not Classic User OAuth, and that it’s registered with every scope listed under Permissions.
Last updated on