# How to connect New Relic to Hermes Agent (paste one key, 158 tools)

> Connect New Relic to Hermes with ClawLink: paste your New Relic key once and 158 tools work from chat. No MCP server to run, nothing stored on your machine.

Web version: https://claw-link.dev/hermes/new-relic

Most guides for giving Hermes Agent New Relic access start with registering your own OAuth app or pasting API keys into env files, then leave the token refresh and tool wiring to you. ClawLink gives Hermes a more practical New Relic setup: pair once in the browser and your always-on Hermes agent can act on New Relic for you, reading and doing real work on your behalf with no auth, token refresh, or tool wiring to build yourself.

**Start here — paste this into Hermes to set up ClawLink:**

> Set up ClawLink for Hermes and tell me when it's ready.
> 1. Install the plugin: `hermes plugins install ClawLink-HQ/hermes-plugin --enable`
> 2. Start pairing with `hermes clawlink begin`. It prints an approval link, so show me the link and stop, don't wait.
> 3. I'll approve it in my browser, then reply "approved".
> 4. When I say approved, finish setup: `hermes clawlink finish`
> 5. Then run `hermes clawlink test` and tell me whether ClawLink is ready.

## Setup

It takes three steps to connect Hermes to New Relic.

1. **Install ClawLink** — add the plugin to Hermes Agent once.
2. **Connect New Relic** — one-click OAuth in the ClawLink dashboard.
3. **Use it from chat** — ask Hermes Agent in plain English.

**Alternative for any agent (no plugin needed):** if the Hermes Agent plugin route isn't available or doesn't work, any AI agent with shell access can use the ClawLink CLI instead:

```bash
npx -y @useclawlink/cli login          # sign in via browser — no API key to paste
npx -y @useclawlink/cli connect new-relic  # connect New Relic (browser OAuth)
npx -y @useclawlink/cli actions new-relic  # list available actions
npx -y @useclawlink/cli run new-relic <action> --input '<json>'  # execute (add --confirm for writes)
```

### Install by command

The prompt above walks Hermes through this. By hand, it is four commands and a browser approval:

```bash
hermes plugins install ClawLink-HQ/hermes-plugin --enable
hermes clawlink begin    # prints an approval link — open it and approve
hermes clawlink finish   # after approving in the browser
hermes clawlink test
```

Then connect New Relic in the [ClawLink dashboard](https://claw-link.dev/dashboard) — paste your New Relic API key once.

Verify the connection by asking Hermes:

> Use new_relic_execute_nrql_query to find the error rate for \<app name> over the last 24 hours, broken down by hour. Show me the NRQL before you run it.

### Using a different agent?

The Hermes plugin is one client of ClawLink's MCP server. Claude Code, Cursor, Codex, or any agent that can run a shell command pairs with the same ClawLink account through the CLI:

```bash
npx -y @useclawlink/cli login
```

`login` opens the same browser approval and stores a credential locally. Once New Relic is connected in the dashboard, that agent calls the same 158 New Relic tools over MCP. Full setup for MCP clients and shell agents: [connect apps to any AI agent](https://claw-link.dev/learn/connect-apps-to-any-ai-agent).

## New Relic MCP for Hermes

Looking for a New Relic MCP server for Hermes Agent? ClawLink connects New Relic to Hermes Agent and exposes 158 New Relic tools your agent can call over [MCP](https://claw-link.dev/learn/what-is-an-mcp-server), with [hosted auth](https://claw-link.dev/learn/oauth-for-ai-agents) and nothing to run or maintain yourself. Using OpenClaw instead? The [OpenClaw New Relic integration](https://claw-link.dev/openclaw/new-relic) works the same way.

Hermes Agent — the MCP-native runtime from Nous Research, not the OpenTelemetry agent of the same name — has no built-in New Relic integration, which is why search results keep saying one does not exist. This is the route that gives it one. New Relic authenticates with an API key, so you do paste a key; what you skip is everything after it. There is no MCP server to run, no `config.yaml` to edit, and no key sitting in an environment file on a machine you have to keep in sync. You paste it once into the hosted setup page, pair Hermes with `hermes clawlink begin` and `hermes clawlink finish`, and the 158 New Relic tools below are callable from chat.

## What the Hermes Agent New Relic integration can do

158 New Relic tools are ready for Hermes Agent once the account is connected. The 30 below are the ones people reach for most; your agent can call all 158.

### 30 of 158 New Relic tools for Hermes

| Tool | What it does |
|---|---|
| **Add notification channels to policy** `new_relic_add_notification_channels_to_policy` | Tool to add notification channels to an alert policy using the NerdGraph GraphQL API. |
| **Add tags to entity** `new_relic_add_tags_to_entity` | Tool to add tags with values to a specific New Relic entity via NerdGraph GraphQL API. Use when you need to organize and categorize entities for filtering and organization. |
| **Add widgets to dashboard page** `new_relic_add_widgets_to_dashboard_page` | Tool to add widgets to an existing New Relic dashboard page via NerdGraph GraphQL API. |
| **Configure cloud integration** `new_relic_configure_cloud_integration` | Tool to enable and configure cloud integrations for monitoring in New Relic. Use this to set up monitoring for AWS, Azure, or GCP services. |
| **Create AI notifications channel** `new_relic_create_ai_notifications_channel` | Tool to create a New Relic AI Notifications channel via NerdGraph GraphQL API. Use when setting up notification channels for Applied Intelligence alerts. |
| **Create AI notifications destination** `new_relic_create_ai_notifications_destination` | Tool to create an AI notifications destination in New Relic for services like Jira or ServiceNow. Use when you need to configure a new notification endpoint for AI-powered alerts. |
| **Create AI workflow** `new_relic_create_ai_workflow` | Tool to create an AI workflow for automated incident response in New Relic. Use when you need to set up automated notifications and enrichments for specific types of issues based on filtering rules. |
| **Create alert channel** `new_relic_create_alert_channel` | Tool to create an alert notification channel. Use when you need to register a new endpoint (email, webhook, etc.) for alert notifications. |
| **Create alert policy** `new_relic_create_alert_policy` | Creates a new alert policy in New Relic. Alert policies are containers for alert conditions and define how incidents are grouped. |
| **Create alerts nrql condition static** `new_relic_create_alerts_nrql_condition_static` | Tool to create a static NRQL alert condition using New Relic's NerdGraph GraphQL API. Use when you need to set up monitoring for specific NRQL query results with threshold-based alerting. |
| **Create alerts policy graphql** `new_relic_create_alerts_policy_graphql` | Tool to create a new alert policy using New Relic's NerdGraph GraphQL API. Use when you need to create a container for grouping alert conditions. |
| **Create API access keys** `new_relic_create_api_access_keys` | Tool to create New Relic API access keys using NerdGraph. Use when you need to generate user API keys or ingest keys (BROWSER or LICENSE types). Maximum 1,000 keys per ingest key type allowed. |
| **Execute nrql query** `new_relic_execute_nrql_query` | Execute NRQL queries to retrieve data from New Relic via NerdGraph GraphQL API |
| **Fetch browser configuration** `new_relic_fetch_browser_configuration` | Fetch browser application configuration via New Relic's NerdGraph GraphQL API |
| **Fetch browser java script snippet** `new_relic_fetch_browser_java_script_snippet` | Fetch the JavaScript loader script snippet for a New Relic browser application |
| **Fetch mobile application token** `new_relic_fetch_mobile_application_token` | Fetch mobile application token for a given mobile app entity GUID via New Relic's NerdGraph |
| **Fetch rules collection** `new_relic_fetch_rules_collection` | Fetch rules from a New Relic collection (Scorecard) via NerdGraph GraphQL API |
| **Fetch your org ID** `new_relic_fetch_your_org_id` | Fetch your organization ID and name via New Relic's NerdGraph GraphQL API |
| **Get alert channels** `new_relic_get_alert_channels` | Retrieves a paginated list of alert notification channels configured in your New Relic account |
| **Get alert conditions** `new_relic_get_alert_conditions` | Retrieve alert conditions for a specified policy |
| **Get alert policies** `new_relic_get_alert_policies` | Retrieve a list of alert policies |
| **Get alerts violations json** `new_relic_get_alerts_violations_json` | Retrieve a list of alert violations from New Relic |
| **Get app metric data** `new_relic_get_app_metric_data` | Retrieve metric timeslice data for a New Relic application |
| **Get app metrics names** `new_relic_get_app_metrics_names` | Retrieve a list of available metric names for a New Relic application |
| **Get applications** `new_relic_get_applications` | Retrieve a list of New Relic applications |
| **Get browser applications** `new_relic_get_browser_applications` | List New Relic browser applications |
| **Get dashboard entity query** `new_relic_get_dashboard_entity_query` | Query detailed information about a New Relic dashboard entity using its GUID via NerdGraph |
| **Get infra condition** `new_relic_get_infra_condition` | Retrieve details for a specific infrastructure alert condition |
| **Get lookup table** `new_relic_get_lookup_table` | Download a lookup table that was previously uploaded to New Relic |
| **Get mobile application** `new_relic_get_mobile_application` | Retrieve details for a specific New Relic mobile application including crash count and crash |

## Example prompts

**Ask a real question with NRQL**

> Use new_relic_execute_nrql_query to find the error rate for \<app name> over the last 24 hours, broken down by hour. Show me the NRQL before you run it.

**Triage a slow service**

> Find \<app name> with new_relic_get_applications, then pull its key metrics with new_relic_get_app_metric_data for the last day and tell me what changed compared with the previous day.

**Review what is alerting**

> List my alert policies with new_relic_get_alert_policies and current violations with new_relic_get_alerts_violations_json. Tell me what is firing and which policy owns it. Do not change anything.

**Draft an alert condition before creating it**

> Propose an NRQL alert condition for \<app name> that fires when the error rate exceeds 2% for 5 minutes. Show me the exact condition you would create with new_relic_create_alerts_nrql_condition_static, and wait for my approval before creating it.

## How the New Relic tools behave

What decides whether a New Relic prompt answers the question or quietly returns nothing.

- **`new_relic_execute_nrql_query` is the workhorse.** Most real questions are an NRQL query, not a dedicated tool. Ask the agent to show the NRQL before running it — that is where the mistakes are visible.
- **NRQL needs an explicit SINCE for anything but the recent past.** Without one, a question about last month silently answers about the last hour.
- **Entities are resolved before they are read.** `new_relic_get_applications` and the entity search tools return the identifiers the metric tools need; a guessed application name or GUID fails.
- **Alerting tools change who gets paged.** Creating policies, NRQL conditions, notification channels, and workflows are all real writes. Review before approving.
- **`new_relic_create_api_access_keys` mints credentials.** Treat it as the most privileged tool in the set and do not leave it reachable by an open-ended instruction.
- **Account scope matters in multi-account orgs.** `new_relic_fetch_your_org_id` plus the application list is the quickest way to confirm the agent is looking where you think it is.

## ClawLink vs. building it yourself

The alternative to ClawLink is usually manual API key setup plus your own token handling, permission troubleshooting, and tool plumbing for Hermes Agent. That is fine if you want to build and maintain the integration yourself. Most teams just want New Relic working from chat.

| | Manual | ClawLink |
|---|---|---|
| **Credential handling** | Collect, validate, store, and rotate the New Relic API key yourself, then make sure every tool call uses the right account. | Users complete the hosted ClawLink setup once and the connected New Relic account becomes available to the agent without you building credential management. |
| **Ongoing maintenance** | You own refresh logic, permission debugging, environment config, and every provider-specific edge case for New Relic. | ClawLink handles the repetitive integration plumbing so your team can focus on the workflow instead of the infrastructure. |
| **Agent usability** | You still need to expose the right New Relic actions to the runtime in a format your agent can reliably use. | 158 tools for New Relic are already exposed through ClawLink, so the agent can read and act from chat immediately. |

## ClawLink vs. Composio

Composio also exposes New Relic to AI agents. It is developer infrastructure: Python and TypeScript SDKs, an MCP server, and a catalog past 1,000 apps, aimed at teams shipping agent products. ClawLink is built for Hermes Agent users instead. You install the plugin once, connect New Relic in the browser, and the 158 tools above work from chat. There is no SDK and no config file, and the New Relic key you paste at setup is stored server-side rather than kept in your environment. Choosing between them? Read the full [Composio alternatives](https://claw-link.dev/hub/composio-alternatives) comparison.

### Hermes paired but still can't use New Relic
Pairing is a two-step handshake: run `hermes clawlink begin`, approve the link in your browser, then run `hermes clawlink finish`. If you ran finish before approving, or the approval link expired, run `hermes clawlink begin` again to get a fresh link. Confirm the plugin was installed with `--enable`, then verify with `hermes clawlink test`.

### Connection succeeds but no tools appear
Reconnect New Relic from the dashboard, then start a fresh chat if the runtime still has the old tool catalog loaded.

### "Tool schema not loaded yet" error when calling New Relic tools
New Relic tool schemas load on demand the first time a tool runs and are cached after that, so this error usually clears on its own: wait a few seconds and retry the same request. If every New Relic call keeps failing with it in a fresh chat, reconnect from the dashboard, and contact support if it still persists — that pattern points to a configuration problem on our side, not something you can fix by reconnecting again.

### New Relic returns 403 or "permission denied" on one action while others work
Two usual causes. The connected account may not have access to the specific workspace, inbox, store, or project in the request — check that first. If access looks right, the agent may have sent a placeholder value (like "YOUR_ID" or an example id from documentation) instead of a real one: ask it to run a list or search tool first, then retry the action with a real id from those results. Most failures at this stage are one of these two, not ClawLink bugs.

### New Relic returns 401 Unauthorized or 403 although the connection shows as connected
Start with the key rather than the connection, because this is a key-based integration and "connected" only means a key was accepted at setup time. If the key was rotated or deleted in New Relic afterwards, every call fails from that moment and re-pasting the current key from the dashboard is the fix. If only some calls fail, the key is alive and you are looking at permissions: New Relic scopes access by the user the key belongs to, so a key from a read-only user queries fine and fails on anything that creates a policy or a key. The third cause is account selection — New Relic organisations can hold several accounts, and a key tied to one account returns permission errors for entities that live in another, which looks like a broken integration but is not.

Ask the agent to diagnose it:

```text
Call new_relic_fetch_your_org_id and new_relic_get_applications, and tell me which org and account this connection can actually see. Then quote the exact error from the failed call. Do not retry it yet.
```

### An NRQL query returns no data although the chart in New Relic shows some
Usually the account or the window rather than the query. NRQL runs against a specific account, so a query issued against the wrong one in a multi-account organisation returns an empty result rather than an error. The second cause is the time window: NRQL defaults to a recent window unless a SINCE clause is given, so a question about last month returns nothing unless the agent says so explicitly. The third is retention — data older than your plan's retention period is genuinely gone and no query will find it. Ask the agent to show you the NRQL it is about to run, including the SINCE clause, before you debug anything else.

Ask the agent to diagnose it:

```text
Show me the exact NRQL you ran, including the SINCE clause and which account it targeted. Then re-run it with SINCE 7 days ago and tell me what changes.
```

### New Relic tools are missing or one tool name is not found
Two different problems. If Hermes has no New Relic tools at all, the connection or the pairing is incomplete — confirm the plugin was installed with `--enable`, that `hermes clawlink begin` and `hermes clawlink finish` both ran, and that New Relic shows as connected in the dashboard. If most tools work and one name fails, that name is wrong rather than missing and the error lists the closest real ones. There is also a timing case specific to this setup: schemas load on demand, so the first New Relic call in a fresh session can arrive before the catalog and simply needs a retry. None of these are fixed by editing a client config file, which is what most search results for this symptom assume.

Ask the agent to diagnose it:

```text
List the New Relic tools you actually have access to. If there are none, say so plainly. If there are, tell me which one runs an NRQL query and use that exact name.
```

### API key setup works but results look incomplete
Double-check that the API key for New Relic has the right scopes or account access. A valid key can still be too limited for some reads or writes.

### Is there a Hermes Agent New Relic integration?
Yes. ClawLink is the fastest way to connect Hermes to New Relic: link your New Relic account once in the browser and Hermes Agent can call the New Relic API through 158 ready-made tools — no custom code or token handling.

### How do I connect New Relic to Hermes with ClawLink?
Install the plugin with `hermes plugins install ClawLink-HQ/hermes-plugin --enable`, then pair once: run `hermes clawlink begin`, approve the link in your browser, and run `hermes clawlink finish`. Connect New Relic in the dashboard and Hermes can use it from the next message — no config files, and the New Relic key you paste is stored server-side instead of in your environment.

### How long does it take to connect New Relic to Hermes Agent?
About two minutes. Sign in, click Connect next to New Relic in the dashboard, authenticate, and Hermes Agent can use it from the next chat message.

### Why use ClawLink instead of wiring New Relic up myself?
The alternative to ClawLink is usually manual API key setup plus your own token handling, permission troubleshooting, and tool plumbing for Hermes Agent. That is fine if you want to build and maintain the integration yourself. Most teams just want New Relic working from chat.

### Does Hermes Agent have a New Relic integration?
Not natively, and that is the answer most sources stop at. Hermes ships without New Relic tools, so they have to come from somewhere — the usual suggestions are running an MCP server yourself and pointing Hermes at it, or wiring the New Relic API in by hand. Installing the ClawLink plugin gives Hermes the tools directly: one plugin install, one pairing handshake, one key pasted in the browser, and the tools appear in chat. Nothing runs on your machine afterwards.

### Which New Relic key do I need, and where does it go?
New Relic issues several kinds of key for different jobs, and the one that matters here is a User key, which is what the REST and NerdGraph APIs accept for querying and managing your account. It goes into the hosted setup page once, and then lives server-side rather than in an environment variable or a config file. The practical consequences are worth knowing: if you rotate the key in New Relic you update it in one place, and if you remove the connection from the ClawLink dashboard the agent loses access immediately rather than whenever someone remembers to clean up a `.env`.

### Can the agent run NRQL queries?
Yes, and it is the single most useful tool in the set. new_relic_execute_nrql_query runs NRQL against your account, which is how you get from a vague question to an actual number — error rates over a window, slowest transactions, throughput by host. The rest of the toolset covers the things around it: applications and their metrics, alert policies and conditions, violations, dashboards and widgets, notification channels and workflows, tags, and entity search. Ask for NRQL when you want data, and the entity or alert tools when you want to change configuration.

### Can it change my alerting?
Yes, and that is the part to be deliberate about. The toolset can create alert policies and NRQL conditions, add notification channels to policies, and build AI workflows and destinations — real changes to whether your team gets paged. It can also create API access keys, which is a genuinely privileged action. The agent inherits whatever your New Relic user can do, so if it should not be able to touch alerting, connect a key belonging to a user without those permissions rather than relying on how you word the prompt.

### Hermes paired but still can't use New Relic
Pairing is a two-step handshake: run `hermes clawlink begin`, approve the link in your browser, then run `hermes clawlink finish`. If you ran finish before approving, or the approval link expired, run `hermes clawlink begin` again to get a fresh link. Confirm the plugin was installed with `--enable`, then verify with `hermes clawlink test`.

## Related

- [Hermes GitHub integration](https://claw-link.dev/hermes/github) — Manage repositories, issues, pull requests, and workflows
- [PagerDuty tools](https://claw-link.dev/hermes/pagerduty) — Manage incidents, on-call schedules, and services
- [Connect SafetyCulture](https://claw-link.dev/hermes/safetyculture) — SafetyCulture (formerly iAuditor) is a workplace operations platform that enables teams to conduct digital inspections, manage audits, track issues, schedule tasks, and maintain compliance through mobile and web applications.
