Documentation for automated readers
A curated documentation index is available at: https://grafana.com/llms.txt
A complete documentation index is available at: https://grafana.com/llms-full.txt
These indexes can help with page discovery before fetching individual documents.
This page is also available in Markdown, which may be easier for automated readers and AI tools to parse than HTML. The Markdown version is available at https://grafana.com/docs/grafana-cloud/send-data/logs/authenticate-to-query-logs.md, or by sending Accept: text/markdown to https://grafana.com/docs/grafana-cloud/send-data/logs/authenticate-to-query-logs/. For broader documentation discovery, the curated index is available at https://grafana.com/llms.txt and the complete index is available at https://grafana.com/llms-full.txt.
Authenticate to query Cloud Logs
Use the Loki HTTP API to query and troubleshoot your Grafana Cloud Logs data without using Grafana Explore. This is useful when you need to automate diagnostics, run long-running queries, or integrate log queries into your own tooling.
Before you begin
Ensure you have the following:
- A Grafana Cloud access policy token with
logs:readscope. curlinstalled.
Find your Loki endpoint in the Cloud Portal
You find your Loki endpoint URL and User ID in the Cloud Portal:
Sign in to the Cloud Portal.
Open your stack.
In the Loki card, click Details.
From the details page, copy the values you need:
- The Loki URL.
- The User value for the endpoint (your Loki instance ID, also called the tenant ID).
For more information, refer to Find instance endpoints.
Note
Grafana Cloud URLs use one of two formats depending on when your region was created. If you need to construct a URL manually instead of copying it from the portal, refer to Determine Grafana Cloud URLs based on region.
Create an access policy and token
To query Cloud Logs using the HTTP API, you need a Grafana Cloud access policy token with the logs:read scope.
For the full procedure to create an access policy and generate a token, refer to Create access policies and tokens.
Authenticate to the API
Grafana Cloud Logs uses HTTP Basic Authentication for the Loki HTTP API:
- Username: your Loki instance ID (the endpoint User value).
- Password: your Grafana Cloud access policy token.
For example, set a LOGIN variable:
LOGIN="<LOKI_INSTANCE_ID>:<CLOUD_ACCESS_POLICY_TOKEN>"Then use it with curl -u to query logs:
curl -s -u "$LOGIN" \
-G "<LOKI_URL>/loki/api/v1/query_range" \
--data-urlencode 'query={job="varlogs"}' | jqNote
Some Cloud Logs API endpoints (such as the self-serve settings API) show examples using an
Authorization: Bearer <LOKI_INSTANCE_ID>:<CLOUD_ACCESS_POLICY_TOKEN>header instead ofcurl -u. Both forms authenticate the same way;curl -uis the more common convention and is used throughout this page.
Common errors
- 401 Unauthorized: The Loki instance ID (username) is incorrect, or the access policy token is invalid, expired, or revoked.
- 403 Forbidden: The access policy associated with the token doesn’t include the
logs:readscope, or a label policy on the access policy excludes the labels in your query.
Next steps
- For the full set of query and management endpoints, refer to the Loki HTTP API reference.
- To remove sensitive or unwanted log lines using the delete API (which uses the same authentication pattern with a
logs:deletescope), refer to Delete unwanted information in log lines.
Was this page helpful?
Related resources from Grafana Labs


