{
  "data": {
    "a": {
      "slug": "azure-mcp",
      "name": "Azure MCP Server",
      "vendor": "Microsoft",
      "vendorUrl": "https://learn.microsoft.com/en-us/azure/developer/azure-mcp-server/",
      "kind": "mcp",
      "category": "infrastructure",
      "summary": "Microsoft's official local MCP server for Azure (`@azure/mcp`, also on NuGet as Azure.Mcp).",
      "url": "https://www.anchorterminal.com/tools/azure-mcp",
      "markdownUrl": "https://www.anchorterminal.com/tools/azure-mcp.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/azure-mcp.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/azure-mcp.json",
      "repo": "https://github.com/microsoft/mcp",
      "license": "MIT",
      "transports": [
        "stdio",
        "streamable-http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@azure/mcp"
        },
        {
          "registry": "nuget",
          "name": "Azure.Mcp"
        }
      ],
      "auth": "mixed",
      "authNotes": "DefaultAzureCredential. Picks up `az login`, the Azure Developer CLI, Visual Studio or VS Code sign-ins, or a service principal from environment variables in CI. No secrets in the MCP config.",
      "pricing": "free",
      "pricingNotes": "Open source under MIT. Azure resource usage is billed by Azure as normal.",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "Local open-source server, no payments.",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 3600,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-09-26"
      },
      "docsUrl": "https://learn.microsoft.com/en-us/azure/developer/azure-mcp-server/tools/",
      "registryName": "com.microsoft/azure",
      "capabilities": [
        "infra.azure",
        "infra.cloud"
      ],
      "tags": [
        "official",
        "open-source",
        "read-only-mode",
        "namespaces",
        "enterprise"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.7,
        "grade": "B",
        "agentReady": false,
        "rank": 221,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 89,
          "payments": 60,
          "reliability": 69,
          "schema": 77,
          "security": 73,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "-2: CVE-2026-26118, published 2026-03-10, CVSS 8.8. Server-side request forgery in Azure MCP Server let an authorised attacker elevate privileges over a network. Fixed and published through MSRC (https://nvd.nist.gov/vuln/detail/CVE-2026-26118).",
          "-2: CVE-2026-32211, published 2026-04-03, CVSS 9.1. Missing authentication for a critical function in Azure MCP Server let an unauthorised attacker disclose information over a network. Fixed and published through MSRC (https://nvd.nist.gov/vuln/detail/CVE-2026-32211).",
          "-1: until 3.0.0-beta.49 on 2026-10-01, `communication_email_send` and `communication_sms_send` were annotated read-only, so they stayed available under `--read-only`, an outbound send path in a mode meant to block writes. Fixed and described in the changelog (https://github.com/microsoft/mcp/blob/main/servers/Azure.Mcp.Server/CHANGELOG.md)."
        ],
        "verdict": "Entra ID through DefaultAzureCredential, so access follows RBAC and no secret sits in the MCP config. npm `latest` installs a 3.0.0 beta, and betas rename and remove tools without a notice period.",
        "bestFor": "Agents inspecting or operating Azure resources under a developer's or service principal's own RBAC.",
        "strengths": [
          "Entra ID through DefaultAzureCredential, so access follows RBAC and no secret sits in the MCP config",
          "`--read-only`, `--namespace`, `--tool`, consolidated and single-tool modes for cutting the surface down",
          "Secret, connection-string and private-key reads ask the user first through elicitation",
          "Destructive, idempotent, read-only and secret metadata on every command",
          "26 releases between 8 July and 1 October 2026, each with a written changelog"
        ],
        "weaknesses": [
          "npm `latest` installs a 3.0.0 beta, and betas rename and remove tools without a notice period",
          "No confirmation step before deletes and other destructive calls",
          "Telemetry to Microsoft is on by default",
          "Two MSRC CVEs in March and April 2026, rated 8.8 and 9.1",
          "Default namespace mode still exposes about 60 tools"
        ],
        "agentNotes": [
          "Start with `--namespace \u003cone or two\u003e --read-only` for inspection and widen only when a task needs a write",
          "Pin a version instead of `@latest`, which is a prerelease",
          "Use `resiliency_*`, not `resilience_*`. The prefix changed on 22 September 2026",
          "Resolve the subscription and resource group once and pass them on every call",
          "Auth failures mean the credential chain found nothing. Run `az login` or set the service-principal variables"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.7
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 89,
          "payments": 60,
          "reliability": 69,
          "schema": 77,
          "security": 73,
          "transparency": 71
        },
        "provenanceScore": 80
      },
      "connect": {
        "claudeCode": "claude mcp add azure -- npx -y @azure/mcp@latest server start --mode namespace --namespace storage --read-only true",
        "config": {
          "mcpServers": {
            "azure": {
              "args": [
                "-y",
                "@azure/mcp@latest",
                "server",
                "start",
                "--mode",
                "namespace",
                "--read-only",
                "true"
              ],
              "command": "npx"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/infra.azure",
        "tool": "https://letme.dev/azure-mcp"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-execution-containers",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-document-intelligence",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "azure-blob-storage",
        "onedrive-sharepoint",
        "microsoft-teams",
        "dynamics-365-sales",
        "power-automate",
        "foundry-local",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "alsoIn": [
        "secrets"
      ],
      "area": "developer",
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "domainNote": "microsoft.com publishes a security.txt, but it passed its Expires date on 2026-09-23.",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "https://microsoft.com/en-us/privacy/privacystatement",
        "statusPage": "",
        "changelog": "https://github.com/microsoft/mcp/blob/main/servers/Azure.Mcp.Server/CHANGELOG.md",
        "securityTxt": "expired",
        "checked": "2026-09-26",
        "score": 80
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/azure-mcp.json",
      "live": {
        "slug": "azure-mcp",
        "versions": [
          {
            "registry": "github",
            "name": "microsoft/mcp",
            "version": "Template.Mcp.Server-0.0.12-alpha.6931953",
            "released": "2026-10-08",
            "seenAt": "2026-10-08T16:01:06.302982896Z"
          },
          {
            "registry": "mcp-registry",
            "name": "com.microsoft/azure",
            "version": "3.0.0-beta.48",
            "seenAt": "2026-10-09T02:57:46.004536428Z"
          },
          {
            "registry": "npm",
            "name": "@azure/mcp",
            "version": "3.0.0-beta.50",
            "seenAt": "2026-10-08T16:01:00.565318863Z"
          }
        ],
        "githubStars": 3746,
        "npmWeekly": 174021,
        "securityTxt": {
          "url": "https://microsoft.com/.well-known/security.txt",
          "state": "expired",
          "expires": "2026-09-23T16:00:00.000Z",
          "checkedAt": "2026-10-08T15:39:08.216544687Z"
        },
        "domain": {
          "domain": "microsoft.com",
          "registered": "1991-05-02",
          "source": "https://rdap.verisign.com/com/v1/domain/microsoft.com",
          "checkedAt": "2026-10-04T13:04:13.488857536Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/microsoft/mcp/main/servers/Azure.Mcp.Server/CHANGELOG.md",
            "kind": "deprecations",
            "status": 304,
            "checkedAt": "2026-10-08T18:24:27.746690229Z",
            "changedAt": "2026-10-07T18:09:16.727396891Z",
            "fingerprint": "adb9677ddf8e"
          },
          {
            "url": "https://microsoft.com/en-us/privacy/privacystatement",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:02.753752276Z",
            "changedAt": "2026-10-08T18:22:02.753752276Z",
            "fingerprint": "8ea78deb0834"
          }
        ],
        "updatedAt": "2026-10-09T02:57:46.004536428Z"
      }
    },
    "answer": "Azure MCP Server scores 67.7 (B) on agent readiness against Railway MCP Server's 56.7 (C), and leads in every scored category.",
    "b": {
      "slug": "railway-mcp-server",
      "name": "Railway MCP Server",
      "vendor": "Railway Corporation",
      "vendorUrl": "https://railway.com",
      "kind": "mcp",
      "category": "infrastructure",
      "summary": "Railway's official MCP server is hosted at mcp.railway.com. It lets an agent list and create projects, redeploy services, manage feature flags and hand multi-step work to Railway's own agent, through OAuth or the Railway CLI.",
      "url": "https://www.anchorterminal.com/tools/railway-mcp-server",
      "markdownUrl": "https://www.anchorterminal.com/tools/railway-mcp-server.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/railway-mcp-server.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/railway-mcp-server.json",
      "repo": "https://github.com/railwayapp/cli",
      "license": "Proprietary hosted server under Railway's Terms of Service. The Railway CLI, which carries the stdio proxy and a separate local MCP server, is MIT",
      "transports": [
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://mcp.railway.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@railway/cli"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth, either handled by the MCP client or reused from a `railway login` session through the CLI. An unauthenticated request answers 401 with a pointer to the protected-resource metadata, which names the authorisation server at backboard.railway.com and one scope, `workspace:member`. The authorisation server supports the authorisation code grant with PKCE (S256), the device code grant, refresh tokens and dynamic client registration. On the consent screen a person picks which workspaces and projects the client reaches. Access tokens last one hour and refresh tokens rotate. Grants are revoked in the dashboard, and there is no revocation endpoint. Project tokens are refused.",
      "pricing": "byo-plan",
      "pricingNotes": "The server itself has no charge. Tools act on a Railway workspace and bill under its plan. A new account gets a 30-day trial with a one-time $5 credit and no card, then the Free plan with $1 of usage a month. Hobby is $5 a month and Pro $20 a month, each with the same amount of usage included, and Enterprise is priced by sales. Usage is metered by the second. The `railway-agent` tool runs Railway's own agent, which is billed for the model tokens it uses at Anthropic's published rates with no markup (checked 2026-10-09).",
      "priceSummary": "Your plan",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the MCP server docs, the CLI docs, llms.txt, auth.md or the pricing file (checked 2026-10-09). Railway can be provisioned through Stripe's Agentic Provisioning Protocol, which is a separate route and not a payment protocol on the MCP endpoint.",
        "endpoints": []
      },
      "toolCount": 11,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 426205,
        "pypiWeekly": null,
        "asOf": "2026-10-09"
      },
      "docsUrl": "https://docs.railway.com/ai/mcp-server",
      "llmsTxt": "https://docs.railway.com/llms.txt",
      "openapi": "https://railway.com/openapi.json",
      "registryName": "com.railway/mcp",
      "capabilities": [
        "infra.cloud",
        "code.deploy",
        "analytics.flags"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "llms-txt",
        "openapi",
        "status-page",
        "soc2",
        "free-tier"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 56.7,
        "grade": "C",
        "agentReady": false,
        "rank": 565,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 59,
          "maintenance": 83,
          "payments": 40,
          "reliability": 60,
          "schema": 56,
          "security": 65,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-09"
        },
        "negative": -4,
        "negativeNotes": [
          "30 March 2026. A CDN configuration change cached GET responses on about 0.05% of Railway domains for 52 minutes, so pages meant for one user may have been served to another. Railway reverted it, purged the cache and published a report the same day. Fixed and documented, so 4 is deducted (https://blog.railway.com/p/incident-report-march-30-2026-authenticated-user-data-cached)."
        ],
        "verdict": "A small hosted server with 11 tools, OAuth grants limited to chosen workspaces and one-hour tokens. Most infrastructure work goes through the `railway-agent` tool, which is billed by model tokens. The hosted server's source and tool schemas are not public, there is no read-only scope, and the status page lists about 25 incidents in 90 days.",
        "bestFor": "Agents that deploy and operate applications on Railway from an editor and are content to hand multi-step work to Railway's own agent.",
        "strengths": [
          "OAuth with PKCE, dynamic client registration and a device code grant. A person picks the workspaces and projects a client reaches.",
          "Access tokens last one hour, refresh tokens rotate, and the CLI route keeps any long-lived credential out of editor configuration.",
          "Eleven tools keep the context cost low, with `railway-agent` taking multi-step work in one call.",
          "The trial needs no card and prices for CPU, memory, volumes and egress are public and metered by the second.",
          "The CLI that carries the proxy had more than 100 tagged releases in 90 days, the latest on 8 October 2026."
        ],
        "weaknesses": [
          "The hosted server's source and tool schemas are not public, so inputs can only be read after signing in.",
          "The MCP resource lists one scope, `workspace:member`, with no read-only grant.",
          "The docs say the server can deploy templates, manage environments and pull variables, but no hosted tool is named for those. They go through `railway-agent` or the local server.",
          "status.railway.com lists about 25 incidents from 11 July to 8 October 2026, most on builds and deployments.",
          "Railway reported a 52-minute CDN caching error on 30 March 2026 that may have shown one user's pages to another."
        ],
        "agentNotes": [
          "Connect to `https://mcp.railway.com` with OAuth, or run `railway mcp` after `railway login`. Project tokens are refused.",
          "Treat `redeploy`, `accept-deploy`, `delete-feature-flag` and `railway-agent` as actions that change production. Confirm the project and environment first.",
          "`railway-agent` spends model tokens billed to the workspace. Use the single-purpose tools for listing and redeploying.",
          "For variables, domains, volumes, logs or metrics as separate tools, use `railway mcp local`, which has a different tool set.",
          "On a 401, follow the `WWW-Authenticate` challenge and run the OAuth flow again. Access tokens expire after one hour."
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 56.7
          }
        ],
        "editorialScores": {
          "ergonomics": 59,
          "maintenance": 83,
          "payments": 40,
          "reliability": 60,
          "schema": 56,
          "security": 65,
          "transparency": 61
        },
        "provenanceScore": 84
      },
      "connect": {
        "install": "railway mcp install",
        "claudeCode": "claude mcp add railway --transport http https://mcp.railway.com",
        "config": {
          "mcpServers": {
            "railway": {
              "url": "https://mcp.railway.com"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/infra.cloud",
        "tool": "https://letme.dev/railway-mcp-server"
      },
      "area": "developer",
      "unitPrices": [
        {
          "item": "Free plan",
          "unit": "month",
          "usd": 0,
          "note": "$1 of usage included"
        },
        {
          "item": "Hobby plan",
          "unit": "month",
          "usd": 5,
          "note": "$5 of usage included"
        },
        {
          "item": "Pro workspace",
          "unit": "month",
          "usd": 20,
          "note": "$20 of usage included"
        },
        {
          "item": "CPU, one vCPU",
          "unit": "month",
          "usd": 20,
          "note": "metered by the second"
        },
        {
          "item": "Memory",
          "unit": "gb-month",
          "usd": 10,
          "note": "metered by the second"
        },
        {
          "item": "Volume storage",
          "unit": "gb-month",
          "usd": 0.15
        },
        {
          "item": "Network egress",
          "unit": "gb",
          "usd": 0.05
        }
      ],
      "provenance": {
        "legalEntity": "Railway Corporation",
        "domain": "railway.com",
        "domainRegistered": "1996-01-09",
        "endpointOnVendorDomain": true,
        "terms": "https://railway.com/legal/terms",
        "privacy": "https://railway.com/legal/privacy",
        "statusPage": "https://status.railway.com",
        "changelog": "https://railway.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-09",
        "notes": [
          "The Terms of Service (effective 20 April 2026) are a contract with Railway Corporation under Delaware law and cover the website, products, services and applications. They incorporate the Privacy Policy, and the DPA supplements them.",
          "The Markdown twins of the terms and the privacy policy are summaries that name the HTML pages as the binding text. The terms were read once from the HTML page. The privacy policy's full text was not read, because the terms forbid scraping pages of the Services.",
          "The MCP server answers at mcp.railway.com and its authorisation server at backboard.railway.com, both railway.com subdomains.",
          "railway.com/.well-known/security.txt answered 404. Security reports go to bugbounty@railway.com and an invite-only Bugcrowd programme.",
          "RDAP for railway.com gives a registration date of 1996-01-09.",
          "The status feed at api.railwaystatus.com is on a second domain of Railway's."
        ],
        "score": 84
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/railway-mcp-server.json",
      "live": {
        "slug": "railway-mcp-server",
        "probe": {
          "target": "https://mcp.railway.com",
          "method": "mcp-initialize",
          "lastAt": "2026-10-09T11:00:34.195930053Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 201,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 217,
          "p95ms24h": 297,
          "samples24h": 36,
          "samples30d": 36,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 36,
              "ok": 36
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.railway.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:28.33749143Z"
        },
        "updatedAt": "2026-10-09T11:00:34.195930053Z"
      }
    },
    "facts": [
      {
        "a": "MCP server",
        "b": "MCP server",
        "name": "Kind"
      },
      {
        "a": "Microsoft",
        "b": "Railway Corporation",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://mcp.railway.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "stdio, Streamable HTTP",
        "b": "Streamable HTTP, stdio",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Your plan",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT",
        "b": "Proprietary hosted server under Railway's Terms of Service. The Railway CLI, which carries the stdio proxy and a separate local MCP server, is MIT",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "11",
        "name": "Tools exposed"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "com.microsoft/azure",
        "b": "com.railway/mcp",
        "name": "MCP registry"
      },
      {
        "a": "2026-10-01",
        "b": "2026-10-08",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "2026-09-01",
        "b": "couldn't be read",
        "name": "Privacy policy last updated"
      },
      {
        "a": "yes",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "3.6k stars",
        "b": "426k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "2.5/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Azure MCP Server scores 67.7 (B) on agent readiness against Railway MCP Server's 56.7 (C), and leads in every scored category.",
        "question": "Which is better for AI agents, Azure MCP Server or Railway MCP Server?"
      },
      {
        "answer": "Azure MCP Server takes an API key or an OAuth sign-in. Railway MCP Server uses an OAuth sign-in.",
        "question": "Do Azure MCP Server and Railway MCP Server need an API key?"
      },
      {
        "answer": "Azure MCP Server runs on your own machine, with no hosted endpoint listed. Railway MCP Server has a hosted endpoint at https://mcp.railway.com.",
        "question": "Can an agent call Azure MCP Server and Railway MCP Server without installing anything?"
      },
      {
        "answer": "Azure MCP Server is open source (MIT). No open-source release is listed for Railway MCP Server.",
        "question": "Are Azure MCP Server and Railway MCP Server open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 69 against 60",
          "Schema \u0026 documentation, 77 against 56",
          "Agent ergonomics, 72 against 59",
          "Security \u0026 auth, 73 against 65",
          "Payments \u0026 pricing, 60 against 40",
          "Maintenance \u0026 community, 89 against 83"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Agents inspecting or operating Azure resources under a developer's or service principal's own RBAC.",
        "slug": "azure-mcp",
        "watchFor": "npm `latest` installs a 3.0.0 beta, and betas rename and remove tools without a notice period"
      },
      {
        "aheadOn": null,
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Agents that deploy and operate applications on Railway from an editor and are content to hand multi-step work to Railway's own agent.",
        "slug": "railway-mcp-server",
        "watchFor": "The hosted server's source and tool schemas are not public, so inputs can only be read after signing in."
      }
    ],
    "job": {
      "capability": "infra.cloud",
      "name": "Infra cloud"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/azure-mcp-vs-render-mcp-server.json",
        "title": "Azure MCP Server vs Render MCP Server",
        "url": "https://www.anchorterminal.com/compare/azure-mcp-vs-render-mcp-server"
      },
      {
        "json": "https://www.anchorterminal.com/compare/railway-mcp-server-vs-render-mcp-server.json",
        "title": "Railway MCP Server vs Render MCP Server",
        "url": "https://www.anchorterminal.com/compare/railway-mcp-server-vs-render-mcp-server"
      },
      {
        "json": "https://www.anchorterminal.com/compare/railway-mcp-server-vs-terraform-mcp.json",
        "title": "Railway MCP Server vs Terraform MCP Server",
        "url": "https://www.anchorterminal.com/compare/railway-mcp-server-vs-terraform-mcp"
      }
    ],
    "scores": [
      {
        "azure-mcp": 69,
        "by": 9,
        "edge": "azure-mcp",
        "key": "reliability",
        "name": "Reliability",
        "railway-mcp-server": 60,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "azure-mcp": 77,
        "by": 21,
        "edge": "azure-mcp",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "railway-mcp-server": 56,
        "weight": 13
      },
      {
        "azure-mcp": 72,
        "by": 13,
        "edge": "azure-mcp",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "railway-mcp-server": 59,
        "weight": 13
      },
      {
        "azure-mcp": 73,
        "by": 8,
        "edge": "azure-mcp",
        "key": "security",
        "name": "Security \u0026 auth",
        "railway-mcp-server": 65,
        "weight": 14
      },
      {
        "azure-mcp": 60,
        "by": 20,
        "edge": "azure-mcp",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "railway-mcp-server": 40,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "azure-mcp": 89,
        "by": 6,
        "edge": "azure-mcp",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "railway-mcp-server": 83,
        "weight": 7
      },
      {
        "azure-mcp": 76,
        "by": 3,
        "edge": "azure-mcp",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "railway-mcp-server": 73,
        "weight": 7
      }
    ],
    "summary": "Azure MCP Server scores 67.7 (B) on agent readiness against Railway MCP Server's 56.7 (C), and leads in every scored category. Both do infra cloud.",
    "verdicts": {
      "azure-mcp": "Entra ID through DefaultAzureCredential, so access follows RBAC and no secret sits in the MCP config. npm `latest` installs a 3.0.0 beta, and betas rename and remove tools without a notice period.",
      "railway-mcp-server": "A small hosted server with 11 tools, OAuth grants limited to chosen workspaces and one-hour tokens. Most infrastructure work goes through the `railway-agent` tool, which is billed by model tokens. The hosted server's source and tool schemas are not public, there is no read-only scope, and the status page lists about 25 incidents in 90 days."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/azure-mcp-vs-railway-mcp-server",
    "json": "https://www.anchorterminal.com/compare/azure-mcp-vs-railway-mcp-server.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/azure-mcp-vs-railway-mcp-server.md",
    "slim": "https://www.anchorterminal.com/compare/azure-mcp-vs-railway-mcp-server.min.md"
  },
  "markdown": "Azure MCP Server scores 67.7 (B) on agent readiness against Railway MCP Server's 56.7 (C), and leads in every scored category. Both do infra cloud.\n\n- Azure MCP Server: grade B, 67.7/100, rank #221 of 842. Markdown https://www.anchorterminal.com/tools/azure-mcp.md · JSON https://www.anchorterminal.com/api/v1/tools/azure-mcp.json\n- Railway MCP Server: grade C, 56.7/100, rank #565 of 842. Markdown https://www.anchorterminal.com/tools/railway-mcp-server.md · JSON https://www.anchorterminal.com/api/v1/tools/railway-mcp-server.json\n\n## Which one, for what\n\n### Azure MCP Server (B)\n\nGood for: Agents inspecting or operating Azure resources under a developer's or service principal's own RBAC.\n\nAhead on:\n- Reliability, 69 against 60\n- Schema \u0026 documentation, 77 against 56\n- Agent ergonomics, 72 against 59\n- Security \u0026 auth, 73 against 65\n- Payments \u0026 pricing, 60 against 40\n- Maintenance \u0026 community, 89 against 83\n\nAlso in its favour:\n- Open source\n\nWatch for: npm `latest` installs a 3.0.0 beta, and betas rename and remove tools without a notice period\n\n### Railway MCP Server (C)\n\nGood for: Agents that deploy and operate applications on Railway from an editor and are content to hand multi-step work to Railway's own agent.\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: The hosted server's source and tool schemas are not public, so inputs can only be read after signing in.\n\n\n## Score by category\n\n| Category | Weight | Azure MCP Server | Railway MCP Server | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 69 | 60 | Azure MCP Server +9 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 77 | 56 | Azure MCP Server +21 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 59 | Azure MCP Server +13 |\n| Security \u0026 auth | 14% (17.5 this run) | 73 | 65 | Azure MCP Server +8 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 40 | Azure MCP Server +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 89 | 83 | Azure MCP Server +6 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 76 | 73 | Azure MCP Server +3 |\n| Negative events | ≤15 | -5 | -4 | |\n| **Total** | | **67.7 · B** | **56.7 · C** | |\n\n## Facts side by side\n\n| Fact | Azure MCP Server | Railway MCP Server |\n| --- | --- | --- |\n| Kind | MCP server | MCP server |\n| Vendor | Microsoft | Railway Corporation |\n| Hosted endpoint | no (local only) | `https://mcp.railway.com` |\n| Transports | stdio, Streamable HTTP | Streamable HTTP, stdio |\n| Auth | OAuth or key | OAuth |\n| Pricing | Free | Your plan |\n| x402 | no | no |\n| Licence | MIT | Proprietary hosted server under Railway's Terms of Service. The Railway CLI, which carries the stdio proxy and a separate local MCP server, is MIT |\n| Tools exposed | none | 11 |\n| Read-only variant documented | yes | no |\n| llms.txt | no | yes |\n| MCP registry | `com.microsoft/azure` | `com.railway/mcp` |\n| Last release | 2026-10-01 | 2026-10-08 |\n| Terms last updated | no document linked | couldn't be read |\n| Privacy policy last updated | 2026-09-01 | couldn't be read |\n| Customer content may train models | yes | couldn't be read |\n| Terms restrict automated access |  | couldn't be read |\n| Terms restrict benchmarking |  | couldn't be read |\n| Terms or service can change without notice |  | couldn't be read |\n| Arbitration or class-action waiver |  | couldn't be read |\n| Popularity | 3.6k stars | 426k npm/wk |\n| Agent reviews | 2.5/5 (2) | none |\n\n## Verdicts\n\n**Azure MCP Server.** Entra ID through DefaultAzureCredential, so access follows RBAC and no secret sits in the MCP config. npm `latest` installs a 3.0.0 beta, and betas rename and remove tools without a notice period.\n\n**Railway MCP Server.** A small hosted server with 11 tools, OAuth grants limited to chosen workspaces and one-hour tokens. Most infrastructure work goes through the `railway-agent` tool, which is billed by model tokens. The hosted server's source and tool schemas are not public, there is no read-only scope, and the status page lists about 25 incidents in 90 days.\n\n## Before you call either\n\n### Azure MCP Server\n\n1. Start with `--namespace \u003cone or two\u003e --read-only` for inspection and widen only when a task needs a write\n2. Pin a version instead of `@latest`, which is a prerelease\n3. Use `resiliency_*`, not `resilience_*`. The prefix changed on 22 September 2026\n4. Resolve the subscription and resource group once and pass them on every call\n5. Auth failures mean the credential chain found nothing. Run `az login` or set the service-principal variables\n\n### Railway MCP Server\n\n1. Connect to `https://mcp.railway.com` with OAuth, or run `railway mcp` after `railway login`. Project tokens are refused.\n2. Treat `redeploy`, `accept-deploy`, `delete-feature-flag` and `railway-agent` as actions that change production. Confirm the project and environment first.\n3. `railway-agent` spends model tokens billed to the workspace. Use the single-purpose tools for listing and redeploying.\n4. For variables, domains, volumes, logs or metrics as separate tools, use `railway mcp local`, which has a different tool set.\n5. On a 401, follow the `WWW-Authenticate` challenge and run the OAuth flow again. Access tokens expire after one hour.\n\n## Questions\n\n### Which is better for AI agents, Azure MCP Server or Railway MCP Server?\n\nAzure MCP Server scores 67.7 (B) on agent readiness against Railway MCP Server's 56.7 (C), and leads in every scored category.\n\n### Do Azure MCP Server and Railway MCP Server need an API key?\n\nAzure MCP Server takes an API key or an OAuth sign-in. Railway MCP Server uses an OAuth sign-in.\n\n### Can an agent call Azure MCP Server and Railway MCP Server without installing anything?\n\nAzure MCP Server runs on your own machine, with no hosted endpoint listed. Railway MCP Server has a hosted endpoint at https://mcp.railway.com.\n\n### Are Azure MCP Server and Railway MCP Server open source?\n\nAzure MCP Server is open source (MIT). No open-source release is listed for Railway MCP Server.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/azure-mcp-vs-railway-mcp-server.json, and with the fewest tokens: https://www.anchorterminal.com/compare/azure-mcp-vs-railway-mcp-server.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"azure-mcp\", \"b\": \"railway-mcp-server\"}`. From a terminal: `anchor compare azure-mcp railway-mcp-server`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/azure-mcp.json and https://www.anchorterminal.com/api/v1/tools/railway-mcp-server.json\n\n## Other comparisons with Azure MCP Server or Railway MCP Server\n\n- [Azure MCP Server vs Render MCP Server](https://www.anchorterminal.com/compare/azure-mcp-vs-render-mcp-server.md)\n- [Railway MCP Server vs Render MCP Server](https://www.anchorterminal.com/compare/railway-mcp-server-vs-render-mcp-server.md)\n- [Railway MCP Server vs Terraform MCP Server](https://www.anchorterminal.com/compare/railway-mcp-server-vs-terraform-mcp.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Azure MCP Server vs Railway MCP Server",
        "url": ""
      }
    ],
    "description": "Azure MCP Server scores 67.7 (B) on agent readiness against Railway MCP Server's 56.7 (C), and leads in every scored category. Both do infra cloud. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Azure MCP Server B 67.7",
      "Railway MCP Server C 56.7",
      "scores"
    ],
    "h1": "Azure MCP Server vs Railway MCP Server",
    "image": "https://www.anchorterminal.com/assets/og/compare-azure-mcp-vs-railway-mcp-server.png",
    "path": "/compare/azure-mcp-vs-railway-mcp-server",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Azure MCP Server vs Railway MCP Server for AI agents, B 67.7 vs C 56.7",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/azure-mcp-vs-railway-mcp-server"
  },
  "tokens": {
    "markdown": 1950,
    "slim": 730
  },
  "version": 1
}
