# Railway MCP Server (slim) > Railway's official MCP server is hosted at mcp.railway.com. It lets an agent list and create projects, redeploy services, manage feature flags and hand multi-step work to Railway's own agent, through OAuth or the Railway CLI. - Full: https://www.anchorterminal.com/tools/railway-mcp-server.md (~7,800 tokens) · this version ~1,880 tokens · JSON https://www.anchorterminal.com/tools/railway-mcp-server.json · canonical https://www.anchorterminal.com/tools/railway-mcp-server - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **C · 56.7/100 · rank #565 of 842 · #6 in Cloud & infrastructure · not agent-ready · confidence medium** Assessment: A small hosted server with 11 tools, OAuth grants limited to chosen workspaces and one-hour tokens. Most infrastructure work goes through the `railway-agent` tool, which is billed by model tokens. The hosted server's source and tool schemas are not public, there is no read-only scope, and the status page lists about 25 incidents in 90 days. ## Facts - Kind: MCP server · vendor: Railway Corporation · category: Cloud & infrastructure · legal entity: Railway Corporation · provenance 84/100 - Endpoint: `https://mcp.railway.com` (Streamable HTTP, stdio) - Auth: OAuth · pricing: Your plan · x402: no · licence: Proprietary hosted server under Railway's Terms of Service. The Railway CLI, which carries the stdio proxy and a separate local MCP server, is MIT - Probe metrics: not measured yet (probes haven't run) - Surface graded: The hosted MCP server at https://mcp.railway.com, reached with OAuth from the MCP client or through the `railway mcp` stdio proxy in the Railway CLI (5.44.0 or later). The CLI's local server, `railway mcp local`, and the GraphQL API at https://backboard.railway.com/graphql/v2 are separate surfaces - Tools: 11 per the docs. `whoami`, `list-projects`, `create-project`, `list-services`, `list-feature-flags`, `get-feature-flag`, `set-feature-flag`, `delete-feature-flag`, `redeploy`, `accept-deploy` and `railway-agent` - Not in the hosted tool list: Tools for variables, environments, domains, volumes, buckets, templates, logs and metrics. The docs send multi-step work to `railway-agent`, and the local server has 47 tools covering these - Protocol: Streamable HTTP, run statelessly with no session id per the CLI proxy source. The proxy does not forward server-initiated messages - Credentials: OAuth authorisation code with PKCE (S256 required), device code grant, dynamic client registration and client ID metadata documents at backboard.railway.com. One resource scope, `workspace:member`. One-hour access tokens, rotating refresh tokens with a one-year life, revocation in the dashboard only - Rate limits: None stated for the MCP server. The public API allows 100 requests an hour on Free, 1,000 on Hobby and 10,000 on Pro, with 10 a second on Hobby and 50 on Pro, and sends `Retry-After` on 429 - Audit: Workspace audit logs for admins, exportable through the GraphQL API. Kept 48 hours on Free, Trial and Hobby, 30 days on Pro and 18 months on Enterprise. Actor types are user, Railway staff and Railway system, with no marker for MCP calls found - Releases: The hosted server shows version 1.0.0 in its server card and the registry and has no public release history. The CLI that carries the proxy reached v5.64.1 on 8 October 2026 - Certifications: SOC 2 Type II and SOC 3 per the compliance docs, with a HIPAA BAA as a paid add-on. Reports are requested through trust.railway.com - Status: status.railway.com, built in-house, with components by region and for the dashboard, the API at backboard.railway.com and Railway OAuth login. No component for the MCP server. A JSON feed is at https://api.railwaystatus.com/status - Sub-processors: The DPA points to a list at trust.railway.com, which was not read, and promises ten days' notice of a new one. The DPA names Google Cloud Platform for infrastructure and the United States as the primary place of processing - Prices: Free plan free per month (plan); Hobby plan $5 per month (plan); Pro workspace $20 per month (plan); CPU, one vCPU $20 per month (plan); Memory $10 per GB per month; Volume storage $0.15 per GB per month; Network egress $0.05 per GB of traffic - Scores: Reliability 60, Performance pending, Schema & documentation 56, Agent ergonomics 59, Security & auth 65, Payments & pricing 40, Task success pending, Maintenance & community 83, Transparency & trust 73 · negative events -4 · total over the 7 assessed categories - Why: Reliability, Scored as a hosted server. · Schema & documentation, The hosted server's source is closed and `tools/list` needs a signed-in client, so no tool schema was read. · Agent ergonomics, Eleven tools, one over the ten that earns full marks, with `railway-agent` taking multi-step work in a single call (20 of 25). · Security & auth, OAuth with PKCE required, dynamic client registration, grants limited to the workspaces and projects a person picks, one-hour access tokens… · Payments & pricing, No x402, MPP or L402 on the server (0). · Maintenance & community, The CLI that carries the proxy reached v5.64.1 on 8 October 2026 and Railway's changelog has an entry dated 1 October (30). · Transparency & trust, The hosted server is closed source under clear terms. - Sources: 41, open questions: 12, both in the full twin - Capabilities: infra.cloud, code.deploy, analytics.flags - JSON: https://www.anchorterminal.com/api/v1/tools/railway-mcp-server.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/railway-mcp-server.svg` or a link to https://www.anchorterminal.com/tools/railway-mcp-server from a page on railway.com or one of its subdomains, or the README of github.com/railwayapp/cli, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Connect to `https://mcp.railway.com` with OAuth, or run `railway mcp` after `railway login`. Project tokens are refused. 2. Treat `redeploy`, `accept-deploy`, `delete-feature-flag` and `railway-agent` as actions that change production. Confirm the project and environment first. 3. `railway-agent` spends model tokens billed to the workspace. Use the single-purpose tools for listing and redeploying. 4. For variables, domains, volumes, logs or metrics as separate tools, use `railway mcp local`, which has a different tool set. 5. On a 401, follow the `WWW-Authenticate` challenge and run the OAuth flow again. Access tokens expire after one hour. ## Connect ```bash railway mcp install ``` ```bash claude mcp add railway --transport http https://mcp.railway.com ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/railway-mcp-server ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Render MCP Server | B | 63.6 | infra.cloud, code.deploy | https://www.anchorterminal.com/tools/render-mcp-server.min.md | | Google Cloud Secret Manager | BB | 76.5 | infra.cloud | https://www.anchorterminal.com/tools/google-secret-manager.min.md | | Statsig | BB | 72.3 | analytics.flags | https://www.anchorterminal.com/tools/statsig.min.md | | Terraform MCP Server | BB | 71.9 | infra.cloud | https://www.anchorterminal.com/tools/terraform-mcp.min.md | | GrowthBook | BB | 70.1 | analytics.flags | https://www.anchorterminal.com/tools/growthbook.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)