AI agents

Let your coding agent ship.

Railyard has a built-in MCP server. Your agent can see your apps, read their logs, deploy and restart, with a token you scope. Anything destructive waits for a person.

01 / the MCP server

Nine tools on one endpoint.

POST https://app.railyard.run/api/mcp speaks the Model Context Protocol (JSON-RPC over streamable HTTP) and authenticates with a Railyard API token as a Bearer header. It sees only the team that token belongs to.

ToolWhat it doesNeeds
list_servers The team's servers with status, provider, load and pending security updates read
list_apps The team's apps with status, URL, server and environment read
get_app One app: status, URL, domains, variable names and recent deploys read
app_logs Recent log lines of an app, up to 500 read
deploy_app Build and deploy the app's latest commit write
restart_app Restart the app's running containers write
set_env Set a variable, applied on the next deploy write
unset_env Remove a variable write + approval
delete_app Delete an app and its data write + approval

02 / connect

Add it to your agent.

Create an API token under Team settings, then paste it in place of rly_....

Claude Code
claude mcp add --transport http railyard https://app.railyard.run/api/mcp \
  --header "Authorization: Bearer rly_..."
Cursor · .cursor/mcp.json
{
  "mcpServers": {
    "railyard": {
      "url": "https://app.railyard.run/api/mcp",
      "headers": {
        "Authorization": "Bearer rly_..."
      }
    }
  }
}

03 / guard rails

Scoped tokens, human approvals.

  • A read token can list servers and apps, show an app and read its logs. Nothing else.
  • A write token can also deploy, restart and set variables.
  • Tokens can expire, are revoked one at a time, and are stored only as a hash.
  • Deploys an agent starts are marked as coming from MCP in the deploy history.
  1. The agent asks to delete an app or remove a variable.
  2. Nothing changes. Railyard files an approval request and tells the agent it is waiting.
  3. An admin decides under Approvals in Railyard, where pending requests also show on the dashboard.
  4. It runs or it doesn't. The decision and who made it go into the activity log.

04 / shell and HTTP

The CLI and REST API work too.

Agents that run shell commands can use the same CLI you do, and anything can call the REST API with the same tokens. API errors exit non-zero and railyard run exits with the remote command's own code, so an agent knows when something failed.

terminal
railyard login https://app.railyard.run
railyard deploy shop --follow
railyard logs shop --follow --process web
railyard run shop -- bin/rails db:migrate
railyard rollback shop 218

05 / why your own servers

Agent experiments run on servers you already pay for.

Agents deploy often and try things. On a platform that bills per service or per usage, every experiment is a line on the invoice. On Railyard, an agent's staging copies and retries are containers on servers you already pay for. Its staging copies and the data they hold stay on your own servers, and you can cut its access by revoking one token.

Deploy your first app on a server you own.

Attach a machine with a host, a user and an SSH key, or let Railyard create one in your cloud account. It installs the rest and watches it come online.

Free plan, no card, and 14 days of Pro for every new team. One flat price per team.