MCP for AI agents
← Docs · Reference

MCP for AI agents

Let Claude Code, Cursor or any MCP client list, inspect, deploy and restart your apps with a scoped token. Destructive actions wait for a human.

Railyard runs a Model Context Protocol server at https://app.railyard.run/api/mcp, over streamable HTTP. It uses the same API tokens as the CLI and REST API, so an agent can do exactly what its token allows and nothing more.

Connect an agent

Create a token under Settings → Team → API tokens. Use a read token if the agent only needs to look. Then:

Claude Code

claude mcp add --transport http railyard https://app.railyard.run/api/mcp --header "Authorization: Bearer rly_..."

Cursor (.cursor/mcp.json)

{ "mcpServers": { "railyard": { "url": "https://app.railyard.run/api/mcp", "headers": { "Authorization": "Bearer rly_..." } } } }

Any other MCP client that speaks streamable HTTP and can send an Authorization header works the same way.

Tools

ToolTokenWhat it does
list_serversreadThe team’s servers
list_appsreadThe team’s apps
get_appreadOne app’s details
app_logsreadAn app’s recent log lines (100 by default, up to 500)
deploy_appwriteDeploy an app, through the same approval rules and rate limit as the dashboard
restart_appwriteRestart an app
set_envwriteSet an environment variable (it applies on the next deploy)
unset_envwrite, approvalRemove a variable
delete_appwrite, approvalDelete an app

Approvals

Removing a variable or deleting an app never runs straight from an agent. It creates a request on the Approvals page, which also shows on the dashboard, and changes nothing until a team admin approves it. Approving runs the action and records the result. Rejecting drops it.

Good habits

  • Give each agent its own token with an expiry date, and revoke it when you’re done.
  • Use a read token for agents that only answer questions (“why is checkout slow?”).
  • Deploys an agent starts go through the app’s deploy approval and rate limit like any other.

Limits

The MCP server covers the actions above. Anything else, such as servers, domains or databases, goes through the REST API or the CLI.