Teams, SSO and access
Roles, invitations, API tokens, single sign-on over OpenID Connect, SCIM, team SSH keys, the audit log and the security score.
Everything in Railyard belongs to a team: its servers, apps, cloud keys and history. Team settings are under Settings → Team. Admins see every tab; the other roles see less.
Roles
| Role | Can |
|---|---|
| viewer | See apps, servers, logs and deploys |
| deployer | Also deploy, restart, change variables and run commands |
| admin | Also manage members, cloud credentials, notifications, tokens, SSH keys and team settings |
| owner | Everything. Only owners can grant, change or remove the owner role |
An app can also require deploy approval. Its deploys then wait until someone approves them.
Members and invitations
Team → Members → Invite a member. The invitation is emailed. You can resend it, and the list shows when it expires.
API tokens
Team → API tokens. A token is read or write and can have an expiry date. It’s shown once, so copy it then. Tokens are what the CLI, the REST API and MCP use. A token also works as a service account for CI.
Single sign-on (OpenID Connect)
Settings → Single sign-on (admins). You can use Google Workspace, Okta, Microsoft Entra, Authentik, Keycloak or any other OpenID Connect provider:
- In your identity provider, create an OpenID Connect web app with the redirect URI shown on the page.
- Fill in the Issuer URL, Client ID, Client secret and your Email domain.
- Choose the role new people join as: viewer, deployer or admin.
- Optionally tick Require SSO for @domain emails, which turns off passwords for that domain.
People with that email domain use Sign in with SSO on the login page and join the team on first sign-in.
SAML 2.0 is supported next to OpenID Connect: pick SAML on the Single sign-on page, paste the identity provider’s sign-in URL and certificate, and Railyard shows the ACS (reply) URL, the entity ID and SP metadata to paste into Okta, Entra, OneLogin, JumpCloud or ADFS. Responses are checked for signature, audience, time and request ID.
Domain verification: before anyone can sign in through SSO for @yourdomain, add the TXT record shown on the page (_railyard-sso.<domain>) at your DNS provider and check it. SSO never signs into a site operator or into an existing account outside the team, and users with two-factor on are still asked for their code. Changing the domain means verifying again.
SCIM provisioning
Once SSO is saved, Create SCIM token and point your identity provider’s SCIM 2.0 app at https://app.railyard.run/scim/v2 with that bearer token:
- Assigning someone in your identity provider adds them to the team.
- Deactivating them removes them.
- Owners are never removed.
A bad token gets 401.
Team SSH keys
Team → SSH keys. Add a public key (the single line in ~/.ssh/id_ed25519.pub, never a private key). Railyard installs it on every team server, for the user it set the server up with. It sits in its own block of authorized_keys, so keys you added yourself are never touched. Removing a key, or removing a member, takes their keys off every server within about a minute. Each server’s Security tab shows who can SSH in.
Two-factor sign-in
Members can turn on two-factor sign-in from Settings → Security. The security score counts anyone without it.
Audit log
Activity (sidebar → Operate) records deploys, variable changes, member changes, approvals and data jobs. You can filter it by member, app, kind and dates, page through it, and export the filtered view as CSV. Variable changes also show on the app’s Variables tab: who changed which name and when, but never the value.
Actions a Railyard operator takes on your team — changing its server or app limits, suspending or reinstating it — land in this same log, not a hidden one, so you can see what was done and when.
Security score
Settings → Security scores the team from 0 to 100 using ten checks:
- two-factor on every member;
- admins who haven’t signed in for 90 days;
- servers with pending security updates;
- operating systems past end of life;
- ActiveProtect turned off;
- extra open ports;
- certificates close to expiry;
- no backup verified in 30 days;
- public stagings with no password or IP rules;
- old API tokens that never expire.
Each check links to its fix. The score also shows on the dashboard.
Moving an app to another team
From the app’s Settings → General, an app can move to another team. Its databases, volumes, domains and history come with it, and a deployed app’s data moves to a server in the new team.