Base44
Build and edit Base44 apps from an AI assistant, and query data your app's users submit.
Deploy, redeploy and debug apps on Railway's usage-billed cloud.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Railway MCP server connects Claude, ChatGPT and other MCP clients to Railway, the usage-billed platform-as-a-service, over OAuth at a hosted endpoint. Its 16 tools create projects, deploy and redeploy services, read production logs, and set or delete feature flags — a control plane that provisions billable compute and changes what is running live.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
create-deployment, deploy-artifact, get-logs, get-status and list-deployments appear nowhere in Railway's documentation corpus. Two of them write.tools/list was performed, so we have no tool annotations — no readOnlyHint or destructiveHint values for any of the 16. Every safety claim here is Railway's documented prose, not a protocol annotation we observed. Railway says destructive tools are marked at the protocol level; we did not verify which ones carry the marking.get-logs returns.accept-deploy has no documented human-in-the-loop. Staged changes are a review buffer for the same actor. The only gate is the MCP client's confirmation prompt.railway-agent is a second model. It hands the request to Railway's own agent, which acts with your access and bills separately on token consumption.Yes. Railway documents accept-deploy as committing staged changes and deploying, and redeploy as redeploying a service, and the directory description says the connector can deploy services from connected GitHub repositories. Railway's docs list both among destructive tools you should review before approving. Anthropic's directory record for this connector carries no permissions field at all over that surface.
Effectively yes, because Railway's staged changes are a review buffer rather than a second-person approval. The docs describe staging as changes collected for you to review, then applied by clicking Deploy, with no separate approver named. An agent holding accept-deploy stages and applies as one actor. The documented brake is the client confirmation prompt, not Railway.
Railway bills resource usage on top of a plan fee: 10 dollars per GB of RAM per month and 20 dollars per vCPU per month, with plans at 0, 5 and 20 dollars monthly. A deployment an agent creates therefore accrues charges until it is removed. Railway documents workspace usage limits with a hard cap that shuts workloads down, minimum 10 dollars.
Whatever your application writes. Railway captures anything a build or deployment emits to standard output or standard error, plus HTTP logs carrying request paths, user agents and source IP addresses. Railway's logging documentation describes no redaction or scrubbing of application log content. The get-logs tool pipes that material straight into a model's context window.
Any plan with a Railway account, including the free tier. Railway documents Free at 0 dollars a month with 1 dollar of monthly credit, and a 30-day trial granting 5 dollars. Remote MCP requires only a Railway account and rejects project tokens, requiring a user identity for billing and audit. Feature flag writes additionally require a project admin role.
https://mcp.railway.com/ — anonymous initialize returning 401 with a www-authenticate headerhttps://mcp.railway.com/.well-known/oauth-protected-resource — RFC 9728 descriptor, 200https://mcp.railway.com/.well-known/oauth-authorization-server — RFC 8414 metadata, 200Connect Railway once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.