# Railway MCP connector

Connect Railway to Elaichi and Claude, ChatGPT, Cursor, or any MCP client can list your projects and services, check deployments and metrics, set variables, and ship changes, all inside each person's own Railway access.

Source: https://elaichi.ai/connectors/railway/

## Facts

| | |
| --- | --- |
| Application | Railway |
| Category | Application Development |
| AI tools | 68 |
| Authentication | Connects over OAuth |
| Bring your own OAuth app | No |
| Native MCP | Yes. Railway builds and runs this MCP server. Elaichi adds sign-in, access controls and an audit log on top |
| Support for its tools | station.railway.com |
| MCP endpoint | https://api.elaichi.ai/mcp |
| Works with | Claude, ChatGPT, Cursor, any MCP client, and the Elaichi Agent |
| Tools advertised by name | No. Connected tools are never listed one by one, however few there are. The endpoint advertises `search_tools` and `execute_tool` instead |

## What you can ask once Railway is connected

- List the variables on the api service in production
- Show CPU and memory for checkout over the last day
- Create a staging deployment for the billing service

## Connect Railway in Elaichi

This happens once for the organization, before any client is involved.

1. Open Connections, choose Add connection, and pick Railway.
2. Optionally set Share with, then press Connect.
3. Approve it in Railway. Railway's own window opens. Whoever approves it decides what this connection can reach.

Credentials are vaulted and nobody, including the AI, reads them back. The connection becomes a toolbox immediately, so you can curate which Railway tools are exposed, rename them, or freeze arguments before anyone points a client at it.

## Railway MCP connector for Claude

Endpoint: https://api.elaichi.ai/mcp

1. Open Customize, then Connectors.
2. Press Add.
3. Name it, paste the MCP server URL, then Continue.
4. Sign in and approve.

On Team and Enterprise, an Owner adds it once. Everyone else turns it on for themselves.

## Railway MCP connector for ChatGPT

Endpoint: https://api.elaichi.ai/mcp

1. Open Plugins, then press the + button.
2. Name it and paste the endpoint into Server URL.
3. Leave Authentication on OAuth, then tick the risk acknowledgement.
4. Press Create, then sign in and approve.

Works on the web today. The plugin directory lives at chatgpt.com/plugins.

## Railway MCP connector for Cursor

Endpoint: https://api.elaichi.ai/mcp

1. Open `~/.cursor/mcp.json`.
2. Add the endpoint under `mcpServers`.
3. Reload Cursor, then sign in and approve.

Set up per machine, so repeat it on each computer you work from.

## Connect Railway to any MCP client

Endpoint: https://api.elaichi.ai/mcp

1. Add the endpoint as a remote MCP server.
2. Sign in and approve.

The Elaichi Agent already has these tools, with nothing to set up.

## What the consent screen decides

Only Read is granted by default, which is not enough to call a Railway tool. Over MCP there is no trusted place to confirm a write in the moment, so the consent screen is the standing approval rather than a formality. Grant Read and Run tools. Think hard before granting Delete, which reaches into connected apps and cannot be undone.

## What teams do with Railway through Elaichi

### Ship a service without opening the dashboard

Engineering. Ask for a new service in an existing Railway project, set its variables, and create a deployment from the same chat where the code was written.

### Keep variables straight across environments

Platform. List the variables on staging and production side by side, spot what is missing, and set the right values before the next deploy.

### Find out what changed before the incident

On-call. Pull the service description, staged changes, and recent metrics for the service that paged you, and get a plain summary of what moved.

### Check whether a customer-facing service is healthy

Support. Ask for a service's CPU, memory, and network metrics in plain language before telling a customer the problem is on your side.

### See what every project is running

Product. List workspaces, projects, and services in one answer so you know which features are live and in which environment.

### Add storage without filing a ticket

Data. Create a volume or bucket for a service, resize it later, and clean up what is no longer needed when a project winds down.

## Elaichi vs Zapier MCP vs Composio for Railway

All three can connect Railway to an AI assistant, and all three have admin controls. They differ in where access lives and how you pay.

| What to check | Elaichi | Zapier MCP | Composio |
| --- | --- | --- | --- |
| Where the AI connects | One address for the whole organization. Endpoint: https://api.elaichi.ai/mcp | A server per member, created at sign-in. | An MCP endpoint per team, or an SDK. |
| Control over Railway tools | Allow or restrict single Railway tools, per role or user. | App and action restrictions on the account. | Role permissions, down to the action. |
| Record of calls | One audit entry per Railway call. | A History tab of tool calls. | A log of every tool call. |
| Single sign-on | SAML or OIDC, plus SCIM, on Gold. | SAML on Enterprise. | SAML and OIDC on Enterprise. |
| Price | $15 per user per month. | 2 tasks per successful call. | Billed per tool call. |

Sources: Zapier MCP [docs](https://docs.zapier.com/mcp/get-started/quickstart), [security](https://docs.zapier.com/mcp/manage/security), [usage](https://docs.zapier.com/mcp/features/usage); Composio [docs](https://docs.composio.dev/docs/composio-connect), [gateway](https://composio.dev/mcp-gateway), [enterprise](https://composio.dev/enterprise), [pricing](https://composio.dev/pricing). Checked September 2026.

Longer take: [Zapier MCP alternative](/blog/zapier-mcp-alternative/) and [when you don't need an MCP gateway](/blog/when-you-dont-need-an-mcp-gateway/).

## Frequently asked questions

### How do I connect Railway to Claude?

Connect Railway in Elaichi first: pick Railway from the catalog, click connect, and approve the request on Railway's own OAuth screen with the account you already use. There is no OAuth application to register and no client ID or secret to generate. Then open Claude, go to Customize, then Connectors, then Add, and paste https://api.elaichi.ai/mcp. Claude signs you in through Elaichi and your Railway projects are available in the conversation.

### Does Railway work with ChatGPT and Cursor as well as Claude?

Yes. Once Railway is connected in Elaichi, the same endpoint, https://api.elaichi.ai/mcp, works in Claude, ChatGPT, Cursor, the Elaichi Agent, and any other MCP client. You connect Railway once and every client picks it up.

### What can an AI agent actually do with my Railway data?

Through Elaichi, an agent can list your Railway workspaces, projects, and services, describe an environment or service, read staged changes and metrics, and list or set variables. It can also create projects, services, deployments, volumes, and buckets, and read or update a function's source code. Short, concrete asks work best, such as asking for the variables on one service in production.

### Does connecting Railway give the AI my whole workspace?

No. Every call runs as the person who signed in, so the agent sees only the Railway workspaces, projects, and environments that person can already open. Elaichi can narrow that further by role or restriction, but it can never grant more than Railway itself allows.

### Can my team share one Railway connection?

Yes. One person connects Railway in Elaichi and shares it with a team, and nobody else ever handles a token or credential. Each teammate still signs in as themselves, so the audit log names the actual person behind every deployment or variable change.

### Can I stop an agent from deleting or changing things in Railway?

Yes. In Elaichi, restrictions apply per action, so you can block deleting services or volumes, updating function code, or setting variables in Railway while leaving read access in place. A restricted action is never advertised to Claude, ChatGPT, or Cursor, so no prompt can reach it.

### What happens to a Railway connection when someone leaves?

Offboarding a person in Elaichi ends their access to Railway through every AI client at once. A Railway connection that was shared with a team keeps working for everyone else. If you want to remove Railway entirely, disconnecting it once in Elaichi removes it from every client.

### Does the Railway MCP connector work with Gemini, Codex, Claude Code or other MCP clients?

Yes. Railway is reached over the same MCP endpoint every client uses, so anything that speaks MCP can call it — Gemini, Codex, Claude Code, Windsurf, Cline, Zed and OpenCode among them — alongside Claude, ChatGPT, Cursor, and the Elaichi Agent. The tools on offer and the access behind them are identical whichever client asks. Only the setup screen differs.

### Is Elaichi an alternative to Zapier MCP for Railway?

Yes. Both let Claude, ChatGPT or Cursor use Railway. Zapier MCP fits a team that already automates in Zapier, since each person signs in and acts as themselves in that account. Elaichi fits when IT wants one address for the whole company, per-tool rules by role, and a record of every Railway call.

### How is Elaichi different from Composio for Railway?

Composio gives AI agents tools and sign-in handling across 1,000+ apps, for developers building agents or people using an assistant, billed per tool call. Elaichi gives a company's own people governed access to Railway: one address, restrictions per role or user, and $15 per user per month. Both have role permissions and a log of every call.

## All 68 Railway tools

Every tool below is callable through https://api.elaichi.ai/mcp once Railway is connected, subject to the toolbox it is in and the restrictions on the caller.

- **Whoami** (Action). Get the current authenticated Railway user's profile information
- **List workspaces** (List). List the Railway workspaces the current user belongs to. Use a workspace ID with create-project to choose where a project is created.
- **List projects** (List). List all Railway projects accessible to the authenticated user
- **Create project** (Create). Create a new Railway project
- **Create deployment** (Create). Create a new service from a GitHub repository and trigger its first deployment. The repo must be one the authenticated user has connected via GitHub. Returns the new service; use get-status or list-deployments to follow the deploy. Before calling this tool you MUST have a…
- **Create service** (Create). Create a new service in a project from a Docker image, or an empty service to configure later (e.g. before setting variables and attaching a source). Public images only: credentials for a private registry are not accepted here — the user sets them on the service in the Railway…
- **Update service** (Update). Update a service's configuration: build/start/pre-deploy commands and pre-deploy timeout, builder, healthcheck, sleep mode, root directory, cron schedule, Dockerfile path, restart policy, config file path, watch patterns, replicas per region, resource limits, deployment…
- **Delete service** (Delete). Permanently delete a service: its deployments stop and are removed, along with its domains, variables and deployment triggers. Any volume attached to it is detached and kept — delete-volume removes a volume and its data. By default the service is deleted in every environment…
- **Create function** (Create). Create a Railway Function: a service that runs one file of TypeScript on the Bun runtime, with no repository, Dockerfile or build step. Use this for webhook receivers, small HTTP APIs, cron jobs and scripts. Pass the complete code — a function with no code deploys nothing.…
- **Update function source code** (Update). Replace a Railway Function's source code. Send the complete file — this overwrites the function's code, it does not patch it, so anything you leave out is gone. Read the current code with get-function-source-code first if you are modifying rather than rewriting. Applies live…
- **Get function source code** (Get). Get a Railway Function's source code and runtime in an environment. Works for a function that is deployed and for one that exists only as a staged change — `code` is whichever is current, `deployedCode` is what is actually running, and `staged` says whether a commit is…
- **List services** (List). List the ids and names of all services and environments in a Railway project. Prefer describe-environment for what is actually in an environment: it includes volumes, buckets, deployments and staged changes.
- **Describe environment** (Describe). Inventory of everything in a Railway environment — services, volumes, buckets, shared variable names — with staged changes applied. Each resource carries a `state`: live, staged-create (exists only in the pending patch), staged-delete, or live-with-staged-changes. Includes…
- **Describe service** (Describe). Everything about one service in an environment: its config with staged changes applied (source, build, deploy, networking, volume mounts), the per-field staged changes pending on it, mounted volumes, live domains and TCP proxies, the latest deployment, and its tracing state.…
- **Get staged changes** (Get). Show the changes staged in a Railway environment that accept-deploy would commit: per resource (service, volume, bucket, group) the action — create, delete, update — and each changed field with its live and staged value. Variable values and registry credentials are redacted to…
- **Get service config** (Get). Prefer describe-service: it applies the staged changes onto the live config for you and adds mounted volumes, domains, TCP proxies and the latest deployment. Get a service's configuration in an environment: source (repo/image), build settings, deploy settings (start command,…
- **Get service metrics** (Get). Get resource usage metrics (CPU, memory, disk, network) for a service, summarized as current/average/min/max over a time window. Defaults to CPU_USAGE and MEMORY_USAGE_GB over the last hour. If environmentId is omitted, the production environment is used.
- **List variables** (List). List all environment variables for a service, fully rendered (reference variables like ${{Postgres.DATABASE_URL}} are resolved). With a Railway session or API token, values are returned in plaintext and may contain secrets. Connected OAuth apps receive variable names only.…
- **Set variables** (Set). Set one or more environment variables on a service (or environment-wide shared variables when serviceId is omitted). Existing variables with the same name are overwritten; others are left unchanged. Reference syntax like ${{Postgres.DATABASE_URL}} is supported. Affected…
- **Create volume** (Create). Create a persistent volume in a project and optionally attach it to a service at a mount path. The attach and redeploy are committed together so the service comes up with the mount applied. Pass staged: true to stage the volume in one environment instead of provisioning it live.
- **Update volume** (Update). Update a volume's name, mount path, or which service it is attached to. Pass serviceId with mountPath to attach or move the volume; pass serviceId: null to detach it from its service, keeping the data. Every mount change redeploys the affected service so it takes effect. Only…
- **Delete volume** (Delete). Permanently delete a volume and its data. The volume is unmounted from any service it is attached to (redeploying that service). By default it is removed from every environment; pass an environmentId to remove it from that one environment only. Pass staged: true to stage the…
- **Create bucket** (Create). Create an S3-compatible object storage bucket in a project and provision it in an environment. Default region is sjc. Pass staged: true to stage the bucket in the environment's pending changes instead of provisioning it live — it then only becomes real when the staged changes…
- **Update bucket** (Update). Rename a bucket. The name is project-wide (not per environment) and takes effect immediately. Reference variables address the bucket by name (${{BucketName.ACCESS_KEY_ID}} and so on), so after a rename update any service variables that reference the old name and redeploy those…
- **Delete bucket** (Delete). Permanently delete an object storage bucket and its contents. By default it is removed from every environment it is provisioned in; pass an environmentId to remove it from that one environment only. Pass staged: true to stage the removal in one environment instead of applying…
- **Get bucket credentials** (Get). Get the S3-compatible connection details for a bucket in an environment: endpoint, bucket name, region, URL style, access key and secret. With a Railway session or API token the access key and secret are returned in plaintext; connected OAuth apps receive the connection…
- **Reset bucket credentials** (Action). Regenerate the S3-compatible credentials for a bucket in an environment and return the new ones. The current access key stops working immediately; bucket data is not affected. Every client using the old key needs the new values, and services that reference the bucket through…
- **List domains** (List). List all domains (Railway-generated service domains and custom domains) for a service in an environment. If environmentId is omitted, the production environment is used.
- **Domain status** (Action). Get detailed status for one domain on a service, by hostname, URL, or domain ID: required DNS records and whether they currently match, ownership verification, certificate status, and any certificate error. Use list-domains first if you do not know which domains exist. If…
- **Generate domain** (Generate). Expose a service publicly. Without `domain`, generates a Railway *.up.railway.app service domain (if the service already has domains, they are returned instead of creating another). With `domain`, attaches a custom domain you own and returns the DNS records the user must…
- **Update domain** (Update). Repoint or rename an existing domain on a service. targetPort changes which container port the domain routes to (for a service listening on several ports). subdomain renames a Railway-generated service domain to &lt;subdomain&gt;.up.railway.app; custom domains cannot be renamed —…
- **Delete domain** (Delete). Remove a domain from a service: a Railway-generated *.up.railway.app service domain or a custom domain. Requests to that hostname stop being routed to the service as soon as the removal applies. Pass staged: true to stage the removal of a service domain in the environment's…
- **Retry domain certificate** (Action). Request a new TLS certificate for a custom domain whose issuance failed. Use domain-status first: it reports the certificate error and whether a retry can help (certificate.retryable). A retry cannot succeed until the domain's DNS records point at Railway. Railway-generated…
- **Search docs** (Search). Search the Railway documentation (docs.railway.com) for features, configuration, guides, and tutorials. Returns matching sections with URLs — use fetch-docs to read a full page.
- **Fetch docs** (Action). Fetch the full markdown content of a Railway documentation page by URL or slug (e.g. 'https://docs.railway.com/quick-start' or 'reference/variables'). Use search-docs first to find the right page.
- **Search templates** (Search). Search the Railway template marketplace by name, description or keyword — databases (postgres, mysql, mongo, redis, clickhouse), their high-availability variants, and application templates. Returns published templates ranked by relevance. Use describe-template to read a…
- **Describe template** (Describe). Read one Railway template: its name, description, README, the services it creates, every env-var input it takes (which are required and which are optional), and — for clustered database templates like postgres-ha — the HA topology counts deploy-template can size. Call this…
- **Deploy template** (Action). Deploy a Railway template into a project — a database (postgres, mysql, redis, mongo), a clustered high-availability database, or an application template. Creates every service the template declares, wired together, and deploys them. Pass staged: true to stage them for the…
- **List feature flags** (List). List Railway feature flags (Signals) for a project and optionally the parent workspace. Project flags are editable with admin access; workspace flags are read-only from project context.
- **Get feature flag** (Get). Get a Railway feature flag (Signal) by name for a project or its parent workspace scope.
- **Set feature flag** (Set). Create a project-scoped feature flag or update its default value, optionally replacing its targeting rules. Use list-feature-flags and get-feature-flag to inspect existing flags first.
- **Delete feature flag** (Delete). Delete a project-scoped feature flag. Workspace-scoped flags cannot be deleted from project context.
- **List deployments** (List). List recent deployments for a Railway project, optionally filtered by environment, service, or status. Returns the most recent first, with who triggered each one, its regions, and whether it can be redeployed or rolled back.
- **Get status** (Get). Prefer describe-environment: it also lists services that exist only in the staged patch, unattached volumes, and each resource's staged state. Get the deployment status of a Railway project environment. Returns project + environment metadata, whether the environment has…
- **Get logs** (Get). Get logs from Railway — deploy (runtime), build, http (proxy request), network-flow (per-connection egress/ingress) and dns (name lookups) streams. Pass a deploymentId to read one deployment, or serviceId (+ optional environmentId) to read the service's logs across its recent…
- **List traces** (List). List distributed traces of an environment, newest first — one row per request that has at least one span matching the filter. Use it to find slow or failing requests across services, then call get-trace with a traceId for the spans. Defaults to the last hour. If environmentId…
- **Get trace** (Get). Get the spans of one distributed trace, as a tree from the edge down through every service that handled the request. Find trace IDs with list-traces. Only spans belonging to the environment are returned. If environmentId is omitted, the production environment is used.
- **Get tracing** (Get). Read the tracing settings of an environment's services: whether each is traced and its auto-instrumentation switch. Pass serviceId for one service, omit it for every service in the environment. Tracing is set per service and environment; if environmentId is omitted, the…
- **Get tracing coverage** (Get). Report what one service's own instrumentation covers: the spans its app exported in the window, by span kind, by the remote system they name (database, cache, queue, RPC or HTTP client) and by the instrumentation library that emitted them. Use it after instrumenting a service…
- **Set service tracing** (Set). Enable or disable tracing and auto-instrumentation for one service in one environment, each independently. tracingEnabled switches whether the edge traces requests to the service and whether its next deploy gets the OpenTelemetry exporter variables. autoInstrumentationEnabled…
- ...and 18 more tools. Call `tools/list` via the MCP endpoint, or see the full catalog via the API, for the complete set.
