☁️

Railway MCP Server

Updated June 2026✓ OfficialTrust grade A96/100

Railway's official MCP server puts your Railway projects — services, databases, environment variables, deployments, networking, volumes, and templates — inside natural-language reach of Claude Code, Cursor, GitHub Copilot, OpenAI Codex, Factory Droid, and OpenCode. Built by Railway, it is officially maintained and best for Cloud.

by Railway

About

Railway's official MCP server puts your Railway projects — services, databases, environment variables, deployments, networking, volumes, and templates — inside natural-language reach of Claude Code, Cursor, GitHub Copilot, OpenAI Codex, Factory Droid, and OpenCode. As of the current release, the standalone `@railway/mcp-server` npm package is deprecated in favor of shipping MCP support directly inside the Railway CLI: running `railway mcp` starts a local stdio server, while `railway mcp install` auto-detects installed AI tools and writes the correct client config for you (add `--agent <tool>` to target one of claude-code, cursor, factory-droid, copilot, codex or opencode; add `--remote` to route through `railway mcp proxy` to Railway's hosted server at mcp.railway.com using your CLI login, or `--remote --oauth` to write the HTTPS endpoint directly and let the client run OAuth). `railway setup agent` does the same thing and also installs Railway's `use-railway` agent skill. The installer merges Railway's entry into existing MCP configs without clobbering other servers you've already set up. Local and Remote are not the same tool set: Local exposes roughly fifty tools including domains, volumes, TCP proxies, buckets, logs and metrics, while Remote exposes eleven — and only Remote has `railway-agent`, which hands multi-step debugging to Railway's own agent. Remote also refuses project tokens; it requires a user identity for billing and audit. Once connected, you can ask your AI agent to spin up a new environment from a GitHub repo, roll environment variables across services, inspect deploy logs when a build fails, provision a Postgres or Redis instance, or manage networking and volume mounts — all without leaving your editor or touching the Railway dashboard. Because the CLI is the source of truth, keeping `railway` up to date is enough to pick up new MCP tools; there's no separate npm package to track anymore. The legacy `@railway/mcp-server` package is a deprecated compatibility shim, last published as 0.1.12 on 2026-05-23, and the repository it came from (railwayapp/railway-mcp-server, 192★) was archived the same day — both still install cleanly, which is why people are still running the old path.

A
Reliable96/100
low confidence · 1 measured signal

Grade A (96/100, reliable) from 1 measured signal, based on repository evidence. Only one signal stands behind it, so treat the grade as provisional.

What was measured

  • Repository maintenance100/100 · weight 20

    The repository has been pushed to or released within the last six months. — last push 2026-07-25, last release 2026-07-24 (v5.28.1).

  • Source verification100/100 · weight 25

    The repository URL was confirmed to resolve against the live GitHub API and is not archived.

  • Provenance90/100 · weight 10

    Published and maintained by the vendor of the service it connects to, rather than by a third party.

  • Listing ↔ repository match70/100 · weight 5

    The linked repository railwayapp/cli was confirmed to exist, but its name does not obviously correspond to this listing. Worth opening the repo before you trust the mapping.

What could not be measured

These contributed nothing to the score — not a penalty, not a zero. They are why the confidence reads the way it does.

  • Live MCP handshakeunknown

    No remote endpoint to handshake — this server installs and runs locally over stdio, so there is nothing to probe from the outside.

  • Measured uptimeunknown

    No probe history recorded for this server yet.

  • Tool-schema stabilityunknown

    Drift is a difference between two successive checks, and this server has none recorded.

Installation

binary
curl -fsSL agents.railway.com | sh

Searching "railway mcp" turns up four things and only one of them is current. `railwayapp/railway-mcp-server` was the official repository; it is archived, last pushed 2026-05-23, and still clones and builds. `@railway/mcp-server` on npm is a deprecated compatibility shim — its own npm metadata says "Railway MCP is now bundled into the Railway CLI. Use `railway mcp`". `jason-tan-swe/railway-mcp` is an unofficial community server, untouched since June 2025. The live one is not a package at all: it ships inside the Railway CLI, and `railway mcp` starts it. There is also a genuine name collision — several of the top GitHub hits for "railway mcp" are Indian Railways train-status servers, unrelated to the PaaS. The decision that actually matters once you are in the right place is Local versus Remote, and it is not a transport preference: they expose different tool sets, and picking on convenience silently costs you tools.

Installing Railway MCP

  1. 1.Install the CLI and configure agents in one step

    The bootstrap installs the CLI to `~/.railway/bin` and then runs `railway setup agent`, which writes MCP config for every AI coding tool it detects and installs Railway's `use-railway` agent skill. macOS and Linux natively; Windows through WSL with a Bash shell. If you would rather install the CLI without touching any editor config, drop the agent flag.

    shell
    curl -fsSL agents.railway.com | sh
    
    # CLI only, no agent/MCP configuration:
    bash <(curl -fsSL railway.com/install.sh) -y
  2. 2.Or install the CLI the way you install everything else

    Homebrew, npm and Scoop all work, as do the pre-built binaries on the releases page. The npm route needs Node 16 or later. Note which npm package you want: `@railway/cli` is the CLI and is the right one — `@railway/mcp-server` is the deprecated shim and installing it is the most common way people end up on the old path.

    shell
    brew install railway          # macOS
    npm i -g @railway/cli         # needs Node >= 16
    scoop install railway         # Windows
  3. 3.Authenticate before you configure anything

    Local MCP has no credentials of its own — it uses whatever the CLI is logged in as. On a box without a browser, `--browserless` prints a code to paste. For CI, set a token instead of logging in: `RAILWAY_TOKEN` is project-scoped, `RAILWAY_API_TOKEN` is account or workspace scoped. Neither works for Remote MCP; see the gotcha below.

    shell
    railway login
    railway login --browserless   # SSH sessions
    railway whoami
  4. 4.Pick a server, then install it

    Three install shapes, and the flags are the whole choice. Bare `install` writes Local MCP (the CLI runs the server on your machine). `--remote` writes `railway mcp proxy`, which speaks stdio to the editor and forwards to `mcp.railway.com` over HTTPS using your `railway login` session — so no long-lived credential ever lands in an editor config file. `--remote --oauth` writes the HTTPS URL directly and lets the client run OAuth itself. Add `--agent` once per tool to skip detection.

    shell
    railway mcp install                       # Local MCP, all detected tools
    railway mcp install --remote              # Remote MCP via the CLI proxy
    railway mcp install --remote --oauth      # Remote MCP, client handles OAuth
    railway mcp install --agent claude-code --agent copilot
  5. 5.Know the six agent values

    `--agent` accepts `claude-code`, `cursor`, `factory-droid`, `copilot`, `codex` and `opencode`. Anything else is not a supported target — including VS Code, which you configure by hand. `railway skills` installs into a universal `.agents` directory as well, but that directory has no MCP configuration convention, so skills land there and MCP config does not.

    shell
    railway mcp install --agent cursor
    railway skills --agent claude-code
  6. 6.Configure it by hand instead

    The installer only merges — it never removes MCP servers you already had — but if you want to see exactly what it writes, this is it. Claude Code and Codex have one-liners of their own. VS Code is not a supported `--agent` target and has to be written manually.

    json
    // .cursor/mcp.json
    { "mcpServers": { "railway": { "command": "railway", "args": ["mcp"] } } }
    
    // .vscode/mcp.json — manual only
    { "servers": { "railway": { "type": "stdio", "command": "railway", "args": ["mcp"] } } }
    
    // Claude Code:  claude mcp add railway railway mcp
    // Codex:        codex mcp add railway -- railway mcp
    // Factory:      droid mcp add railway "railway mcp"
  7. 7.If your editor is Windsurf, Cline or Devin

    Those three only support Remote MCP with OAuth — there is no local stdio path for them in Railway's own per-editor matrix. Point them at the HTTPS endpoint and let the client do the OAuth dance. That also means those editors get the remote tool set, which is the smaller one.

    shell
    railway mcp install --remote --oauth
    # writes: { "type": "http", "url": "https://mcp.railway.com" }

What it can do — and why Local and Remote are not the same server

Local MCP exposes roughly fifty tools across ten families, because it drives the CLI. Remote MCP exposes eleven, plus one that Local does not have: `railway-agent`, which hands a natural-language request to Railway's own agent for multi-step work. So Remote is not "Local over HTTPS" — choose Remote and you lose domains, volumes, TCP proxies, logs and metrics as tools; choose Local and you lose the agent handoff.

whoami

The only tool both servers share by name. Worth calling first — it tells you which identity the connection actually resolved to.

list_projects / create_project / list_services / create_service / remove_service

Local. Project and service CRUD, including `connect_service_source` to attach a GitHub repo and `scale_service`.

deploy / list_deployments / environment_status

Local. Deploy and read deployment state, per environment, alongside `create_environment` and `link_environment`.

list_variables / set_variables / add_reference_variable

Local. The variables family — reference variables are how one service points at another's value rather than copying it.

generate_domain / list_domains / domain_status / retry_domain_certificate

Local only. Domain issuance and the certificate retry, which is the tool you want when a custom domain is stuck.

list_tcp_proxies / create_tcp_proxy / private_network_status / private_network_update

Local only. Networking, including the TCP proxy you need to reach a database from outside the private network.

create_volume / update_volume / remove_volume / create_bucket / remove_bucket

Local only. Persistent storage and object buckets.

get_logs / service_metrics / http_requests / http_error_rate / http_response_time

Local only. The observability family — this is the set that makes "why did the deploy fail" answerable in-editor.

search_templates / deploy_template

Local. How "deploy a Postgres" resolves to an actual template rather than a hand-rolled service.

docs_search / docs_fetch

Local. Railway's documentation, in the client, so the model stops guessing at flag names.

railway-agent

Remote only. Hands a request to Railway's AI agent for multi-step operations — log analysis, debugging, service configuration. The reason to pick Remote.

list-feature-flags / get-feature-flag / set-feature-flag / delete-feature-flag

Remote only. Feature flags per project; delete is admin and marked destructive at the protocol level.

redeploy / accept-deploy

Remote. `accept-deploy` commits staged changes and deploys — destructive, and clients that honour protocol hints will prompt.

What people use it for

Stand up and deploy an app without opening the dashboard

Create a Next.js app in this directory and deploy it to Railway. Also assign it a domain.

This is the path Local MCP is built for: `create_project`, `deploy` and `generate_domain` in one turn. Remote MCP cannot finish it — it has no domain tools.

Debug a crashing service with Railway's own agent

Use the railway agent to figure out why my backend service is crashing on deploy.

`railway-agent` is remote-only and does the multi-step log reading itself rather than streaming a deploy log through your context window. If this prompt does nothing, you are on Local MCP.

Pull environment variables into a local .env

Pull environment variables for my project and save them to a .env file.

`list_variables` plus the model writing the file. The reason to do it conversationally rather than with `railway variable list` is that the agent can reconcile against the `.env.example` already in the repo.

Which one should you use?

Four things answer to this name. Only one is maintained.

Railway CLI (railway mcp)

This one. Bundled in `railwayapp/cli`, 587★ and pushed the day this guide was verified. Updating the CLI is how you get new MCP tools — there is no package to track separately.

railwayapp/railway-mcp-server

Never, for new setups. It was the official repo and is archived as of 2026-05-23. Fine as a reference for how the tools are implemented; not a thing to install.

@railway/mcp-server (npm)

Never. Deprecated shim, last published 0.1.12 on 2026-05-23. It exists so old configs fail loudly rather than silently.

jason-tan-swe/railway-mcp

Only if you specifically want the community implementation and its API-token auth model. Unofficial, 73★, last pushed June 2025 — it predates the CLI bundling and Remote MCP entirely.

Railway MCP vs a Vercel or Cloudflare MCP server

Whichever hosts the thing. Worth noting the shape difference: Vercel and Cloudflare lead with hosted remote servers, while Railway's richer surface is the local one — the reverse of the usual assumption that remote means fuller.

Frequently Asked Questions

Is @railway/mcp-server deprecated?
Yes. The npm package is explicitly marked deprecated — its own registry metadata reads "Railway MCP is now bundled into the Railway CLI. Use `railway mcp`" — and its last publish was 0.1.12 on 2026-05-23. The repository it came from, `railwayapp/railway-mcp-server`, is archived on the same date. Neither is broken, which is the problem: an install that still succeeds is why people are running the old path months later. Install `@railway/cli` and run `railway mcp` instead.
What is the difference between Railway Local MCP and Remote MCP?
The tool set, not just the transport. Local runs through your CLI and exposes roughly fifty tools — domains, volumes, TCP proxies, buckets, logs, metrics, templates, docs search. Remote runs at `mcp.railway.com` and exposes eleven: whoami, three project tools, four feature-flag tools, redeploy, accept-deploy and `railway-agent`. `railway-agent` exists nowhere else. If a prompt about domains or volumes quietly does nothing, check which one your editor is pointed at.
Can I use a Railway project token with Remote MCP?
No. Remote MCP does not accept project tokens — it requires a user identity so that usage has a billing and audit trail. `RAILWAY_TOKEN` and `RAILWAY_API_TOKEN` are for CLI automation. For Remote you either proxy your `railway login` session with `railway mcp proxy`, or let the client run OAuth against `https://mcp.railway.com`.
Why does the Railway MCP proxy say I am not authenticated?
The proxy reads and refreshes the credentials from your `railway login` session; if that session is gone, the tool call reports it. Run `railway login` in a terminal — the next tool call picks up the new session, with no editor restart. This is also the argument for the proxy over direct OAuth: the editor config holds `railway mcp proxy` and no credential at all.
Will railway mcp install overwrite my other MCP servers?
No. Both `railway mcp install` and `railway setup agent` merge the Railway entry into existing tool configs and leave other servers alone, and both are idempotent — re-run them to update. `railway setup agent` additionally refreshes the Railway-owned skill directories, which are the only directories it will rewrite.
Does the Railway MCP server confirm before destructive actions?
Local MCP marks destructive tools with protocol-level hints and returns a preview before requiring `confirm: true` on the call. Remote marks `delete-feature-flag` and `accept-deploy` as destructive and relies on the client honouring the hint. Railway names the ones to watch: `remove_service`, `delete_domain`, `remove_tcp_proxy`, `remove_bucket`, `remove_volume`, `redeploy`, `accept-deploy` and `railway-agent` — the last because it acts on its own.
Is "railway mcp" the Indian Railways MCP server?
Different thing entirely. Several of the most-starred GitHub repositories matching "railway mcp" are Indian Railways servers for train schedules, seat availability and live station status. They have no relationship to Railway.com the deployment platform. If you are looking at a repo whose tools mention PNR numbers, you are in the wrong catalog entry.
How do I uninstall the Railway CLI?
The installer ships its own removal flag: `bash <(curl -fsSL cli.new) -r`. Worth knowing because the bootstrap puts the binary in `~/.railway/bin` rather than anywhere a package manager tracks, so uninstalling by deleting what `which railway` prints leaves the rest behind.
What is Railway MCP Server?
Railway is an MCP server built by Railway. Railway's official MCP server puts your Railway projects — services, databases, environment variables, deployments, networking, volumes, and templates — inside natural-language reach of Claude Code, Cursor, GitHub Copilot, OpenAI Codex, Factory Droid, and OpenCode. As of the current release, the standalone `@railway/mcp-server` npm package is deprecated in favor of shipping MCP support directly inside the Railway CLI: running `railway mcp` starts a local stdio server, while `railway mcp install` auto-detects installed AI tools and writes the correct client config for you (add `--agent <tool>` to target one of claude-code, cursor, factory-droid, copilot, codex or opencode; add `--remote` to route through `railway mcp proxy` to Railway's hosted server at mcp.railway.com using your CLI login, or `--remote --oauth` to write the HTTPS endpoint directly and let the client run OAuth). `railway setup agent` does the same thing and also installs Railway's `use-railway` agent skill. The installer merges Railway's entry into existing MCP configs without clobbering other servers you've already set up. Local and Remote are not the same tool set: Local exposes roughly fifty tools including domains, volumes, TCP proxies, buckets, logs and metrics, while Remote exposes eleven — and only Remote has `railway-agent`, which hands multi-step debugging to Railway's own agent. Remote also refuses project tokens; it requires a user identity for billing and audit. Once connected, you can ask your AI agent to spin up a new environment from a GitHub repo, roll environment variables across services, inspect deploy logs when a build fails, provision a Postgres or Redis instance, or manage networking and volume mounts — all without leaving your editor or touching the Railway dashboard. Because the CLI is the source of truth, keeping `railway` up to date is enough to pick up new MCP tools; there's no separate npm package to track anymore. The legacy `@railway/mcp-server` package is a deprecated compatibility shim, last published as 0.1.12 on 2026-05-23, and the repository it came from (railwayapp/railway-mcp-server, 192★) was archived the same day — both still install cleanly, which is why people are still running the old path.
Who built Railway MCP Server?
Railway MCP Server was built by Railway.
Is Railway MCP Server free?
Yes, Railway MCP Server has a free option. This MCP server is free and open-source. Check the GitHub repository for details.
How do I install Railway MCP Server?
Install Railway MCP Server with binary: curl -fsSL agents.railway.com | sh
What does Railway MCP Server integrate with?
Railway MCP Server integrates with Claude Desktop, Cursor, VS Code, Windsurf.

Repo Health

Actively maintained

Local/stdio install — runs on your machine, so there is no remote endpoint to verify live. Trust signal below is from the source repo.

Last commit
1mo ago
Last release
v5.28.1 · 1mo ago
Install
binary

Quick Info

Install Type
binary
Author
Railway
Categories
2
Integrations
4

Related Servers

💻

Git

Tools to read, search, and manipulate Git repositories. Full Git operations support.

Local
💻

GitHub MCP Server

authenticated access to the whole GitHub platform — repositories, files, branches, issues, pull requests, Actions runs, security alerts, discussions and notifications — from Claude, Cursor, VS Code, Copilot CLI and any other MCP host. There is no npm package for this server, and that trips up most people who try to install it: `@github/mcp-server` is not published to the npm registry, so any `npx` line you find for it will fail. GitHub ships it three other ways. The easiest is the hosted remote server at https://api.githubcopilot.com/mcp/, which needs no install at all — point an HTTP-transport MCP client at that URL and log in with OAuth (VS Code 1.101+, Claude Desktop, Claude Code, Cursor and Windsurf all support this). The second is the official Docker image ghcr.io/github/github-mcp-server, which is what the copy-paste command on this page runs; on github.com it now performs a browser-based OAuth login on first use and keeps the token in memory only, which is why the published Docker configs map a fixed loopback callback port (-p 127.0.0.1:8085:8085 with GITHUB_OAUTH_CALLBACK_PORT=8085) so the container can receive the callback. Prefer a token? Set GITHUB_PERSONAL_ACCESS_TOKEN instead — it takes precedence over OAuth, and the minimum useful scopes are repo, read:org and read:packages. The third is the native Go binary from the repository's releases, which needs no fixed port for the OAuth flow. GitHub Enterprise Server has no hosted option: use the local server with --gh-host or GITHUB_HOST set to your instance (include the https:// scheme — it defaults to http://, which GHES rejects). Toolsets can be narrowed with GITHUB_TOOLSETS, and an insiders channel is available at /mcp/insiders or via the X-MCP-Insiders header.

Auth required📘
💻

GitLab MCP Server

a first-party MCP endpoint built into the GitLab instance itself — there is no package to install, because the server ships inside GitLab and answers at https://<your-gitlab>/api/v4/mcp (gitlab.com exposes the same path, so https://gitlab.com/api/v4/mcp works for SaaS projects). It landed as an experiment in GitLab 18.3 and moved to beta in 18.6. Authentication is the part that makes it different from every community GitLab server: it uses OAuth 2.0 Dynamic Client Registration, so the first time a client connects it registers itself as an OAuth application on your instance and is issued an access token — no personal access token pasted into a config file. Administrators who do not want one OAuth application per tool can pre-create a shared application instead. Three prerequisites are what actually block most first connections: GitLab Duo must be set to Always on or On by default, beta and experimental features must be enabled, and MCP access must be switched on at the group or instance level. The tool surface covers issues and merge requests (create_issue, get_issue, create_merge_request, get_merge_request, list_merge_requests, get_merge_request_commits, get_merge_request_diffs, get_merge_request_pipelines, create_merge_request_note, get_merge_request_notes), CI/CD (manage_pipeline for list/create/delete/retry/cancel, get_pipeline_jobs, get_job_log), work items (create_workitem_note, get_workitem_notes, link_work_items, get_saved_view_work_items), search (search across the instance, search_labels, semantic_code_search), list_wiki_pages, and attach_scan_profile. HTTP is the recommended transport — claude mcp add --transport http GitLab https://gitlab.com/api/v4/mcp — and clients that only speak stdio can wrap it with npx mcp-remote <url> on Node 20+. Send the X-Gitlab-Mcp-Server-Tool-Name-Prefix header if generic names like search collide with another connected server. If your instance predates 18.3 or Duo is not available to you, the community alternative most teams land on is zereight/gitlab-mcp (1,889 stars as of 2026-08-16, npm @zereight/mcp-gitlab), which authenticates with a plain personal access token and ships 217 tools — including merge_merge_request, approve_merge_request, execute_graphql and full CI/CD variable management, none of which the built-in server exposes — behind GITLAB_PERMISSION_MODE=readonly/modify and GITLAB_TOOLSETS/GITLAB_TOOLS filtering. One further change worth noting: MCP server access moved from GitLab Premium to GitLab Free in 19.2 and became a setting of its own.

Auth required📘
☁️

AWS MCP Servers

AWS Labs maintains a monorepo of specialized, open-source MCP servers that bring AWS best practices directly into AI-assisted development workflows, spanning infrastructure, data, AI/ML, cost management, and healthcare/life-sciences domains. Rather than one monolithic server, the project ships dozens of focused servers you install individually depending on the task: the AWS Documentation MCP Server for real-time official docs and API references, dedicated servers for Terraform/CDK/CloudFormation infrastructure-as-code, container and serverless platforms (ECS, EKS, Lambda), SQL/NoSQL databases (DynamoDB, RDS, Aurora), search and analytics (OpenSearch), messaging (SQS/SNS), and cost/billing analysis. Most servers install via uvx with a package name like awslabs.aws-documentation-mcp-server, run locally over stdio, and use standard AWS credential chains (IAM roles, profiles, or access keys) rather than exposing raw account credentials to the model. AWS also now offers a managed, remote "AWS MCP Server" (in preview) that combines full API coverage with pre-built agent SOPs, syntactically validated API calls, and complete CloudTrail audit logging for teams that want centralized governance instead of running servers locally. The Getting Started with Kiro/Cursor/VS Code/Claude Code sections in the repo provide one-click install configs for each server, making it straightforward to wire up only the AWS services a given project actually touches.

Local
☁️

Cloudflare MCP Server

Cloudflare ships two different things under this name. The mcp-server-cloudflare repo provides 16 remote, domain-specific MCP servers rather than one monolith — Documentation, Workers Bindings (storage/AI/compute primitives), Workers Builds, Observability (logs/analytics), Container sandboxes, Browser Rendering (fetch pages, convert to markdown, screenshots), Logpush health, AI Gateway (prompt/response search), AI Search, Audit Logs, DNS Analytics, Digital Experience Monitoring, Cloudflare One CASB, Radar, GraphQL analytics and the Agents SDK docs server, each on its own `*.mcp.cloudflare.com/mcp` hostname. Separately, the Cloudflare API MCP server at mcp.cloudflare.com/mcp (repo: cloudflare/mcp) exposes the whole 2,500+ endpoint Cloudflare API through just two tools, `search` and `execute`, using the Code Mode pattern — model-written JavaScript runs in an isolated Dynamic Worker, costing ~1,000 tokens of context against the ~1.17M an equivalent native-tool server would need. Pick a domain server when you want a readable, curated tool list for one product area; pick the API server for breadth or for endpoints nobody wrote a tool for. All endpoints are Streamable HTTP on `/mcp` and support the MCP 2026-07-28 spec; the historical `/sse` URLs remain as aliases for the same Streamable HTTP handler but no longer serve the deprecated HTTP+SSE transport, so clients pinned to SSE must switch. Auth is OAuth on connect, or a scoped Cloudflare API token as a bearer header for CI. Clients without native remote-MCP support bridge via `npx mcp-remote https://<subdomain>.mcp.cloudflare.com/mcp`.

Live📘

Sponsored

Better Stack

Free Plan

Get alerted when your APIs, browser tests, payment pipelines, or MCP server dependencies go down. Used by 100K+ developers.

Start monitoring free →