Railway for AI agents

Railway is a deployment platform for building and shipping applications with instant deployments and managed infrastructure. Developers use it to deploy services without managing servers directly. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Developer toolsOAuth 2.0MCP + RESTrailway.app
AUDIT LOG · RAILWAYPOLICY: acme-support
09:41:07 · claude · u_8f2read
railway.list_domains
List Domains✓ allowed · 212ms
09:41:08 · claude · u_8f2read
railway.get_template
Get Template✓ allowed · 164ms
09:41:09 · claude · u_8f2write
railway.create_domain
Create Domain✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
railway.delete_domain
Delete Domain✕ blocked · policy: deny
EVERY RAILWAY CALL, ON THE RECORD
01 · USE CASES

What agents do in Railway.

01

Deploy a service

Trigger a deployment of a service so the latest code goes live.

02

Check deployment logs read-only

Pull build and deployment logs to debug why a release failed.

03

Delete an environment with approval

Remove an environment and its resources only after a team member confirms it is unused.

02 · ACTIONS

59 Railway actions, graded by risk.

Every Railway action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

25

Look things up. Allowed by default.

  • railway.get_template
    Get Template
  • railway.list_domains
    List Domains
  • railway.list_volumes
    List Volumes
  • railway.get_http_logs
    Get HTTP Logs
  • railway.list_projects
    List Projects
  • railway.list_services
    List Services
  • railway.get_build_logs
    Get Build Logs
  • railway.get_deployment
    Get Deployment
  • railway.list_variables
    List Variables
  • railway.get_environment
    Get Environment
  • railway.list_api_tokens
    List API Tokens
  • railway.get_http_metrics
    Get HTTP Metrics
  • railway.list_deployments
    List Deployments
  • railway.search_templates
    Search Templates
  • railway.list_environments
    List Environments
  • railway.list_git_hub_repos
    List GitHub Repos
+ 9 MORE

write

27

Create and change things. Allow, or ask the user first.

  • railway.create_domain
    Create Domain
  • railway.create_plugin
    Create Plugin
  • railway.create_volume
    Create Volume
  • railway.update_domain
    Update Domain
  • railway.update_volume
    Update Volume
  • railway.create_project
    Create Project
  • railway.create_service
    Create Service
  • railway.update_project
    Update Project
  • railway.update_service
    Update Service
  • railway.create_environment
    Create Environment
  • railway.update_volume_instance
    Update Volume Instance
  • railway.update_service_instance
    Update Service Instance
  • railway.deploy_service
    Deploy Service
  • railway.stage_template
    Stage Template
  • railway.deploy_template
    Deploy Template
  • railway.stop_deployment
    Stop Deployment
+ 11 MORE

destructive

7

Delete, cancel or archive. Ask first, or deny outright.

  • railway.delete_domain
    Delete Domain
  • railway.delete_volume
    Delete Volume
  • railway.delete_variable
    Delete Variable
  • railway.delete_workspace
    Delete workspace
  • railway.cancel_deployment
    Cancel Deployment
  • railway.delete_deployment
    Delete Deployment
  • railway.delete_environment
    Delete Environment
03 · HOW IT WORKS

Railway in three steps.

  1. 01Your users connect RailwayThey sign in to Railway on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, writes like “create Domain” can wait for the user, and “delete Domain” can be denied outright.
  3. 03Any agent can actYour agent calls Railway through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('railway', {
  read: 'allow',
  write: 'ask',        // create_domain
  destructive: 'deny',  // delete_domain
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Railway connects.

Users sign in to Railway on Arc0 Connect and approve the scopes you request. Build with Arc0’s Railway OAuth app, or bring your own so the Railway consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

The same Railway connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key · OAuth 2.0
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Railway from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Railway and Arc0, answered.

Q01

Can I use Railway with Claude, ChatGPT or Cursor?

Yes. Connect Railway to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Railway actions you allow.

Q02

How do users connect Railway?

Users sign in to Railway on Arc0 Connect and approve the scopes you request. Build with Arc0’s Railway OAuth app, or bring your own so the Railway consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

Q03

Which Railway actions can my agent take?

59 in total: 25 read, 27 write and 7 destructive, such as “create Domain”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Railway?

Yes. Actions like “delete Domain” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Railway too?

Yes. The same Railway connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Railway into your agent.

Your users connect Railway once, under your brand. Your agent gets 59 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan