Paperclip’s Railway MCP connector gives your AI agents tools to inspect projects, services and deployment status when Railway accepts this connection for API access. Each tool can be Allowed, Ask first or Off.
Railway enforces workspaces selected at consent. Direct actions require explicit workspace, project, environment and service IDs; mismatched targets are rejected.
What agents can do with Railway
- Inspect services in a project
Available when Railway accepts this connection for API access.
paperclip-railway-list-projects·paperclip-railway-list-services - Inspect service and deployment status
Available when Railway accepts this connection for API access.
paperclip-railway-service-status·paperclip-railway-deployment-status - Inspect deployments and bounded logs
Available when Railway accepts this connection for API access.
paperclip-railway-list-deployments·paperclip-railway-read-logs
How to connect Railway
These setup instructions follow the documentation. They have not been tested with a live connection.
- In Paperclip, open Connectors and select Railway.
- On the Access step, choose the identity and which agents may use the connection.
- Select Connect Railway, sign in through its hosted connection and select workspaces at consent. Check API access with a read before relying on direct actions.
Railway tools for agents20
Read 12
get-feature-flaglist-feature-flagslist-projectslist-servicespaperclip-railway-deployment-statusInspect an exact deployment and its container instance IDs.
paperclip-railway-list-deploymentsList deployments for one explicit project, environment, and service.
Show all 12 Read tools
Read tools 7–12
paperclip-railway-list-environmentsList environments in one Railway project.
paperclip-railway-list-projectsList Railway projects in an explicit authorized workspace, with bounded pagination.
Full description
List Railway projects in an explicit authorized workspace, with bounded pagination. Use the hosted list-workspaces action to find workspace IDs.
paperclip-railway-list-servicesList services in one Railway project.
Full description
List services in one Railway project. Use service-status to inspect a specific environment.
paperclip-railway-read-logsRead at most 500 build or runtime log lines for an exact deployment.
Full description
Read at most 500 build or runtime log lines for an exact deployment. Output is bounded; logs may contain sensitive application data.
paperclip-railway-service-statusInspect a service's running and latest deployments in an explicit project and environment.
whoami
Write 8
create-projectdelete-feature-flagpaperclip-railway-redeployRedeploy an exact deployment using its previous image.
Full description
Redeploy an exact deployment using its previous image. This changes a running service.
paperclip-railway-restartRestart an exact deployment without rebuilding.
Full description
Restart an exact deployment without rebuilding. This interrupts a running service.
paperclip-railway-rollbackRoll back to an exact eligible deployment.
Full description
Roll back to an exact eligible deployment. This changes a running service.
paperclip-railway-run-commandRun a bounded noninteractive shell command in an exact deployed container using this connection's configured SSH key.
Full description
Run a bounded noninteractive shell command in an exact deployed container using this connection's configured SSH key. Broad privileged access: commands can read secrets and mutate application data. Requires Container access setup. Timeout closes SSH; remote child termination is not guaranteed.
Show all 8 Write tools
Write tools 7–8
redeployset-feature-flag
Tool availability and permissions
This list describes the reviewed tools. Your selected method, provider access and action permissions determine what agents can use.
These lists use a conservative permission policy. Read requires a provider read-only hint or a reviewed Paperclip read rule. Evidence that an action changes data or submits information elsewhere puts it in Write. Write also includes actions we cannot verify as read-only. Read describes the reviewed evidence; it does not guarantee that an action has no side effects. A connected account can group actions differently.
This list combines Railway’s hosted tools with Paperclip’s direct actions. Hosted tools without published descriptions have none here. Direct actions require the branded sign-in endpoint and an authorized workspace. run-command also requires Container access and SSH setup, and is grouped as Write because it can make destructive changes.
Connection policies
New or changed actions found on refresh are held for review before agents can use them. Review their permissions and set actions to Ask first or Off as needed. Browser sign-in alone does not prove API access. Deployment changes and container commands need separate review.
Railway connector FAQ
Can I require approval for actions?
Set an action to Ask first to require human approval of each call or Off to prevent calls. Allowed actions run without approval. Read and Write grouping is separate from these settings.
What can agents reach in Railway?
Railway enforces workspaces selected at consent. Direct actions require explicit workspace, project, environment and service IDs; mismatched targets are rejected.
What do I need before connecting?
Use a Railway account with access to the intended workspaces. Live API qualification is pending; project tokens are not supported. Container commands require separate SSH setup.