# Railway MCP Server

> Railway MCP Server is an officially published MCP server from Railway. Anomity scores its risk at 20 out of 100 (low).

- **Canonical URL:** https://catalog.anomity.ai/mcp/railway-mcp-server
- **Kind:** MCP server
- **Publisher:** Railway
- **Trust level:** official
- **Risk score:** 20/100 (low)
- **Website:** https://docs.railway.com/guides/mcp
- **Documentation:** https://docs.railway.com/guides/mcp
- **Last updated:** 2026-09-02
- **JSON:** https://catalog.anomity.ai/api/entries/mcp/railway-mcp-server

## Description

Railway's official server exposes projects, services, deployments, variables, and logs, so an agent can deploy a service, read why a build failed, or inspect environment configuration.

Declared capabilities are outbound network access and credential access. Two things deserve attention: deployment is a code-execution primitive — an agent that can deploy can run arbitrary code in your infrastructure — and environment variables are where secrets live, so a server that can read them is a server that can read your secrets. Scope tokens per project, and keep production deploys behind a human even when the assistant is trusted for staging.

## Why it scored 20

The score starts at the catalog's neutral base of 50 and moves only through the signals below. The formula is published at https://catalog.anomity.ai/about — there is no model and no hidden heuristic.

| Signal | Contribution | Severity | Evidence |
| --- | --- | --- | --- |
| Published by the vendor | -40 | trust offset |  |
| 1 high-risk capability: credentials:access | +10 | high |  |

Clamped result: **20/100**, band **low**.

## Capabilities

| Capability | Name | Security implication |
| --- | --- | --- |
| `network:outbound` | Outbound network | Can make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access. |
| `credentials:access` | Credentials access | Reads provider API keys, OAuth tokens, or other secrets from the host keychain or environment. |

## Related MCP servers

- [Airtable MCP Server](https://catalog.anomity.ai/mcp/airtable-mcp-server) — risk 45 (medium)
- [Cloudflare MCP Server](https://catalog.anomity.ai/mcp/cloudflare-mcp-server) — risk 45 (medium)
- [ElevenLabs MCP Server](https://catalog.anomity.ai/mcp/elevenlabs-mcp-server) — risk 45 (medium)
- [MiniMax MCP Server](https://catalog.anomity.ai/mcp/minimax-mcp-server) — risk 45 (medium)
- [MongoDB MCP Server](https://catalog.anomity.ai/mcp/mongodb-mcp-server) — risk 45 (medium)
- [Neon MCP Server](https://catalog.anomity.ai/mcp/neon-mcp-server) — risk 45 (medium)

---

Source: Anomity Catalog (https://catalog.anomity.ai/). Scoring methodology: https://catalog.anomity.ai/about. Machine-readable index: https://catalog.anomity.ai/llms.txt · https://catalog.anomity.ai/openapi.json
