Give my agent only read access (eg to logs etc)
sohejl1
PROOP

16 days ago

Hi there,

I wanted to ask how i can give my agent (eg. Claude code) a scoped limited access (eg through the mcp server or so)? For example so that he can only have read permissions and that way no dangerous access to my app in prod to accidentally delete something etc.

I wasn‘t able to figure this out.

Thank you!

Cheers,

Sohejl

Solved$20 Bounty

Pinned Solution

8 days ago

Yes, its not evaluated by the AI model instad its hardcoded in the Claude Code Harness :)

6 Replies

Status changed to Awaiting Railway Response Railway • 16 days ago


Railway
BOT

16 days ago

This is the kind of problem the Railway community is well placed to help with, so we'd like to open your thread as a community bounty. Railway pays a bounty to the community member who solves it, and threads like this usually get picked up quickly.

Opening it makes this entire thread public, including everything already posted. Nothing becomes public until you decide. Use the buttons below.

  • Open to the community - Before you click, take a moment to edit or remove anything you'd rather not share. The thread becomes publicly visible right away.
  • Keep it private and close the thread - Nothing becomes public and the thread closes.

Status changed to Awaiting User Response Railway • 16 days ago


Railway
BOT

15 days ago

This thread has been opened as a public bounty so the community can help solve it. The thread and any further activity are now visible to everyone.

Status changed to Open Railway • 15 days ago


13 days ago

If you use Claude Code, you are able to setup in the $home/.claude/settings.json what mcp tools the model can access or not. These were then enforced by the Claude Code runtime.

The work you need to do is get the mcp names of all the "not view" actions you want to block. You can see all mcp Tools in Claude with: /mcp and then the railway connector, there is a list of all tools. Go into one and you see the name. (You could propably ask Claude Code to give you all the Tool Names that do write type of things).

Then you need to put the tool names into the claude settings.json, like so (I asked my Claude Code to give me list (pleasy verify)):

{

"permissions": {

"deny": [

  "mcp__railway__accept-deploy",

  "mcp__railway__connect-service-source",

  "mcp__railway__create-bucket",

  "mcp__railway__create-deployment",

  "mcp__railway__create-function",

  "mcp__railway__create-project",

  "mcp__railway__create-service",

  "mcp__railway__create-tcp-proxy",

  "mcp__railway__create-volume",

  "mcp__railway__delete-bucket",

  "mcp__railway__delete-feature-flag",

  "mcp__railway__delete-service",

  "mcp__railway__delete-tcp-proxy",

  "mcp__railway__delete-volume",

  "mcp__railway__deploy-template",

  "mcp__railway__generate-domain",

  "mcp__railway__redeploy",

  "mcp__railway__restart-service",

  "mcp__railway__set-feature-flag",

  "mcp__railway__set-project-tracing",

  "mcp__railway__set-service-tracing",

  "mcp__railway__set-variables",

  "mcp__railway__update-function-source-code",

  "mcp__railway__update-service",

  "mcp__railway__update-volume",

  "mcp__railway__railway-agent"

]

}

}

hope i haved helped you :)


kobolol

If you use Claude Code, you are able to setup in the $home/.claude/settings.json what mcp tools the model can access or not. These were then enforced by the Claude Code runtime. The work you need to do is get the mcp names of all the "not view" actions you want to block. You can see all mcp Tools in Claude with: /mcp and then the railway connector, there is a list of all tools. Go into one and you see the name. (You could propably ask Claude Code to give you all the Tool Names that do write type of things). Then you need to put the tool names into the claude settings.json, like so (I asked my Claude Code to give me list (pleasy verify)): { "permissions": { "deny": [ "mcp__railway__accept-deploy", "mcp__railway__connect-service-source", "mcp__railway__create-bucket", "mcp__railway__create-deployment", "mcp__railway__create-function", "mcp__railway__create-project", "mcp__railway__create-service", "mcp__railway__create-tcp-proxy", "mcp__railway__create-volume", "mcp__railway__delete-bucket", "mcp__railway__delete-feature-flag", "mcp__railway__delete-service", "mcp__railway__delete-tcp-proxy", "mcp__railway__delete-volume", "mcp__railway__deploy-template", "mcp__railway__generate-domain", "mcp__railway__redeploy", "mcp__railway__restart-service", "mcp__railway__set-feature-flag", "mcp__railway__set-project-tracing", "mcp__railway__set-service-tracing", "mcp__railway__set-variables", "mcp__railway__update-function-source-code", "mcp__railway__update-service", "mcp__railway__update-volume", "mcp__railway__railway-agent" ] } } hope i haved helped you :)

13 days ago

Holy Formatting of the json, sorry i dont figure out how to do this nicely here


sohejl1
PROOP

8 days ago

Thank you kobolol, i’ll try this out! Is this like a hard enforcement that claude cannot make that call at all? even if he tries to do it, it fails?


sohejl1

Thank you kobolol, i’ll try this out! Is this like a hard enforcement that claude cannot make that call at all? even if he tries to do it, it fails?

8 days ago

Yes, its not evaluated by the AI model instad its hardcoded in the Claude Code Harness :)


kobolol

Yes, its not evaluated by the AI model instad its hardcoded in the Claude Code Harness :)

8 days ago

But of course only for the mcp actions, if you let your agent run bash commands and you have railway installed it could to everything with commands. You also can deny commands in claude code.


Status changed to Solved sohejl1 • 5 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...