2 months ago
My service cronometer-mcp-allowlist (project resourceful-cooperation, domain cronometer-mcp-allowlist-production.up.railway.app) is unreachable when called from Anthropic's Claude servers via MCP, but works fine when I hit it directly from my own network.
Symptoms:
- All MCP tool calls from Claude have been failing with generic execution errors since approximately 2026-08-19 23:16 UTC.
-
- Deploy Logs and Network Logs (HTTP tab) show no record of these failed requests at all - they aren't reaching the app or even being logged at the edge.
-
- I navigated directly to the service root URL from my own browser/network just now and got a normal 404 (expected, no route for "/") with request logged fine - so the service itself is healthy and reachable from my IP.
-
- I redeployed the service (fresh build, same config) and the issue persisted.
-
- The service is fronted by an nginx allowlist proxy in log-only mode (ENFORCE_ALLOWLIST=false), so it should not be actively blocking anyone itself, and my own nginx logs would show requests if they were reaching the container at all - they aren't.
This matches a previously reported issue on Central Station: "Production service returning 403 host_not_allowed from outside my home network" (station.railway.com/questions/production-service-returning-403-host-n-ae9b5924), where a Railway edge feature was silently blocking external callers (including Anthropic's servers) while the owner's own traffic got through fine, with 403 responses missing standard railway-edge headers.
Could you check whether a similar edge-level allowlist/anti-abuse rule is active on my project and blocking Anthropic's outbound IP ranges from reaching this service?
Service: cronometer-mcp-allowlist
Project: resourceful-cooperation
Domain: cronometer-mcp-allowlist-production.up.railway.app
Last known-good request in Network Logs: 2026-08-19 23:16 UTC
Current time: 2026-08-19 23:41 UTC
Thanks for taking a look!
3 Replies
2 months ago
This thread has been opened as a bounty so the community can help solve it.
Status changed to Open Railway • about 2 months ago
2 months ago
Hi,
I think the problem is happening before the request reaches your container, such as DNS/TLS/connectivity or an upstream Anthropic/MCP networking issue.
Could you please provide the exact error/status Claude receives? Instead of saying "generic execution errors".
2 months ago
Couldnt it be by "Under Attack Mode" being activated?
vitakili
Couldnt it be by "Under Attack Mode" being activated?
a month ago
Yes, 100%
As it blocks non-browser traffic (such as Claude/MCP requests).