Which token to create
The Railway connector talks to one URL, https://backboard.railway.com/graphql/v2, which is the public GraphQL API described in Railway's public API guide. That guide lists 3 token types. Account tokens reach “all your resources and workspaces.” Workspace tokens reach a single workspace. Project tokens reach “a single environment in a project” and are sent in a Project-Access-Token header rather than as a bearer. Account and workspace tokens come from the tokens page in account settings; project tokens from the tokens page in project settings.
Use a project token for the environment you want watched, usually production. It is the narrowest scope Railway offers. The guide does not describe a read-only token type, so the token Mepa8 holds can also stop a deployment, which is exactly the call the kill makes; the key is encrypted at rest and every call is in the audit log.
Create the token
- Open the project in Railway, go to its settings, and open the tokens page.
- Create a project token for the production environment and name it
mepa8. - Copy it once. Mepa8 keeps the last 4 characters visible and nothing more.
- In Mepa8, Add vendor → Railway → paste → Save. The first check runs immediately.
What Mepa8 reads
Each check runs the deployments query, which Railway's deployment guide describes as “get all deployments for a service in an environment,” and compares the latest deployment's status and time against the newest commit on the branch the service deploys from. It reads the plan and usage figures the API exposes for the environment and prices them at the published rates from the pricing page: $0.00000772 per vCPU-second and $0.00000386 per GB-second of memory, read October 9, 2026, which come to about $20 per vCPU and $10 per GB a month. Three calls per check, 72 a day.
The signal this connector exists for is “main is ahead of production.” On October 8, 2026 our own board showed the CRM backend 321 hours behind its main branch, because CI had been red since September 23 and then the trial expired with an unpaid invoice. Nothing had deployed for 2 weeks and nobody knew. The incident write-up has the timeline.
Alerts this connector raises
- Warning when the latest deployment is skipped or failed.
- Warning when main is more than 6 hours ahead of production, critical past 48 hours.
- Critical when the API reports a paused workspace or a payment problem, because nothing can ship until a person fixes a card.
- Warning when usage is on pace past the budget, critical when it passes Railway's own hard limit if you have set one.
“deploymentStop — Stop a running deployment.”Railway manage-deployments guide, read 2026-10-09
The kill, by API
Railway is Full tier because the kill is a named mutation. Confirming a kill runs deploymentStop on the deployment listed in the propose screen, and restore runs deploymentRedeploy, both quoted from the deployment guide, which also lists deploymentRestart, deploymentRollback and deploymentRemove. Mepa8 never calls remove; the deployment stays in history so the redeploy has something to redeploy. The blast radius is the service itself: it stops serving, including requests in flight, and the propose screen says so with the service name.
Set Railway's own usage limits as a second line. The usage-limits reference describes a soft limit that emails you and a hard limit that takes workloads offline; Mepa8 checks that a hard limit exists and warns if it does not.
Straight answers
Can I give Mepa8 a read-only Railway token?
Railway's public API guide describes token scope by resource, account, workspace or project, and does not describe a read-only type. Use a project token for one environment, which is the narrowest scope. Mepa8 encrypts it, calls 3 queries per check and logs every call.
What does the kill do to my service?
It runs the deploymentStop mutation on the one deployment named in the propose screen. The service stops serving. Restore runs deploymentRedeploy on the same deployment. Both actions are in the audit log with your name, the time and the deployment ID.
Why does Mepa8 check how far main is ahead?
Because an undeployed branch is an outage nobody has noticed yet. Our own backend sat 321 hours behind main in October 2026 while CI was red and a trial had expired. The alert names the hours and the likely cause so the fix is obvious.
Sources
- Railway — public API guide (tokens, endpoint) — read 2026-10-09
- Railway — manage deployments (queries and mutations) — read 2026-10-09
- Railway — usage limits — read 2026-10-09
- Railway — pricing — read 2026-10-09
Change log: October 9, 2026 — First published. Token types and mutation names read from the Railway docs the same day.
Find out what you are paying before the next invoice does.
Five business days. Every vendor listed with real cost, every leak named with its fix, and a board you keep.