rails-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| RAILS_MCP_CONFIG_PATH | No | Path to your rails.config.{yaml,yml,json}. Unset = honest-empty registry. | |
| RAILS_MCP_SPEND_LEDGER_PATH | No | Where the append-only spend-intent ledger lives. | ./rails_data/spend.jsonl |
| RAILS_MCP_SIGNOFF_LEDGER_PATH | No | Where the append-only sign-off ledger lives. | ./rails_data/signoff.jsonl |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| logging | {} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| extensions | {
"io.modelcontextprotocol/ui": {}
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| classify_actionA | Default-deny classification for an action_type: ALWAYS returns GATED, whether or not the action_type is registered. There is no fail-open branch and no argument that can change this -- it is the one invariant this server refuses to make configurable. Use is_action_registered to check whether an action_type has a known enforcement entry; that is a separate, informational question. |
| is_action_registeredA | Whether action_type has an entry in the loaded rails registry, plus its enforcement_layer / enforcement_pointer / ceremony when present. Registration is informational only -- classify_action's GATED verdict never depends on it. |
| get_rails_hashA | 12-hex sha256 digest of the currently loaded action registry, plus its entry count. Changes iff the registry's contents change -- this is the value a human sign-off (rails-mcp sign, CLI-only, never an MCP tool) records into the audit ledger. |
| get_signoff_stateA | Current active human sign-off of the registry (operator, signedAt, the registryHash they signed, optional note), or null if never signed or most-recently revoked. Read-only -- signing itself is a CLI-only ceremony ( |
| record_spend_intentA | Append one spend-intent record to the append-only ledger. This RECORDS intent to spend -- it never calls a vendor, a paid API, or a broker, and it cannot itself authorize or block a spend. |
| evaluate_budgetA | Sum spend_intent amounts recorded within the last window_days and compare against limit_usd. Never raises -- an empty ledger reads as total_spent_usd=0.0, within_budget=True. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 6 tools
Each tool targets a distinct operation: classification, registry lookup, hash digest, sign-off state, spend recording, and budget evaluation. Even the two action-related tools are explicitly differentiated: one always returns a fixed verdict, the other is purely informational.
All tool names follow a clear verb_noun pattern (classify_, is_, get_, record_, evaluate_). The 'is_' prefix for a boolean check is consistent with common naming conventions, and there is no mixing of styles.
Six tools is well within the ideal range for a focused governance/guardrail server. Each tool has a clear responsibility, and the set feels neither sparse nor bloated.
The surface covers the core lifecycle: classification, registry status, hash verification, sign-off state, spend intent recording, and budget evaluation. Minor gaps exist (e.g., no tool to inspect individual ledger entries or revoke sign-off), but these are intentionally delegated to CLI or aggregate operations, so the coverage is reasonable.