Connect a Railway workspace to Jutsu. Jutsu pulls the workspace audit log, which covers shell, exec, file and tunnel access into running containers, variable and secret changes, deployments, and membership changes. It detects threats in those events automatically. Nothing gets installed inside your containers.

TimeAbout 2 minutes with Connect with Railway, or 5 with an API token
You needWorkspace admin access in Railway, and the Owner or Admin role in your Jutsu organization
Collected by defaultThe workspace audit log (railway.audit). Nine more sources can be switched on later

Choose how to connect

Option A: Connect with RailwayOption B: API token
How it worksYou approve Jutsu on Railway's consent screenYou create a token in Railway and paste it into Jutsu
Nothing to copyYesNo. You copy a token and a Workspace ID
Tied to a personYes, the Railway user who approved itNo, if you create a workspace token
If it stops workingJutsu notifies owners and admins, and offers ReconnectThe error shows on the connection page

Choose Option A for the quickest setup. Choose Option B if the connection has to keep running through staff changes without anyone re-approving it.

Both options start the same way.

Step 1 - Open Integrations

Go to app.jutsu.ai and select Integrations in the left navigation. The Data Sources tab opens by default.

Figure 1. Open Integrations. Data Sources is selected.

Step 2 - Select the Railway card

Scroll to the Cloud section and select the Railway card. The Connect Railway dialog opens.

Figure 2. Select the Railway card in the Cloud section.

The card doesn't open? Adding integrations needs the Owner or Admin role in your Jutsu organization. For Analysts, Responders, and Viewers the catalog is read-only.

Option A: Connect with Railway

Step A1 - Choose Connect with Railway

Keep Connect with Railway selected and select Continue.

Figure 3. Connect with Railway is selected. Select Continue.

Step A2 - Name the connection

Enter a name that identifies the workspace, such as Acme — Railway Production, then select Continue to Railway. Railway opens in a new tab.

Figure 4. Name the connection and select Continue to Railway.

Keep the Jutsu tab open. It waits for you to approve access, and closing it abandons the setup.

Step A3 - Review what Jutsu is asking for

Sign in to Railway as a workspace admin if you aren't already. The consent screen shows Jutsu AI asking for:

  • View your identity (openid email profile): shows which Railway account approved the connection.
  • Full control of your workspaces (workspace:admin): Railway only exposes the audit log at this scope. Jutsu uses it to read activity and never changes your workspace.
  • Stay signed in (offline_access): lets Jutsu keep collecting without asking you to sign in again.

Figure 5. Railway's consent screen for Jutsu AI. Select Change to choose workspaces.

Step A4 - Limit access to one workspace and authorize

By default the approval covers All workspaces. Select Change, choose Selected workspaces, and tick only the workspace you want Jutsu to monitor. Then select Authorize.

Figure 6. Tick only the workspace to monitor, then select Authorize.

Warning: You must be a workspace admin. Railway lets anyone approve, but for non-admins it silently narrows the access, and the connection then can't read the audit log. Jutsu checks the audit log before creating the connection, so this shows up as an error rather than a connection that collects nothing.

Railway sends you back to Jutsu, and the Railway tab shows Railway connected. You can close that tab.

Figure 7. The Railway tab confirms the approval. Close it and return to Jutsu.

Step A5 - Choose the workspace and connect

Back in the Jutsu tab, the dialog shows which Railway account approved access and lists the workspaces the approval covers. Select your workspace, then select Connect workspace.

Figure 8. Select the workspace to monitor, then select Connect workspace.

Each connection monitors one workspace. To monitor another workspace, add it as a second connection.

Step A6 - Find it in Connections

Jutsu takes you to Connections. Your workspace appears under Cloud. It shows Warming up for a few seconds, then changes to Healthy.

Figure 9. The Railway connection is listed under Cloud as Healthy.

That's it. Skip ahead to Verify the connection.

Note who approved it: The connection belongs to the Railway user who approved it. Their email appears as Railway account under Configure → Settings. If they leave, or remove Jutsu under Railway Account Settings → Apps, collection stops and Jutsu notifies your organization's owners and admins so someone can select Reconnect.

Option B: API token

Step B1 - Choose API token

In the Connect Railway dialog, select API token, then select Continue.

Figure 10. Choose API token, then select Continue.

Step B2 - Create a token in Railway

In a new tab, sign in to Railway as a workspace admin and open Account Settings → Tokens. Under New Token:

  • Name: something recognisable, such as Jutsu.
  • Workspace: choose your workspace to create a workspace token. It isn't tied to any person, so it keeps working through staff changes. Choosing No workspace creates an Account token instead, which also works if you're an admin.

Select Create.

Figure 11. Name the token, choose the workspace, then select Create.

Warning: A project token will not work. It authenticates fine but can't read anything at workspace level, so the connection would look broken.

Step B3 - Copy the token

Railway shows the token only once. Select the copy button next to it.

Figure 12. Copy the token. Railway won't show it again.

Step B4 - Copy your Workspace ID

Railway doesn't show the Workspace ID on any settings page, even though the Jutsu dialog mentions one. Instead, with your workspace selected, press Ctrl+K (or ⌘K on a Mac), type workspace id, and choose Copy Active Workspace ID.

Figure 13. Press Ctrl+K and choose Copy Active Workspace ID.

Step B5 - Paste the credentials and connect

Back in Jutsu, fill in the Credentials step:

  • Name: something that identifies the workspace, such as Acme — Railway Production.
  • Workspace ID: the value from Step B4.
  • API token: the token from Step B3.

Select Connect.

Figure 14. Name the connection, paste the Workspace ID and token, then select Connect.

What happens next: Jutsu tests the token against your workspace's audit log before it creates anything. If the token can't read the workspace, you'll see why straight away. The token is encrypted at rest, and only its last four characters are ever shown again.

Jutsu takes you to Connections, where the workspace appears under Cloud as Healthy.

Figure 15. The new Railway connection is listed under Cloud as Healthy.

Verify the connection

Open the connection, go to Configure → Settings, and select Test connection. Credentials ok means Jutsu can read the workspace.

Figure 16. Test connection confirms that the credentials are valid.

The ingest counters at the top of the connection page show how many events arrived in the last 5 minutes, hour, and 24 hours.

Figure 17. A Railway connection with events flowing in.

Quiet is normal at first: The audit log only records changes to your workspace, so a new connection can show Healthy · Quiet and last event never until someone deploys, changes a variable, or opens a shell. New connections also start with a Medium and above severity floor. Routine low-severity activity, like redeploys, is kept in raw retention but won't show up as alerts.

What healthy looks like

StatusHealthy
Test connectionCredentials ok
AuthenticationRailway authorization (Option A) or API token (Option B)
Logsrailway.audit, plus any sources you switched on
Poll intervalEvery 5 minutes

Choose what to collect

Under Configure → Settings → Collected sources you can switch on more Railway telemetry for this connection. Changes take effect on the next poll, and nothing already collected is removed.

Figure 18. Collected sources. Only the workspace audit log is on by default.

SourceWhat it adds
Workspace audit logGovernance trail: who changed variables, deployments, members, and settings. On by default
Network flow logsPrivate-network TCP/UDP flows in and out of your containers. High volume
DNS query logsEvery name your services resolve. This source catches DNS tunnelling. High volume
Edge HTTP requestsInbound requests at Railway's edge: client IP, path, status. High volume
Project and deployment eventsRailway's own graded activity stream and per-deployment lifecycle
Application, deployment, and build logsEverything your services write to stdout/stderr. High volume

Warning: High-volume sources can produce orders of magnitude more events than the audit log. They count towards your plan's daily ingest, and going over it pauses collection for every connector in your organization. Turn them on one at a time and watch the 24-hour count.

Troubleshooting

SymptomWhat to do
The Railway card doesn't openYou need the Owner or Admin role in the Jutsu organization.
After approving, no workspaces are listedThe approving account isn't an admin of any workspace it approved. Sign in to Railway as a workspace admin and run Connect with Railway again.
That workspace is not covered by this Railway authorizationThe workspace wasn't ticked on the consent screen. Run Connect with Railway again and tick it.
Railway tab says This link is no longer validThe 15-minute approval window closed, or that link was already used. Start again from Jutsu.
Connection says Re-authorization requiredThe approval was revoked or expired. Select Reconnect on the connection and approve again.
Token is invalid, expired, or was revokedRailway rejected the token. Create a new one and reconnect.
Not entitled to workspace-level dataThis is almost always a project token, or an Account token whose owner isn't a workspace admin. Use a workspace token instead.
Workspace not foundThe Workspace ID is wrong. Copy it again with Ctrl+K → Copy Active Workspace ID.
Connected, but no eventsCheck the Minimum severity floor before you assume the workspace was quiet. At the default of Medium, redeploys and environment changes won't appear.
Ingest stopped across every connectorThe org hit its daily ingest limit after a source was switched on. Switch that source off, then re-enable sources one at a time.

Retention is short: Railway keeps audit logs for 48 hours on Free, Trial, and Hobby plans, 30 days on Pro, and 18 months on Enterprise. Network, DNS, and HTTP logs last about 48 hours on every plan. Railway has no replay, so events that age out while a connection is broken can't be recovered. Fix errors promptly.

Security and access

  • Jutsu only reads from Railway with this connection. It never deploys, edits, or deletes anything.
  • With Connect with Railway, Jutsu never sees your Railway password, and the credential renews itself automatically. With an API token, the token is encrypted at rest and only its last four characters are shown in the UI.
  • Containment actions, such as removing a public TCP proxy or revoking a project token, use a separate response credential that you add on purpose. Revoking the collection credential never affects response, and revoking the response credential never stops collection.

Pause or disconnect

ActionWhat it does
PauseDisable the connection to stop polling without deleting its configuration. Remember the retention window. A long pause on a Hobby plan loses events.
ArchiveStops ingestion and frees the plan slot. Events and alerts already collected stay available.
Revoke access in RailwayArchiving doesn't touch Railway. For Option A, remove Jutsu AI under Railway Account Settings → Apps. For Option B, delete the token in Account Settings → Tokens.