Running Rayrun as a service, AI Agents

Rayrun Agency Implementation, Secure Multi-Tenant AI Agent Delivery

Learn how to deploy and manage MCP servers for multiple clients using Rayrun's central credential vault and per-client access policies. This course covers server deployment from source code and OpenAPI specs, credential isolation workflows, audit trail setup, and productized agent services that clients can't replicate without your infrastructure.

Open the decision record for Rayrun

What does running Rayrun for clients commit you to?

Published figures for this service. Blank fields are not published.

Monthly tool cost
Vendor cost basis: freemium entry tier covering one developer. Paid tier amounts are not published in the supplied pricing data, so higher-tier vendor costs must be quoted directly from Rayrun.
Time to first value
Setup complexity medium; time to value days (vendor published)
Payback
Not modeled
Guided implementation
8 hours

Is Rayrun worth running as a client service?

The evidence supports a real operational offer: one endpoint holding credentials, per-tool policy, and a searchable audit trail that streams to a SIEM, backed by published controls. What remains unknown is the paid vendor tier cost, the client price, labour rate, and expected volume, so delivery economics cannot be modelled from this data alone.

An agency-fit judgement for reselling this service. It is separate from the tool description on the decision record.

Before you start

What has to be in place before the first client engagement.

Tools and subscriptions

  • Rayrun free developer workspace (freemium entry tier)
  • MCP client from the supported list: Claude, Codex, Cursor, VS Code, Windsurf, or OpenCode
  • Node.js SDK or Python SDK access
  • Upstream service credentials for the client's Linear, Stripe, or Notion services
  • TypeScript or Python project scaffolded via rayrun init

People and inputs

  • Engineering or coding-agent capability to build and maintain MCP servers
  • A client willing to give Rayrun custody of upstream credentials or provide an AWS account
  • Security review documentation: published controls, third parties with workspace data, SOC 2 and HIPAA position
  • SIEM destination for signed audit export

Lessons in this course

7 lessons on running Rayrun for clients.

  1. 01Rayrun: Why MCP Credential Centralization Changes Agency Delivery EconomicsStrategy
  2. 02Rayrun Credential Blast RadiusConcept
  3. 03Rayrun Rule: Adopt When Client Tool Calls Stay Under 100,000 Per DeveloperEvaluation Rule
  4. 04Rayrun: Buy vs Skip (Multi-Client MCP Credential Control)Decision Framework
  5. 05The Rayrun Credential Sprawl Trap: Why Agencies Fail With MCP HostingFailure Pattern
  6. 06Rayrun Client Onboarding Sprint (5-7 days)Implementation Blueprint
  7. 07Rayrun Client Workspace Setup (Onboarding)Operating Procedure

Included with the course

7 working documents for delivering this service.

  • MCP Server Deployment Checklist for Multi-Client Setupchecklist
  • Per-Client Access Policy Template and Enforcement Guidetemplate
  • Credential Vault Onboarding SOP for Agency Teamssop
  • Agent-Built MCP Project Scaffolding Worksheetworksheet
  • Audit Trail and SIEM Integration Setup Guideguide
  • Pricing Tier Mapping for Retainer-Based Agent Servicesworksheet
  • Secret Scanning and Injection Attack Prevention Playbookguide

Listed by name. These documents are not yet published as individual downloads.