Rayrun
Rayrun hosts MCP servers behind a single endpoint, eliminating the need for clients to store and manage upstream API credentials. Agencies deploy servers from source code, remote MCP, OpenAPI specs, npm packages, or container images, then enforce per-client, per-tool access policies and record every tool call. It integrates with Claude, Cursor, VS Code, Windsurf, and OpenCode, and supports scaffolding MCP projects for AI agents to build and deploy autonomously. The platform scans tool definitions and payloads for secrets and injection attacks, making it a fit for agencies serving clients that require security review or multi-tenant credential isolation.
Rayrun is an AI agent, priced at $25/month on the Team plan, integrating with Linear, Stripe, Notion, and Claude. InnovaAI scores it 5.5/10 for agency resale.
Agency Audit
Rayrun hosts MCP servers behind a single endpoint, centralizing upstream credentials and enforcing per-client access policies so agencies don't distribute secrets across client environments. It records every tool call, supports deploying from source, remote MCP, OpenAPI, npm, or container images, and integrates with Claude, Cursor, VS Code, and Windsurf. Best for agencies building AI agent tooling or deploying MCP servers across multiple clients. Resale potential exists for agencies serving clients that require security review or multi-tenant credential management, though pricing scales per tool call rather than per-client retainer.
5.5/10
34%
2d 1-2 days
- You're building AI agent tooling for clients and need to deploy MCP servers without distributing API keys or secrets to each client.
- Your clients require security review and you need signed audit streaming to their SIEM (Enterprise plan includes OIDC/SAML and SCIM 2.0 provisioning).
- You manage 5+ client accounts and need per-client, per-tool access policies enforced in one place rather than scattered across client configs.
- Your clients are price-sensitive and you cannot absorb or pass through per-tool-call overage costs beyond the Team plan's 100,000 monthly pooled calls.
- You need a white-labeled portal or dashboard to present to clients under your agency brand.
- Your clients require HIPAA compliance or FedRAMP certification; Rayrun does not publish these compliance certifications.
Profit Path
$25/mo
$600–$1.5K/project
Hybrid
From 242 published agency rates in USA, 25th to 75th percentile x 20h of assumed delivery time. Rates are self-reported directory profiles, not observed transactions.
Platform Features
Core capabilities of Rayrun
Central credential vault with per-client access policies
Agencies store upstream service credentials once in Rayrun, then enforce allow/ask/block policies per service, tool, and argument for each client. Clients never handle raw API keys, reducing secret sprawl and compliance risk.
Deploy MCP servers from multiple source types
Connect remote MCP endpoints, OpenAPI specs, npm packages, or container images as upstream services without writing adapters. Rayrun discovers tools and exposes them over a single endpoint.
Scaffold and deploy agent-built MCP projects
Hand a scaffolded TypeScript or Python project to Claude or Codex, let the agent build and test the server, then deploy with one command. Rayrun streams build status and manages releases with automatic rollback on failure.
Complete audit trail with signed SIEM streaming
Every tool call is recorded with caller identity and applied policy. Enterprise plan supports signed audit streaming to a SIEM for compliance-heavy clients.
Secret and injection scanning
Rayrun scans tool definitions and payloads for exposed secrets, personal data, and prompt injection patterns before execution, reducing data leakage risk in multi-client environments.
Shared credential vault and team roles
Team plan enables credential sharing across developers and role-based access control, so agencies can onboard new team members without duplicating secrets or access setup.
What Makes Rayrun Different
Unique advantages vs similar tools in this niche
One endpoint replaces every client's per-server config and stored secret
vs Distributing mcp.json files with embedded API keys to each clientEach client stores one URL and no secrets, while Rayrun holds the upstream credentials.
Per-argument access decisions with human approval for destructive calls
vs Blanket tool access with no per-call policyA call that needs a person waits for one, and refund_charge can be set to Ask while list_charges is Allow.
Changed tool definitions are held for review and scanned for prompt injection
vs Silently accepting updated tool definitions from upstream servicesContent scanning checks both directions for secrets, personal data, and prompt injection before a definition goes live.
Latest Updates
Recent releases and improvements for Rayrun
Build and host MCP servers from source
NewNew feature allowing users to build and host MCP servers from source via Rayrun Deploy.
Investment ROI Calculator
Value equation analysis for Rayrun, based on the Hormozi framework
What is the Hormozi framework? A four-factor score: (what the service delivers × how reliably it delivers) divided by (how long it takes × how much effort it requires). A higher Value Multiplier means a better return on the time and money invested: faster, easier, and more proven results.
2.1× value multiple: invest $25/mo and agencies typically charge $600–$1.5K/project for the work it powers.
Why This Succeeds
Higher is betterClient Results Potential
What your clients actually get
Incremental gains: position as part of a larger solution stack
Your coding agent builds the servers. Rayrun runs them behind one URL and holds the credentials.
Reliability Score
How consistently this delivers results
Early-stage track record: validate with a small pilot first
Rayrun publishes its controls, the third parties that see workspace data, and where it stands on SOC 2 and HIPAA.
Implementation Challenges
Lower is betterTime to First Revenue
How long until you can start earning
Standard ramp-up: accelerate to 1 day with Academy SOPs
Expect a few days from signup to first client delivery
Setup Effort
What it takes to get running
Near-turnkey: minimal setup before you can sell
Moderate effort: standard configuration with some customization needed
Viable opportunity. Rayrun returns 2.1× on investment. Focus on the highest-margin service packages to maximize return.
Pricing
Rayrun platform cost to your agency
Team: $25/mo
Free
- Up to 25 source-built services
- 50 isolated builds a day and 5 GiB of retained images
- Encrypted build logs and 30 days of rollback images
- Persistent storage for hosted services
Team
- Everything in Free
- Shared credential vault across the team
- Roles and client-specific access
- 100,000 tool calls per developer a month, pooled
Enterprise
- Everything in Team
- OIDC or SAML 2.0 single sign-on
- SCIM 2.0 provisioning
- Access granted by directory group
No verified white-label program for Rayrun: client-facing delivery runs under the platform's native branding.
Market Intelligence
How agencies monetize Rayrun: real offer economics and market positioning
- Agencies building AI agent tooling for clients
- Teams deploying MCP servers for multiple clients
- Organizations that must pass a security review
- Agencies with no engineering or coding-agent capability
- Solo users who only need a single local MCP config
Project-Based
ai-toolsAgency charges per-project fee for implementation. Ongoing optimization as optional retainer.
Offer Economics: What You Charge vs. What It Costs
Margin includes platform cost + agency labor at $75/hr.
Local service businesses (salons, clinics, contractors) needing a single AI tool integration with secure credential management
Funded startups and regional brands integrating multiple SaaS tools into a unified AI agent layer with team access controls
Mid-market companies (50–500 employees) standardizing AI tool access across departments with compliance and audit requirements
Enterprise organizations (500+ employees) requiring SSO, SCIM provisioning, directory-group access, and signed audit streaming for AI tool governance at scale
Scale Economics: Based on Starter Offer
Using Rayrun Starter MCP Deploy at $1.8K/client. Platform: $25/mo. Labor: 4h/client × $75/hr.
Net = MRR - platform cost - labor (4h/client × $75/hr).
Investment Decision Framework
Strategic vetting analysis for Rayrun
Consider
Favorable fit, worth a closer look
Buy If
5Your clients require security review and you need signed audit streaming to their SIEM (Enterprise plan includes OIDC/SAML and SCIM 2.0 provisioning).
You're building AI agent tooling for clients and need to deploy MCP servers without distributing API keys or secrets to each client.
You manage 5+ client accounts and need per-client, per-tool access policies enforced in one place rather than scattered across client configs.
Your agents use Linear, Stripe, or Notion and you want those integrations available without writing adapters.
You want to scaffold MCP projects with Claude or Codex and deploy them without manual credential management.
Skip If
5You're reselling to non-technical clients who cannot integrate an MCP endpoint into their existing Claude or Cursor workflows.
Your clients are price-sensitive and you cannot absorb or pass through per-tool-call overage costs beyond the Team plan's 100,000 monthly pooled calls.
You need a white-labeled portal or dashboard to present to clients under your agency brand.
Your clients require HIPAA compliance or FedRAMP certification; Rayrun does not publish these compliance certifications.
You need support for legacy API integrations that are not available as MCP, OpenAPI, npm, or container images.
Bottom Line
Rayrun hosts MCP servers behind a single endpoint, centralizing upstream credentials and enforcing per-client access policies so agencies don't distribute secrets across client environments. It records every tool call, supports deploying from source, remote MCP, OpenAPI, npm, or container images, and integrates with Claude, Cursor, VS Code, and Windsurf. Best for agencies building AI agent tooling or deploying MCP servers across multiple clients. Resale potential exists for agencies serving clients that require security review or multi-tenant credential management, though pricing scales per tool call rather than per-client retainer.
Reality Check
Rayrun's per-tool-call pricing model (USD 0.2 per 1,000 calls) means agency margins depend on predicting client usage; high-volume agent deployments can exceed the Team plan's 100,000 pooled calls per developer per month. No verified white-label offering means clients see Rayrun branding in their MCP configuration.
Moderate effort: standard configuration with some customization needed
Academy for Rayrun
Work through it in order: the course for this service first, then the modules behind it.
No Academy modules are published for this service yet. Browse the full Academy
Why this category matters
The commercial case before the tooling.
Core concepts
The mental model you need to price and scope the work.
- Wiring Over WidgetsConcept
The AI agent itself is a commodity, but the value for agencies lies in the integration layer: connecting a pre-built agent to a client's CRM, calendar, and review cycle. This framework shifts focus from selecting the 'best' agent to mastering the wiring process. For example, an agency using Vendasta's white-label AI receptionist for a local business must configure it to match the client's booking rules and follow-up cadence, turning a generic tool into a tailored service. As agentic AI adoption grows (77% of decision-makers now run agents in production), clients expect this customization. Agencies that treat agents as components and invest in repeatable wiring processes can charge retainers for ongoing optimization, rather than one-off setup fees.
- Integration MoatConcept
The Integration Moat framework holds that the durability of an AI agent engagement is determined by how deeply the agent is wired into a client's existing systems, not by the agent's underlying capability. Since the agent itself is increasingly a commodity, the switching cost for the client lives in the integrations: the CRM fields mapped, the calendar sync, the review-cycle triggers, and the exception-handling rules. Agencies that invest in this wiring create a moat that competitors offering generic agents cannot cross. For example, a white-label platform like Vendasta lets an agency deploy an AI receptionist for a local business, but the real value is in configuring it to the client's booking flow and follow-up cadence. With 77% of AI decision-makers now running agentic AI in production, clients expect this depth, and agencies that deliver it convert one-off projects into retainers.
- Agent Commodity, Wiring PremiumConcept
The agent itself is a commodity, but the wiring into a client's CRM, calendar, and review cycle is where value accrues. Agencies that treat AI agents as components rather than products win by owning the integration layer. For example, a white-label platform like Vendasta lets agencies resell AI employees, but the real margin comes from configuring those agents for each client's specific workflows. This framework explains why retainer pricing is sustainable: the agent is replaceable, the wiring is not.
Decision and risk
How to judge the fit, and the ways it goes wrong.
- AI Agents Rule: Wire the Agent, Not the ProductEvaluation Rule
Treat the AI agent as a commodity component and focus your value on the integration into the client's specific workflows, systems, and review processes.
- When Clients Ask for AI Agents, Sell the Outcome, Not the AgentEvaluation Rule
Position the AI agent as a component of a larger workflow, and price the integration and ongoing optimization as the retainer.
- The Productized Agent Trap: Why AI Agent Services Stall Without Client-Specific WiringFailure Pattern
- The Agent-as-Product Trap: Why AI Agent Services Stall Without Client-Specific WiringFailure Pattern
8 modules selected for Rayrun
Frequently Asked Questions
Answers about pricing, setup, implementation, and more
Rayrun hosts MCP servers behind a single endpoint, holding upstream service credentials centrally so clients never store secrets. It enforces per-client, per-tool access policies, records every tool call with caller identity and applied policy, and supports deploying servers from source, remote MCP, OpenAPI, npm packages, or container images. Agencies can scaffold MCP projects for Claude or Codex to build, then deploy with one command.
Rayrun offers 3 pricing tiers, at $25/mo (Team). Agencies typically achieve 34% profit margins when reselling to clients.
No verified white-label program. Client-facing MCP configurations and activity surfaces display the Rayrun brand. Agencies can deploy Rayrun infrastructure for clients but cannot rebrand the endpoint or dashboard as their own.
Yes. Rayrun supports Linear as a remote MCP integration (https://mcp.linear.app/mcp) and Stripe as an OpenAPI integration (https://api.stripe.com/openapi.json). Both are available as upstream services in the Rayrun dashboard with no adapter code required.
Initial agency account setup takes 5-10 minutes (sign up, add upstream services). Per-client onboarding depends on policy complexity; a basic setup with Linear and Stripe access takes 10-15 minutes. Clients themselves only need to add one MCP endpoint URL to their config, replacing multiple server entries and secrets.
Agencies building AI agent tooling for clients, teams deploying MCP servers across multiple clients, and organizations that must pass a security review. Best suited for clients running Claude or Cursor with MCP support and needing centralized credential management or audit compliance.
Overage calls are billed at USD 0.2 per 1,000 calls. Agencies can monitor usage in the activity dashboard and either upgrade to Enterprise (custom pricing) or implement client-side rate limits via Rayrun's per-tool access policies.
Rayrun does not publish HIPAA or FedRAMP certifications. Enterprise plan includes OIDC/SAML, SCIM 2.0, and signed audit streaming to a SIEM, which support compliance workflows, but healthcare or government clients should confirm compliance requirements directly with Rayrun sales.