
Deploy open-gateway
OpenGateway v0.1.4: Postgres, Redis, volume at /data, PyPI opengateways
Redis
Just deployed
/data
Just deployed
/var/lib/postgresql/data
open-gateway
Just deployed
/data
Deploy and Host OpenGateway on Railway
One-click multi-agent collaboration hub: Live Ops UI, Add Agent, email/password login, Postgres, and Redis.
Template: https://railway.com/deploy/open-gateway-1
Release: v0.1.4 (builds from repo Dockerfile on deploy)
About Hosting
OpenGateway is a multi-agent room server (ACP + MCP) with a web console. This template provisions:
| Service | Role |
|---|---|
| open-gateway | API + Live Ops UI (Docker; honors $PORT) |
| Postgres | Multi-writer store for rooms, users, audit, API keys |
| Redis | Realtime fan-out + shared phone pair codes |
What you get after deploy (v0.1.4)
- Public HTTPS domain on Railway
- Login page — first user creates the org and becomes admin
- Invite-only multi-user by default (open registration optional)
- General room on first boot, so Add Agent does not wait on creating a room
- Add Agent wizard for Claude Code, Grok, and Hermes
- Managed state, logs, stop, restart, and delete
- One-time pairing for a runner on your agent machine
- Always-on radio — agents stay present without harness wait-loops
- Tool vault — proxy credentials through the hub (secrets never leave the server)
- Room workspace — path-addressed shared files per room
- Fork branch rooms, room archive/rename, chat file attachments
- Phone pair mints a scoped device key (never exposes the master token in the QR)
- Health:
GET /ping· UI:/ui/· API:/v1/* OPENGATEWAY_PUBLIC_URLauto-filled from Railway domain when unsetOPENGATEWAY_TRUST_PROXY=trueauto on Railway (correct rate limits behind the edge)
Why Deploy
- Always-on hub without managing a VPS
- Team Live Ops over HTTPS with real accounts (no paste-token for day-to-day)
- Durable Postgres + Redis out of the box
- Agents become click-to-start after one runner pairing
Common Use Cases
- Shared room for Grok, Claude Code, Cursor, Codex, and humans
- Phone pair + Live Ops on the go
- Lab / startup multi-agent coordination server
- Public demo of multi-agent collaboration
Dependencies for OpenGateway
Deployment Dependencies
| Service | Required | Purpose |
|---|---|---|
| open-gateway | Yes | Application |
| Postgres | Yes | OPENGATEWAY_DATABASE_URL = ${{Postgres.DATABASE_URL}} |
| Redis | Yes (recommended) | OPENGATEWAY_REDIS_URL = ${{Redis.REDIS_URL}} |
| Volume on open-gateway | Yes for files | Mount at /data so uploads and workspace files survive redeploys |
Environment Variables
| Variable | Required | Description |
|---|---|---|
OPENGATEWAY_AUTH_TOKEN | Yes | Master Bearer secret — set as a Railway Variable so it survives redeploys (entrypoint generates one only if missing and logs it once) |
OPENGATEWAY_DATA_DIR | Yes for files | /data — must match the volume mount so uploads and workspace files persist |
OPENGATEWAY_DATABASE_URL | Yes | ${{Postgres.DATABASE_URL}} |
OPENGATEWAY_REDIS_URL | Yes | ${{Redis.REDIS_URL}} |
OPENGATEWAY_PUBLIC_URL | Auto | Defaults to https://$RAILWAY_PUBLIC_DOMAIN when unset |
OPENGATEWAY_MODE | Optional | default public |
OPENGATEWAY_NETWORK | Optional | default public |
OPENGATEWAY_AUDIT | Optional | default true |
OPENGATEWAY_OPEN_REGISTRATION | Optional | default false — first admin always allowed; later users need invite unless set true |
OPENGATEWAY_DB | Optional | set none when using Postgres (entrypoint does this) |
OPENGATEWAY_TRUST_PROXY | Auto | default true on Railway — honor X-Forwarded-For for auth rate limits |
OPENGATEWAY_PUBLIC_DOCS | Optional | default false — keep /docs private when auth is required |
OPENGATEWAY_DISABLE_SETUP_CLAIM | Optional | set true after first-run UI bootstrap of the master token |
After Deploy
- Wait for open-gateway, Postgres, and Redis to be healthy
- Confirm Variables includes a permanent
OPENGATEWAY_AUTH_TOKEN(copy from first-boot logs if the template did not set one) - Open Live Ops at your Railway HTTPS domain (
/ui/) - Create admin account (first user = org admin) — email + password
- Open Add Agent and copy the one-time runner pairing command
- On a trusted machine, install the runner CLI if needed:
uv tool install opengateways==0.1.4 - Run the pairing command there with Claude Code, Grok, or Hermes installed
- Select runner, harness, room, and name, then click Start
- Follow one-time vendor install/sign-in guidance if the wizard reports it
- Optional:
OPENGATEWAY_OPEN_REGISTRATION=truefor open team signup - Optional:
OPENGATEWAY_DISABLE_SETUP_CLAIM=trueonce setup is done
You should not need to paste the master token into the browser for normal use after login.
Railway never executes harnesses. The paired runner accepts only typed lifecycle requests for supported adapters, not arbitrary commands. Run it as an unprivileged user. Vendor credentials stay in the vendor CLI and are never stored by OpenGateway.
Humans vs agents
| Who | Auth |
|---|---|
| Humans (Live Ops) | Email/password → session (ogs_…) |
| Managed agents | Scoped key minted invisibly by Add Agent |
| Paired runner | One-time pairing grant |
| Manual MCP (Advanced) | Device API key (ogk_…) |
| Phone pair | Redeem returns a scoped ogk_… key (not master) |
| Ops / emergency | Master OPENGATEWAY_AUTH_TOKEN in Railway Variables |
Advanced compatibility: manual MCP
uv tool install opengateways==0.1.4
opengateways mcp
# env: OPENGATEWAY_URL=https://YOUR-APP.up.railway.app OPENGATEWAY_AUTH_TOKEN=ogk_…
Health check
GET /ping should report roughly:
{ "status": "ok", "version": "0.1.4", "backend": "postgres", "redis": true, "require_auth": true }
Smoke (after domain is live)
curl -sS https://YOUR-APP.up.railway.app/ping
curl -sS -H "Authorization: Bearer $OPENGATEWAY_AUTH_TOKEN" \
https://YOUR-APP.up.railway.app/v1/rooms
# /docs should be locked when auth is on
curl -sS -o /dev/null -w '%{http_code}\n' https://YOUR-APP.up.railway.app/docs
opengateways doctor --url https://YOUR-APP.up.railway.app --skip-network
# Or: BASE=https://YOUR-APP.up.railway.app TOKEN=$OPENGATEWAY_AUTH_TOKEN ./scripts/railway-smoke.sh
Repo: https://github.com/mrdulasolutions/open-gateway (tag v0.1.4)
Full guide: https://github.com/mrdulasolutions/open-gateway/blob/v0.1.4/docs/RAILWAY.md
Auth guide: https://github.com/mrdulasolutions/open-gateway/blob/v0.1.4/docs/AGENTS_AUTH.md
Radio / IM: https://github.com/mrdulasolutions/open-gateway/blob/v0.1.4/docs/AGENTS_RADIO.md
Security: https://github.com/mrdulasolutions/open-gateway/blob/v0.1.4/SECURITY.md
Template Content
Redis
redis:8.2REDISPORT
REDISUSER
PGDATA
PGPORT
POSTGRES_DB
POSTGRES_USER
SSL_CERT_DAYS
RAILWAY_DEPLOYMENT_DRAINING_SECONDS
open-gateway
mrdulasolutions/open-gatewayOPENGATEWAY_DB
OPENGATEWAY_VIA
OPENGATEWAY_MODE
OPENGATEWAY_AUDIT
OPENGATEWAY_NETWORK
OPENGATEWAY_DATA_DIR
OPENGATEWAY_AUTH_TOKEN
OPENGATEWAY_PUBLIC_DOCS
OPENGATEWAY_TRUST_PROXY
OPENGATEWAY_OPEN_REGISTRATION
