Render’s MCP server lets an agent work with the services in a Render workspace: create them, deploy them, read their logs and metrics, and query their Postgres databases. It cannot delete anything, which makes it a comfortable first infrastructure server.
https://mcp.render.com/mcp
Claude Sonnet 4.5
Chat with 60+ AI models on the same workflow — switch to a different model mid-conversation and re-run the same prompt, or use Compare mode to put several side-by-side and balance quality vs. cost.
OAuth for interactive clients, or a Render API key as a bearer token. The server acts within the workspace you select.
How models use it and what it is built for.
Every action is scoped to one workspace, which you set first with a prompt such as “set my Render workspace to Acme”. From there the agent can create web services, static sites, cron jobs, Postgres databases and Key Value instances; list, read and update services; trigger deploys and read deploy history; filter logs; and read metrics such as CPU, memory, instance count, response codes and times, and bandwidth. Postgres access is read-only SQL. The limits are deliberate: the server does not delete resources, updates are limited to environment variables, and it creates only those five service types. That shape suits the questions an on-call engineer asks — why did the last deploy fail, what changed in error rate — without letting an agent tear anything down.
Typical tools an AI model can call. Exact names vary by version.
Taken from the official Render documentation — see Render MCP Server documentation for the full reference.
Client configuration
API key
For clients that do not support OAuth. Create the key in your Render account settings.
{
"mcpServers": {
"render": {
"type": "http",
"url": "https://mcp.render.com/mcp",
"headers": {
"Authorization": "Bearer <RENDER_API_KEY>"
}
}
}
}Copy any of these into MCP Agent Studio after connecting.
Set my workspace to Acme, then tell me why the last deploy of the api service failed.
Show 5xx responses for the web service over the last hour and the log lines around the spike.
Which of my services used the most memory this week?
Run a read-only query on the orders database: how many orders were created today?
This is not a single-model product: you get the same MCP connection with 60+ models (Claude, GPT, Gemini, DeepSeek, open-weight, and more), you can switch mid-conversation, and you can open Compare mode to run the same prompt against multiple models at once. The card above is a suggested starting point for this server — not the only choice.
Default pick for Render
Claude Sonnet 4.5
Debugging a deploy means joining deploy history, logs and metrics across several calls. Sonnet 4.5 keeps that chain straight and reports what it actually found.
Listing tools proves the server is reachable, not that a model can work with it. Evals go further: they read every tool on the server, write a test suite from its real schemas, and run it — code decides pass/fail on the responses (schema conformance, error codes, pagination, result caps) while a scoring model grades plain-English tasks driven through the tools.
Get a pass/fail report per tool with the evidence behind each verdict — and replay the same suite after every schema change. Destructive tools are excluded from the run.
Run evalsOpen MCP Agent Studio with the connection pre-filled. Add your token, pick any of 60+ models, and start chatting — no install required.
Open Agent StudioCommon questions about connecting, scoping and using it safely.
No. Render’s server does not support deleting resources, so an agent cannot tear down a service or database through it.
Every action is scoped to one workspace. Set it first with a prompt such as “set my Render workspace to Acme”, and the agent works only inside that workspace.
Only environment variables. Other settings, such as IP allowlists, are not supported through the server.
Yes, with read-only SQL on Render Postgres. It cannot write to the database.
Safer than most infrastructure servers, because there are no deletes and Postgres is read-only. It can still trigger deploys and change environment variables, and Render notes it does not guarantee sensitive values will never appear in output, so start with a staging workspace.