Render

Live

BEARER TOKEN

CLOUD HOSTING

Developer Tools

Render gives your agent access to your cloud hosting stack: list services and deploys, read logs and metrics, manage Postgres and Key Value instances, and trigger deploys or rollbacks with each user's own access token.

  • Per-user credentials: each call uses the actual user's access token, never a shared bot.
  • Encrypted per-tenant vault: AES-256, resolved at request time, never in LLM context.
  • Scoped before every call: pre-call scope check, 90-day SIEM-exportable audit chain.
Render
agent · Acme Q3
Run
Show the last 5 deploys for the checkout-api service.
S
render_deploys_list
96ms
DevOps agent
4 of the last 5 deploys of checkout-api went live. The most recent one, triggered by a commit 2 hours ago, failed during build.
Sources: checkout-api deploy history, 5 deploys
render
5 deploys
18:29
Message Claude...

Tools your DevOps agent reaches for on Render, scoped per user.

CALL ANY TOOL
205 tools for cloud hosting on Render: services, deploys, jobs, logs, metrics, Postgres, Key Value, environment groups, custom domains, and workspace settings.
render_blueprint_disconnect
Blueprint disconnect
Disconnect a Blueprint by its ID, stopping automatic resource syncing from its render.yaml file. Returns no content on success. Disconnecting does not delete any services or other resources previously managed by the Blueprint. Use render_blueprint_disconnect when you want to stop a Blueprint from auto-syncing without removing the resources it created.
Parameters
Name
Type
Required
Description
blueprint_id
string
Required
The ID of the Blueprint to disconnect. Render Blueprint IDs use the `exs-` prefix, e.g. exs-cph1rs3idesc73a2b2mg.
render_blueprint_get
Get blueprint
render_blueprint_syncs_list
List blueprint syncs
render_blueprint_update
Update blueprint
render_cron_job_run
Run cron job
render_cron_job_run_cancel
Cancel cron job run
render_custom_domain_create
Create custom domain
render_custom_domain_delete
Delete custom domain
render_env_groups_list
List env groups
render_environment_delete
Delete environment
render_environment_resources_add
Add environment resources
render_environment_resources_remove
Remove environment resources
render_event_get
Get event
render_job_create
Create job
render_key_value_instance_resume
Resume key value instance
render_key_value_instance_update
Update key value instance
render_maintenance_runs_list
List maintenance runs
render_metrics_bandwidth_sources_get
Get metrics bandwidth sources
render_metrics_memory_get
Get metrics memory
render_postgres_connection_info_get
Get postgres connection info
render_postgres_instance_delete
Delete postgres instance
render_postgres_instance_update
Update postgres instance
render_postgres_processes_list
List postgres processes
render_redis_instance_resume
Resume redis instance
render_registry_credential_create
Create registry credential
render_registry_credentials_list
List registry credentials
render_service_autoscaling_delete
Delete service autoscaling
render_service_env_vars_update
Update service env vars
render_service_outbound_ips_get
Get service outbound ips
render_tasks_list
List tasks

For more tools, view docs.

Build your Agent
Same auth pattern across LangChain, OpenAI, Anthropic, and Google ADK.
Python · LlamaIndex
import { ScalekitClient } from "@scalekit-sdk/node";
import { createReactAgent } from "@langchain/langgraph/prebuilt";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

// Render tools scoped to this user
const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["render"], toolNames: [
    "render_services_list",
    "render_deploys_list",
    "render_logs_list"] },
  pageSize: 100,
});

const agent = createReactAgent({ llm, tools });
await agent.invoke({ messages: [{ role: "user", content: "Show the last 5 deploys for the checkout-api service" }] });
import OpenAI from "openai";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
const openai = new OpenAI();

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["render"] }, pageSize: 100,
});

const res = await openai.chat.completions.create({
  model: "gpt-5",
  messages: [{ role: "user", content: "Show the last 5 deploys for the checkout-api service" }],
  tools,
});

// Execute the tool call with the user's vaulted Render access token
await sk.tools.executeTool(res.choices[0].message.tool_calls[0], "user_123");
import Anthropic from "@anthropic-ai/sdk";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
const anthropic = new Anthropic();

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["render"] }, pageSize: 100,
});

const msg = await anthropic.messages.create({
  model: "claude-sonnet-5",
  max_tokens: 1024,
  messages: [{ role: "user", content: "Show the last 5 deploys for the checkout-api service" }],
  tools,
});

// Tool call runs with the user's vaulted Render access token
await sk.tools.executeTool(msg.content, "user_123");
import { Agent } from "@google/adk/agents";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["render"] }, pageSize: 100,
});

const agent = new Agent({
  name: "devops_agent",
  model: "gemini-2.5-pro",
  instruction: "Render tools scoped to this user",
  tools,
});

await agent.run("Show the last 5 deploys for the checkout-api service");
Try these prompts
Copy any prompt into your agent. Each maps directly to a Render tool. Click to copy, paste into your agent, done.
Services and deploys
Copy the prompt
Copied
List every service in my workspace and its current status.
Copy the prompt
Copied
Show the last 5 deploys for the checkout-api service.
Copy the prompt
Copied
Roll back checkout-api to its previous deploy.
Logs and metrics
Copy the prompt
Copied
Pull error logs for checkout-api from the last hour.
Copy the prompt
Copied
Show CPU and memory usage for the worker service today.
Copy the prompt
Copied
Get HTTP request latency for the web service over the last 24 hours.
Databases
Copy the prompt
Copied
List my Postgres instances and their plans.
Copy the prompt
Copied
Show the top queries on the production Postgres instance.
Copy the prompt
Copied
Get connection info for the cache Key Value instance.
SEE HOW AUTH WORKS
Each user connects their own Render access token once; Scalekit sends it with every call. Access tokens stay vaulted, every call is scope checked, and every action is logged.
1
Authorize
Your user connects
Render
once. We tie it to their identity and the meetings they approved — no shared bot account, no org-wide access
Who:
user ‘A’
when:
Once per user
access:
Limited to user
2
Store
Their
Render
token lives in a vault scoped to them. User A's meetings are never reachable by an agent acting for user B, even on the same connection
vault:
encrypted
scope:
per-user
tokens:
auto-refreshed
3
Resolve
When your agent calls a
Render
tool, we fetch the right token server-side. It never touches your agent, never appears in the LLM context, never shows up in your logs
speed:
~40ms
check:
before every call
seen by:
nobody
4
Audit
Every
Render
tool call is logged — who triggered it, which meeting was fetched, what came back. 90 days of history, tied to the user who authorized it
history:
90 days
export:
SIEM-ready
logged:
every call
Test other agents
See the same per-user auth pattern across other developer tools and hosting connectors.
Engineering Teams
DevOps assistant agent
Polls GitHub for failing checks and stale PRs, opens Linear issues for the ones that need work, and posts a daily digest to Slack. It acts as the engineer, not a shared service account.
Engineering Teams
Engineering standup agent
Pulls commits from GitHub and GitLab, tracks issue movement in Jira, and posts a per-engineer standup brief to Slack. Each engineer's activity is read on their own delegated OAuth.
Engineering Teams
Auto release notes agent
Reads merged GitHub PRs, groups them into structured release notes, publishes the page to Notion, and announces the release in Slack. Every call runs on the engineer's own delegated OAuth.
Engineering Teams
Slack triage
Polls Slack for new messages, classifies bugs and support requests with a LangGraph router, files GitHub issues or Zendesk tickets, and confirms in the thread.
Test other agents
See the same per-user auth pattern across other developer tools and hosting connectors.
ENGINEERING
DevOps assistant agent
Poll GitHub for failing checks and stale pull requests, open Linear issues for the ones that need work, and digest to Slack.
ENGINEERING
Engineering standup agent
Pull commits from GitHub and GitLab, track Jira issue movement, and post a per-engineer standup brief to Slack.
ENGINEERING
Auto-release notes agent
Group merged GitHub PRs into structured release notes, publish the page to Notion, and announce the release in Slack.
ENGINEERING
Slack triage agent
Classify new Slack messages as bugs or support requests, file the GitHub issue or Zendesk ticket, and reply in the thread.
Why Scalekit
Secure your agent's access. Connectors ship in minutes
01.
Shared tokens break per-user analytics
A shared Render access token looks fine in a demo. In production every deploy looks like one service account, and you cannot tell which user triggered it. Scalekit resolves the credential of the actual user who triggered the agent, never a shared bot.
// shared key
audit → bot_service_account

// scalekit
audit → user_abc ✓
02.
Authentication is not authorization
03.
Multi-tenancy is architectural
04.
Render today. Ten connectors tomorrow.
“Our agents act across Salesforce, Gong, Google Drive, and more, on behalf of every customer. Scalekit behind the scenes meant we can keep adding tools without ever rebuilding how credentials or tool calling work.”
Venu Madhav Kattagoni
Head of Engineering / Von
FAQs
Frequently Asked Questions
Does the agent access Render as the user or as a shared key?
As the user. Each user connects their own Render access token once, and Scalekit sends it with every call. Audit logs attribute every action to that user, not a shared service account.
Where is the Render access token stored?
In Scalekit's managed AES-256 token vault, namespaced per tenant. To rotate it, the user reconnects with a new access token. Revocation is a single dashboard action. Credentials never appear in prompts, logs, or LLM context.
Can I limit what the agent does in Render?
Yes. Filter by tool name in listScopedTools to expose only what you want, for example the list and get tools for services, deploys, logs, and metrics, without delete or suspend. Scalekit also enforces scope checks before every API call.
What happens when a user revokes Render access?
The connection is invalidated on the next tool call. Subsequent requests for that user fail closed with a clear error. Other users in the tenant remain unaffected. The event is logged for audit.
What can the agent do in Render?
205 tools across services, deploys, cron jobs, one-off jobs, logs, metrics, Postgres, Key Value and Redis instances, disks, environment groups, custom domains, webhooks, projects, and workspace members. Of those, 100 read data, 72 write, and 33 delete or remove resources.
Start in your coding agent
Up and running in one command
Install the Scalekit skill in your editor of choice. Connector, auth, tools, prompt, all wired up
Claude Code REPL
/plugin marketplace add scalekit-inc/claude-code-authstack
/plugin install agentkit@scalekit-auth-stack
Cursor Code REPL
# ~/.cursor/mcp.json
{
""mcpServers"": {
""render"": {
""url"": ""https://mcp.scalekit.com/render"",
""headers"": { ""Authorization"": ""Bearer $SCALEKIT_TOKEN"" }
}
}
}
Codex Code REPL
# ~/.codex/config.toml
[mcp_servers.render]
url = ""https://mcp.scalekit.com/render""
auth_env = ""SCALEKIT_TOKEN""
Copilot Code REPL
# .vscode/mcp.json
{
""servers"": {
""render"": {
""url"": ""https://mcp.scalekit.com/render"",
""type"": ""http""
}
}
}