Fly MCP integration
Reads app and machine state, validates configs before a deploy, sets up health checks, and grants or revokes WireGuard and SSH access on request.
45actions available
Three actions you can hand over today
Every action runs live through MCP. Nothing to build, nothing to maintain.
Get app details
Lyro retrieves detailed Fly.io app information on demand. Support teams diagnose deployment issues without SSH access.
Issue certificate
Lyro issues SSH certificates for Fly.io infrastructure instantly. Agents grant secure access without manual key generation.
Add wireguard peer
Lyro adds WireGuard peers to your Fly.io organization. Your team establishes private network links without configuration work.
How businesses use Fly + Lyro
Each card is one request a support team gets, and the Fly actions Lyro runs to close it.
Answer app and machine status questions
Lyro pulls the current state of an app and the machines behind it across the whole organization, so a question about what is running where gets a live answer rather than a screenshot from whoever has dashboard access.
Get App DetailsList AppsList Organization MachinesStand up monitoring for a new endpoint
When a service needs watching, Lyro creates a health check job against the URL, picks from the global check locations Fly.io offers, and triggers a first run so the result is confirmed before the request is closed.
Create Health Check JobCheck LocationsCreate Check Job RunGrant and revoke private network access
Lyro adds a WireGuard peer for someone joining the team, validates the peer IPs against the organization, and removes that peer again when the access should end.
Add WireGuard PeerValidate WireGuard PeersRemove WireGuard PeerPre-flight a deploy before it ships
Before a new app goes out, Lyro validates the fly.toml, confirms the app name is still available, and returns placement recommendations for the regions its machines should land in.
Validate ConfigCheck App Name AvailabilityGet Placements
How it works
Get started in 3 steps
Connect once, then just ask. There is no workflow builder to learn and nothing to maintain — Lyro reads the Fly actions it has and picks the ones a request needs.
- 01
Connect Fly
Authorize the Fly account your team already uses — one consent screen, no API keys, no mapping tables. Lyro can only do what you granted that account, and you can disconnect it at any time.
- 02
Tell your agent what you need
Describe the job the way you would hand it to a teammate. Lyro maps it to the Fly actions that close it and chains as many as the request needs.
- 03
Watch it work
The agent runs the actions inside the conversation the customer is already in, so nobody copies data between tabs and your team can take over at any point.
Get started free
Everything else about Fly
Setup, permissions, and the limits of what Lyro can do inside Fly.
Yes, within whatever the connected token allows. Get Organization, List Apps, and List Organization Machines all take an organization slug, and Check User Only Token reports whether the token you connected is limited to a single user or reaches organization resources, so you can confirm the blast radius before relying on it.
Every action available in Fly
All 45 actions your agent can call on Fly, straight from the live MCP connection.
Add wireguard peer
Add a WireGuard peer connection to a Fly.io organization for private network access.
Check app name availability
Validate an app name for Fly.io app creation.
Check jobs
Execute GraphQL queries against the Fly.io checkJobs endpoint.
Check user only token
Check whether the authentication token only allows user access.
Create health check job
Create a health check job for monitoring application endpoints in Fly.io.
Create check job run
Triggers a run of an existing health check job on Fly.io.
Create delegated wireguard token
Create a delegated WireGuard token for peer management in a Fly.io organization.
Create third-party configuration
Create a third-party service configuration for discharging macaroon caveats.
Delete delegated wireguard token
Delete a delegated WireGuard token from a Fly.io organization.
Delete organization
Delete a Fly.io organization and all its associated resources using the GraphQL API.
Delete remote builder
Delete a remote builder configuration for a Fly.io organization.
Delete third party configuration
Delete a third-party service configuration from Fly.io.
Detach postgres cluster
Detach a Postgres cluster from a Fly.io application, revoking access credentials.
Establish ssh key
Establish an SSH key for a Fly.io organization.
Fetch nodes by ids
Fetches a list of node objects from Fly.io given a list of IDs using the GraphQL nodes query.
Get add-on
Find a Fly.io add-on by ID, name, or provider.
Get add-on provider
Query information about a specific Fly.io add-on provider (extension) by name.
Get app details
Retrieve detailed information about a specific Fly.io application.
Get certificate
Retrieve a certificate by its ID from Fly.io.
Get current token info
Get information about the current authentication token.
Get latest image details
Retrieve the latest available tag details for a given image repository from Fly.io's registry.
Get latest image tag
Retrieve the latest available image tag for a Fly.io Docker repository.
Get machine
Get a single machine by ID from Fly.io.
Get nearest region
Retrieve the nearest Fly.io region to the requesting client based on network location.
Get node by ID
Fetch an object by its globally unique ID using Fly.io's GraphQL node query.
Get organization
Find a Fly.io organization by slug using the GraphQL API.
Get personal organization
Retrieve the user's personal organization details from Fly.io.
Get placements
Get placement recommendations for Machines in Fly.io regions.
Get platform information
Retrieve Fly.io platform information including available regions, VM sizes, and flyctl version.
Get products and pricing
Retrieve Fly.io product and price information via GraphQL.
The tools Fly sits next to
Same connection, same setup. Pick the next one your team already uses.
Backendless
Queries app tables, registers users and starts password recovery, reorganises file storage, and schedules server-side timers and channel messages.
Codeinterpreter
Spins up a Python sandbox, uploads files into it, runs code or shell commands, and returns the file that comes out.
Emailable
Verifies an address the moment it is given, pushes a full list through as one batch, and follows the job until its results are ready.
Mezmo
Checks ingestion status, builds filtered views and preset alerts, writes exclusion rules to hold down index cost, and rotates API keys and member roles.
Rollbar
Reports occurrence counts and resolution times, maps team-to-project ownership, confirms who belongs where, and lists the projects on an account.
Turbot pipes
Runs workspace SQL and reads the rows back, triggers Flowpipe pipelines and returns their logs, tests cloud connections, and pulls the workspace audit trail.

Ready to connect Fly?
Authorize the account and your agent has all 45 actions from the first conversation.


