Studio Guide
A tour of every tab at 127.0.0.1:8799 — the local browser app that runs entirely on loopback, with no cloud console anywhere in the picture.
127.0.0.1:8799 and is session-gated. There is no remote counterpart — if you can't reach it from another machine, that's by design.Launch
railcall studio # opens http://127.0.0.1:8799
railcall daemon & # optional: keep the loopback runtime aliveTabs
Studio's left nav is stable across releases — each tab owns a slice of the governed loop. Highlighted cards below (Modules and Licenses) are the paid-module install flow you'll hit right after buying a connector.
Builder
Prompt-to-plan surface. Type an intent, watch the interpreter draft a workflow CSV and pipe it through the airlock — nothing sends until you approve.
When to use: Starting a new automation. Best for turning "send X to Y when Z" into a signed plan.
Canvas
Node-and-edge editor for the same workflow spec Builder produces. Every node is a governed step; branches make the airlock's decision points visible.
When to use: Editing an existing plan by hand — reordering, splitting, or wiring conditional branches.
Workflows
Library of every plan on this machine — installed from marketplace, drafted locally, or restored from backup. Rerun, diff, or archive from here.
When to use: Finding, cloning, or scheduling something you built earlier.
Marketplace
In-Studio view of railcall.ai/marketplace with one-click install into the current workspace. Signature and provenance visible up front.
When to use: You want a template someone else already shipped, without leaving Studio.
Modules
Signed handler bundles under ~/.railcall/station/modules/<slug>/. Loader verifies Ed25519 signatures before any handler runs.
When to use: Enabling a paid connector (Salesforce, HubSpot) or your own signed handler.
Licenses
Installed paid-module entitlements — per-install, offline-verified, seven-day grace past expiry. Activate, verify, or release from one place.
When to use: You just bought a paid module or need to move it to another machine.
Integrations
Long-lived connections to real SaaS systems — OAuth tokens for Salesforce, bearer secrets for HubSpot, webhook targets for Discord/Slack. All stored in the local vault.
When to use: First-time hookup of a provider before a workflow can use it.
Monitor
Live view of the loopback daemon — active plans, pending approvals, current spend, per-provider status.
When to use: You want to know what's in flight right now.
Webhooks
Inbound webhook receivers. Trigger workflows from Stripe, GitHub, Slack, or anything else that can POST — with signature verification.
When to use: You need something external to kick off a workflow.
Sends
Manual outbound channel — email, Slack, Discord, HTTP. Preview the payload, hit send, get a signed receipt.
When to use: One-off, human-authored actions that don't warrant a full workflow.
Runs
Every execution as a row: who invoked it (Studio / MCP / CLI), who approved it, the result, and the Ed25519 signer — with per-row independent verify, search, and pagination. Failed and rolled-back runs show honestly. Each receipt deep-links to the offline verifier at railcall.ai/verify.
When to use: Audit, evidence, compliance review, or debugging what actually happened — this is the governance surface you show a CTO.
Audit
Zero-retention structural audits of workflow CSVs. Pass a file, get a signed audit receipt — no execution, no send.
When to use: Reviewing a plan before you ever intend to run it.
Router
Local policy router — which model, which provider, which fallback for each class of request. All decisions logged with the receipt.
When to use: Tuning the local Ollama / gateway model choice or provider routing.
Settings
Workspace paths, signing key, safety flags, and Live Execution policy — which surfaces (Studio / MCP / apply) may fire live workflows, per-workflow whitelists, and MCP payload exposure. Every policy change is signed on save; no restart needed.
When to use: Environment moves, key rotation, granting or revoking live execution, or a fresh install.
The Modules → Licenses flow
Buying a paid module on the marketplace is one purchase; getting it running is two Studio tabs.
1. Modules tab — install the bundle
Marketplace install drops the signed bundle under ~/.railcall/station/modules/<slug>/ as three files: module.json, handlers/handler.py, and module.sig. The loader checks the Ed25519 signature before ever importing the handler; a bad signature refuses to load.
2. Licenses tab — activate
If module.json has license_required: true, the module stays gated until a valid entitlement is present. Activate from Studio or the CLI.
railcall license activate sami666/salesforce
railcall license list # confirm days remaining
railcall license verify # offline re-checkLicenses are per-install, bound to the machine's install pubkey, and verified offline against the pinned issuer key. Seven-day grace past expiry so a flaky network doesn't break production.
sami666/hubspot) skip the Licenses step entirely — install and go. Paid modules (e.g. sami666/salesforce) need the Licenses step to unlock.