API token cannot perform serviceDelete mutation despite personal token with broad capability
brezzy1337
PROOP

3 months ago

Hi,

I'm testing Railway API mutations and running into a persistent issue: my personal API tokens can create services but cannot delete them. The serviceDelete mutation is consistently rejected with "Not Authorized" even after generating a fresh personal token.

Setup:

Project: gracious-luck (375daff1-6138-4a59-a5c3-a7ee9f4867b9)

Environment: development (90dc4434-8e5c-40a9-af76-ff99305cf3ec)

Token type: Personal account token

What works:

✅ Token auth and API reachability

✅ Project/environment/service reads

✅ serviceCreate mutation (verified with throwaway services)

✅ All other mutations introspect successfully

What fails:

❌ serviceDelete mutation → "Not Authorized"

Steps taken:

Tried two different personal API tokens (regenerated the second)

Confirmed tokens are personal account tokens (not workspace/team tokens)

Confirmed serviceDelete is available in the schema and properly typed

The tokens can read everything and create services, but deletions are blocked at the API level. I can delete services manually from the Dashboard without issue, suggesting this is an API-specific restriction, not an account-level block.

Is this a known limitation, or is there a workspace-level setting I'm missing that blocks API-based deletions?

Feature request: A way to scope/restrict API token permissions (e.g., read-only, create-only, specific mutation allowlists) would make automation much safer and more auditable.

Solved

2 Replies

Status changed to Awaiting Railway Response Railway • 3 months ago


sam-a
EMPLOYEE

3 months ago

The "Not Authorized" error on your serviceDelete calls is coming from an OAuth scope check, which means the token you're using is actually an OAuth access token, not a personal API token. Personal API tokens bypass that check entirely and would work for deletions given your ADMIN role. You can generate a personal API token at railway.com/account/tokens - if you're instead using a token obtained through an OAuth flow or a third-party integration, it would need the project:admin or workspace:admin scope granted to perform deletions.


Status changed to Awaiting User Response Railway • 3 months ago


sam-a

The "Not Authorized" error on your `serviceDelete` calls is coming from an OAuth scope check, which means the token you're using is actually an OAuth access token, not a personal API token. Personal API tokens bypass that check entirely and would work for deletions given your ADMIN role. You can generate a personal API token at [railway.com/account/tokens](https://railway.com/account/tokens) - if you're instead using a token obtained through an OAuth flow or a third-party integration, it would need the `project:admin` or `workspace:admin` scope granted to perform deletions.

brezzy1337
PROOP

3 months ago

Thanks for the quick response :), it must be my code that's not pointing to the correct token because I do have a token created and set in my env vars, from railway.com/account/tokens. I'll look into OAuth Scoped tokens as well. I feel that having a token scoped for my project or workspace feels more organized.

Best Regards.


Status changed to Awaiting Railway Response Railway • 3 months ago


Status changed to Solved Railway • 3 months ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...