19 days ago
Project: juma-bottle-tracker (ID: 4ebb299a-d3f2-43e1-8f07-92034ef4ed44)
Environment: production (ID: 6bee1118-6cab-4a1a-b28b-e9cddd2f606f)
BLOCKED FOR 3 WEEKS: Every project token is rejected immediately.
Error messages (confirmed by support):
- CLI: "Invalid RAILWAY_TOKEN"
- GraphQL API: "Project Token not found"
Support already diagnosed this as a Railway backend token validation issue.
No engineering escalation happened. No workaround provided.
I need engineering to investigate immediately why this project's token records are not being recognized by Railway's validation systems.
This is a critical production blocker.
5 Replies
19 days ago
The "Project Token not found" error on the GraphQL API is typically caused by sending the token in the Authorization: Bearer header - project tokens require the Project-Access-Token header instead, as documented here. For the CLI, the token value goes in the RAILWAY_TOKEN environment variable (e.g. RAILWAY_TOKEN=xxx railway up), and RAILWAY_API_TOKEN must not be set at the same time, as setting both produces an error.
Status changed to Awaiting User Response Railway • 19 days ago
19 days ago
For the direct GraphQL test, I sent:
Project-Access-Token:
I did not use Authorization: Bearer for that project-token test.
For the CLI test, I ran it with:
env -u RAILWAY_API_TOKEN RAILWAY_TOKEN="$RAILWAY_TOKEN" railway whoami
This explicitly removed RAILWAY_API_TOKEN and supplied the new token only through RAILWAY_TOKEN.
The environment check also confirmed:
RAILWAY_TOKEN: set
RAILWAY_API_TOKEN: not set
Despite following those rules, Railway returned:
GraphQL: Project Token not found
CLI: Unauthorized
So yes, that guidance was followed correctly.
Status changed to Awaiting Railway Response Railway • 19 days ago
19 days ago
This is the kind of problem the Railway community is well placed to help with, so we'd like to open your thread as a community bounty. Railway pays a bounty to the community member who solves it, and threads like this usually get picked up quickly.
Opening it makes this entire thread public, including everything already posted. Nothing becomes public until you decide. Use the buttons below.
- Open to the community - Before you click, take a moment to edit or remove anything you'd rather not share. The thread becomes publicly visible right away.
- Keep it private and close the thread - Nothing becomes public and the thread closes.
Status changed to Awaiting User Response Railway • 19 days ago
18 days ago
This thread has been opened as a public bounty so the community can help solve it. The thread and any further activity are now visible to everyone.
Status changed to Open Railway • 18 days ago
15 days ago
I’m unable to authenticate newly created project tokens for an existing Railway project. We have tested multiple newly generated tokens, including tokens created immediately before testing, and they are consistently rejected by both Railway’s GraphQL API and Railway CLI.
RAILWAY RESOURCE DETAILS
Project ID: 4ebb299a-d3f2-43e1-8f07-92034ef4ed44
Environment ID: 6bee1118-6cab-4a1a-b28b-e9cddd2f606f
Service name: api-server
Railway CLI version used: railway 5.23.0
The CLI reports that version 5.57.5 is available.
Please let me know if you also need the workspace ID, service ID, account email, or another identifier.
PROBLEM
Project tokens created from the Railway dashboard are not recognized by Railway.
We can provide a sample affected token through a secure private support channel. We will not include an active token in a public ticket or ordinary email.
DIRECT GRAPHQL API TEST
We opened and followed Railway’s current documentation:
https://docs.railway.com/integrations/api#using-a-project-token
The request was sent to:
https://backboard.railway.com/graphql/v2
The project token was placed in the required Project-Access-Token header—not in Authorization: Bearer.
The request, with the token redacted, was equivalent to:
curl --request POST \
--url https://backboard.railway.com/graphql/v2 \
--header 'Project-Access-Token: <REDACTED_PROJECT_TOKEN>' \
--header 'Content-Type: application/json' \
--data '{"query":"query { projectToken { projectId environmentId } }"}'
Railway returned:
{
"errors": [
{
"message": "Project Token not found",
"path": ["projectToken"],
"extensions": {
"code": "INTERNAL_SERVER_ERROR"
}
}],
"data": null
}
The request format matches Railway’s documentation exactly:
- Correct GraphQL endpoint
- Correct Project-Access-Token header
- Correct Content-Type: application/json
- Correct projectToken { projectId environmentId } query
RAILWAY CLI TEST
For the CLI test, the token was supplied through RAILWAY_TOKEN.
Before running the check, we verified:
RAILWAY_TOKEN: SET
RAILWAY_API_TOKEN: NOT SET
We also explicitly removed RAILWAY_API_TOKEN from the command environment:
env -u RAILWAY_API_TOKEN RAILWAY_TOKEN="<REDACTED_PROJECT_TOKEN>" railway whoami
Railway CLI returned:
Unauthorized. Please check that your RAILWAY_TOKEN is valid and has access to the resource you're trying to use.
Therefore:
- RAILWAY_TOKEN was set.
- RAILWAY_API_TOKEN was not set.
- Both variables were not present simultaneously.
- The token was tested without running railway up.
- No deployment was attempted during these tests.
ACCOUNT/WORKSPACE TOKEN COMPARISON
For diagnostic purposes, the supplied value was also tested as an account/workspace token using Authorization: Bearer. When querying the known project ID, Railway returned:
Not Authorized
We understand that a project token should not work as an account token. This comparison was only performed to rule out the possibility that the token had been created as a different token type.
WHAT WE HAVE RULED OUT
We have confirmed that the failure is not caused by:
- Sending a project token through Authorization: Bearer
- Using the wrong GraphQL endpoint
- Using the wrong GraphQL query
- Setting both RAILWAY_TOKEN and RAILWAY_API_TOKEN
- Accidentally running a deployment instead of a read-only check
- Testing only an old or previously revoked token
- Relying solely on Railway CLI
The direct GraphQL request also fails, so the issue does not appear to be caused solely by the installed CLI version.
ADDITIONAL CONTEXT
We have tested numerous project tokens. They have consistently failed with the same response, including tokens created immediately before testing.
The project exists in the Railway dashboard, and its known identifiers are:
Project ID: 4ebb299a-d3f2-43e1-8f07-92034ef4ed44
Environment ID: 6bee1118-6cab-4a1a-b28b-e9cddd2f606f
WHAT WE NEED RAILWAY TO INVESTIGATE
Could you please check:
- Whether project tokens are being issued and persisted correctly for this project and environment
- Whether the account or workspace has a restriction preventing project-token authentication
- Whether generated tokens are associated with project ID 4ebb299a-d3f2-43e1-8f07-92034ef4ed44
- Whether tokens are being revoked, invalidated, or deleted immediately after creation
- Whether there is an ownership, membership, workspace, or permissions mismatch
- Whether environment ID 6bee1118-6cab-4a1a-b28b-e9cddd2f606f is valid and belongs to the project
- Whether there is a backend token-indexing or lookup issue explaining “Project Token not found”
- Whether upgrading Railway CLI from 5.23.0 to 5.57.5 is required, despite the same failure through the direct GraphQL API
- Whether you can identify the failed requests using these GraphQL trace IDs:
760567510628427225
7837604059136226186
Additional trace IDs from earlier attempts are available if needed.
6 days ago
no solution?