16 days ago
I am on Railway Free using CLI 5.58.0. The authenticated Railway UI can list my private GitHub repository under New Project → GitHub, and the Railway GitHub App is installed with access to All repositories. However, Railway Public API GitHub queries consistently return Not Authorized / INTERNAL_SERVER_ERROR.
What I already tried:
- Reconnected the Railway GitHub OAuth authorization.
- Completely uninstalled and reinstalled the Railway GitHub App, creating a fresh installation with All repositories access.
- Opened New Project → GitHub and ran Refresh exactly once. The private repository was visible in the selector.
- Logged out of Railway CLI and completed a fresh device-code login to the same Railway account.
- Re-ran each affected read-only query exactly once.
Affected queries:
- githubRepos
- githubRepo(fullRepoName: )
- githubRepoBranches(owner: , repo: )
- githubRepoAccessAvailable(fullRepoName: )
Latest trace IDs after the fresh CLI login:
- githubRepos: 5044549550514374647
- githubRepo: 4641928831587435160
- githubRepoBranches: 4045928337060291345
- githubRepoAccessAvailable: 5221150619579392429
Trace IDs immediately after the UI Refresh:
- githubRepos: 669837444456197231
- githubRepo: 8030571185519971058
- githubRepoBranches: 6820790927163979891
- githubRepoAccessAvailable: 5763799769548579665
Other authenticated account queries work correctly. The workspace reports ACTIVE/FREE and zero active projects. An empty projectCreate API call also returned Not Authorized, while project listing and workspace reads succeed. No project, service, repository source, or deployment was created during this reproduction.
Expected behavior:
The Public API should return the same GitHub repository access that the authenticated Railway UI currently displays.
Actual behavior:
The UI lists the private repository, but all four authenticated Public API GitHub fields return Not Authorized.
Could the Railway team inspect the account/provider authorization state for these trace IDs and confirm whether the GitHub OAuth/App linkage is internally inconsistent, or whether these API fields require an authorization step not reflected in the documentation?
1 Replies
16 days ago
The "Not Authorized" with INTERNAL_SERVER_ERROR on API queries is typically a token scope issue, not a server crash or platform fault. Queries that resolve against your user identity (including GitHub-linked data) need an account-scoped token. A workspace-scoped token authenticates as the workspace rather than as a person, so there is no user principal for those resolvers and the request is refused. The CLI works because railway login authenticates as the user directly, a different auth path than a static API token. Check your token's scope at railway.com/account/tokens, where the Scope column reads "Account" for an account-scoped token or shows a workspace name for a workspace-scoped one, and to create an account-scoped token, select "No workspace" in the token creation form.
Status changed to Awaiting User Response Railway • 16 days ago
9 days ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • 9 days ago