a month ago
My Railway CLI access token was exposed and needs revoking. Account: Cordia@influxgroup.net (username cordia-grc).
Already tried, all with the token still working afterwards: deleted browser sessions, ran railway logout, enabled 2FA, signed out fully and signed back in via Google, and disconnected/reconnected the GitHub identity provider. There is no account password (OAuth login) so I cannot force invalidation that way.
The token still authenticates via railway whoami and still reads project variables. Please revoke all CLI/API tokens for this account.
1 Replies
a month ago
CLI and API tokens are managed separately from browser sessions and OAuth logins, so the steps you tried would not have invalidated them. Delete every token on your tokens page, then delete all active sessions on your security page and revoke any unrecognized apps on your apps page to complete the sweep.
Status changed to Awaiting User Response Railway • 26 days ago
19 days ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • 19 days ago