a month ago
Hello Railway Support,
I am troubleshooting a Native/Public OAuth application used for a read-only SportsModel Railway integration.
The authorization flow succeeds through browser consent and the registered loopback callback, but the token exchange is consistently rejected by Railway with HTTP 403.
Application configuration:
Application type:
Native / Public
Client secret:
None
Redirect URI:
http://127.0.0.1:49152/oauth/callback
PKCE:
S256
Scopes:
openid
project:viewer
offline_access
Authorized Apps:
The application appears successfully authorized.
Project access:
All Projects viewer access is granted.
The client performs a fresh authorization transaction with:
- fresh PKCE verifier/challenge
- fresh OAuth state
- fresh single-use authorization code
- successful callback
- successful state validation
- immediate token exchange
- prompt=consent
Token request:
POST
https://backboard.railway.com/oauth/token
Content-Type:
application/x-www-form-urlencoded
The request contains:
grant_type=authorization_code
code=
redirect_uri=http://127.0.0.1:49152/oauth/callback
client_id=<registered Native/Public client>
code_verifier=
The request does NOT contain:
- client_secret
- Authorization header
- browser cookies
- token-request scope parameter
Result:
HTTP status:
403
Content-Type:
application/json; charset=utf-8
Response body length:
711 bytes
Sanitized parsed response:
{}
No OAuth error or error_description field was returned.
Cloudflare trace ID:
a2fff730097742c7-EWR
Response timestamp:
2026-08-24T05:30:32Z
Exchange attempts for this authorization code:
1
The authorization code was not retried.
No credentials were written and no Railway API/GraphQL calls were made after the failed exchange.
We have independently verified:
- Native/Public application type
- no client-secret requirement
- exact registered redirect URI
- PKCE S256
- supported scopes
- successful user consent
- Authorized App presence
- All Projects viewer authorization
- correct form-encoded token request
- matching PKCE transaction
Can you please check the trace ID above and determine why the Railway OAuth token endpoint rejected this Native/Public PKCE exchange with HTTP 403?
If there is any additional configuration required for Native/Public applications using project:viewer + offline_access, please let me know.
Thank you.