Native/Public OAuth PKCE token exchange returns HTTP 403 after successful consent
dmackp
HOBBYOP

a month ago

Hello Railway Support,

I am troubleshooting a Native/Public OAuth application used for a read-only SportsModel Railway integration.

The authorization flow succeeds through browser consent and the registered loopback callback, but the token exchange is consistently rejected by Railway with HTTP 403.

Application configuration:

Application type:

Native / Public

Client secret:

None

Redirect URI:

http://127.0.0.1:49152/oauth/callback

PKCE:

S256

Scopes:

openid

project:viewer

offline_access

Authorized Apps:

The application appears successfully authorized.

Project access:

All Projects viewer access is granted.

The client performs a fresh authorization transaction with:

  • fresh PKCE verifier/challenge
  • fresh OAuth state
  • fresh single-use authorization code
  • successful callback
  • successful state validation
  • immediate token exchange
  • prompt=consent

Token request:

POST

https://backboard.railway.com/oauth/token

Content-Type:

application/x-www-form-urlencoded

The request contains:

grant_type=authorization_code

code=

redirect_uri=http://127.0.0.1:49152/oauth/callback

client_id=<registered Native/Public client>

code_verifier=

The request does NOT contain:

  • client_secret
  • Authorization header
  • browser cookies
  • token-request scope parameter

Result:

HTTP status:

403

Content-Type:

application/json; charset=utf-8

Response body length:

711 bytes

Sanitized parsed response:

{}

No OAuth error or error_description field was returned.

Cloudflare trace ID:

a2fff730097742c7-EWR

Response timestamp:

2026-08-24T05:30:32Z

Exchange attempts for this authorization code:

1

The authorization code was not retried.

No credentials were written and no Railway API/GraphQL calls were made after the failed exchange.

We have independently verified:

  • Native/Public application type
  • no client-secret requirement
  • exact registered redirect URI
  • PKCE S256
  • supported scopes
  • successful user consent
  • Authorized App presence
  • All Projects viewer authorization
  • correct form-encoded token request
  • matching PKCE transaction

Can you please check the trace ID above and determine why the Railway OAuth token endpoint rejected this Native/Public PKCE exchange with HTTP 403?

If there is any additional configuration required for Native/Public applications using project:viewer + offline_access, please let me know.

Thank you.

Solved$10 Bounty

0 Replies

Railway
BOT

a month ago

This thread has been opened as a bounty so the community can help solve it.

Status changed to Open Railway • about 1 month ago


Status changed to Solved dmackp • about 1 month ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...