Newly created API tokens (Account + Workspace scope) return "Not Authorized" / INTERNAL_SERVER_ERROR on me query
andresgarhou
HOBBYOP

21 days ago

Workspace: Andres Garcia's Projects

I created two brand-new API tokens today from railway.com/account/tokens:

  • One with scope "No workspace" (Account token)
  • One with "Andres Garcia's Projects" selected (Workspace token)

Both immediately return Not Authorized with extensions.code: INTERNAL_SERVER_ERROR on the simplest possible query, reproduced 3 different ways (Railway CLI 5.55.0 via RAILWAY_API_TOKEN env var, raw curl, and Python via urllib with a browser User-Agent) — all converge on the identical error, ruling out a client-side issue:

curl -X POST https://backboard.railway.com/graphql/v2 \

-H "Authorization: Bearer " \

-H "Content-Type: application/json" \

-d '{"query": "query { me { name email } }"}'

Response:

{"errors":[{"message":"Not Authorized","locations":[{"line":1,"column":9}],"path":["me"],"extensions":{"code":"INTERNAL_SERVER_ERROR"},"traceId":"5885081070386397517"}],"data":null}

Second reproduction traceId: 2807226902392749719

My interactive browser-login CLI session works fine (railway usage, railway status, etc. all succeed) — only static API token auth is affected. Status page shows all systems operational, so this seems account/token-specific rather than a general outage.

Solved

1 Replies

Status changed to Awaiting Railway Response Railway • 21 days ago


Railway
BOT

21 days ago

The me query requires an account-scoped token (created with "No workspace" selected) because it resolves the authenticated user. A workspace-scoped token authenticates as the workspace rather than as a person, so there is no user principal for me to return, and the request is refused. The INTERNAL_SERVER_ERROR extension code is GraphQL's default when the error carries none of its own, not a server-side crash. To confirm the scope of each token, check the Scope column at https://railway.com/account/tokens, where it reads "Account" for account-scoped and shows the workspace name for workspace-scoped. If you need a token that works with workspace-level queries rather than me, you can verify it is live by running query { apiToken { workspaces { id name } } } instead.


Status changed to Awaiting User Response Railway • 21 days ago


Railway
BOT

14 days ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • 14 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...