SSH host-key change: please verify ssh.railway.com fingerprints
fahil100
HOBBYOP

16 days ago

Hello Railway Support,

On September 19, 2026, an SSH connection to ssh.railway.com presented a different ED25519 host key after earlier successful connections. OpenSSH rejected the connection because it did not match the stored key.

Previously trusted fingerprint:

SHA256:+S1xg92FrnHz6pY3bpkmh1OGtWQGNANXilPzlxA7B1g

Newly presented fingerprint:

SHA256

Please confirm:

Are either or both fingerprints currently valid for ssh.railway.com?

Was there a host-key rotation, or do different SSH gateway instances use different keys?

Where can we obtain the authoritative fingerprints and the supported procedure for updating known_hosts?

We have kept the existing known_hosts entry unchanged and have not disabled host-key verification. This is blocking our deployment work.

Please provide confirmation from the Railway team before we trust the replacement key.

Thank you.

Solved

5 Replies

Railway
BOT

16 days ago

The endpoint at ssh.railway.com is served by multiple hosts, each with its own key, and those hosts change routinely, so a different fingerprint between connections is expected rather than evidence of compromise or something to report each time. We do not publish a fingerprint list, an SSHFP record, or a known_hosts entry for ssh.railway.com, and we cannot confirm or deny whether a specific fingerprint is one of ours. How you choose to handle host-key trust for this endpoint is yours to decide.


Status changed to Awaiting User Response Railway • 16 days ago


fahil100
HOBBYOP

16 days ago

Correction: the newly presented ED25519 fingerprint was truncated in my original post. The complete fingerprint is:

SHA256:pf0ggJhvyqVw1VRieSsZ3NxYm4MdOqD7NFIZcyE3YVo

Please verify this exact fingerprint for ssh.railway.com.


Status changed to Awaiting Railway Response Railway • 16 days ago


Railway
BOT

16 days ago

We're not able to confirm or deny whether a specific fingerprint belongs to ssh.railway.com, including the one you've provided here. As noted, the endpoint is served by multiple hosts with independent keys that rotate without notice, so we hold no canonical list to check a pasted fingerprint against.


Status changed to Awaiting User Response Railway • 16 days ago


fahil100
HOBBYOP

16 days ago

Please escalate this to a human Railway engineer. We need a supported way to authenticate ssh.railway.com when gateway host keys change, while keeping strict host-key verification enabled.

If individual fingerprints cannot be verified, what supported alternative provides authenticated remote access? We need an actionable solution, not instructions to disable verification.


Status changed to Awaiting Railway Response Railway • 16 days ago


16 days ago

The ssh.railway.com endpoint is served by multiple hosts, each with its own key, and those hosts change routinely, so there is no stable fingerprint to pin and no published fingerprint list, SSHFP record, or host CA to verify against. This is the current design, not a gap with a planned fix. The railway ssh CLI command connects through the same ssh.railway.com endpoint, so the same host-key behavior applies there as well.


Status changed to Awaiting User Response brody • 16 days ago


Railway
BOT

9 days ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • 9 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...