19 days ago
Hello Railway Support Team,
I'm facing a persistent issue with a WordPress/WooCommerce site hosted on Railway. External API requests to WooCommerce REST API fail with "401 Unauthorized", even though the same credentials work perfectly when used directly from a browser.
Setup:
- WordPress + WooCommerce site: hosted on Railway (Docker template).
- URL: https://wordpress-production-343a.up.railway.app
- Automation tool: n8n (self-hosted on Railway, separate project).
- n8n URL: https://n8n-production-beb87.up.railway.app
The Problem:
When I try to connect n8n to WooCommerce using the official WooCommerce node, I get:
"Authorization failed - please check your credentials"
What I have already tried and verified:
-
Created new WooCommerce API keys with Read/Write permissions.
-
Verified the API keys work directly in the browser (returns valid JSON data):
✅ This returns valid product JSON, so the keys and endpoint are correct.
-
Changed WordPress Permalinks to "Post name" (recommended for REST API).
-
Tried with "Include Credentials in Query" enabled and disabled in n8n.
-
Tried "Allowed HTTP Request Domains" set to "All" and "Specific Domains".
-
Tried "Ignore SSL Issues" — no such option found in n8n's WooCommerce node.
-
Sometimes the connection test shows "Connection tested successfully" but then fails again on Execute Step with 401.
My suspicion:
The issue may be caused by one of the following on Railway's side:
- Railway's reverse proxy stripping or modifying the "Authorization" HTTP header before it reaches WordPress.
- A forced HTTP-to-HTTPS redirect that drops the Authorization header.
- A Web Application Firewall (WAF) blocking n8n's default User-Agent header.
My questions:
- Does Railway's proxy or networking layer modify or strip HTTP "Authorization" headers on inbound requests?
- Is there any known limitation with WordPress/WooCommerce REST API on Railway that prevents external API authentication?
- Can you provide any logs or access to network-level diagnostics to verify whether the Authorization header reaches the WordPress container?
- Are there any recommended Railway settings (e.g., disabling redirects, configuring networking, or using a specific service configuration) that would allow WooCommerce REST API authentication to work correctly?
This issue has been blocking my store's automation for days. Any help would be greatly appreciated.
Thank you,
Mojahed Abdelbasit
1 Replies
19 days ago
This thread has been opened as a bounty so the community can help solve it.
Status changed to Open Railway • 19 days ago
19 days ago
Since Railways can tamper with the Authorization header during redirection, the most likely solution is to avoid Basic Auth through Railway's proxy and supply the WooCommerce consumer_key and consumer_secret as query parameters (or configure n8n to send them in the query).