Accounts
POST
Destroys the current authentication session while reporting metrics like url and reason for logout.
/v3/logoutauth.roblox.com
POST
Authenticates as a user given a two step verification verification token.
/v3/users/{userId}/two-step-verification/loginauth.roblox.com
POST
Endpoint for login with identity verification
/v2/identity-verification/loginauth.roblox.com
POST
Authenticates a user.
/v2/loginauth.roblox.com
POST
Endpoint for logging in a user, specifically for linked authentication on PCGDK
/v2/login/linkedauth.roblox.com
POST
Logs out user from all other sessions.
/v2/logoutfromallsessionsandreauthenticateauth.roblox.com
GET
Returns password status for current user, asynchronously.
/v2/passwords/current-statusauth.roblox.com
POST
Resets a password for a user that belongs to the password reset ticket.
/v2/passwords/resetauth.roblox.com
POST
Sends a password reset email or challenge to the specified target.
/v2/passwords/reset/sendauth.roblox.com
POST
Verifies a password reset challenge solution.
/v2/passwords/reset/verifyauth.roblox.com
GET
Endpoint for checking if a password is valid.
/v2/passwords/validateauth.roblox.com
POST
Endpoint for checking if a password is valid.
/v2/passwords/validateauth.roblox.com
GET
Get Revert Account ticket info
/v2/revert/accountauth.roblox.com
POST
Submit Revert Account Request
/v2/revert/accountauth.roblox.com
POST
Invalidates all account security tickets for the authenticated user. This endpoint should be called before enrolling in EPP to ensure old revert links cannot be used.
/v2/revert/invalidate-ticketsauth.roblox.com
POST
Logs out user from the current session and create a new one.
/v2/session/refreshauth.roblox.com
POST
Endpoint for signing up a new user
/v2/signupauth.roblox.com
POST
Endpoint for signing up a new user, specifically for linked authentication on PCGDK
/v2/signup/linkedauth.roblox.com
POST
Changes the password for the authenticated user.
/v2/user/passwords/changeauth.roblox.com
POST
Change the user's username
/v2/usernameauth.roblox.com
GET
Get the current price for a username change
/v2/username/change/priceauth.roblox.com
GET
Gets a list of existing usernames on Roblox based on the query parameters
/v2/usernamesauth.roblox.com
POST
Sends an email of all accounts belonging to an email
/v2/usernames/recoverauth.roblox.com
GET
Checks if a username is valid.
/v2/usernames/validateauth.roblox.com
POST
Checks if a username is valid.
/v2/usernames/validateauth.roblox.com
GET
Gets the account pin status.
/v1/account/pinauth.roblox.com
POST
Request to create the account pin.
/v1/account/pinauth.roblox.com
PATCH
Request made to update the account pin on the account.
/v1/account/pinauth.roblox.com
DELETE
Request for deletes the account pin from the account.
/v1/account/pinauth.roblox.com
POST
Request to locks the account which has an account pin enabled.
/v1/account/pin/lockauth.roblox.com
POST
Requests to unlock the account pin.
/v1/account/pin/unlockauth.roblox.com
GET
Get a user's current account country setting.
/v1/account/settings/account-countryaccountsettings.roblox.com
POST
Updates the user's account country.
/v1/account/settings/account-countryaccountsettings.roblox.com
GET
Returns metadata used by the account settings page
/v1/account/settings/metadataaccountsettings.roblox.com
GET
Get metadata for adding auth methods.
/v1/account-creation/metadataauth.roblox.com
GET
Migrate from RobloxWebsite project, return news notification for Private Message page
/v1/announcementsprivatemessages.roblox.com
GET
/v1/announcements/metadata
privatemessages.roblox.com
GET
Get the user's birthdate
/v1/birthdateusers.roblox.com
POST
Update the user's birthdate
/v1/birthdateusers.roblox.com
GET
Creates a client assertion to be used when generating an auth ticket.
/v1/client-assertionauth.roblox.com
GET
Gets the authenticated user's email address and verified status
/v1/emailaccountsettings.roblox.com
POST
Updates the authenticated user's email address
/v1/emailaccountsettings.roblox.com
PATCH
Updates the authenticated user's email address
/v1/emailaccountsettings.roblox.com
POST
Verify the user's email address from token
/v1/email/verifyaccountinformation.roblox.com
POST
Send verify email to the authenticated user's email address
/v1/email/verifyaccountsettings.roblox.com
GET
Gets the authenticated user's verified email and pending (unverified) email if one exists
/v1/emailsaccountsettings.roblox.com
GET
OAuth callback for identity providers that return the authorization code on a GET redirect (Okta, Google).
/v1/external/{identityProviderId}/sso/oauth/callbackauth.roblox.com
GET
Signs a user up for Roblox and links the account to the authenticated external provider ID via OAuth.
/v1/external/{identityProviderId}/sso/oauth/initauth.roblox.com
POST
Signs a user up for Roblox and links the account to the authenticated external provider ID.
/v1/external/accessauth.roblox.com
POST
Logs in a user to Roblox based on the user's authenticated external provider session
/v1/external/loginauth.roblox.com
POST
Deprecated endpoint Logins in a user to Roblox, then links the Roblox account to the external provider ID
/v1/external/loginAndLinkauth.roblox.com
POST
Signs a user up for Roblox and links the account to the authenticated external provider ID
/v1/external/signupauth.roblox.com
POST
Unlink the logged in Roblox account from the current external provider ID
/v1/external/unlinkauth.roblox.com
GET
Get the user's gender
/v1/genderusers.roblox.com
POST
Update the user's gender
/v1/genderusers.roblox.com
POST
Initiates identifier-first login flow by returning a list of login methods for user(s).
/v1/identity/initialize-loginauth.roblox.com
POST
Endpoint for login with identity verification
/v1/identity-verification/loginauth.roblox.com
GET
Gets a user's messages.
/v1/messagesprivatemessages.roblox.com
GET
Gets a message's details.
/v1/messages/{messageId}privatemessages.roblox.com
POST
Archives a batch of messages.
/v1/messages/archiveprivatemessages.roblox.com
POST
Marks a batch of messages as read.
/v1/messages/mark-readprivatemessages.roblox.com
POST
Marks a batch of messages as unread.
/v1/messages/mark-unreadprivatemessages.roblox.com
POST
Unarchives a batch of messages.
/v1/messages/unarchiveprivatemessages.roblox.com
GET
Gets unread messages for the authenticated user.
/v1/messages/unread/countprivatemessages.roblox.com
POST
Disables a batch of credentials for the specified user.
/v1/passkey/DeleteCredentialBatchauth.roblox.com
POST
Finishes account recovery pre-auth passkey registration by validating the recovery session, deactivating the user's password, and completing passkey registration.
/v1/passkey/finish-ar-preauth-registrationauth.roblox.com
POST
/v1/passkey/finish-preauth-registration
auth.roblox.com
POST
Complete Passkey registration by providing credential creation options.
/v1/passkey/FinishRegistrationauth.roblox.com
POST
List a user's registered passkeys.
/v1/passkey/ListCredentialsauth.roblox.com
POST
Initializes passkey authentication for the user(s) corresponding to the identifier provided.
/v1/passkey/start-authentication-by-userauth.roblox.com
POST
Initiates Passkey preauthenticated registration by providing credential creation options.
/v1/passkey/start-preauth-registrationauth.roblox.com
POST
Provides a challenge for the Passkey to authenticate.
/v1/passkey/StartAuthenticationauth.roblox.com
POST
Initiates Passkey registration by providing credential creation options.
/v1/passkey/StartRegistrationauth.roblox.com
GET
Checks whether the authenticated user is eligible for silent passkey upgrade. Route and response are intentionally obfuscated ("su-eligibility" = "silent-upgrade-eligibility").
/v1/passkey/su-eligibilityauth.roblox.com
GET
Get Verified Phone Number
/v1/phoneaccountinformation.roblox.com
POST
Set Phone Number
/v1/phoneaccountinformation.roblox.com
POST
Delete Phone
/v1/phone/deleteaccountinformation.roblox.com
POST
Resend Phone code
/v1/phone/resendaccountinformation.roblox.com
POST
Verify Phone
/v1/phone/verifyaccountinformation.roblox.com
POST
Update the user's promotion channels
/v1/promotion-channelsaccountinformation.roblox.com
POST
Removes the given social authentication method from current Roblox user if it is connected.
/v1/social/{provider}/disconnectauth.roblox.com
GET
Get social network user information if the given social auth method is connected to current user.
/v1/social/connected-providersauth.roblox.com
GET
returns the theme type for a specific consumer.
/v1/themes/{consumerType}/{consumerId}accountsettings.roblox.com
PATCH
Modify the theme type for consumer.
/v1/themes/{consumerType}/{consumerId}accountsettings.roblox.com
GET
returns all the enabled theme types.
/v1/themes/typesaccountsettings.roblox.com
GET
Get a user's trade privacy setting
/v1/trade-privacyaccountsettings.roblox.com
POST
Updates a user's trade privacy setting
/v1/trade-privacyaccountsettings.roblox.com
GET
Get a user's trade quality filter setting
/v1/trade-valueaccountsettings.roblox.com
POST
Updates a user's trade quality filter setting
/v1/trade-valueaccountsettings.roblox.com
POST
Changes the password for the authenticated user.
/v1/user/passwords/changeauth.roblox.com
POST
Change the user's username
/v1/usernameauth.roblox.com
GET
Get the current price for a username change
/v1/username/change/priceauth.roblox.com
GET
Gets a list of existing usernames on Roblox based on the query parameters
/v1/usernamesauth.roblox.com
POST
Sends an email of all accounts belonging to an email
/v1/usernames/recoverauth.roblox.com
GET
Checks if a username is valid.
/v1/usernames/validateauth.roblox.com
POST
Checks if a username is valid.
/v1/usernames/validateauth.roblox.com
POST
Verifies a two step verification challenge code via authenticator app.
/v1/users/{userId}/challenges/authenticator/verifytwostepverification.roblox.com
POST
Reverts a user's dialog state from ACTIVE to PENDING.
/v1/users/{userId}/challenges/cross-device/retracttwostepverification.roblox.com
POST
Retry a Cross Device two step verification approval.
/v1/users/{userId}/challenges/cross-device/retrytwostepverification.roblox.com
POST
Verifies a two step verification approval via Cross Device. Cross Device approval does not use a verification code.
/v1/users/{userId}/challenges/cross-device/verifytwostepverification.roblox.com
POST
Sends a two step verification challenge code via email.
/v1/users/{userId}/challenges/email/send-codetwostepverification.roblox.com
POST
Verifies a two step verification challenge with a code sent via email.
/v1/users/{userId}/challenges/email/verifytwostepverification.roblox.com
POST
Validates the assertion data returned by the passkey.
/v1/users/{userId}/challenges/passkey/verify-finishtwostepverification.roblox.com
POST
Provides a challenge for the passkey to authenticate.
/v1/users/{userId}/challenges/passkey/verify-starttwostepverification.roblox.com
POST
Verifies a two step verification challenge with a password (code).
/v1/users/{userId}/challenges/password/verifytwostepverification.roblox.com
POST
Verifies a two step verification challenge via a recovery code.
/v1/users/{userId}/challenges/recovery-codes/verifytwostepverification.roblox.com
POST
Validates the assertion data returned by the security key.
/v1/users/{userId}/challenges/security-key/verify-finishtwostepverification.roblox.com
POST
Provides a challenge for the security key to authenticate.
/v1/users/{userId}/challenges/security-key/verify-starttwostepverification.roblox.com
POST
Sends a two step verification code via SMS for the specified user.
/v1/users/{userId}/challenges/sms/send-codetwostepverification.roblox.com
POST
Verifies a two step verification challenge with a code sent via SMS.
/v1/users/{userId}/challenges/sms/verifytwostepverification.roblox.com
GET
Gets two step verification configuration for the specified user.
/v1/users/{userId}/configurationtwostepverification.roblox.com
POST
Disables two step verification via authenticator for the specified user.
/v1/users/{userId}/configuration/authenticator/disabletwostepverification.roblox.com
POST
Initiates enabling authenticator-based two step verification for the specified user.
/v1/users/{userId}/configuration/authenticator/enabletwostepverification.roblox.com
POST
Finishes enabling authenticator-based two step verification for the specified user.
/v1/users/{userId}/configuration/authenticator/enable-verifytwostepverification.roblox.com
POST
Disables two step verification via email for the specified user.
/v1/users/{userId}/configuration/email/disabletwostepverification.roblox.com
POST
Enables two step verification via email for the specified user.
/v1/users/{userId}/configuration/email/enabletwostepverification.roblox.com
POST
Disables a batch of credentials for the specified user.
/v1/users/{userId}/configuration/security-key/disabletwostepverification.roblox.com
POST
Initiates security key registration by providing credential creation options.
/v1/users/{userId}/configuration/security-key/enabletwostepverification.roblox.com
POST
Finishes security key registration and stores credential. Enables security key as a 2sv media type if it is a user's first key.
/v1/users/{userId}/configuration/security-key/enable-verifytwostepverification.roblox.com
POST
List a user's registered security keys.
/v1/users/{userId}/configuration/security-key/listtwostepverification.roblox.com
POST
Disables two step verification via SMS for the specified user.
/v1/users/{userId}/configuration/sms/disabletwostepverification.roblox.com
POST
Enables two step verification via SMS for the specified user.
/v1/users/{userId}/configuration/sms/enabletwostepverification.roblox.com
GET
Gets the current status of recovery codes for a user.
/v1/users/{userId}/recovery-codestwostepverification.roblox.com
POST
Clears any existing recovery codes for the user.
/v1/users/{userId}/recovery-codes/cleartwostepverification.roblox.com
POST
Clears any existing recovery codes and generates a new batch of recovery codes.
/v1/users/{userId}/recovery-codes/regeneratetwostepverification.roblox.com
GET
Gets the minimal authenticated user.
/v1/users/authenticatedusers.roblox.com
GET
Gets the age bracket of the authenticated user.
/v1/users/authenticated/age-bracketusers.roblox.com
GET
Gets the country code of the authenticated user.
/v1/users/authenticated/country-codeusers.roblox.com
GET
Gets the (public) roles of the authenticated user, such as `"Soothsayer"` and `"BetaTester"`.
/v1/users/authenticated/rolesusers.roblox.com
GET
Tries to check if an email is valid
/v1/validators/emailauth.roblox.com
GET
Validates the given display name, and if valid, will convert it to a valid username and return suggested username(s) if available.
/v1/validators/recommendedUsernameFromDisplayNameauth.roblox.com
POST
Validates the given display name, and if valid, will convert it to a valid username and return suggested username(s) if available. This is a POST request and explicitly does not receive the parameter values from the query
/v1/validators/recommendedUsernameFromDisplayNameauth.roblox.com
GET
Tries to get a valid username if the current username is taken
/v1/validators/usernameauth.roblox.com
POST
Tries to get a valid username if the current username is taken This is a POST request and explicitly does not receive the parameter values from the query
/v1/validators/usernameauth.roblox.com
GET
Check if the current user has an Xbox connected. Also returns the gamertag of the Xbox account if connected.
/v1/xbox/connectionauth.roblox.com
POST
Unlink the current ROBLOX account from the Xbox live account.
/v1/xbox/disconnectauth.roblox.com
GET
Get the consecutive days the xbox user has been logged in.
/v1/xbox/get-login-consecutive-daysauth.roblox.com
POST
Translate the xbox user to roblox user.
/v1/xbox/translateauth.roblox.com
Badges
GET
Returns a list of Roblox badges belonging to a user.
/v1/users/{userId}/roblox-badgesaccountinformation.roblox.com
Metadata
GET
Gets Auth meta data
/v2/auth/metadataauth.roblox.com
GET
Get the metadata
/v2/metadataauth.roblox.com
GET
Gets metadata needed for the password reset view.
/v2/passwords/resetauth.roblox.com
GET
Get metadata for forgot endpoints
/v2/recovery/metadataauth.roblox.com
GET
Get the metadata
/v1/metadataaccountinformation.roblox.com
GET
Gets two step verification system metadata.
/v1/metadatatwostepverification.roblox.com
Notifications
GET
Gets valid destinations associated with the signed user
/v2/push-notifications/get-destinationsnotifications.roblox.com
Universes
GET
Gets a list of universe playability statuses for the authenticated user
/v1/games/multiget-playability-statusgames.roblox.com
User profiles
GET
Get the user's description
/v1/descriptionusers.roblox.com
POST
Update the user's description
/v1/descriptionusers.roblox.com
GET
Get the user's promotion channels
/v1/promotion-channelsaccountinformation.roblox.com
Users
GET
Get promotion channels for a given user ID
/v1/users/{userId}/promotion-channelsaccountinformation.roblox.com
Not Recommended
POST
Destroys the current authentication session.
/v2/logoutauth.roblox.com
GET
Gets Auth meta data
/v1/auth/metadataauth.roblox.com
GET
Get the user's birthdate
/v1/birthdateaccountinformation.roblox.com
GET
Get the user's description
/v1/descriptionaccountinformation.roblox.com
POST
Update the user's description
/v1/descriptionaccountinformation.roblox.com
GET
Get the user's gender
/v1/genderaccountinformation.roblox.com
POST
Update the user's gender
/v1/genderaccountinformation.roblox.com
POST
Authenticates a user.
/v1/loginauth.roblox.com
POST
Endpoint for logging in a user, specifically for linked authentication on PCGDK
/v1/login/linkedauth.roblox.com
POST
Destroys the current authentication session.
/v1/logoutauth.roblox.com
POST
Logs out user from all other sessions.
/v1/logoutfromallsessionsandreauthenticateauth.roblox.com
GET
Get the metadata
/v1/metadataauth.roblox.com
GET
Endpoint for checking if a password is valid.
/v1/passwords/validateauth.roblox.com
POST
Endpoint for checking if a password is valid.
/v1/passwords/validateauth.roblox.com
GET
Get metadata for forgot endpoints
/v1/recovery/metadataauth.roblox.com
GET
Get Revert Account ticket info
/v1/revert/accountauth.roblox.com
POST
Submit Revert Account Request
/v1/revert/accountauth.roblox.com
POST
Invalidates all account security tickets for the authenticated user. This endpoint should be called before enrolling in EPP to ensure old revert links cannot be used.
/v1/revert/invalidate-ticketsauth.roblox.com
POST
Logs out user from the current session and create a new one.
/v1/session/refreshauth.roblox.com
POST
Endpoint for signing up a new user
/v1/signupauth.roblox.com
POST
Endpoint for signing up a new user, specifically for linked authentication on PCGDK
/v1/signup/linkedauth.roblox.com
GET
Gets whether the specified user's inventory can be viewed.
/v1/users/{userId}/can-view-inventoryinventory.roblox.com