auth.roblox.com
POST
Attaches a sign-in credential to the calling account.
/v1/account/upgradeauth.roblox.com
Accounts
POST
Destroys the current authentication session while reporting metrics like url and reason for logout.
/v3/logoutauth.roblox.com
POST
Authenticates as a user given a two step verification verification token.
/v3/users/{userId}/two-step-verification/loginauth.roblox.com
POST
Endpoint for login with identity verification
/v2/identity-verification/loginauth.roblox.com
POST
Authenticates a user.
/v2/loginauth.roblox.com
POST
Endpoint for logging in a user, specifically for linked
authentication on PCGDK
/v2/login/linkedauth.roblox.com
POST
Logs out user from all other sessions.
/v2/logoutfromallsessionsandreauthenticateauth.roblox.com
GET
Returns password status for current user, asynchronously.
/v2/passwords/current-statusauth.roblox.com
POST
Resets a password for a user that belongs to the password reset ticket.
/v2/passwords/resetauth.roblox.com
POST
Sends a password reset email or challenge to the specified target.
/v2/passwords/reset/sendauth.roblox.com
POST
Verifies a password reset challenge solution.
/v2/passwords/reset/verifyauth.roblox.com
GET
Endpoint for checking if a password is valid.
/v2/passwords/validateauth.roblox.com
POST
Endpoint for checking if a password is valid.
/v2/passwords/validateauth.roblox.com
GET
Get Revert Account ticket info
/v2/revert/accountauth.roblox.com
POST
Submit Revert Account Request
/v2/revert/accountauth.roblox.com
POST
Invalidates all account security tickets for the authenticated user.
This endpoint should be called before enrolling in EPP to ensure old revert links cannot be used.
/v2/revert/invalidate-ticketsauth.roblox.com
POST
Logs out user from the current session and create a new one.
/v2/session/refreshauth.roblox.com
POST
Endpoint for signing up a new user
/v2/signupauth.roblox.com
POST
Endpoint for signing up a new user through linked authentication.
/v2/signup/linkedauth.roblox.com
POST
Changes the password for the authenticated user.
/v2/user/passwords/changeauth.roblox.com
POST
Change the user's username
/v2/usernameauth.roblox.com
GET
Get the current price for a username change
/v2/username/change/priceauth.roblox.com
GET
Gets a list of existing usernames on Roblox based on the query parameters
/v2/usernamesauth.roblox.com
POST
Sends an email of all accounts belonging to an email
/v2/usernames/recoverauth.roblox.com
GET
Checks if a username is valid.
/v2/usernames/validateauth.roblox.com
POST
Checks if a username is valid.
/v2/usernames/validateauth.roblox.com
GET
Gets the account pin status.
/v1/account/pinauth.roblox.com
POST
Request to create the account pin.
/v1/account/pinauth.roblox.com
PATCH
Request made to update the account pin on the account.
/v1/account/pinauth.roblox.com
DELETE
Request for deletes the account pin from the account.
/v1/account/pinauth.roblox.com
POST
Request to locks the account which has an account pin enabled.
/v1/account/pin/lockauth.roblox.com
POST
Requests to unlock the account pin.
/v1/account/pin/unlockauth.roblox.com
GET
Get metadata for adding auth methods.
/v1/account-creation/metadataauth.roblox.com
GET
Creates a client assertion to be used when generating an auth ticket.
/v1/client-assertionauth.roblox.com
POST
Reserves a nonce for a native SSO sign-in attempt.
/v1/external/{identityProviderId}/sso/native/nonceauth.roblox.com
GET
OAuth callback for identity providers that return the authorization code on a GET redirect (Okta, Google).
/v1/external/{identityProviderId}/sso/oauth/callbackauth.roblox.com
POST
OAuth callback for identity providers that POST the authorization code as form fields (Apple form_post).
Apple's first-auth `user` JSON is parsed and carried to identity storage; the form
`id_token` is ignored....
/v1/external/{identityProviderId}/sso/oauth/callbackauth.roblox.com
GET
Signs a user up for Roblox and links the account to the authenticated external provider ID via OAuth.
/v1/external/{identityProviderId}/sso/oauth/initauth.roblox.com
POST
SAML Assertion Consumer Service endpoint that external identity provider calls post user authentication.
/v1/external/{identityProviderId}/sso/saml/assertion-consumer-serviceauth.roblox.com
POST
Signs a user up for Roblox and links the account to the authenticated external provider ID.
/v1/external/accessauth.roblox.com
POST
Logs in a user to Roblox based on the user's authenticated external provider session
/v1/external/loginauth.roblox.com
POST
Deprecated endpoint
Logins in a user to Roblox, then links the Roblox account to the external provider ID
/v1/external/loginAndLinkauth.roblox.com
POST
Signs a user up for Roblox and links the account to the authenticated external provider ID
/v1/external/signupauth.roblox.com
POST
Unlink the logged in Roblox account from the current external provider ID
/v1/external/unlinkauth.roblox.com
POST
Initiates identifier-first login flow by returning a list of login methods for user(s).
/v1/identity/initialize-loginauth.roblox.com
POST
Endpoint for login with identity verification
/v1/identity-verification/loginauth.roblox.com
POST
Disables a batch of credentials for the specified user.
/v1/passkey/DeleteCredentialBatchauth.roblox.com
POST
Finishes account recovery pre-auth passkey registration by validating the recovery session,
deactivating the user's password, and completing passkey registration.
/v1/passkey/finish-ar-preauth-registrationauth.roblox.com
POST
/v1/passkey/finish-preauth-registration
auth.roblox.com
POST
Complete Passkey registration by providing credential creation options.
/v1/passkey/FinishRegistrationauth.roblox.com
POST
List a user's registered passkeys.
/v1/passkey/ListCredentialsauth.roblox.com
POST
Rename a credential for the specified user.
/v1/passkey/RenameCredentialauth.roblox.com
POST
Initializes passkey authentication for the user(s) corresponding to the identifier provided.
/v1/passkey/start-authentication-by-userauth.roblox.com
POST
Initiates Passkey preauthenticated registration by providing credential creation options.
/v1/passkey/start-preauth-registrationauth.roblox.com
POST
Provides a challenge for the Passkey to authenticate.
/v1/passkey/StartAuthenticationauth.roblox.com
POST
Initiates Passkey registration by providing credential creation options.
/v1/passkey/StartRegistrationauth.roblox.com
GET
Checks whether the authenticated user is eligible for silent passkey upgrade.
Route and response are intentionally obfuscated ("su-eligibility" = "silent-upgrade-eligibility").
/v1/passkey/su-eligibilityauth.roblox.com
POST
Removes the given social authentication method from current Roblox user if it is connected.
/v1/social/{provider}/disconnectauth.roblox.com
GET
Get social network user information if the given social auth method is connected to current user.
/v1/social/connected-providersauth.roblox.com
POST
Changes the password for the authenticated user.
/v1/user/passwords/changeauth.roblox.com
POST
Change the user's username
/v1/usernameauth.roblox.com
GET
Get the current price for a username change
/v1/username/change/priceauth.roblox.com
GET
Gets a list of existing usernames on Roblox based on the query parameters
/v1/usernamesauth.roblox.com
POST
Sends an email of all accounts belonging to an email
/v1/usernames/recoverauth.roblox.com
GET
Checks if a username is valid.
/v1/usernames/validateauth.roblox.com
POST
Checks if a username is valid.
/v1/usernames/validateauth.roblox.com
GET
Tries to check if an email is valid
/v1/validators/emailauth.roblox.com
GET
Validates the given display name, and if valid, will convert it to a valid username and return suggested username(s) if available.
/v1/validators/recommendedUsernameFromDisplayNameauth.roblox.com
POST
Validates the given display name, and if valid, will convert it to a valid username and return suggested username(s) if available.
This is a POST request and explicitly does not receive the parameter values from the query
/v1/validators/recommendedUsernameFromDisplayNameauth.roblox.com
GET
Tries to get a valid username if the current username is taken
/v1/validators/usernameauth.roblox.com
POST
Tries to get a valid username if the current username is taken
This is a POST request and explicitly does not receive the parameter values from the query
/v1/validators/usernameauth.roblox.com
GET
Check if the current user has an Xbox connected.
Also returns the gamertag of the Xbox account if connected.
/v1/xbox/connectionauth.roblox.com
POST
Unlink the current ROBLOX account from the Xbox live account.
/v1/xbox/disconnectauth.roblox.com
GET
Get the consecutive days the xbox user has been logged in.
/v1/xbox/get-login-consecutive-daysauth.roblox.com
POST
Translate the xbox user to roblox user.
/v1/xbox/translateauth.roblox.com
Metadata
GET
Gets Auth meta data
/v2/auth/metadataauth.roblox.com
GET
Get the metadata
/v2/metadataauth.roblox.com
GET
Gets metadata needed for the password reset view.
/v2/passwords/resetauth.roblox.com
GET
Get metadata for forgot endpoints
/v2/recovery/metadataauth.roblox.com
Not Recommended
POST
Destroys the current authentication session.
/v2/logoutauth.roblox.com
GET
Gets Auth meta data
/v1/auth/metadataauth.roblox.com
POST
Authenticates a user.
/v1/loginauth.roblox.com
POST
Endpoint for logging in a user, specifically for linked
authentication on PCGDK
/v1/login/linkedauth.roblox.com
POST
Destroys the current authentication session.
/v1/logoutauth.roblox.com
POST
Logs out user from all other sessions.
/v1/logoutfromallsessionsandreauthenticateauth.roblox.com
GET
Get the metadata
/v1/metadataauth.roblox.com
GET
Endpoint for checking if a password is valid.
/v1/passwords/validateauth.roblox.com
POST
Endpoint for checking if a password is valid.
/v1/passwords/validateauth.roblox.com
GET
Get metadata for forgot endpoints
/v1/recovery/metadataauth.roblox.com
GET
Get Revert Account ticket info
/v1/revert/accountauth.roblox.com
POST
Submit Revert Account Request
/v1/revert/accountauth.roblox.com
POST
Invalidates all account security tickets for the authenticated user.
This endpoint should be called before enrolling in EPP to ensure old revert links cannot be used.
/v1/revert/invalidate-ticketsauth.roblox.com
POST
Logs out user from the current session and create a new one.
/v1/session/refreshauth.roblox.com
POST
Endpoint for signing up a new user
/v1/signupauth.roblox.com
POST
Endpoint for signing up a new user through linked authentication.
/v1/signup/linkedauth.roblox.com