Skip to content

Auth v1

Reference for the Auth v1 endpoints on Roblox.

Base URL: https://auth.roblox.com

Method Path Name
GET /v1/account-creation/metadata getAccountCreationMetadata
GET /v1/account/pin getAccountPin
POST /v1/account/pin postAccountPin
DELETE /v1/account/pin deleteAccountPin
PATCH /v1/account/pin patchAccountPin
POST /v1/account/pin/lock postAccountPinLock
POST /v1/account/pin/unlock postAccountPinUnlock
GET /v1/auth/metadata getAuthMetadata
GET /v1/client-assertion getClientAssertion
POST /v1/external/:identityProviderId/sso/native/nonce postExternalIdentityprovideridSsoNativeNonce
GET /v1/external/:identityProviderId/sso/oauth/callback getExternalIdentityprovideridSsoOauthCallback
POST /v1/external/:identityProviderId/sso/oauth/callback postExternalIdentityprovideridSsoOauthCallback
GET /v1/external/:identityProviderId/sso/oauth/init getExternalIdentityprovideridSsoOauthInit
POST /v1/external/:identityProviderId/sso/saml/assertion-consumer-service postExternalIdentityprovideridSsoSamlAssertionConsumerService
POST /v1/external/access postExternalAccess
POST /v1/external/login postExternalLogin
POST /v1/external/loginAndLink postExternalLoginandlink
POST /v1/external/signup postExternalSignup
POST /v1/external/unlink postExternalUnlink
POST /v1/identity-verification/login postIdentityVerificationLogin
POST /v1/identity/initialize-login postIdentityInitializeLogin
POST /v1/login postLogin
POST /v1/login/linked postLoginLinked
POST /v1/logout postLogout
POST /v1/logoutfromallsessionsandreauthenticate postLogoutfromallsessionsandreauthenticate
GET /v1/metadata getMetadata
POST /v1/passkey/DeleteCredentialBatch postPasskeyDeletecredentialbatch
POST /v1/passkey/finish-ar-preauth-registration postPasskeyFinishArPreauthRegistration
POST /v1/passkey/finish-preauth-registration postPasskeyFinishPreauthRegistration
POST /v1/passkey/FinishRegistration postPasskeyFinishregistration
POST /v1/passkey/ListCredentials postPasskeyListcredentials
POST /v1/passkey/RenameCredential postPasskeyRenamecredential
POST /v1/passkey/start-authentication-by-user postPasskeyStartAuthenticationByUser
POST /v1/passkey/start-preauth-registration postPasskeyStartPreauthRegistration
POST /v1/passkey/StartAuthentication postPasskeyStartauthentication
POST /v1/passkey/StartRegistration postPasskeyStartregistration
GET /v1/passkey/su-eligibility getPasskeySuEligibility
GET /v1/passwords/validate getPasswordsValidate
POST /v1/passwords/validate postPasswordsValidate
GET /v1/recovery/metadata getRecoveryMetadata
GET /v1/revert/account getRevertAccount
POST /v1/revert/account postRevertAccount
POST /v1/revert/invalidate-tickets postRevertInvalidateTickets
POST /v1/session/refresh postSessionRefresh
POST /v1/signup postSignup
POST /v1/signup/linked postSignupLinked
POST /v1/social/:provider/disconnect postSocialProviderDisconnect
GET /v1/social/connected-providers getSocialConnectedProviders
POST /v1/user/passwords/change postUserPasswordsChange
POST /v1/username postUsername
GET /v1/username/change/price getUsernameChangePrice
GET /v1/usernames getUsernames
POST /v1/usernames/recover postUsernamesRecover
GET /v1/usernames/validate getUsernamesValidate
POST /v1/usernames/validate postUsernamesValidate
GET /v1/validators/email getValidatorsEmail
GET /v1/validators/recommendedUsernameFromDisplayName getValidatorsRecommendedusernamefromdisplayname
POST /v1/validators/recommendedUsernameFromDisplayName postValidatorsRecommendedusernamefromdisplayname
GET /v1/validators/username getValidatorsUsername
POST /v1/validators/username postValidatorsUsername
GET /v1/xbox/connection getXboxConnection
POST /v1/xbox/disconnect postXboxDisconnect
GET /v1/xbox/get-login-consecutive-days getXboxGetLoginConsecutiveDays
POST /v1/xbox/translate postXboxTranslate

GET /v1/account-creation/metadata

Get metadata for adding auth methods.

Usage
import { fetchApi } from 'rozod';
import { getAccountCreationMetadata } from 'rozod/endpoints/authv1';
const data = await fetchApi(getAccountCreationMetadata, undefined);
Field Type Description
isEligibleForALSignup boolean

GET /v1/account/pin

Gets the account pin status.

Usage
import { fetchApi } from 'rozod';
import { getAccountPin } from 'rozod/endpoints/authv1';
const data = await fetchApi(getAccountPin, undefined);
Field Type Description
isEnabled boolean
unlockedUntil number
Status Description
401 0: Authorization has been denied for this request.

POST /v1/account/pin

Request to create the account pin.

Usage
import { fetchApi } from 'rozod';
import { postAccountPin } from 'rozod/endpoints/authv1';
const data = await fetchApi(postAccountPin, {
body: { /* ... */ }
});
Field Type Description
pin string
reauthenticationToken string
Field Type Description
success boolean
Status Description
401 0: Authorization has been denied for this request.
403 0: Token Validation Failed

DELETE /v1/account/pin

Request for deletes the account pin from the account.

Usage
import { fetchApi } from 'rozod';
import { deleteAccountPin } from 'rozod/endpoints/authv1';
const data = await fetchApi(deleteAccountPin, {
body: { /* ... */ }
});

Type: ModelsAccountPinRequest.optional()

Field Type Description
success boolean
Status Description
401 0: Authorization has been denied for this request.
403 0: Token Validation Failed

PATCH /v1/account/pin

Request made to update the account pin on the account.

Usage
import { fetchApi } from 'rozod';
import { patchAccountPin } from 'rozod/endpoints/authv1';
const data = await fetchApi(patchAccountPin, {
body: { /* ... */ }
});
Field Type Description
pin string
reauthenticationToken string
Field Type Description
success boolean
Status Description
401 0: Authorization has been denied for this request.
403 0: Token Validation Failed

POST /v1/account/pin/lock

Request to locks the account which has an account pin enabled.

Usage
import { fetchApi } from 'rozod';
import { postAccountPinLock } from 'rozod/endpoints/authv1';
const data = await fetchApi(postAccountPinLock, undefined);
Field Type Description
success boolean
Status Description
401 0: Authorization has been denied for this request.
403 0: Token Validation Failed

POST /v1/account/pin/unlock

Requests to unlock the account pin.

Usage
import { fetchApi } from 'rozod';
import { postAccountPinUnlock } from 'rozod/endpoints/authv1';
const data = await fetchApi(postAccountPinUnlock, {
body: { /* ... */ }
});
Field Type Description
pin string
reauthenticationToken string
Field Type Description
unlockedUntil number
Status Description
401 0: Authorization has been denied for this request.
403 0: Token Validation Failed

GET /v1/auth/metadata

Gets Auth meta data

Usage
import { fetchApi } from 'rozod';
import { getAuthMetadata } from 'rozod/endpoints/authv1';
const data = await fetchApi(getAuthMetadata, undefined);
Field Type Description
cookieLawNoticeTimeout number

GET /v1/client-assertion

Creates a client assertion to be used when generating an auth ticket.

Usage
import { fetchApi } from 'rozod';
import { getClientAssertion } from 'rozod/endpoints/authv1';
const data = await fetchApi(getClientAssertion, undefined);
Field Type Description
clientAssertion string
Status Description
401 0: Authorization has been denied for this request.

postExternalIdentityprovideridSsoNativeNonce

Section titled “postExternalIdentityprovideridSsoNativeNonce”

POST /v1/external/:identityProviderId/sso/native/nonce

Reserves a nonce for a native SSO sign-in attempt.

Usage
import { fetchApi } from 'rozod';
import { postExternalIdentityprovideridSsoNativeNonce } from 'rozod/endpoints/authv1';
const data = await fetchApi(postExternalIdentityprovideridSsoNativeNonce, {
identityProviderId: /* integer */
});
Name Type Required Description
identityProviderId integer Yes
Field Type Description
nonce string

getExternalIdentityprovideridSsoOauthCallback

Section titled “getExternalIdentityprovideridSsoOauthCallback”

GET /v1/external/:identityProviderId/sso/oauth/callback

OAuth callback for identity providers that return the authorization code on a GET redirect (Okta, Google).

Usage
import { fetchApi } from 'rozod';
import { getExternalIdentityprovideridSsoOauthCallback } from 'rozod/endpoints/authv1';
const data = await fetchApi(getExternalIdentityprovideridSsoOauthCallback, {
identityProviderId: /* integer */,
code: /* string */,
state: /* string */
});
Name Type Required Description
identityProviderId integer Yes
code string Yes
state string Yes

Type: unknown

Status Description
302 Redirect

postExternalIdentityprovideridSsoOauthCallback

Section titled “postExternalIdentityprovideridSsoOauthCallback”

POST /v1/external/:identityProviderId/sso/oauth/callback

OAuth callback for identity providers that POST the authorization code as form fields (Apple form_post).

Usage
import { fetchApi } from 'rozod';
import { postExternalIdentityprovideridSsoOauthCallback } from 'rozod/endpoints/authv1';
const data = await fetchApi(postExternalIdentityprovideridSsoOauthCallback, {
identityProviderId: /* integer */,
body: { /* ... */ }
});
Name Type Required Description
identityProviderId integer Yes

Type: unknown

Type: unknown

Status Description
302 Redirect

GET /v1/external/:identityProviderId/sso/oauth/init

Signs a user up for Roblox and links the account to the authenticated external provider ID via OAuth.

Usage
import { fetchApi } from 'rozod';
import { getExternalIdentityprovideridSsoOauthInit } from 'rozod/endpoints/authv1';
const data = await fetchApi(getExternalIdentityprovideridSsoOauthInit, {
identityProviderId: /* integer */,
postAuthenticationIntentId: /* string */
});
Name Type Required Description
identityProviderId integer Yes The identity provider to authenticate against.
postAuthenticationIntentId string Yes Which post-authentication intent to carry out at the end of the handshake. Optional, and omitting it selects the provider’s web redirect.

Type: unknown

Status Description
302 Redirect

postExternalIdentityprovideridSsoSamlAssertionConsumerService

Section titled “postExternalIdentityprovideridSsoSamlAssertionConsumerService”

POST /v1/external/:identityProviderId/sso/saml/assertion-consumer-service

SAML Assertion Consumer Service endpoint that external identity provider calls post user authentication.

Usage
import { fetchApi } from 'rozod';
import { postExternalIdentityprovideridSsoSamlAssertionConsumerService } from 'rozod/endpoints/authv1';
const data = await fetchApi(postExternalIdentityprovideridSsoSamlAssertionConsumerService, {
identityProviderId: /* integer */,
body: { /* ... */ }
});
Name Type Required Description
identityProviderId integer Yes
Field Type Description
SAMLResponse string
RelayState string

Type: unknown

Status Description
302 Redirect

POST /v1/external/access

Signs a user up for Roblox and links the account to the authenticated external provider ID.

Usage
import { fetchApi } from 'rozod';
import { postExternalAccess } from 'rozod/endpoints/authv1';
const data = await fetchApi(postExternalAccess, {
body: { /* ... */ }
});
Field Type Description
authenticationProof string
identityProviderPlatformType `“Undefined” “Xbox”
postAuthenticationIntentId string
additionalInfoPayload object See below
Field Type Description
placeId number
isolationContext string
launchData string

POST /v1/external/login

Logs in a user to Roblox based on the user’s authenticated external provider session

Usage
import { fetchApi } from 'rozod';
import { postExternalLogin } from 'rozod/endpoints/authv1';
const data = await fetchApi(postExternalLogin, {
body: { /* ... */ }
});
Field Type Description
identityProvider `0 1
additionalData object See below
authenticationProof string
Field Type Description
success boolean
Status Description
400 30: Platform is not supported for SSO login.
401 31: No linked account found for SSO login.
403 0: Token Validation Failed
500 0: An unexpected error occurred.
501 0: An unexpected error occurred.

POST /v1/external/loginAndLink

Deprecated endpoint

Usage
import { fetchApi } from 'rozod';
import { postExternalLoginandlink } from 'rozod/endpoints/authv1';
const data = await fetchApi(postExternalLoginandlink, {
body: { /* ... */ }
});
Field Type Description
ctype `“Email” “Username”
cvalue string
password string
authenticationProof string
IdentityProviderPlatformType `“Undefined” “Xbox”
additionalInfoPayload object See below
Field Type Description
user object See below
twoStepVerificationData object See below
identityVerificationLoginTicket string
isBanned boolean
accountBlob string
shouldUpdateEmail boolean
recoveryEmail string
passkeyRegistrationSucceeded boolean
shouldAutoLoginFromRecovery boolean
shouldPrompt2svRemoval boolean
shouldPromptPasskeyAddition boolean
shouldPromptCredentialInvalidation boolean

user fields:

Field Type Description
id number
name string
displayName string

twoStepVerificationData fields:

Field Type Description
mediaType `“Email” “SMS”
ticket string
Status Description
403 0: Token Validation Failed

POST /v1/external/signup

Signs a user up for Roblox and links the account to the authenticated external provider ID

Usage
import { fetchApi } from 'rozod';
import { postExternalSignup } from 'rozod/endpoints/authv1';
const data = await fetchApi(postExternalSignup, {
body: { /* ... */ }
});
Field Type Description
username string
password string
birthday string
locale string
authenticationProof string
IdentityProviderPlatformType `“Undefined” “Xbox”
additionalInfoPayload object See below

Type: unknown

Status Description
403 0: Token Validation Failed

POST /v1/external/unlink

Unlink the logged in Roblox account from the current external provider ID

Usage
import { fetchApi } from 'rozod';
import { postExternalUnlink } from 'rozod/endpoints/authv1';
const data = await fetchApi(postExternalUnlink, {
body: { /* ... */ }
});
Field Type Description
IdentityProviderPlatformType `“Undefined” “Xbox”
additionalInfoPayload object See below

Type: unknown

Status Description
403 0: Token Validation Failed

POST /v1/identity-verification/login

Endpoint for login with identity verification

Usage
import { fetchApi } from 'rozod';
import { postIdentityVerificationLogin } from 'rozod/endpoints/authv1';
const data = await fetchApi(postIdentityVerificationLogin, {
body: { /* ... */ }
});
Field Type Description
loginTicket string
resultToken string

Type: unknown

Status Description
403 0: Token Validation Failed
1: Invalid login ticket.
2: Invalid result token.
3: Invalid user.
4: Authentication failure.

POST /v1/identity/initialize-login

Initiates identifier-first login flow by returning a list of login methods for user(s).

Usage
import { fetchApi } from 'rozod';
import { postIdentityInitializeLogin } from 'rozod/endpoints/authv1';
const data = await fetchApi(postIdentityInitializeLogin, {
body: { /* ... */ }
});
Field Type Description
ctype `0 1
cvalue string
captchaId string | undefined
captchaToken string | undefined
captchaProvider string | undefined
challengeId string | undefined
Field Type Description
loginMethods object[] See below

loginMethods[] item fields:

Field Type Description
method `“EmailOtp” “Passkey”
priority number
Status Description
400 3: User identifier and type are required.
403 0: Token Validation Failed
2: Invalid user identifier.
4: No login methods available. Please use account recovery.
500 0: An unknown error occurred.
503 1: This feature is disabled.

POST /v1/login

Authenticates a user.

Usage
import { fetchApi } from 'rozod';
import { postLogin } from 'rozod/endpoints/authv1';
const data = await fetchApi(postLogin, {
body: { /* ... */ }
});
Field Type Description
ctype `“Email” “Username”
cvalue string
password string
userId number
securityQuestionSessionId string
securityQuestionRedemptionToken string
secureAuthenticationIntent object See below
accountBlob string
accountLinkParameters object See below
captchaId string
captchaToken string
captchaProvider string
challengeId string

secureAuthenticationIntent fields:

Field Type Description
clientPublicKey string
clientEpochTimestamp number
saiSignature string
serverNonce string

accountLinkParameters fields:

Field Type Description
LinkingPlatform `“Invalid” “Xbox”
Field Type Description
user object See below
twoStepVerificationData object See below
identityVerificationLoginTicket string
isBanned boolean
accountBlob string
shouldUpdateEmail boolean
recoveryEmail string
passkeyRegistrationSucceeded boolean
shouldAutoLoginFromRecovery boolean
shouldPrompt2svRemoval boolean
shouldPromptPasskeyAddition boolean
shouldPromptCredentialInvalidation boolean

user fields:

Field Type Description
id number
name string
displayName string

twoStepVerificationData fields:

Field Type Description
mediaType `“Email” “SMS”
ticket string
Status Description
400 0: An unexpected error occurred.
3: Username and Password are required. Please try again.
8: Login with received credential type is not supported.
403 0: Token Validation Failed
1: Incorrect username or password. Please try again.
2: You must pass the robot test before logging in.
4: Account has been locked. Please request a password reset.
5: Unable to login. Please use Social Network sign on.
6: Account issue. Please contact Support.
9: Unable to login with provided credentials. Default login is required.
10: Received credentials are unverified.
12: Existing login session found. Please log out first.
14: The account is unable to log in. Please log in to the LuoBu app.
15: Too many attempts. Please wait a bit.
27: The account is unable to login. Please log in with the VNG app.
429 7: Too many attempts. Please wait a bit.
503 11: Service unavailable. Please try again.

POST /v1/login/linked

Endpoint for logging in a user, specifically for linked

Usage
import { fetchApi } from 'rozod';
import { postLoginLinked } from 'rozod/endpoints/authv1';
const data = await fetchApi(postLoginLinked, {
body: { /* ... */ }
});
Field Type Description
ctype `“Email” “Username”
cvalue string
password string
userId number
securityQuestionSessionId string
securityQuestionRedemptionToken string
secureAuthenticationIntent object See below
accountBlob string
accountLinkParameters object See below
captchaId string
captchaToken string
captchaProvider string
challengeId string

secureAuthenticationIntent fields:

Field Type Description
clientPublicKey string
clientEpochTimestamp number
saiSignature string
serverNonce string

accountLinkParameters fields:

Field Type Description
LinkingPlatform `“Invalid” “Xbox”
Field Type Description
user object See below
twoStepVerificationData object See below
identityVerificationLoginTicket string
isBanned boolean
accountBlob string
shouldUpdateEmail boolean
recoveryEmail string
passkeyRegistrationSucceeded boolean
shouldAutoLoginFromRecovery boolean
shouldPrompt2svRemoval boolean
shouldPromptPasskeyAddition boolean
shouldPromptCredentialInvalidation boolean

user fields:

Field Type Description
id number
name string
displayName string

twoStepVerificationData fields:

Field Type Description
mediaType `“Email” “SMS”
ticket string
Status Description
400 0: An unexpected error occurred.
3: Username and Password are required. Please try again.
8: Login with received credential type is not supported.
403 0: Token Validation Failed
1: Incorrect username or password. Please try again.
2: You must pass the robot test before logging in.
4: Account has been locked. Please request a password reset.
5: Unable to login. Please use Social Network sign on.
6: Account issue. Please contact Support.
9: Unable to login with provided credentials. Default login is required.
10: Received credentials are unverified.
12: Existing login session found. Please log out first.
14: The account is unable to log in. Please log in to the LuoBu app.
15: Too many attempts. Please wait a bit.
27: The account is unable to login. Please log in with the VNG app.
43: This account is not eligible for this platform.
429 7: Too many attempts. Please wait a bit.
503 11: Service unavailable. Please try again.

POST /v1/logout

Destroys the current authentication session.

Usage
import { fetchApi } from 'rozod';
import { postLogout } from 'rozod/endpoints/authv1';
const data = await fetchApi(postLogout, undefined);

Type: unknown

Status Description
401 0: Authorization has been denied for this request.
403 0: Token Validation Failed

postLogoutfromallsessionsandreauthenticate

Section titled “postLogoutfromallsessionsandreauthenticate”

POST /v1/logoutfromallsessionsandreauthenticate

Logs out user from all other sessions.

Usage
import { fetchApi } from 'rozod';
import { postLogoutfromallsessionsandreauthenticate } from 'rozod/endpoints/authv1';
const data = await fetchApi(postLogoutfromallsessionsandreauthenticate, {
body: { /* ... */ }
});
Field Type Description
SecureAuthenticationIntent object See below

SecureAuthenticationIntent fields:

Field Type Description
clientPublicKey string
clientEpochTimestamp number
saiSignature string
serverNonce string

Type: unknown

Status Description
401 0: Authorization has been denied for this request.
403 0: Token Validation Failed

GET /v1/metadata

Get the metadata

Usage
import { fetchApi } from 'rozod';
import { getMetadata } from 'rozod/endpoints/authv1';
const data = await fetchApi(getMetadata, undefined);
Field Type Description
isUpdateUsernameEnabled boolean
ftuxAvatarAssetMap string
IsEmailUpsellAtLogoutEnabled boolean
ShouldFetchEmailUpsellIXPValuesAtLogout boolean
IsAccountRecoveryPromptEnabled boolean
IsContactMethodRequiredAtSignup boolean
IsUserAgreementsSignupIntegrationEnabled boolean
IsPasswordRequiredForUsernameChange boolean
IsPasskeyFeatureEnabled boolean
IsAltBrowserTracker boolean
IsLoginRedirectPageEnabled boolean

POST /v1/passkey/DeleteCredentialBatch

Disables a batch of credentials for the specified user.

Usage
import { fetchApi } from 'rozod';
import { postPasskeyDeletecredentialbatch } from 'rozod/endpoints/authv1';
const data = await fetchApi(postPasskeyDeletecredentialbatch, {
body: { /* ... */ }
});
Field Type Description
credentialIDs string[]
credentialNicknames string[]

Type: unknown

Status Description
400 3: Invalid security key nickname.
401 0: Authorization has been denied for this request.
0: An unknown error occurred with the request.
403 0: Token Validation Failed
503 2: Feature disabled.

POST /v1/passkey/finish-ar-preauth-registration

Finishes account recovery pre-auth passkey registration by validating the recovery session,

Usage
import { fetchApi } from 'rozod';
import { postPasskeyFinishArPreauthRegistration } from 'rozod/endpoints/authv1';
const data = await fetchApi(postPasskeyFinishArPreauthRegistration, {
body: { /* ... */ }
});
Field Type Description
recoverySession string
passkeySessionId string
passkeyRegistrationResponse string
userId number
isPostRecovery boolean
source string

Type: unknown

Status Description
400 0: An unknown error occurred with the request.
401 0: An unknown error occurred with the request.
403 0: Token Validation Failed
1: Reached limit of pass keys registered.
500 0: An unknown error occurred with the request.
503 2: Feature disabled.

POST /v1/passkey/finish-preauth-registration

Usage
import { fetchApi } from 'rozod';
import { postPasskeyFinishPreauthRegistration } from 'rozod/endpoints/authv1';
const data = await fetchApi(postPasskeyFinishPreauthRegistration, {
body: { /* ... */ }
});
Field Type Description
sessionId string
registrationResponse string
source string

Type: unknown

Status Description
400 0: An unknown error occurred with the request.
401 0: Authorization has been denied for this request.
0: An unknown error occurred with the request.
403 0: Token Validation Failed
1: Reached limit of pass keys registered.
500 0: An unknown error occurred with the request.
503 2: Feature disabled.

POST /v1/passkey/FinishRegistration

Complete Passkey registration by providing credential creation options.

Usage
import { fetchApi } from 'rozod';
import { postPasskeyFinishregistration } from 'rozod/endpoints/authv1';
const data = await fetchApi(postPasskeyFinishregistration, {
body: { /* ... */ }
});
Field Type Description
sessionId string
credentialNickname string
attestationResponse string
source string

Type: unknown

Status Description
400 0: An unknown error occurred with the request.
3: Invalid security key nickname.
401 0: Authorization has been denied for this request.
0: An unknown error occurred with the request.
403 0: Token Validation Failed
3: Invalid security key nickname.
503 2: Feature disabled.

POST /v1/passkey/ListCredentials

List a user’s registered passkeys.

Usage
import { fetchApi } from 'rozod';
import { postPasskeyListcredentials } from 'rozod/endpoints/authv1';
const data = await fetchApi(postPasskeyListcredentials, {
body: { /* ... */ }
});
Field Type Description
all boolean
Field Type Description
credentials object[] See below

credentials[] item fields:

Field Type Description
nickname string
credentialID string
Status Description
401 0: Authorization has been denied for this request.
0: An unknown error occurred with the request.
403 0: Token Validation Failed
503 2: Feature disabled.

POST /v1/passkey/RenameCredential

Rename a credential for the specified user.

Usage
import { fetchApi } from 'rozod';
import { postPasskeyRenamecredential } from 'rozod/endpoints/authv1';
const data = await fetchApi(postPasskeyRenamecredential, {
body: { /* ... */ }
});
Field Type Description
credentialID string
newNickname string

Type: unknown

Status Description
400 3: Invalid security key nickname.
7: Invalid passkey ID.
401 0: Authorization has been denied for this request.
0: An unknown error occurred with the request.
403 0: Token Validation Failed
3: Invalid security key nickname.
503 2: Feature disabled.

POST /v1/passkey/start-authentication-by-user

Initializes passkey authentication for the user(s) corresponding to the identifier provided.

Usage
import { fetchApi } from 'rozod';
import { postPasskeyStartAuthenticationByUser } from 'rozod/endpoints/authv1';
const data = await fetchApi(postPasskeyStartAuthenticationByUser, {
body: { /* ... */ }
});
Field Type Description
ctype `0 1
cvalue string
Field Type Description
authenticationOptions string
sessionId string
Status Description
400 5: User identifier and type are required.
6: Multi-user passkey authentication is not supported for this credential type.
403 0: Token Validation Failed
4: No passkeys registered for any users found.
503 2: Feature disabled.

POST /v1/passkey/start-preauth-registration

Initiates Passkey preauthenticated registration by providing credential creation options.

Usage
import { fetchApi } from 'rozod';
import { postPasskeyStartPreauthRegistration } from 'rozod/endpoints/authv1';
const data = await fetchApi(postPasskeyStartPreauthRegistration, {
body: { /* ... */ }
});
Field Type Description
username string
Field Type Description
creationOptions string
sessionId string
Status Description
403 0: Token Validation Failed
503 2: Feature disabled.

POST /v1/passkey/StartAuthentication

Provides a challenge for the Passkey to authenticate.

Usage
import { fetchApi } from 'rozod';
import { postPasskeyStartauthentication } from 'rozod/endpoints/authv1';
const data = await fetchApi(postPasskeyStartauthentication, undefined);
Field Type Description
authenticationOptions string
sessionId string
Status Description
403 0: Token Validation Failed
503 2: Feature disabled.

POST /v1/passkey/StartRegistration

Initiates Passkey registration by providing credential creation options.

Usage
import { fetchApi } from 'rozod';
import { postPasskeyStartregistration } from 'rozod/endpoints/authv1';
const data = await fetchApi(postPasskeyStartregistration, {
flow: /* string? */,
body: { /* ... */ }
});
Name Type Required Description
flow string? No
Field Type Description
isSilentUpgrade boolean
Field Type Description
creationOptions string
sessionId string
Status Description
401 0: Authorization has been denied for this request.
0: An unknown error occurred with the request.
403 0: Token Validation Failed
1: Reached limit of pass keys registered.
503 2: Feature disabled.

GET /v1/passkey/su-eligibility

Checks whether the authenticated user is eligible for silent passkey upgrade.

Usage
import { fetchApi } from 'rozod';
import { getPasskeySuEligibility } from 'rozod/endpoints/authv1';
const data = await fetchApi(getPasskeySuEligibility, undefined);
Field Type Description
suEligibility boolean
Status Description
401 0: Authorization has been denied for this request.
0: An unknown error occurred with the request.
503 2: Feature disabled.

GET /v1/passwords/validate

Endpoint for checking if a password is valid.

Usage
import { fetchApi } from 'rozod';
import { getPasswordsValidate } from 'rozod/endpoints/authv1';
const data = await fetchApi(getPasswordsValidate, {
Username: /* string */,
Password: /* string */
});
Name Type Required Description
Username string Yes
Password string Yes
Field Type Description
code `“ValidPassword” “WeakPasswordError”
message string
Status Description
400 1: Valid Username and Password are required. Please try again.

POST /v1/passwords/validate

Endpoint for checking if a password is valid.

Usage
import { fetchApi } from 'rozod';
import { postPasswordsValidate } from 'rozod/endpoints/authv1';
const data = await fetchApi(postPasswordsValidate, {
body: { /* ... */ }
});
Field Type Description
username string
password string
Field Type Description
code `“ValidPassword” “WeakPasswordError”
message string
Status Description
400 1: Valid Username and Password are required. Please try again.
403 0: Token Validation Failed

GET /v1/recovery/metadata

Get metadata for forgot endpoints

Usage
import { fetchApi } from 'rozod';
import { getRecoveryMetadata } from 'rozod/endpoints/authv1';
const data = await fetchApi(getRecoveryMetadata, undefined);
Field Type Description
isOnPhone boolean
codeLength number
isPhoneFeatureEnabledForUsername boolean
isPhoneFeatureEnabledForPassword boolean
isBedev2CaptchaEnabledForPasswordReset boolean
isUsernameRecoveryDeprecated boolean
Status Description
503 7: The Roblox WeChat API is currently unavailable.

GET /v1/revert/account

Get Revert Account ticket info

Usage
import { fetchApi } from 'rozod';
import { getRevertAccount } from 'rozod/endpoints/authv1';
const data = await fetchApi(getRevertAccount, {
ticket: /* string */
});
Name Type Required Description
ticket string Yes Ticket Guid to revert account.
Field Type Description
isTwoStepVerificationEnabled boolean
isEmailVerified boolean
isEmailChanged boolean
isPhoneVerified boolean
userId number
username string
ticket string
Status Description
400 2: The account revert ticket is not valid
403 13: Revert links are disabled for users in the Enhanced Protection Program.
503 1: This feature is disabled

POST /v1/revert/account

Submit Revert Account Request

Usage
import { fetchApi } from 'rozod';
import { postRevertAccount } from 'rozod/endpoints/authv1';
const data = await fetchApi(postRevertAccount, {
body: { /* ... */ }
});
Field Type Description
UserId number
NewPassword string
NewPasswordRepeated string
Ticket string
TwoStepVerificationChallengeId string
TwoStepVerificationToken string
Field Type Description
user object See below
twoStepVerificationData object See below
identityVerificationLoginTicket string
isBanned boolean
accountBlob string
shouldUpdateEmail boolean
recoveryEmail string
passkeyRegistrationSucceeded boolean
shouldAutoLoginFromRecovery boolean
shouldPrompt2svRemoval boolean
shouldPromptPasskeyAddition boolean
shouldPromptCredentialInvalidation boolean

user fields:

Field Type Description
id number
name string
displayName string

twoStepVerificationData fields:

Field Type Description
mediaType `“Email” “SMS”
ticket string
Status Description
400 2: The account revert ticket is not valid
3: Password is not valid
4: Passwords do not match
5: Password cannot be used
8: The account security ticket is expired.
403 0: Token Validation Failed
503 0: Unknown
1: This feature is disabled

POST /v1/revert/invalidate-tickets

Invalidates all account security tickets for the authenticated user.

Usage
import { fetchApi } from 'rozod';
import { postRevertInvalidateTickets } from 'rozod/endpoints/authv1';
const data = await fetchApi(postRevertInvalidateTickets, undefined);

Type: unknown

Status Description
401 0: Authorization has been denied for this request.
403 0: Token Validation Failed
503 1: This feature is disabled

POST /v1/session/refresh

Logs out user from the current session and create a new one.

Usage
import { fetchApi } from 'rozod';
import { postSessionRefresh } from 'rozod/endpoints/authv1';
const data = await fetchApi(postSessionRefresh, undefined);

Type: unknown

Status Description
401 0: Authorization has been denied for this request.
403 0: Token Validation Failed

POST /v1/signup

Endpoint for signing up a new user

Usage
import { fetchApi } from 'rozod';
import { postSignup } from 'rozod/endpoints/authv1';
const data = await fetchApi(postSignup, {
body: { /* ... */ }
});
Field Type Description
username string
password string
gender `“Unknown” “Male”
birthday string
displayName string
isTosAgreementBoxChecked boolean
signupType `“Regular” “Express”`
email string
locale string
assetIds number[]
bodyColorId number
bodyTypeScale number
headScale number
heightScale number
widthScale number
proportionScale number
referralData object See below
agreementIds string[]
identityVerificationResultToken string
secureAuthenticationIntent object See below
otpSession object See below
dataToken string
accountBlob string
passkeySessionId string
passkeyRegistrationResponse string
accountLinkParameters object See below
auditSystemContent object See below
captchaId string
captchaToken string
captchaProvider string
challengeId string

referralData fields:

Field Type Description
acquisitionTime string
acquisitionReferrer string
medium string
source string
campaign string
adGroup string
keyword string
matchType string
sendInfo boolean
requestSessionId string
offerId string

secureAuthenticationIntent fields:

Field Type Description
clientPublicKey string
clientEpochTimestamp number
saiSignature string
serverNonce string

otpSession fields:

Field Type Description
otpSessionToken string
otpContactType `“Unset” “Email”`

accountLinkParameters fields:

Field Type Description
LinkingPlatform `“Invalid” “Xbox”

auditSystemContent fields:

Field Type Description
capturedAuditContent object See below
additionalAuditContent string

capturedAuditContent fields:

Field Type Description
translationKey string
translationNamespace string
translatedSourceString string
parameters string
Field Type Description
userId number
starterPlaceId number
returnUrl string
accountBlob string
Status Description
400 Bad request
16: User agreement ids are null.
21: Empty account switch blob required
403 0: Token Validation Failed
2: Captcha Failed.
4: Invalid Birthday.
5: Invalid Username.
6: Username already taken.
7: Invalid Password.
8: Password and Username are same.
9: Password is too simple.
10: Email is invalid.
11: Asset is invalid.
12: Too many attempts. Please wait a bit.
17: One time Passcode session was not valid
22: Maximum logged in accounts limit reached.
429 3: Too many attempts. Please wait a bit.
500 Internal server error
15: Insert acceptances failed.
27: Pre-auth passkey registration failed
503 Service unavailable

POST /v1/signup/linked

Endpoint for signing up a new user through linked authentication.

Usage
import { fetchApi } from 'rozod';
import { postSignupLinked } from 'rozod/endpoints/authv1';
const data = await fetchApi(postSignupLinked, {
body: { /* ... */ }
});
Field Type Description
username string
password string
gender `“Unknown” “Male”
birthday string
displayName string
isTosAgreementBoxChecked boolean
signupType `“Regular” “Express”`
email string
locale string
assetIds number[]
bodyColorId number
bodyTypeScale number
headScale number
heightScale number
widthScale number
proportionScale number
referralData object See below
agreementIds string[]
identityVerificationResultToken string
secureAuthenticationIntent object See below
otpSession object See below
dataToken string
accountBlob string
passkeySessionId string
passkeyRegistrationResponse string
accountLinkParameters object See below
auditSystemContent object See below
captchaId string
captchaToken string
captchaProvider string
challengeId string

referralData fields:

Field Type Description
acquisitionTime string
acquisitionReferrer string
medium string
source string
campaign string
adGroup string
keyword string
matchType string
sendInfo boolean
requestSessionId string
offerId string

secureAuthenticationIntent fields:

Field Type Description
clientPublicKey string
clientEpochTimestamp number
saiSignature string
serverNonce string

otpSession fields:

Field Type Description
otpSessionToken string
otpContactType `“Unset” “Email”`

accountLinkParameters fields:

Field Type Description
LinkingPlatform `“Invalid” “Xbox”

auditSystemContent fields:

Field Type Description
capturedAuditContent object See below
additionalAuditContent string

capturedAuditContent fields:

Field Type Description
translationKey string
translationNamespace string
translatedSourceString string
parameters string
Field Type Description
userId number
starterPlaceId number
returnUrl string
accountBlob string
Status Description
400 Bad request
16: User agreement ids are null.
21: Empty account switch blob required
403 0: Token Validation Failed
2: Captcha Failed.
4: Invalid Birthday.
5: Invalid Username.
6: Username already taken.
7: Invalid Password.
8: Password and Username are same.
9: Password is too simple.
10: Email is invalid.
11: Asset is invalid.
12: Too many attempts. Please wait a bit.
17: One time Passcode session was not valid
22: Maximum logged in accounts limit reached.
29: Account Linking already exists on this account
30: Account Linking required but failed
429 3: Too many attempts. Please wait a bit.
500 Internal server error
15: Insert acceptances failed.
27: Pre-auth passkey registration failed
30: Account Linking required but failed
503 30: Account Linking required but failed

POST /v1/social/:provider/disconnect

Removes the given social authentication method from current Roblox user if it is connected.

Usage
import { fetchApi } from 'rozod';
import { postSocialProviderDisconnect } from 'rozod/endpoints/authv1';
const data = await fetchApi(postSocialProviderDisconnect, {
provider: /* string */,
body: { /* ... */ }
});
Name Type Required Description
provider string Yes The social authentication provider, e.g. Facebook
Field Type Description
Password string

Type: unknown

Status Description
400 Bad request
2: Unsupported social provider type.
401 0: Authorization has been denied for this request.
403 Forbidden
0: Token Validation Failed
3: Cannot disconnect the only authentication method. Password on account is required.
4: The password provided is invalid.
500 Internal server error

GET /v1/social/connected-providers

Get social network user information if the given social auth method is connected to current user.

Usage
import { fetchApi } from 'rozod';
import { getSocialConnectedProviders } from 'rozod/endpoints/authv1';
const data = await fetchApi(getSocialConnectedProviders, undefined);
Field Type Description
providers object[] See below

providers[] item fields:

Field Type Description
provider string
identifier string
Status Description
401 0: Authorization has been denied for this request.

POST /v1/user/passwords/change

Changes the password for the authenticated user.

Usage
import { fetchApi } from 'rozod';
import { postUserPasswordsChange } from 'rozod/endpoints/authv1';
const data = await fetchApi(postUserPasswordsChange, {
body: { /* ... */ }
});
Field Type Description
currentPassword string
newPassword string
secureAuthenticationIntent object See below

secureAuthenticationIntent fields:

Field Type Description
clientPublicKey string
clientEpochTimestamp number
saiSignature string
serverNonce string

Type: unknown

Status Description
400 Roblox.Web.Authentication.Passwords.PasswordResponseCodes.InvalidCurrentPassword
OR
Roblox.Web.Authentication.Passwords.PasswordResponseCodes.InvalidPassword
401 0: Authorization has been denied for this request.
403 Roblox.Web.Authentication.Passwords.PasswordResponseCodes.PinLocked
0: Token Validation Failed
429 Roblox.Web.Authentication.Passwords.PasswordResponseCodes.Flooded

POST /v1/username

Change the user’s username

Usage
import { fetchApi } from 'rozod';
import { postUsername } from 'rozod/endpoints/authv1';
const data = await fetchApi(postUsername, {
body: { /* ... */ }
});
Field Type Description
username string
password string

Type: unknown

Status Description
400 5: You don't have enough Robux to change your username.
10: This username is already in use
11: Username not appropriate for Roblox
12: Usernames can be 3 to 20 characters long
13: Usernames can’t start or end with _ and can have at most one _
14: Only a-z, A-Z, 0-9, and _ are allowed
15: Username is null
16: Username might contain private information
17: This username is not available
18: Username is same as current
401 0: Authorization has been denied for this request.
403 0: Token Validation Failed
1: PIN is locked.
2: A verified email is missing
3: Your password is incorrect.
100: Unknown birthday
500 0: An unknown error occured.
5: You don't have enough Robux to change your username.
503 4: The feature is currently not available. Please try again later.

GET /v1/username/change/price

Get the current price for a username change

Usage
import { fetchApi } from 'rozod';
import { getUsernameChangePrice } from 'rozod/endpoints/authv1';
const data = await fetchApi(getUsernameChangePrice, undefined);
Field Type Description
priceInRobux number
basePriceInRobux number
Status Description
401 0: Authorization has been denied for this request.

GET /v1/usernames

Gets a list of existing usernames on Roblox based on the query parameters

Usage
import { fetchApi } from 'rozod';
import { getUsernames } from 'rozod/endpoints/authv1';
const data = await fetchApi(getUsernames, {
username: /* string */
});
Name Type Required Description
username string Yes The username
Field Type Description
usernames string[]

POST /v1/usernames/recover

Sends an email of all accounts belonging to an email

Usage
import { fetchApi } from 'rozod';
import { postUsernamesRecover } from 'rozod/endpoints/authv1';
const data = await fetchApi(postUsernamesRecover, {
body: { /* ... */ }
});
Field Type Description
targetType `“Email” “PhoneNumber”
target string
Field Type Description
transmissionType `0 1`
Status Description
400 20: Invalid Email
21: Invalid Phone
23: No Account Found
403 0: Token Validation Failed
11: Too many attempts. Please wait a bit.
500 0: An unexpected error occurred.

GET /v1/usernames/validate

Checks if a username is valid.

Usage
import { fetchApi } from 'rozod';
import { getUsernamesValidate } from 'rozod/endpoints/authv1';
const data = await fetchApi(getUsernamesValidate, {
Username: /* string */,
Birthday: /* string */
});
Name Type Required Description
Username string Yes
Birthday string Yes
Field Type Description
code `“ValidUsername” “AlreadyInUseError”
message string
Status Description
400 1: A valid username is required.
2: A valid birthday or authenticated user is required.

POST /v1/usernames/validate

Checks if a username is valid.

Usage
import { fetchApi } from 'rozod';
import { postUsernamesValidate } from 'rozod/endpoints/authv1';
const data = await fetchApi(postUsernamesValidate, {
body: { /* ... */ }
});
Field Type Description
username string
birthday string
context `0 1
Field Type Description
code `“ValidUsername” “AlreadyInUseError”
message string
Status Description
400 1: A valid username is required.
2: A valid birthday or authenticated user is required.
403 0: Token Validation Failed

GET /v1/validators/email

Tries to check if an email is valid

Usage
import { fetchApi } from 'rozod';
import { getValidatorsEmail } from 'rozod/endpoints/authv1';
const data = await fetchApi(getValidatorsEmail, {
Email: /* string */
});
Name Type Required Description
Email string Yes
Field Type Description
isEmailValid boolean

getValidatorsRecommendedusernamefromdisplayname

Section titled “getValidatorsRecommendedusernamefromdisplayname”

GET /v1/validators/recommendedUsernameFromDisplayName

Validates the given display name, and if valid, will convert it to a valid username and return suggested username(s) if available.

Usage
import { fetchApi } from 'rozod';
import { getValidatorsRecommendedusernamefromdisplayname } from 'rozod/endpoints/authv1';
const data = await fetchApi(getValidatorsRecommendedusernamefromdisplayname, {
DisplayName: /* string */,
BirthDay: /* string */
});
Name Type Required Description
DisplayName string Yes
BirthDay string Yes
Field Type Description
didGenerateNewUsername boolean
suggestedUsernames string[]

postValidatorsRecommendedusernamefromdisplayname

Section titled “postValidatorsRecommendedusernamefromdisplayname”

POST /v1/validators/recommendedUsernameFromDisplayName

Validates the given display name, and if valid, will convert it to a valid username and return suggested username(s) if available.

Usage
import { fetchApi } from 'rozod';
import { postValidatorsRecommendedusernamefromdisplayname } from 'rozod/endpoints/authv1';
const data = await fetchApi(postValidatorsRecommendedusernamefromdisplayname, {
body: { /* ... */ }
});
Field Type Description
displayName string
birthday string
Field Type Description
didGenerateNewUsername boolean
suggestedUsernames string[]
Status Description
403 0: Token Validation Failed

GET /v1/validators/username

Tries to get a valid username if the current username is taken

Usage
import { fetchApi } from 'rozod';
import { getValidatorsUsername } from 'rozod/endpoints/authv1';
const data = await fetchApi(getValidatorsUsername, {
Username: /* string */,
BirthDay: /* string */
});
Name Type Required Description
Username string Yes
BirthDay string Yes
Field Type Description
didGenerateNewUsername boolean
suggestedUsernames string[]

POST /v1/validators/username

Tries to get a valid username if the current username is taken

Usage
import { fetchApi } from 'rozod';
import { postValidatorsUsername } from 'rozod/endpoints/authv1';
const data = await fetchApi(postValidatorsUsername, {
body: { /* ... */ }
});
Field Type Description
username string
birthday string
Field Type Description
didGenerateNewUsername boolean
suggestedUsernames string[]
Status Description
403 0: Token Validation Failed

GET /v1/xbox/connection

Check if the current user has an Xbox connected.

Usage
import { fetchApi } from 'rozod';
import { getXboxConnection } from 'rozod/endpoints/authv1';
const data = await fetchApi(getXboxConnection, undefined);
Field Type Description
hasConnectedXboxAccount boolean
gamertag string
Status Description
401 0: Authorization has been denied for this request.

POST /v1/xbox/disconnect

Unlink the current ROBLOX account from the Xbox live account.

Usage
import { fetchApi } from 'rozod';
import { postXboxDisconnect } from 'rozod/endpoints/authv1';
const data = await fetchApi(postXboxDisconnect, undefined);
Field Type Description
success boolean
Status Description
401 0: Authorization has been denied for this request.
403 Forbidden
0: Token Validation Failed

GET /v1/xbox/get-login-consecutive-days

Get the consecutive days the xbox user has been logged in.

Usage
import { fetchApi } from 'rozod';
import { getXboxGetLoginConsecutiveDays } from 'rozod/endpoints/authv1';
const data = await fetchApi(getXboxGetLoginConsecutiveDays, undefined);
Field Type Description
count number
Status Description
400 36: Invalid Xbox Live Account
401 0: Authorization has been denied for this request.

POST /v1/xbox/translate

Translate the xbox user to roblox user.

Usage
import { fetchApi } from 'rozod';
import { postXboxTranslate } from 'rozod/endpoints/authv1';
const data = await fetchApi(postXboxTranslate, {
body: { /* ... */ }
});
Field Type Description
ids string[]
Field Type Description
Users object[] See below

Users[] item fields:

Field Type Description
Id string
UserId number
Username string
Status Description
401 0: Authorization has been denied for this request.
403 0: Token Validation Failed