5 min read

Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.

PATCH /cloud/v2/universes/{universe_id}/places/{place_id}/user-restrictions/{user_restriction_id} — openapi

Update User Restriction

Update the user restriction.

Endpoint

Method: PATCH

Path: /cloud/v2/universes/{universe_id}/places/{place_id}/user-restrictions/{user_restriction_id}

Servers:

Parameters

NameLocationRequiredDescription
universe_idpathtrueThe universe ID.
place_idpathtrueThe place ID.
user_restriction_idpathtrueThe user-restriction ID.
updateMaskqueryfalseThe list of fields to update. The game_join_restriction field must be updated atomically; field masks that index into game_join_restriction (such as "game_join_restriction.active") are not supported.
idempotencyKey.keyqueryfalseThe unique key to use for idempotency.
idempotencyKey.firstSentqueryfalseThe timestamp at which the first request was sent. If this is further in the past than the lifetime of the idempotency key (which may exceed the annotated minimum lifetime), the server must return an error.
[
  {
    "name": "universe_id",
    "in": "path",
    "description": "The universe ID.",
    "required": true,
    "schema": {
      "type": "string"
    }
  },
  {
    "name": "place_id",
    "in": "path",
    "description": "The place ID.",
    "required": true,
    "schema": {
      "type": "string"
    }
  },
  {
    "name": "user_restriction_id",
    "in": "path",
    "description": "The user-restriction ID.",
    "required": true,
    "schema": {
      "type": "string"
    }
  },
  {
    "name": "updateMask",
    "in": "query",
    "description": "The list of fields to update.\n\nThe `game_join_restriction` field must be updated atomically; field masks\nthat index into `game_join_restriction` (such as\n`\"game_join_restriction.active\"`) are not supported.",
    "schema": {
      "type": "string",
      "format": "field-mask"
    }
  },
  {
    "name": "idempotencyKey.key",
    "in": "query",
    "description": "The unique key to use for idempotency.",
    "schema": {
      "type": "string"
    }
  },
  {
    "name": "idempotencyKey.firstSent",
    "in": "query",
    "description": "The timestamp at which the first request was sent.\n\nIf this is further in the past than the lifetime of the idempotency key\n(which *may* exceed the annotated minimum lifetime), the server *must*\nreturn an error.",
    "schema": {
      "example": "2023-07-05T12:34:56Z",
      "type": "string",
      "format": "date-time"
    }
  }
]

Request Body

{
  "content": {
    "application/json": {
      "schema": {
        "$ref": "#/components/schemas/UserRestriction"
      }
    }
  },
  "required": true
}

Responses

StatusDescription
200OK
{
  "200": {
    "description": "OK",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/UserRestriction"
        }
      }
    }
  }
}

Authentication

{
  "security": [
    {
      "roblox-api-key": []
    },
    {
      "roblox-oauth2": []
    }
  ],
  "securitySchemes": {
    "roblox-api-key": {
      "type": "apiKey",
      "description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
      "name": "x-api-key",
      "in": "header"
    },
    "roblox-legacy-cookie": {
      "type": "apiKey",
      "description": "A browser cookie that represents the identity of a Roblox user. DO NOT SHARE THIS. Sharing this will allow someone to log in as you and to steal your Robux and items. We do not recommend using cookies to call endpoints. When possible, use API keys with the x-api-key header or OAuth 2.0 instead for authentication.",
      "in": "cookie",
      "name": ".ROBLOSECURITY"
    },
    "roblox-oauth2": {
      "type": "oauth2",
      "description": "Build or authorize apps to access Roblox resources. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
      "flows": {
        "authorizationCode": {
          "authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
          "tokenUrl": "https://apis.roblox.com/oauth/v1/token",
          "refreshUrl": "https://apis.roblox.com/oauth/v1/token",
          "scopes": {}
        }
      }
    }
  }
}

Complete Operation Definition

{
  "tags": [
    "Bans and blocks",
    "Places",
    "Universes",
    "Users"
  ],
  "summary": "Update User Restriction",
  "description": "Update the user restriction.",
  "operationId": "Cloud_UpdateUserRestriction__Using_Universes_Places",
  "parameters": [
    {
      "name": "universe_id",
      "in": "path",
      "description": "The universe ID.",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "place_id",
      "in": "path",
      "description": "The place ID.",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "user_restriction_id",
      "in": "path",
      "description": "The user-restriction ID.",
      "required": true,
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "updateMask",
      "in": "query",
      "description": "The list of fields to update.\n\nThe `game_join_restriction` field must be updated atomically; field masks\nthat index into `game_join_restriction` (such as\n`\"game_join_restriction.active\"`) are not supported.",
      "schema": {
        "type": "string",
        "format": "field-mask"
      }
    },
    {
      "name": "idempotencyKey.key",
      "in": "query",
      "description": "The unique key to use for idempotency.",
      "schema": {
        "type": "string"
      }
    },
    {
      "name": "idempotencyKey.firstSent",
      "in": "query",
      "description": "The timestamp at which the first request was sent.\n\nIf this is further in the past than the lifetime of the idempotency key\n(which *may* exceed the annotated minimum lifetime), the server *must*\nreturn an error.",
      "schema": {
        "example": "2023-07-05T12:34:56Z",
        "type": "string",
        "format": "date-time"
      }
    }
  ],
  "requestBody": {
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/UserRestriction"
        }
      }
    },
    "required": true
  },
  "responses": {
    "200": {
      "description": "OK",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/UserRestriction"
          }
        }
      }
    }
  },
  "x-roblox-engine-usability": {
    "apiKeyWithHttpService": true
  },
  "x-roblox-rate-limits": {
    "description": "User Restrictions are subject to the additional rate limits, applied per universe\n\n* Get User Restriction: 50 req/s\n* List User Restrictions: 50 req/s\n* Update User Restrictions: 10 req/s\n* List User Restriction Logs: 50 req/s\n\nAdditionally, we impose the following rate limit for the same user within a universe:\n\n* Update User Restriction: 2 req/min\n\nFor example, Update User Restriction may not be called for user 123 more than twice every minute.",
    "perApiKeyOwner": {
      "period": "SECOND",
      "maxInPeriod": 150
    },
    "perOauth2Authorization": {
      "period": "SECOND",
      "maxInPeriod": 30
    }
  },
  "x-roblox-scopes": [
    {
      "name": "universe.user-restriction:write"
    }
  ],
  "x-roblox-docs": {
    "category": "Users and groups",
    "methodProperties": {
      "scopes": [
        "universe.user-restriction:write"
      ]
    },
    "resource": {
      "$ref": "#/components/schemas/UserRestriction",
      "name": "UserRestriction"
    }
  },
  "x-roblox-stability": "BETA",
  "security": [
    {
      "roblox-api-key": []
    },
    {
      "roblox-oauth2": []
    }
  ],
  "externalDocs": {
    "url": "https://create.roblox.com/docs/cloud/reference/features/bans-and-blocks#Cloud_UpdateUserRestriction__Using_Universes_Places"
  }
}