3 min read

Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.

GET /cloud/v2/universes/{universeId}/secrets — openapi

List Secrets

Lists all secrets defined for a universe. Secret content is not returned for security reasons - only metadata such as ID, domain, creation and update timestamps are included.

Only the owner of the universe can list secrets. For group-owned universes, only the group owner or authorized members can list secrets.

Endpoint

Method: GET

Path: /cloud/v2/universes/{universeId}/secrets

Servers:

Parameters

NameLocationRequiredDescription
universeIdpathtrueThe universe ID
limitqueryfalseNumber of secrets to return per page (1-500, default 10)
cursorqueryfalsePagination cursor from previous response
[
  {
    "name": "universeId",
    "in": "path",
    "description": "The universe ID",
    "required": true,
    "schema": {
      "type": "integer",
      "format": "int64"
    }
  },
  {
    "name": "limit",
    "in": "query",
    "description": "Number of secrets to return per page (1-500, default 10)",
    "schema": {
      "type": "integer",
      "format": "int32",
      "default": 10
    }
  },
  {
    "name": "cursor",
    "in": "query",
    "description": "Pagination cursor from previous response",
    "schema": {
      "type": "string"
    }
  }
]

Responses

StatusDescription
200OK
400Bad Request
403Forbidden
{
  "200": {
    "description": "OK",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/SecretPaginatedList"
        }
      }
    }
  },
  "400": {
    "description": "Bad Request",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
        }
      }
    }
  },
  "403": {
    "description": "Forbidden",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
        }
      }
    }
  }
}

Authentication

{
  "security": [
    {
      "roblox-api-key": []
    },
    {
      "roblox-oauth2": []
    }
  ],
  "securitySchemes": {
    "roblox-api-key": {
      "type": "apiKey",
      "description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
      "name": "x-api-key",
      "in": "header"
    },
    "roblox-legacy-cookie": {
      "type": "apiKey",
      "description": "A browser cookie that represents the identity of a Roblox user. DO NOT SHARE THIS. Sharing this will allow someone to log in as you and to steal your Robux and items. We do not recommend using cookies to call endpoints. When possible, use API keys with the x-api-key header or OAuth 2.0 instead for authentication.",
      "in": "cookie",
      "name": ".ROBLOSECURITY"
    },
    "roblox-oauth2": {
      "type": "oauth2",
      "description": "Build or authorize apps to access Roblox resources. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
      "flows": {
        "authorizationCode": {
          "authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
          "tokenUrl": "https://apis.roblox.com/oauth/v1/token",
          "refreshUrl": "https://apis.roblox.com/oauth/v1/token",
          "scopes": {}
        }
      }
    }
  }
}

Complete Operation Definition

{
  "tags": [
    "Universes"
  ],
  "summary": "List Secrets",
  "description": "Lists all secrets defined for a universe.\nSecret content is not returned for security reasons - only metadata such as ID, domain, creation and update timestamps are included.\n\nOnly the owner of the universe can list secrets. For group-owned universes, only the group owner or authorized\nmembers can list secrets.",
  "parameters": [
    {
      "name": "universeId",
      "in": "path",
      "description": "The universe ID",
      "required": true,
      "schema": {
        "type": "integer",
        "format": "int64"
      }
    },
    {
      "name": "limit",
      "in": "query",
      "description": "Number of secrets to return per page (1-500, default 10)",
      "schema": {
        "type": "integer",
        "format": "int32",
        "default": 10
      }
    },
    {
      "name": "cursor",
      "in": "query",
      "description": "Pagination cursor from previous response",
      "schema": {
        "type": "string"
      }
    }
  ],
  "responses": {
    "200": {
      "description": "OK",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/SecretPaginatedList"
          }
        }
      }
    },
    "400": {
      "description": "Bad Request",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
          }
        }
      }
    },
    "403": {
      "description": "Forbidden",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
          }
        }
      }
    }
  },
  "x-roblox-scopes": [
    {
      "name": "universe.secret:read",
      "description": "Required"
    }
  ],
  "x-roblox-stability": "BETA",
  "x-roblox-rate-limits": {
    "perApiKeyOwner": {
      "period": "MINUTE",
      "maxInPeriod": 120
    },
    "perOauth2Authorization": {
      "period": "MINUTE",
      "maxInPeriod": 120
    }
  },
  "x-roblox-engine-usability": {
    "apiKeyWithHttpService": false
  },
  "security": [
    {
      "roblox-api-key": []
    },
    {
      "roblox-oauth2": []
    }
  ],
  "externalDocs": {
    "url": "https://create.roblox.com/docs/cloud/reference/features/universes#get_cloud_v2_universes__universeId__secrets"
  }
}