3 min read

Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.

GET /v1/external/{identityProviderId}/sso/oauth/init — openapi

Signs a user up for Roblox and links the account to the authenticated external provider ID via OAuth.

Stored with the PKCE secrets rather than accepted at the callback, where it would let anyone turn a plain web login into a redirect carrying a live session.

Endpoint

Method: GET

Path: /v1/external/{identityProviderId}/sso/oauth/init

Servers:

Parameters

NameLocationRequiredDescription
identityProviderIdpathtrueThe identity provider to authenticate against.
postAuthenticationIntentIdquerytrueWhich post-authentication intent to carry out at the end of the handshake. Optional, and omitting it selects the provider's web redirect.
[
  {
    "in": "path",
    "name": "identityProviderId",
    "description": "The identity provider to authenticate against.",
    "required": true,
    "schema": {
      "type": "integer",
      "format": "int64"
    }
  },
  {
    "in": "query",
    "name": "postAuthenticationIntentId",
    "description": "Which post-authentication intent to carry out at the end of the handshake. Optional, and omitting it\nselects the provider's web redirect.",
    "required": true,
    "schema": {
      "type": "string"
    }
  }
]

Responses

StatusDescription
302Found
{
  "302": {
    "description": "Found"
  }
}

Authentication

{
  "security": [
    {}
  ],
  "securitySchemes": {
    "roblox-api-key": {
      "type": "apiKey",
      "description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
      "name": "x-api-key",
      "in": "header"
    },
    "roblox-legacy-cookie": {
      "type": "apiKey",
      "description": "A browser cookie that represents the identity of a Roblox user. DO NOT SHARE THIS. Sharing this will allow someone to log in as you and to steal your Robux and items. We do not recommend using cookies to call endpoints. When possible, use API keys with the x-api-key header or OAuth 2.0 instead for authentication.",
      "in": "cookie",
      "name": ".ROBLOSECURITY"
    },
    "roblox-oauth2": {
      "type": "oauth2",
      "description": "Build or authorize apps to access Roblox resources. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
      "flows": {
        "authorizationCode": {
          "authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
          "tokenUrl": "https://apis.roblox.com/oauth/v1/token",
          "refreshUrl": "https://apis.roblox.com/oauth/v1/token",
          "scopes": {}
        }
      }
    }
  }
}

Complete Operation Definition

{
  "tags": [
    "Accounts"
  ],
  "summary": "Signs a user up for Roblox and links the account to the authenticated external provider ID via OAuth.",
  "description": "Stored with the PKCE secrets rather than accepted at the callback, where it would let anyone turn a\nplain web login into a redirect carrying a live session.",
  "parameters": [
    {
      "in": "path",
      "name": "identityProviderId",
      "description": "The identity provider to authenticate against.",
      "required": true,
      "schema": {
        "type": "integer",
        "format": "int64"
      }
    },
    {
      "in": "query",
      "name": "postAuthenticationIntentId",
      "description": "Which post-authentication intent to carry out at the end of the handshake. Optional, and omitting it\nselects the provider's web redirect.",
      "required": true,
      "schema": {
        "type": "string"
      }
    }
  ],
  "responses": {
    "302": {
      "description": "Found"
    }
  },
  "servers": [
    {
      "url": "https://auth.roblox.com"
    }
  ],
  "x-roblox-engine-usability": {
    "apiKeyWithHttpService": false
  },
  "security": [
    {}
  ],
  "externalDocs": {
    "url": "https://create.roblox.com/docs/cloud/reference/features/accounts#auth_get_v1_external__identityProviderId__sso_oauth_init"
  }
}