4 min read

Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.

PATCH /cloud/v2/universes/{universeId}/secrets/{secretId} — openapi

Update Secret

Updates an existing secret.

Only the owner of the universe can update secrets. For group-owned universes, only the group owner or authorized members can update secrets.

Only the secret content, key_id, and domain can be updated - the secret ID cannot be changed.

To encrypt the updated secret:

  1. Get the current public key using the GetPublicKey endpoint
  2. Encrypt your new secret content using LibSodium sealed box
  3. Base64 encode the encrypted content

Include the key_id from the public key response in the request.

For an example, see the Secrets store guide.

Endpoint

Method: PATCH

Path: /cloud/v2/universes/{universeId}/secrets/{secretId}

Servers:

Parameters

NameLocationRequiredDescription
universeIdpathtrueThe universe ID
secretIdpathtrueThe ID of the secret to update
[
  {
    "name": "universeId",
    "in": "path",
    "description": "The universe ID",
    "required": true,
    "schema": {
      "type": "integer",
      "format": "int64"
    }
  },
  {
    "name": "secretId",
    "in": "path",
    "description": "The ID of the secret to update",
    "required": true,
    "schema": {
      "type": "string"
    }
  }
]

Request Body

The updated secret data with encrypted content

{
  "description": "The updated secret data with encrypted content",
  "content": {
    "application/json": {
      "schema": {
        "$ref": "#/components/schemas/Secret"
      }
    }
  }
}

Responses

StatusDescription
200OK
400Bad Request
403Forbidden
404Not Found
{
  "200": {
    "description": "OK",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/Secret"
        }
      }
    }
  },
  "400": {
    "description": "Bad Request",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
        }
      }
    }
  },
  "403": {
    "description": "Forbidden",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
        }
      }
    }
  },
  "404": {
    "description": "Not Found",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
        }
      }
    }
  }
}

Authentication

{
  "security": [
    {
      "roblox-api-key": []
    },
    {
      "roblox-oauth2": []
    }
  ],
  "securitySchemes": {
    "roblox-api-key": {
      "type": "apiKey",
      "description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
      "name": "x-api-key",
      "in": "header"
    },
    "roblox-legacy-cookie": {
      "type": "apiKey",
      "description": "A browser cookie that represents the identity of a Roblox user. DO NOT SHARE THIS. Sharing this will allow someone to log in as you and to steal your Robux and items. We do not recommend using cookies to call endpoints. When possible, use API keys with the x-api-key header or OAuth 2.0 instead for authentication.",
      "in": "cookie",
      "name": ".ROBLOSECURITY"
    },
    "roblox-oauth2": {
      "type": "oauth2",
      "description": "Build or authorize apps to access Roblox resources. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
      "flows": {
        "authorizationCode": {
          "authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
          "tokenUrl": "https://apis.roblox.com/oauth/v1/token",
          "refreshUrl": "https://apis.roblox.com/oauth/v1/token",
          "scopes": {}
        }
      }
    }
  }
}

Complete Operation Definition

{
  "tags": [
    "Universes"
  ],
  "summary": "Update Secret",
  "description": "Updates an existing secret.\n\nOnly the owner of the universe can update secrets. For group-owned universes, only the group owner or authorized\nmembers can update secrets.\n\nOnly the secret content, key_id, and domain can be updated - the secret ID cannot be changed.\n\nTo encrypt the updated secret:\n1. Get the current public key using the GetPublicKey endpoint\n2. Encrypt your new secret content using LibSodium sealed box\n3. Base64 encode the encrypted content\n\nInclude the key_id from the public key response in the request.\n\nFor an example, see the [Secrets store guide](https://create.roblox.com/docs/cloud/guides/secrets-store).",
  "parameters": [
    {
      "name": "universeId",
      "in": "path",
      "description": "The universe ID",
      "required": true,
      "schema": {
        "type": "integer",
        "format": "int64"
      }
    },
    {
      "name": "secretId",
      "in": "path",
      "description": "The ID of the secret to update",
      "required": true,
      "schema": {
        "type": "string"
      }
    }
  ],
  "requestBody": {
    "description": "The updated secret data with encrypted content",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/Secret"
        }
      }
    }
  },
  "responses": {
    "200": {
      "description": "OK",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/Secret"
          }
        }
      }
    },
    "400": {
      "description": "Bad Request",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
          }
        }
      }
    },
    "403": {
      "description": "Forbidden",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
          }
        }
      }
    },
    "404": {
      "description": "Not Found",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
          }
        }
      }
    }
  },
  "x-roblox-scopes": [
    {
      "name": "universe.secret:write",
      "description": "Required"
    }
  ],
  "x-roblox-stability": "BETA",
  "x-roblox-rate-limits": {
    "perApiKeyOwner": {
      "period": "MINUTE",
      "maxInPeriod": 120
    },
    "perOauth2Authorization": {
      "period": "MINUTE",
      "maxInPeriod": 120
    }
  },
  "x-roblox-engine-usability": {
    "apiKeyWithHttpService": false
  },
  "security": [
    {
      "roblox-api-key": []
    },
    {
      "roblox-oauth2": []
    }
  ],
  "externalDocs": {
    "url": "https://create.roblox.com/docs/cloud/reference/features/universes#patch_cloud_v2_universes__universeId__secrets__secretId_"
  }
}