Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.
POST /cloud/v2/universes/{universeId}/secrets — openapi
Create Secret
Creates a new secret. A maximum of 500 secrets per universe is allowed.
Only the owner of the universe can create secrets. For group-owned universes, only the group owner or authorized members can create secrets.
To encrypt the secret:
- Get the public key using the Get Public Key endpoint
- Encrypt your secret using LibSodium sealed box
- Base64 encode the encrypted content
Include the key_id from the public key response in the request.
For an example, see the Secrets store guide.
Endpoint
Method: POST
Path: /cloud/v2/universes/{universeId}/secrets
Servers:
https://apis.roblox.com
Parameters
| Name | Location | Required | Description |
|---|---|---|---|
| universeId | path | true | The universe ID |
[
{
"name": "universeId",
"in": "path",
"description": "The universe ID",
"required": true,
"schema": {
"type": "integer",
"format": "int64"
}
}
] Request Body
The secret to create with encrypted content
{
"description": "The secret to create with encrypted content",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Secret"
}
}
}
} Responses
| Status | Description |
|---|---|
| 201 | Created |
| 400 | Bad Request |
| 403 | Forbidden |
| 409 | Conflict |
{
"201": {
"description": "Created",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Secret"
}
}
}
},
"400": {
"description": "Bad Request",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
}
}
}
},
"403": {
"description": "Forbidden",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
}
}
}
},
"409": {
"description": "Conflict",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
}
}
}
}
} Authentication
{
"security": [
{
"roblox-api-key": []
},
{
"roblox-oauth2": []
}
],
"securitySchemes": {
"roblox-api-key": {
"type": "apiKey",
"description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
"name": "x-api-key",
"in": "header"
},
"roblox-legacy-cookie": {
"type": "apiKey",
"description": "A browser cookie that represents the identity of a Roblox user. DO NOT SHARE THIS. Sharing this will allow someone to log in as you and to steal your Robux and items. We do not recommend using cookies to call endpoints. When possible, use API keys with the x-api-key header or OAuth 2.0 instead for authentication.",
"in": "cookie",
"name": ".ROBLOSECURITY"
},
"roblox-oauth2": {
"type": "oauth2",
"description": "Build or authorize apps to access Roblox resources. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
"tokenUrl": "https://apis.roblox.com/oauth/v1/token",
"refreshUrl": "https://apis.roblox.com/oauth/v1/token",
"scopes": {}
}
}
}
}
} Related Schemas
Complete Operation Definition
{
"tags": [
"Universes"
],
"summary": "Create Secret",
"description": "Creates a new secret. A maximum of 500 secrets per universe is allowed.\n \nOnly the owner of the universe can create secrets. For group-owned universes, only the group owner or authorized\nmembers can create secrets.\n \nTo encrypt the secret:\n1. Get the public key using the Get Public Key endpoint\n2. Encrypt your secret using LibSodium sealed box\n3. Base64 encode the encrypted content\n\nInclude the key_id from the public key response in the request.\n\nFor an example, see the [Secrets store guide](https://create.roblox.com/docs/cloud/guides/secrets-store).",
"parameters": [
{
"name": "universeId",
"in": "path",
"description": "The universe ID",
"required": true,
"schema": {
"type": "integer",
"format": "int64"
}
}
],
"requestBody": {
"description": "The secret to create with encrypted content",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Secret"
}
}
}
},
"responses": {
"201": {
"description": "Created",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Secret"
}
}
}
},
"400": {
"description": "Bad Request",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
}
}
}
},
"403": {
"description": "Forbidden",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
}
}
}
},
"409": {
"description": "Conflict",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
}
}
}
}
},
"x-roblox-scopes": [
{
"name": "universe.secret:write",
"description": "Required"
}
],
"x-roblox-stability": "BETA",
"x-roblox-rate-limits": {
"perApiKeyOwner": {
"period": "MINUTE",
"maxInPeriod": 120
},
"perOauth2Authorization": {
"period": "MINUTE",
"maxInPeriod": 120
}
},
"x-roblox-engine-usability": {
"apiKeyWithHttpService": false
},
"security": [
{
"roblox-api-key": []
},
{
"roblox-oauth2": []
}
],
"externalDocs": {
"url": "https://create.roblox.com/docs/cloud/reference/features/universes#post_cloud_v2_universes__universeId__secrets"
}
}