4 min read

Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.

POST /cloud/v2/universes/{universeId}/secrets — openapi

Create Secret

Creates a new secret. A maximum of 500 secrets per universe is allowed.

Only the owner of the universe can create secrets. For group-owned universes, only the group owner or authorized members can create secrets.

To encrypt the secret:

  1. Get the public key using the Get Public Key endpoint
  2. Encrypt your secret using LibSodium sealed box
  3. Base64 encode the encrypted content

Include the key_id from the public key response in the request.

For an example, see the Secrets store guide.

Endpoint

Method: POST

Path: /cloud/v2/universes/{universeId}/secrets

Servers:

Parameters

NameLocationRequiredDescription
universeIdpathtrueThe universe ID
[
  {
    "name": "universeId",
    "in": "path",
    "description": "The universe ID",
    "required": true,
    "schema": {
      "type": "integer",
      "format": "int64"
    }
  }
]

Request Body

The secret to create with encrypted content

{
  "description": "The secret to create with encrypted content",
  "content": {
    "application/json": {
      "schema": {
        "$ref": "#/components/schemas/Secret"
      }
    }
  }
}

Responses

StatusDescription
201Created
400Bad Request
403Forbidden
409Conflict
{
  "201": {
    "description": "Created",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/Secret"
        }
      }
    }
  },
  "400": {
    "description": "Bad Request",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
        }
      }
    }
  },
  "403": {
    "description": "Forbidden",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
        }
      }
    }
  },
  "409": {
    "description": "Conflict",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
        }
      }
    }
  }
}

Authentication

{
  "security": [
    {
      "roblox-api-key": []
    },
    {
      "roblox-oauth2": []
    }
  ],
  "securitySchemes": {
    "roblox-api-key": {
      "type": "apiKey",
      "description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
      "name": "x-api-key",
      "in": "header"
    },
    "roblox-legacy-cookie": {
      "type": "apiKey",
      "description": "A browser cookie that represents the identity of a Roblox user. DO NOT SHARE THIS. Sharing this will allow someone to log in as you and to steal your Robux and items. We do not recommend using cookies to call endpoints. When possible, use API keys with the x-api-key header or OAuth 2.0 instead for authentication.",
      "in": "cookie",
      "name": ".ROBLOSECURITY"
    },
    "roblox-oauth2": {
      "type": "oauth2",
      "description": "Build or authorize apps to access Roblox resources. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
      "flows": {
        "authorizationCode": {
          "authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
          "tokenUrl": "https://apis.roblox.com/oauth/v1/token",
          "refreshUrl": "https://apis.roblox.com/oauth/v1/token",
          "scopes": {}
        }
      }
    }
  }
}

Complete Operation Definition

{
  "tags": [
    "Universes"
  ],
  "summary": "Create Secret",
  "description": "Creates a new secret. A maximum of 500 secrets per universe is allowed.\n            \nOnly the owner of the universe can create secrets. For group-owned universes, only the group owner or authorized\nmembers can create secrets.\n            \nTo encrypt the secret:\n1. Get the public key using the Get Public Key endpoint\n2. Encrypt your secret using LibSodium sealed box\n3. Base64 encode the encrypted content\n\nInclude the key_id from the public key response in the request.\n\nFor an example, see the [Secrets store guide](https://create.roblox.com/docs/cloud/guides/secrets-store).",
  "parameters": [
    {
      "name": "universeId",
      "in": "path",
      "description": "The universe ID",
      "required": true,
      "schema": {
        "type": "integer",
        "format": "int64"
      }
    }
  ],
  "requestBody": {
    "description": "The secret to create with encrypted content",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/Secret"
        }
      }
    }
  },
  "responses": {
    "201": {
      "description": "Created",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/Secret"
          }
        }
      }
    },
    "400": {
      "description": "Bad Request",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
          }
        }
      }
    },
    "403": {
      "description": "Forbidden",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
          }
        }
      }
    },
    "409": {
      "description": "Conflict",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/SecretsStoreService.ProblemDetails"
          }
        }
      }
    }
  },
  "x-roblox-scopes": [
    {
      "name": "universe.secret:write",
      "description": "Required"
    }
  ],
  "x-roblox-stability": "BETA",
  "x-roblox-rate-limits": {
    "perApiKeyOwner": {
      "period": "MINUTE",
      "maxInPeriod": 120
    },
    "perOauth2Authorization": {
      "period": "MINUTE",
      "maxInPeriod": 120
    }
  },
  "x-roblox-engine-usability": {
    "apiKeyWithHttpService": false
  },
  "security": [
    {
      "roblox-api-key": []
    },
    {
      "roblox-oauth2": []
    }
  ],
  "externalDocs": {
    "url": "https://create.roblox.com/docs/cloud/reference/features/universes#post_cloud_v2_universes__universeId__secrets"
  }
}