3 min read

Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.

POST /v1/external/{identityProviderId}/sso/native/nonce — openapi

Reserves a nonce for a native SSO sign-in attempt.

The web flow gets its nonce from M:Roblox.Authentication.Api.Controllers.V1.ExternalIdentitiesGatewayController.OAuthInit(System.Int64,System.String,System.Threading.CancellationToken), which native clients never call because they have no authorization redirect. They call this instead, pass the nonce to the provider SDK, and post the resulting id_token to /access.

The client must pass this value to the SDK verbatim. Both providers treat the nonce as an opaque string and echo it into the id_token unchanged, and redemption looks the value up as issued. The SHA256(nonce) convention seen in Apple examples belongs to Firebase, which hashes on its own side before comparing; hashing here would make the lookup miss.

Endpoint

Method: POST

Path: /v1/external/{identityProviderId}/sso/native/nonce

Servers:

Parameters

NameLocationRequiredDescription
identityProviderIdpathtrue
[
  {
    "in": "path",
    "name": "identityProviderId",
    "required": true,
    "schema": {
      "type": "integer",
      "format": "int64"
    }
  }
]

Responses

StatusDescription
200OK
{
  "200": {
    "description": "OK",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/Roblox.Authentication.Api.Models.Response.ExternalIdentityGateway.ExternalIdentityNonceResponse"
        }
      }
    }
  }
}

Authentication

{
  "security": [
    {}
  ],
  "securitySchemes": {
    "roblox-api-key": {
      "type": "apiKey",
      "description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
      "name": "x-api-key",
      "in": "header"
    },
    "roblox-legacy-cookie": {
      "type": "apiKey",
      "description": "A browser cookie that represents the identity of a Roblox user. DO NOT SHARE THIS. Sharing this will allow someone to log in as you and to steal your Robux and items. We do not recommend using cookies to call endpoints. When possible, use API keys with the x-api-key header or OAuth 2.0 instead for authentication.",
      "in": "cookie",
      "name": ".ROBLOSECURITY"
    },
    "roblox-oauth2": {
      "type": "oauth2",
      "description": "Build or authorize apps to access Roblox resources. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
      "flows": {
        "authorizationCode": {
          "authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
          "tokenUrl": "https://apis.roblox.com/oauth/v1/token",
          "refreshUrl": "https://apis.roblox.com/oauth/v1/token",
          "scopes": {}
        }
      }
    }
  }
}

Complete Operation Definition

{
  "tags": [
    "Accounts"
  ],
  "summary": "Reserves a nonce for a native SSO sign-in attempt.",
  "description": "The web flow gets its nonce from M:Roblox.Authentication.Api.Controllers.V1.ExternalIdentitiesGatewayController.OAuthInit(System.Int64,System.String,System.Threading.CancellationToken), which native clients never call\nbecause they have no authorization redirect. They call this instead, pass the nonce to the\nprovider SDK, and post the resulting id_token to /access.\n            \nThe client must pass this value to the SDK verbatim. Both providers treat the nonce as an\nopaque string and echo it into the id_token unchanged, and redemption looks the value up as\nissued. The SHA256(nonce) convention seen in Apple examples belongs to Firebase, which hashes\non its own side before comparing; hashing here would make the lookup miss.",
  "parameters": [
    {
      "in": "path",
      "name": "identityProviderId",
      "required": true,
      "schema": {
        "type": "integer",
        "format": "int64"
      }
    }
  ],
  "responses": {
    "200": {
      "description": "OK",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/Roblox.Authentication.Api.Models.Response.ExternalIdentityGateway.ExternalIdentityNonceResponse"
          }
        }
      }
    }
  },
  "servers": [
    {
      "url": "https://auth.roblox.com"
    }
  ],
  "x-roblox-engine-usability": {
    "apiKeyWithHttpService": false
  },
  "security": [
    {}
  ],
  "externalDocs": {
    "url": "https://create.roblox.com/docs/cloud/reference/features/accounts#auth_post_v1_external__identityProviderId__sso_native_nonce"
  }
}