2 min read

Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.

POST /v1/external/{identityProviderId}/sso/oauth/callback — openapi

OAuth callback for identity providers that POST the authorization code as form fields (Apple form_post). Apple's first-auth user JSON is parsed and carried to identity storage; the form id_token is ignored. Web login exchanges code via PKCE and does not treat a form id_token as proof.

Endpoint

Method: POST

Path: /v1/external/{identityProviderId}/sso/oauth/callback

Servers:

Parameters

NameLocationRequiredDescription
identityProviderIdpathtrue
[
  {
    "in": "path",
    "name": "identityProviderId",
    "required": true,
    "schema": {
      "type": "integer",
      "format": "int64"
    }
  }
]

Responses

StatusDescription
302Found
{
  "302": {
    "description": "Found"
  }
}

Authentication

{
  "security": [
    {}
  ],
  "securitySchemes": {
    "roblox-api-key": {
      "type": "apiKey",
      "description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
      "name": "x-api-key",
      "in": "header"
    },
    "roblox-legacy-cookie": {
      "type": "apiKey",
      "description": "A browser cookie that represents the identity of a Roblox user. DO NOT SHARE THIS. Sharing this will allow someone to log in as you and to steal your Robux and items. We do not recommend using cookies to call endpoints. When possible, use API keys with the x-api-key header or OAuth 2.0 instead for authentication.",
      "in": "cookie",
      "name": ".ROBLOSECURITY"
    },
    "roblox-oauth2": {
      "type": "oauth2",
      "description": "Build or authorize apps to access Roblox resources. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
      "flows": {
        "authorizationCode": {
          "authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
          "tokenUrl": "https://apis.roblox.com/oauth/v1/token",
          "refreshUrl": "https://apis.roblox.com/oauth/v1/token",
          "scopes": {}
        }
      }
    }
  }
}

Complete Operation Definition

{
  "tags": [
    "Accounts"
  ],
  "summary": "OAuth callback for identity providers that POST the authorization code as form fields (Apple form_post).\nApple's first-auth `user` JSON is parsed and carried to identity storage; the form\n`id_token` is ignored. Web login exchanges code via PKCE and does\nnot treat a form id_token as proof.",
  "parameters": [
    {
      "in": "path",
      "name": "identityProviderId",
      "required": true,
      "schema": {
        "type": "integer",
        "format": "int64"
      }
    }
  ],
  "responses": {
    "302": {
      "description": "Found"
    }
  },
  "servers": [
    {
      "url": "https://auth.roblox.com"
    }
  ],
  "x-roblox-engine-usability": {
    "apiKeyWithHttpService": false
  },
  "security": [
    {}
  ],
  "externalDocs": {
    "url": "https://create.roblox.com/docs/cloud/reference/features/accounts#auth_post_v1_external__identityProviderId__sso_oauth_callback"
  }
}