Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.
POST /v1/user/passwords/change — openapi
Changes the password for the authenticated user.
The current password is needed for verification that the password can be changed.
Endpoint
Method: POST
Path: /v1/user/passwords/change
Servers:
https://auth.roblox.com
Request Body
The request model including the current password, and the new password.
{
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.Authentication.Api.Models.PasswordChangeModel"
}
},
"text/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.Authentication.Api.Models.PasswordChangeModel"
}
}
},
"description": "The request model including the current password, and the new password.",
"required": true
} Responses
| Status | Description |
|---|---|
| 200 | OK |
| 400 | Roblox.Web.Authentication.Passwords.PasswordResponseCodes.InvalidCurrentPassword OR Roblox.Web.Authentication.Passwords.PasswordResponseCodes.InvalidPassword |
| 401 | 0: Authorization has been denied for this request. |
| 403 | Roblox.Web.Authentication.Passwords.PasswordResponseCodes.PinLocked 0: Token Validation Failed |
| 429 | Roblox.Web.Authentication.Passwords.PasswordResponseCodes.Flooded |
{
"200": {
"description": "OK",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.Web.WebAPI.ApiEmptyResponseModel"
}
},
"text/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.Web.WebAPI.ApiEmptyResponseModel"
}
}
}
},
"400": {
"description": "Roblox.Web.Authentication.Passwords.PasswordResponseCodes.InvalidCurrentPassword\n OR\n Roblox.Web.Authentication.Passwords.PasswordResponseCodes.InvalidPassword"
},
"401": {
"description": "0: Authorization has been denied for this request."
},
"403": {
"description": "Roblox.Web.Authentication.Passwords.PasswordResponseCodes.PinLocked\r\n0: Token Validation Failed"
},
"429": {
"description": "Roblox.Web.Authentication.Passwords.PasswordResponseCodes.Flooded"
}
} Authentication
{
"security": [
{},
{
"roblox-legacy-cookie": []
}
],
"securitySchemes": {
"roblox-api-key": {
"type": "apiKey",
"description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
"name": "x-api-key",
"in": "header"
},
"roblox-legacy-cookie": {
"type": "apiKey",
"description": "A browser cookie that represents the identity of a Roblox user. DO NOT SHARE THIS. Sharing this will allow someone to log in as you and to steal your Robux and items. We do not recommend using cookies to call endpoints. When possible, use API keys with the x-api-key header or OAuth 2.0 instead for authentication.",
"in": "cookie",
"name": ".ROBLOSECURITY"
},
"roblox-oauth2": {
"type": "oauth2",
"description": "Build or authorize apps to access Roblox resources. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
"tokenUrl": "https://apis.roblox.com/oauth/v1/token",
"refreshUrl": "https://apis.roblox.com/oauth/v1/token",
"scopes": {}
}
}
}
}
} Related Schemas
Complete Operation Definition
{
"tags": [
"Accounts"
],
"summary": "Changes the password for the authenticated user.",
"description": "The current password is needed for verification that the password can be changed.",
"requestBody": {
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.Authentication.Api.Models.PasswordChangeModel"
}
},
"text/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.Authentication.Api.Models.PasswordChangeModel"
}
}
},
"description": "The request model including the current password, and the new password.",
"required": true
},
"responses": {
"200": {
"description": "OK",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.Web.WebAPI.ApiEmptyResponseModel"
}
},
"text/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.Web.WebAPI.ApiEmptyResponseModel"
}
}
}
},
"400": {
"description": "Roblox.Web.Authentication.Passwords.PasswordResponseCodes.InvalidCurrentPassword\n OR\n Roblox.Web.Authentication.Passwords.PasswordResponseCodes.InvalidPassword"
},
"401": {
"description": "0: Authorization has been denied for this request."
},
"403": {
"description": "Roblox.Web.Authentication.Passwords.PasswordResponseCodes.PinLocked\r\n0: Token Validation Failed"
},
"429": {
"description": "Roblox.Web.Authentication.Passwords.PasswordResponseCodes.Flooded"
}
},
"servers": [
{
"url": "https://auth.roblox.com"
}
],
"x-roblox-engine-usability": {
"apiKeyWithHttpService": false
},
"security": [
{},
{
"roblox-legacy-cookie": []
}
],
"externalDocs": {
"url": "https://create.roblox.com/docs/cloud/reference/features/accounts#auth_post_v1_user_passwords_change"
}
}