Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.
POST /v1/users/{userId}/challenges/passkey/verify-start — openapi
Provides a challenge for the passkey to authenticate.
Endpoint
Method: POST
Path: /v1/users/{userId}/challenges/passkey/verify-start
Servers:
https://twostepverification.roblox.com
Parameters
| Name | Location | Required | Description |
|---|---|---|---|
| userId | path | true | The user ID. |
[
{
"in": "path",
"name": "userId",
"description": "The user ID.",
"required": true,
"schema": {
"type": "integer",
"format": "int64"
}
}
] Request Body
{
"$ref": "#/components/requestBodies/Roblox.TwoStepVerification.Api.SendCodeRequest2"
} Responses
| Status | Description |
|---|---|
| 200 | OK |
| 400 | 1: Invalid challenge ID. 2: The user ID is invalid. |
| 403 | 0: Token Validation Failed 8: The user is not allowed to perform the requested action. |
| 503 | 7: Two step verification is currently under maintenance. |
{
"200": {
"description": "OK",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.VerifyStartPasskeyResponse"
}
},
"text/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.VerifyStartPasskeyResponse"
}
}
}
},
"400": {
"description": "1: Invalid challenge ID.\r\n2: The user ID is invalid."
},
"403": {
"description": "0: Token Validation Failed\r\n8: The user is not allowed to perform the requested action."
},
"503": {
"description": "7: Two step verification is currently under maintenance."
}
} Authentication
{
"security": [
{},
{
"roblox-legacy-cookie": []
}
],
"securitySchemes": {
"roblox-api-key": {
"type": "apiKey",
"description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
"name": "x-api-key",
"in": "header"
},
"roblox-legacy-cookie": {
"type": "apiKey",
"description": "A browser cookie that represents the identity of a Roblox user. DO NOT SHARE THIS. Sharing this will allow someone to log in as you and to steal your Robux and items. We do not recommend using cookies to call endpoints. When possible, use API keys with the x-api-key header or OAuth 2.0 instead for authentication.",
"in": "cookie",
"name": ".ROBLOSECURITY"
},
"roblox-oauth2": {
"type": "oauth2",
"description": "Build or authorize apps to access Roblox resources. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
"tokenUrl": "https://apis.roblox.com/oauth/v1/token",
"refreshUrl": "https://apis.roblox.com/oauth/v1/token",
"scopes": {}
}
}
}
}
} Related Schemas
Related Components
Complete Operation Definition
{
"tags": [
"Accounts"
],
"summary": "Provides a challenge for the passkey to authenticate.",
"parameters": [
{
"in": "path",
"name": "userId",
"description": "The user ID.",
"required": true,
"schema": {
"type": "integer",
"format": "int64"
}
}
],
"requestBody": {
"$ref": "#/components/requestBodies/Roblox.TwoStepVerification.Api.SendCodeRequest2"
},
"responses": {
"200": {
"description": "OK",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.VerifyStartPasskeyResponse"
}
},
"text/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.VerifyStartPasskeyResponse"
}
}
}
},
"400": {
"description": "1: Invalid challenge ID.\r\n2: The user ID is invalid."
},
"403": {
"description": "0: Token Validation Failed\r\n8: The user is not allowed to perform the requested action."
},
"503": {
"description": "7: Two step verification is currently under maintenance."
}
},
"servers": [
{
"url": "https://twostepverification.roblox.com"
}
],
"x-roblox-engine-usability": {
"apiKeyWithHttpService": false
},
"security": [
{},
{
"roblox-legacy-cookie": []
}
],
"externalDocs": {
"url": "https://create.roblox.com/docs/cloud/reference/features/accounts#twostepverification_post_v1_users__userId__challenges_passkey_verify_start"
}
}