4 min read

Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.

POST /v1/users/{userId}/configuration/authenticator/enable-verify — openapi

Finishes enabling authenticator-based two step verification for the specified user.

Enabling authenticator-based two step verification requires two parts to help ensure the user has properly stored the authenticator key in their authenticator app.

Endpoint

Method: POST

Path: /v1/users/{userId}/configuration/authenticator/enable-verify

Servers:

Parameters

NameLocationRequiredDescription
userIdpathtrueThe user ID.
[
  {
    "in": "path",
    "name": "userId",
    "description": "The user ID.",
    "required": true,
    "schema": {
      "type": "integer",
      "format": "int64"
    }
  }
]

Request Body

The Roblox.TwoStepVerification.Api.EnableVerifyAuthenticatorRequest.

{
  "content": {
    "application/json": {
      "schema": {
        "$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.EnableVerifyAuthenticatorRequest"
      }
    },
    "text/json": {
      "schema": {
        "$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.EnableVerifyAuthenticatorRequest"
      }
    }
  },
  "description": "The Roblox.TwoStepVerification.Api.EnableVerifyAuthenticatorRequest.",
  "required": true
}

Responses

StatusDescription
200OK
4002: The user ID is invalid. 4: The password is invalid. 10: The two step verification challenge code is invalid. 12: Invalid setup token.
4010: Authorization has been denied for this request.
4030: Token Validation Failed 11: The two step verification configuration is already enabled.
5037: Two step verification is currently under maintenance.
{
  "200": {
    "description": "OK",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.EnableVerifyAuthenticatorResponse"
        }
      },
      "text/json": {
        "schema": {
          "$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.EnableVerifyAuthenticatorResponse"
        }
      }
    }
  },
  "400": {
    "description": "2: The user ID is invalid.\r\n4: The password is invalid.\r\n10: The two step verification challenge code is invalid.\r\n12: Invalid setup token."
  },
  "401": {
    "description": "0: Authorization has been denied for this request."
  },
  "403": {
    "description": "0: Token Validation Failed\r\n11: The two step verification configuration is already enabled."
  },
  "503": {
    "description": "7: Two step verification is currently under maintenance."
  }
}

Authentication

{
  "security": [
    {
      "roblox-legacy-cookie": []
    }
  ],
  "securitySchemes": {
    "roblox-api-key": {
      "type": "apiKey",
      "description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
      "name": "x-api-key",
      "in": "header"
    },
    "roblox-legacy-cookie": {
      "type": "apiKey",
      "description": "A browser cookie that represents the identity of a Roblox user. DO NOT SHARE THIS. Sharing this will allow someone to log in as you and to steal your Robux and items. We do not recommend using cookies to call endpoints. When possible, use API keys with the x-api-key header or OAuth 2.0 instead for authentication.",
      "in": "cookie",
      "name": ".ROBLOSECURITY"
    },
    "roblox-oauth2": {
      "type": "oauth2",
      "description": "Build or authorize apps to access Roblox resources. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
      "flows": {
        "authorizationCode": {
          "authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
          "tokenUrl": "https://apis.roblox.com/oauth/v1/token",
          "refreshUrl": "https://apis.roblox.com/oauth/v1/token",
          "scopes": {}
        }
      }
    }
  }
}

Complete Operation Definition

{
  "tags": [
    "Accounts"
  ],
  "summary": "Finishes enabling authenticator-based two step verification for the specified user.",
  "description": "Enabling authenticator-based two step verification requires two parts to help ensure\r\nthe user has properly stored the authenticator key in their authenticator app.",
  "parameters": [
    {
      "in": "path",
      "name": "userId",
      "description": "The user ID.",
      "required": true,
      "schema": {
        "type": "integer",
        "format": "int64"
      }
    }
  ],
  "requestBody": {
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.EnableVerifyAuthenticatorRequest"
        }
      },
      "text/json": {
        "schema": {
          "$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.EnableVerifyAuthenticatorRequest"
        }
      }
    },
    "description": "The Roblox.TwoStepVerification.Api.EnableVerifyAuthenticatorRequest.",
    "required": true
  },
  "responses": {
    "200": {
      "description": "OK",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.EnableVerifyAuthenticatorResponse"
          }
        },
        "text/json": {
          "schema": {
            "$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.EnableVerifyAuthenticatorResponse"
          }
        }
      }
    },
    "400": {
      "description": "2: The user ID is invalid.\r\n4: The password is invalid.\r\n10: The two step verification challenge code is invalid.\r\n12: Invalid setup token."
    },
    "401": {
      "description": "0: Authorization has been denied for this request."
    },
    "403": {
      "description": "0: Token Validation Failed\r\n11: The two step verification configuration is already enabled."
    },
    "503": {
      "description": "7: Two step verification is currently under maintenance."
    }
  },
  "servers": [
    {
      "url": "https://twostepverification.roblox.com"
    }
  ],
  "x-roblox-engine-usability": {
    "apiKeyWithHttpService": false
  },
  "security": [
    {
      "roblox-legacy-cookie": []
    }
  ],
  "externalDocs": {
    "url": "https://create.roblox.com/docs/cloud/reference/features/accounts#twostepverification_post_v1_users__userId__configuration_authenticator_enable_verify"
  }
}