Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.
POST /v1/users/{userId}/recovery-codes/regenerate — openapi
Clears any existing recovery codes and generates a new batch of recovery codes.
Two step verification recovery codes do not enforce that two step verification must be passed when logging in. At least one two step verification media type must be enabled to trigger the two step verification flow. Recovery codes are intended to be used to pass two step verification when the enabled media type is unavailable.
Recovery codes generated by this endpoint do not have an expiration.
Once a recovery code generated by this endpoint has been used it cannot be used again.
Endpoint
Method: POST
Path: /v1/users/{userId}/recovery-codes/regenerate
Servers:
https://twostepverification.roblox.com
Parameters
| Name | Location | Required | Description |
|---|---|---|---|
| userId | path | true | The user ID to generate recovery codes for. |
[
{
"in": "path",
"name": "userId",
"description": "The user ID to generate recovery codes for.",
"required": true,
"schema": {
"type": "integer",
"format": "int64"
}
}
] Request Body
The Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesRequest.
{
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesRequest"
}
},
"text/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesRequest"
}
}
},
"description": "The Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesRequest.",
"required": true
} Responses
| Status | Description |
|---|---|
| 200 | OK |
| 400 | 2: The user ID is invalid. 4: The password is invalid. |
| 401 | 0: Authorization has been denied for this request. |
| 403 | 0: Token Validation Failed |
| 429 | 5: Too many requests. |
| 503 | 7: Two step verification is currently under maintenance. |
{
"200": {
"description": "OK",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesResponse"
}
},
"text/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesResponse"
}
}
}
},
"400": {
"description": "2: The user ID is invalid.\r\n4: The password is invalid."
},
"401": {
"description": "0: Authorization has been denied for this request."
},
"403": {
"description": "0: Token Validation Failed"
},
"429": {
"description": "5: Too many requests."
},
"503": {
"description": "7: Two step verification is currently under maintenance."
}
} Authentication
{
"security": [
{
"roblox-legacy-cookie": []
}
],
"securitySchemes": {
"roblox-api-key": {
"type": "apiKey",
"description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
"name": "x-api-key",
"in": "header"
},
"roblox-legacy-cookie": {
"type": "apiKey",
"description": "A browser cookie that represents the identity of a Roblox user. DO NOT SHARE THIS. Sharing this will allow someone to log in as you and to steal your Robux and items. We do not recommend using cookies to call endpoints. When possible, use API keys with the x-api-key header or OAuth 2.0 instead for authentication.",
"in": "cookie",
"name": ".ROBLOSECURITY"
},
"roblox-oauth2": {
"type": "oauth2",
"description": "Build or authorize apps to access Roblox resources. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
"tokenUrl": "https://apis.roblox.com/oauth/v1/token",
"refreshUrl": "https://apis.roblox.com/oauth/v1/token",
"scopes": {}
}
}
}
}
} Related Schemas
Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesRequest
Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesResponse
Complete Operation Definition
{
"tags": [
"Accounts"
],
"summary": "Clears any existing recovery codes and generates a new batch of recovery codes.",
"description": "Two step verification recovery codes do not enforce that two step verification must be passed when logging in.\r\nAt least one two step verification media type must be enabled to trigger the two step verification flow.\r\nRecovery codes are intended to be used to pass two step verification when the enabled media type is unavailable.\r\n\r\nRecovery codes generated by this endpoint do not have an expiration.\r\n\r\nOnce a recovery code generated by this endpoint has been used it cannot be used again.",
"parameters": [
{
"in": "path",
"name": "userId",
"description": "The user ID to generate recovery codes for.",
"required": true,
"schema": {
"type": "integer",
"format": "int64"
}
}
],
"requestBody": {
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesRequest"
}
},
"text/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesRequest"
}
}
},
"description": "The Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesRequest.",
"required": true
},
"responses": {
"200": {
"description": "OK",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesResponse"
}
},
"text/json": {
"schema": {
"$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesResponse"
}
}
}
},
"400": {
"description": "2: The user ID is invalid.\r\n4: The password is invalid."
},
"401": {
"description": "0: Authorization has been denied for this request."
},
"403": {
"description": "0: Token Validation Failed"
},
"429": {
"description": "5: Too many requests."
},
"503": {
"description": "7: Two step verification is currently under maintenance."
}
},
"servers": [
{
"url": "https://twostepverification.roblox.com"
}
],
"x-roblox-engine-usability": {
"apiKeyWithHttpService": false
},
"security": [
{
"roblox-legacy-cookie": []
}
],
"externalDocs": {
"url": "https://create.roblox.com/docs/cloud/reference/features/accounts#twostepverification_post_v1_users__userId__recovery_codes_regenerate"
}
}