4 min read

Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.

POST /v1/users/{userId}/recovery-codes/regenerate — openapi

Clears any existing recovery codes and generates a new batch of recovery codes.

Two step verification recovery codes do not enforce that two step verification must be passed when logging in. At least one two step verification media type must be enabled to trigger the two step verification flow. Recovery codes are intended to be used to pass two step verification when the enabled media type is unavailable.

Recovery codes generated by this endpoint do not have an expiration.

Once a recovery code generated by this endpoint has been used it cannot be used again.

Endpoint

Method: POST

Path: /v1/users/{userId}/recovery-codes/regenerate

Servers:

Parameters

NameLocationRequiredDescription
userIdpathtrueThe user ID to generate recovery codes for.
[
  {
    "in": "path",
    "name": "userId",
    "description": "The user ID to generate recovery codes for.",
    "required": true,
    "schema": {
      "type": "integer",
      "format": "int64"
    }
  }
]

Request Body

The Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesRequest.

{
  "content": {
    "application/json": {
      "schema": {
        "$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesRequest"
      }
    },
    "text/json": {
      "schema": {
        "$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesRequest"
      }
    }
  },
  "description": "The Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesRequest.",
  "required": true
}

Responses

StatusDescription
200OK
4002: The user ID is invalid. 4: The password is invalid.
4010: Authorization has been denied for this request.
4030: Token Validation Failed
4295: Too many requests.
5037: Two step verification is currently under maintenance.
{
  "200": {
    "description": "OK",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesResponse"
        }
      },
      "text/json": {
        "schema": {
          "$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesResponse"
        }
      }
    }
  },
  "400": {
    "description": "2: The user ID is invalid.\r\n4: The password is invalid."
  },
  "401": {
    "description": "0: Authorization has been denied for this request."
  },
  "403": {
    "description": "0: Token Validation Failed"
  },
  "429": {
    "description": "5: Too many requests."
  },
  "503": {
    "description": "7: Two step verification is currently under maintenance."
  }
}

Authentication

{
  "security": [
    {
      "roblox-legacy-cookie": []
    }
  ],
  "securitySchemes": {
    "roblox-api-key": {
      "type": "apiKey",
      "description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
      "name": "x-api-key",
      "in": "header"
    },
    "roblox-legacy-cookie": {
      "type": "apiKey",
      "description": "A browser cookie that represents the identity of a Roblox user. DO NOT SHARE THIS. Sharing this will allow someone to log in as you and to steal your Robux and items. We do not recommend using cookies to call endpoints. When possible, use API keys with the x-api-key header or OAuth 2.0 instead for authentication.",
      "in": "cookie",
      "name": ".ROBLOSECURITY"
    },
    "roblox-oauth2": {
      "type": "oauth2",
      "description": "Build or authorize apps to access Roblox resources. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
      "flows": {
        "authorizationCode": {
          "authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
          "tokenUrl": "https://apis.roblox.com/oauth/v1/token",
          "refreshUrl": "https://apis.roblox.com/oauth/v1/token",
          "scopes": {}
        }
      }
    }
  }
}

Complete Operation Definition

{
  "tags": [
    "Accounts"
  ],
  "summary": "Clears any existing recovery codes and generates a new batch of recovery codes.",
  "description": "Two step verification recovery codes do not enforce that two step verification must be passed when logging in.\r\nAt least one two step verification media type must be enabled to trigger the two step verification flow.\r\nRecovery codes are intended to be used to pass two step verification when the enabled media type is unavailable.\r\n\r\nRecovery codes generated by this endpoint do not have an expiration.\r\n\r\nOnce a recovery code generated by this endpoint has been used it cannot be used again.",
  "parameters": [
    {
      "in": "path",
      "name": "userId",
      "description": "The user ID to generate recovery codes for.",
      "required": true,
      "schema": {
        "type": "integer",
        "format": "int64"
      }
    }
  ],
  "requestBody": {
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesRequest"
        }
      },
      "text/json": {
        "schema": {
          "$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesRequest"
        }
      }
    },
    "description": "The Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesRequest.",
    "required": true
  },
  "responses": {
    "200": {
      "description": "OK",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesResponse"
          }
        },
        "text/json": {
          "schema": {
            "$ref": "#/components/schemas/Roblox.TwoStepVerification.Api.RegenerateRecoveryCodesResponse"
          }
        }
      }
    },
    "400": {
      "description": "2: The user ID is invalid.\r\n4: The password is invalid."
    },
    "401": {
      "description": "0: Authorization has been denied for this request."
    },
    "403": {
      "description": "0: Token Validation Failed"
    },
    "429": {
      "description": "5: Too many requests."
    },
    "503": {
      "description": "7: Two step verification is currently under maintenance."
    }
  },
  "servers": [
    {
      "url": "https://twostepverification.roblox.com"
    }
  ],
  "x-roblox-engine-usability": {
    "apiKeyWithHttpService": false
  },
  "security": [
    {
      "roblox-legacy-cookie": []
    }
  ],
  "externalDocs": {
    "url": "https://create.roblox.com/docs/cloud/reference/features/accounts#twostepverification_post_v1_users__userId__recovery_codes_regenerate"
  }
}