2 min read

Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.

POST /v2/revert/invalidate-tickets — openapi

Invalidates all account security tickets for the authenticated user. This endpoint should be called before enrolling in EPP to ensure old revert links cannot be used.

Endpoint

Method: POST

Path: /v2/revert/invalidate-tickets

Servers:

Responses

StatusDescription
200OK
4010: Authorization has been denied for this request.
4030: Token Validation Failed
5031: This feature is disabled
{
  "200": {
    "description": "OK",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/Roblox.Web.WebAPI.ApiEmptyResponseModel"
        }
      },
      "text/json": {
        "schema": {
          "$ref": "#/components/schemas/Roblox.Web.WebAPI.ApiEmptyResponseModel"
        }
      }
    }
  },
  "401": {
    "description": "0: Authorization has been denied for this request."
  },
  "403": {
    "description": "0: Token Validation Failed"
  },
  "503": {
    "description": "1: This feature is disabled"
  }
}

Authentication

{
  "security": [
    {},
    {
      "roblox-legacy-cookie": []
    }
  ],
  "securitySchemes": {
    "roblox-api-key": {
      "type": "apiKey",
      "description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
      "name": "x-api-key",
      "in": "header"
    },
    "roblox-legacy-cookie": {
      "type": "apiKey",
      "description": "A browser cookie that represents the identity of a Roblox user. DO NOT SHARE THIS. Sharing this will allow someone to log in as you and to steal your Robux and items. We do not recommend using cookies to call endpoints. When possible, use API keys with the x-api-key header or OAuth 2.0 instead for authentication.",
      "in": "cookie",
      "name": ".ROBLOSECURITY"
    },
    "roblox-oauth2": {
      "type": "oauth2",
      "description": "Build or authorize apps to access Roblox resources. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
      "flows": {
        "authorizationCode": {
          "authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
          "tokenUrl": "https://apis.roblox.com/oauth/v1/token",
          "refreshUrl": "https://apis.roblox.com/oauth/v1/token",
          "scopes": {}
        }
      }
    }
  }
}

Complete Operation Definition

{
  "tags": [
    "Accounts"
  ],
  "summary": "Invalidates all account security tickets for the authenticated user.\nThis endpoint should be called before enrolling in EPP to ensure old revert links cannot be used.",
  "responses": {
    "200": {
      "description": "OK",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/Roblox.Web.WebAPI.ApiEmptyResponseModel"
          }
        },
        "text/json": {
          "schema": {
            "$ref": "#/components/schemas/Roblox.Web.WebAPI.ApiEmptyResponseModel"
          }
        }
      }
    },
    "401": {
      "description": "0: Authorization has been denied for this request."
    },
    "403": {
      "description": "0: Token Validation Failed"
    },
    "503": {
      "description": "1: This feature is disabled"
    }
  },
  "servers": [
    {
      "url": "https://auth.roblox.com"
    }
  ],
  "x-roblox-engine-usability": {
    "apiKeyWithHttpService": false
  },
  "security": [
    {},
    {
      "roblox-legacy-cookie": []
    }
  ],
  "externalDocs": {
    "url": "https://create.roblox.com/docs/cloud/reference/features/accounts#auth_post_v2_revert_invalidate_tickets"
  }
}