3 min read

Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.

GET /cloud/v2/universes/{universeId}/secrets — secrets-store-service/v1

List Secrets

Lists all secrets defined for a universe. Secret content is not returned for security reasons - only metadata such as ID, domain, creation and update timestamps are included.

Only the owner of the universe can list secrets. For group-owned universes, only the group owner or authorized members can list secrets.

Endpoint

Method: GET

Path: /cloud/v2/universes/{universeId}/secrets

Servers:

Parameters

NameLocationRequiredDescription
universeIdpathtrueThe universe ID
limitqueryfalseNumber of secrets to return per page (1-500, default 10)
cursorqueryfalsePagination cursor from previous response
[
  {
    "name": "universeId",
    "in": "path",
    "description": "The universe ID",
    "required": true,
    "schema": {
      "type": "integer",
      "format": "int64"
    }
  },
  {
    "name": "limit",
    "in": "query",
    "description": "Number of secrets to return per page (1-500, default 10)",
    "schema": {
      "type": "integer",
      "format": "int32",
      "default": 10
    }
  },
  {
    "name": "cursor",
    "in": "query",
    "description": "Pagination cursor from previous response",
    "schema": {
      "type": "string"
    }
  }
]

Responses

StatusDescription
200OK
400Bad Request
403Forbidden
{
  "200": {
    "description": "OK",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/SecretPaginatedList"
        }
      }
    }
  },
  "400": {
    "description": "Bad Request",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/ProblemDetails"
        }
      }
    }
  },
  "403": {
    "description": "Forbidden",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/ProblemDetails"
        }
      }
    }
  }
}

Authentication

{
  "security": [
    {
      "roblox-api-key": []
    },
    {
      "roblox-oauth2": []
    }
  ],
  "securitySchemes": {
    "roblox-api-key": {
      "type": "apiKey",
      "description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
      "in": "header",
      "name": "x-api-key"
    },
    "roblox-oauth2": {
      "type": "oauth2",
      "description": "OAuth 2.0 authentication for Roblox APIs. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
      "flows": {
        "authorizationCode": {
          "authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
          "tokenUrl": "https://apis.roblox.com/oauth/v1/token",
          "refreshUrl": "https://apis.roblox.com/oauth/v1/token",
          "scopes": {
            "universe.secret:write": "universe.secret:write",
            "universe.secret:read": "universe.secret:read"
          }
        }
      }
    }
  }
}

Complete Operation Definition

{
  "tags": [
    "SecretsStoreApiService"
  ],
  "summary": "List Secrets",
  "description": "Lists all secrets defined for a universe.\nSecret content is not returned for security reasons - only metadata such as ID, domain, creation and update timestamps are included.\n\nOnly the owner of the universe can list secrets. For group-owned universes, only the group owner or authorized\nmembers can list secrets.",
  "parameters": [
    {
      "name": "universeId",
      "in": "path",
      "description": "The universe ID",
      "required": true,
      "schema": {
        "type": "integer",
        "format": "int64"
      }
    },
    {
      "name": "limit",
      "in": "query",
      "description": "Number of secrets to return per page (1-500, default 10)",
      "schema": {
        "type": "integer",
        "format": "int32",
        "default": 10
      }
    },
    {
      "name": "cursor",
      "in": "query",
      "description": "Pagination cursor from previous response",
      "schema": {
        "type": "string"
      }
    }
  ],
  "responses": {
    "200": {
      "description": "OK",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/SecretPaginatedList"
          }
        }
      }
    },
    "400": {
      "description": "Bad Request",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/ProblemDetails"
          }
        }
      }
    },
    "403": {
      "description": "Forbidden",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/ProblemDetails"
          }
        }
      }
    }
  },
  "x-roblox-scopes": [
    {
      "name": "universe.secret:read",
      "description": "Required"
    }
  ],
  "x-roblox-stability": "BETA",
  "x-roblox-rate-limits": {
    "perApiKeyOwner": {
      "period": "MINUTE",
      "maxInPeriod": 120
    },
    "perOauth2Authorization": {
      "period": "MINUTE",
      "maxInPeriod": 120
    }
  },
  "x-roblox-engine-usability": {
    "apiKeyWithHttpService": false
  },
  "security": [
    {
      "roblox-api-key": []
    },
    {
      "roblox-oauth2": []
    }
  ]
}