3 min read

Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.

GET /cloud/v2/universes/{universeId}/secrets/public-key — secrets-store-service/v1

Get Public Key

Retrieves the public key for a universe. You need this key to encrypt secret content before sending it to Roblox.

Only the owner of the universe can retrieve the public key. For group-owned universes, only the group owner or authorized members can retrieve the public key.

The secret id field is static and always returns "public-key".

The returned public key in the secret field is universe-specific and derived from a master key using the universe ID. Use this key with LibSodium sealed box encryption to encrypt your secret content before creating or updating secrets.

Include the key_id from the public key response in the request to create or update a secret.

Endpoint

Method: GET

Path: /cloud/v2/universes/{universeId}/secrets/public-key

Servers:

Parameters

NameLocationRequiredDescription
universeIdpathtrueThe universe ID
[
  {
    "name": "universeId",
    "in": "path",
    "description": "The universe ID",
    "required": true,
    "schema": {
      "type": "integer",
      "format": "int64"
    }
  }
]

Responses

StatusDescription
200OK
400Bad Request
403Forbidden
{
  "200": {
    "description": "OK",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/Secret"
        }
      }
    }
  },
  "400": {
    "description": "Bad Request",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/ProblemDetails"
        }
      }
    }
  },
  "403": {
    "description": "Forbidden",
    "content": {
      "application/json": {
        "schema": {
          "$ref": "#/components/schemas/ProblemDetails"
        }
      }
    }
  }
}

Authentication

{
  "security": [
    {
      "roblox-api-key": []
    },
    {
      "roblox-oauth2": []
    }
  ],
  "securitySchemes": {
    "roblox-api-key": {
      "type": "apiKey",
      "description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
      "in": "header",
      "name": "x-api-key"
    },
    "roblox-oauth2": {
      "type": "oauth2",
      "description": "OAuth 2.0 authentication for Roblox APIs. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
      "flows": {
        "authorizationCode": {
          "authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
          "tokenUrl": "https://apis.roblox.com/oauth/v1/token",
          "refreshUrl": "https://apis.roblox.com/oauth/v1/token",
          "scopes": {
            "universe.secret:write": "universe.secret:write",
            "universe.secret:read": "universe.secret:read"
          }
        }
      }
    }
  }
}

Complete Operation Definition

{
  "tags": [
    "SecretsStoreApiService"
  ],
  "summary": "Get Public Key",
  "description": "Retrieves the public key for a universe. You need this key to encrypt secret content \nbefore sending it to Roblox.\n\nOnly the owner of the universe can retrieve the public key. For group-owned universes, only the group owner or\nauthorized members can retrieve the public key.\n\nThe secret id field is static and always returns \"public-key\".\n\nThe returned public key in the secret field is universe-specific and derived from a master key using the universe ID.\nUse this key with LibSodium sealed box encryption to encrypt your secret content before \ncreating or updating secrets.\n\nInclude the key_id from the public key response in the request to create or update a secret.",
  "parameters": [
    {
      "name": "universeId",
      "in": "path",
      "description": "The universe ID",
      "required": true,
      "schema": {
        "type": "integer",
        "format": "int64"
      }
    }
  ],
  "responses": {
    "200": {
      "description": "OK",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/Secret"
          }
        }
      }
    },
    "400": {
      "description": "Bad Request",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/ProblemDetails"
          }
        }
      }
    },
    "403": {
      "description": "Forbidden",
      "content": {
        "application/json": {
          "schema": {
            "$ref": "#/components/schemas/ProblemDetails"
          }
        }
      }
    }
  },
  "x-roblox-scopes": [
    {
      "name": "universe.secret:read",
      "description": "Required"
    }
  ],
  "x-roblox-stability": "BETA",
  "x-roblox-rate-limits": {
    "perApiKeyOwner": {
      "period": "MINUTE",
      "maxInPeriod": 120
    },
    "perOauth2Authorization": {
      "period": "MINUTE",
      "maxInPeriod": 120
    }
  },
  "x-roblox-engine-usability": {
    "apiKeyWithHttpService": false
  },
  "security": [
    {
      "roblox-api-key": []
    },
    {
      "roblox-oauth2": []
    }
  ]
}