Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.
PATCH /cloud/v2/universes/{universeId}/secrets/{secretId} — secrets-store-service/v1
Update Secret
Updates an existing secret.
Only the owner of the universe can update secrets. For group-owned universes, only the group owner or authorized members can update secrets.
Only the secret content, key_id, and domain can be updated - the secret ID cannot be changed.
To encrypt the updated secret:
- Get the current public key using the GetPublicKey endpoint
- Encrypt your new secret content using LibSodium sealed box
- Base64 encode the encrypted content
Include the key_id from the public key response in the request.
For an example, see the Secrets store guide.
Endpoint
Method: PATCH
Path: /cloud/v2/universes/{universeId}/secrets/{secretId}
Servers:
https://apis.roblox.com
Parameters
| Name | Location | Required | Description |
|---|---|---|---|
| universeId | path | true | The universe ID |
| secretId | path | true | The ID of the secret to update |
[
{
"name": "universeId",
"in": "path",
"description": "The universe ID",
"required": true,
"schema": {
"type": "integer",
"format": "int64"
}
},
{
"name": "secretId",
"in": "path",
"description": "The ID of the secret to update",
"required": true,
"schema": {
"type": "string"
}
}
] Request Body
The updated secret data with encrypted content
{
"description": "The updated secret data with encrypted content",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Secret"
}
}
}
} Responses
| Status | Description |
|---|---|
| 200 | OK |
| 400 | Bad Request |
| 403 | Forbidden |
| 404 | Not Found |
{
"200": {
"description": "OK",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Secret"
}
}
}
},
"400": {
"description": "Bad Request",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
},
"403": {
"description": "Forbidden",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
},
"404": {
"description": "Not Found",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
}
} Authentication
{
"security": [
{
"roblox-api-key": []
},
{
"roblox-oauth2": []
}
],
"securitySchemes": {
"roblox-api-key": {
"type": "apiKey",
"description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
"in": "header",
"name": "x-api-key"
},
"roblox-oauth2": {
"type": "oauth2",
"description": "OAuth 2.0 authentication for Roblox APIs. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
"tokenUrl": "https://apis.roblox.com/oauth/v1/token",
"refreshUrl": "https://apis.roblox.com/oauth/v1/token",
"scopes": {
"universe.secret:write": "universe.secret:write",
"universe.secret:read": "universe.secret:read"
}
}
}
}
}
} Related Schemas
Complete Operation Definition
{
"tags": [
"SecretsStoreApiService"
],
"summary": "Update Secret",
"description": "Updates an existing secret.\n\nOnly the owner of the universe can update secrets. For group-owned universes, only the group owner or authorized\nmembers can update secrets.\n\nOnly the secret content, key_id, and domain can be updated - the secret ID cannot be changed.\n\nTo encrypt the updated secret:\n1. Get the current public key using the GetPublicKey endpoint\n2. Encrypt your new secret content using LibSodium sealed box\n3. Base64 encode the encrypted content\n\nInclude the key_id from the public key response in the request.\n\nFor an example, see the [Secrets store guide](https://create.roblox.com/docs/cloud/guides/secrets-store).",
"parameters": [
{
"name": "universeId",
"in": "path",
"description": "The universe ID",
"required": true,
"schema": {
"type": "integer",
"format": "int64"
}
},
{
"name": "secretId",
"in": "path",
"description": "The ID of the secret to update",
"required": true,
"schema": {
"type": "string"
}
}
],
"requestBody": {
"description": "The updated secret data with encrypted content",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Secret"
}
}
}
},
"responses": {
"200": {
"description": "OK",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Secret"
}
}
}
},
"400": {
"description": "Bad Request",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
},
"403": {
"description": "Forbidden",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
},
"404": {
"description": "Not Found",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
}
},
"x-roblox-scopes": [
{
"name": "universe.secret:write",
"description": "Required"
}
],
"x-roblox-stability": "BETA",
"x-roblox-rate-limits": {
"perApiKeyOwner": {
"period": "MINUTE",
"maxInPeriod": 120
},
"perOauth2Authorization": {
"period": "MINUTE",
"maxInPeriod": 120
}
},
"x-roblox-engine-usability": {
"apiKeyWithHttpService": false
},
"security": [
{
"roblox-api-key": []
},
{
"roblox-oauth2": []
}
]
}