Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.
POST /cloud/v2/universes/{universeId}/secrets — secrets-store-service/v1
Create Secret
Creates a new secret. A maximum of 500 secrets per universe is allowed.
Only the owner of the universe can create secrets. For group-owned universes, only the group owner or authorized members can create secrets.
To encrypt the secret:
- Get the public key using the Get Public Key endpoint
- Encrypt your secret using LibSodium sealed box
- Base64 encode the encrypted content
Include the key_id from the public key response in the request.
For an example, see the Secrets store guide.
Endpoint
Method: POST
Path: /cloud/v2/universes/{universeId}/secrets
Servers:
https://apis.roblox.com
Parameters
| Name | Location | Required | Description |
|---|---|---|---|
| universeId | path | true | The universe ID |
[
{
"name": "universeId",
"in": "path",
"description": "The universe ID",
"required": true,
"schema": {
"type": "integer",
"format": "int64"
}
}
] Request Body
The secret to create with encrypted content
{
"description": "The secret to create with encrypted content",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Secret"
}
}
}
} Responses
| Status | Description |
|---|---|
| 201 | Created |
| 400 | Bad Request |
| 403 | Forbidden |
| 409 | Conflict |
{
"201": {
"description": "Created",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Secret"
}
}
}
},
"400": {
"description": "Bad Request",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
},
"403": {
"description": "Forbidden",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
},
"409": {
"description": "Conflict",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
}
} Authentication
{
"security": [
{
"roblox-api-key": []
},
{
"roblox-oauth2": []
}
],
"securitySchemes": {
"roblox-api-key": {
"type": "apiKey",
"description": "A configurable key that allows granular access to Roblox resources. See https://create.roblox.com/docs/cloud/auth/api-keys for more information.",
"in": "header",
"name": "x-api-key"
},
"roblox-oauth2": {
"type": "oauth2",
"description": "OAuth 2.0 authentication for Roblox APIs. See https://create.roblox.com/docs/cloud/auth/oauth2-overview for more information.",
"flows": {
"authorizationCode": {
"authorizationUrl": "https://apis.roblox.com/oauth/v1/authorize",
"tokenUrl": "https://apis.roblox.com/oauth/v1/token",
"refreshUrl": "https://apis.roblox.com/oauth/v1/token",
"scopes": {
"universe.secret:write": "universe.secret:write",
"universe.secret:read": "universe.secret:read"
}
}
}
}
}
} Related Schemas
Complete Operation Definition
{
"tags": [
"SecretsStoreApiService"
],
"summary": "Create Secret",
"description": "Creates a new secret. A maximum of 500 secrets per universe is allowed.\n \nOnly the owner of the universe can create secrets. For group-owned universes, only the group owner or authorized\nmembers can create secrets.\n \nTo encrypt the secret:\n1. Get the public key using the Get Public Key endpoint\n2. Encrypt your secret using LibSodium sealed box\n3. Base64 encode the encrypted content\n\nInclude the key_id from the public key response in the request.\n\nFor an example, see the [Secrets store guide](https://create.roblox.com/docs/cloud/guides/secrets-store).",
"parameters": [
{
"name": "universeId",
"in": "path",
"description": "The universe ID",
"required": true,
"schema": {
"type": "integer",
"format": "int64"
}
}
],
"requestBody": {
"description": "The secret to create with encrypted content",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Secret"
}
}
}
},
"responses": {
"201": {
"description": "Created",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Secret"
}
}
}
},
"400": {
"description": "Bad Request",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
},
"403": {
"description": "Forbidden",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
},
"409": {
"description": "Conflict",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/ProblemDetails"
}
}
}
}
},
"x-roblox-scopes": [
{
"name": "universe.secret:write",
"description": "Required"
}
],
"x-roblox-stability": "BETA",
"x-roblox-rate-limits": {
"perApiKeyOwner": {
"period": "MINUTE",
"maxInPeriod": 120
},
"perOauth2Authorization": {
"period": "MINUTE",
"maxInPeriod": 120
}
},
"x-roblox-engine-usability": {
"apiKeyWithHttpService": false
},
"security": [
{
"roblox-api-key": []
},
{
"roblox-oauth2": []
}
]
}