3 min read

Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.

Secret — secrets-store-service/v1

Universe-specific secret, identified by id, and belonging to a specific environment.

Properties

NameTypeRequiredDescription
idstringfalseThe user-specified secret name. Examples: "aws", "gcp", "discord". Static when getting the public key for a universe. Must be alphanumeric or underscore, 1-64 characters, not starting with a number.
secretstringfalseThe binary secret content. Examples: API key content (text), private keys. When created, the secret must be encrypted using LibSodium sealed box and encoded in base64 with the universe's public key. Contains the public key when getting the public key for a universe.
key_idstringfalseEncryption key identifier. Identifies the key that was used to encrypt the secret content.
domainstringfalseThe domain wildcard that restricts the purpose of the key. You can restrict the URLs callable via HttpService to a specific domain, e.g. "api.example.com" or ".myservice.org". An empty or null domain means that the secret is a private key and cannot be transformed with addPrefix/addSuffix or sent as a header or URL. In order to make the secret accessible for all domains, use ""
create_timestringfalseDate and time when the secret was originally created.
update_timestringfalseDate and time when the secret was last updated

Complete Schema

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "description": "The user-specified secret name. Examples: \"aws\", \"gcp\", \"discord\".\n\nStatic when getting the public key for a universe.\n\nMust be alphanumeric or underscore, 1-64 characters, not starting with a number.",
      "nullable": true
    },
    "secret": {
      "type": "string",
      "description": "The binary secret content. Examples: API key content (text), private keys.\n\nWhen created, the secret must be encrypted using LibSodium sealed box and encoded in base64 with the universe's public key.\n\nContains the public key when getting the public key for a universe.",
      "format": "byte",
      "nullable": true
    },
    "key_id": {
      "type": "string",
      "description": "Encryption key identifier. Identifies the key that was used to encrypt the secret content.",
      "nullable": true
    },
    "domain": {
      "type": "string",
      "description": "The domain wildcard that restricts the purpose of the key. \n\nYou can restrict the URLs callable via HttpService to a specific domain, e.g. \"api.example.com\" or \"*.myservice.org\".\n\nAn empty or null domain means that the secret is a private key and cannot be transformed with addPrefix/addSuffix or sent as a header or URL.\n\nIn order to make the secret accessible for all domains, use \"*\"",
      "nullable": true
    },
    "create_time": {
      "type": "string",
      "description": "Date and time when the secret was originally created.",
      "nullable": true
    },
    "update_time": {
      "type": "string",
      "description": "Date and time when the secret was last updated",
      "nullable": true
    }
  },
  "additionalProperties": false,
  "description": "Universe-specific secret, identified by `id`, and belonging to a specific `environment`."
}