10 min read

Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.

SecurityCapability

SecurityCapability is a bitmask-based permission system that controls which engine APIs and Luau language features are accessible to scripts running inside sandboxed containers. Each value represents one capability bit that can be granted or restricted.

When an Instance has its Sandboxed property enabled, the engine intersects the capabilities of all ancestor containers to determine the effective permission set of any script that executes within that container. API members, classes, and Luau built-ins are each annotated with one or more SecurityCapability values; a script's thread must hold every required capability to call them.

Items

NameValueDescription
RunClientScript0Indicates that a script container is permitted to execute scripts on the client (LocalScript).
RunServerScript1Indicates that a script container is permitted to execute scripts on the server (Script).
AccessOutsideWrite2Grants a script read-write access to instances that live outside its sandboxed container.
AssetRequire3Deprecated. Use SecurityCapability.LoadUnownedAsset instead.
LoadString4Allows a script to use the loadstring() Luau built-in to compile and execute a string as code.
ScriptGlobals5Allows a script to access the shared and _G shared global variable tables.
CreateInstances6Allows a script to create new Instance objects using Instance.new().
Basic7Guards access to a broad set of general-purpose engine APIs that do not belong to a more specific capability category.
Audio8Guards access to audio engine APIs such as Sound, AudioPlayer, and related classes.
DataStore9Guards access to data store APIs such as DataStoreService and its associated objects.
Network10Guards access to low-level networking APIs such as HttpService.
Physics11Guards access to physics engine APIs such as Constraint classes and BasePart physics properties.
UI12Guards access to UI engine APIs such as ScreenGui, Frame, and other GuiObject classes.
CSG13Guards access to Constructive Solid Geometry (CSG) APIs such as UnionOperation and NegateOperation.
Chat14Guards access to chat engine APIs such as TextChatService and related chat classes.
Animation15Guards access to animation engine APIs such as AnimationController and related classes.
Avatar16Deprecated. Use SecurityCapability.AvatarAppearance instead.
Input17Guards access to user input APIs such as UserInputService and ContextActionService.
Environment18Guards access to environment and world-setting APIs such as Lighting and Atmosphere.
RemoteEvent19Guards access to remote event and function APIs such as RemoteEvent and RemoteFunction.
LegacySound20Guards access to the legacy Sound and pre-VoiceChatService.UseAudioApi sound stack APIs.
Players21Guards access to Players service APIs that query or manage connected players.
CapabilityControl22Guards access to the Instance.Capabilities and Instance.Sandboxed properties that configure script sandboxing.
Plugin23Mirrors the legacy Plugin permission level, granting access to Studio plugin APIs.
LocalUser24Mirrors the legacy LocalUser permission level, granting access to IDE-only and Studio-level APIs.
WritePlayer25Mirrors the legacy WritePlayer permission level, granting the ability to modify player identity properties such as name and UserId.
RobloxScript26Mirrors the legacy RobloxScript permission level, granting access to CoreScript APIs.
RobloxEngine27Mirrors the legacy RobloxEngine permission level, granting access to internal engine-level APIs.
Unassigned28The default capability assigned to API members that have not been explicitly assigned to any other capability category.
InternalTest29Restricts access to non-sensitive APIs that are intentionally kept internal.
PluginOrOpenCloud30Restricts access to APIs callable only from Studio plugin or Open Cloud Luau execution sessions.
Assistant31Restricts access to APIs that may only be called from Studio Assistant execution contexts.
RemoteCommand32Restricts access to APIs that are executable only from Studio's RemoteCommandService in Team Create sessions.
AssetRead33Guards access to APIs that read or query asset metadata from the Roblox catalog.
AssetManagement34Guards access to asset management APIs such as ContentProvider:PreloadAsync() and encryption-key registration.
DynamicGeneration35Guards access to procedural and AI-driven content generation APIs such as EditableMesh and AvatarCreationService.
PlatformAvatarEditing36Guards access to platform-level avatar editing APIs provided by AvatarEditorService.
AssetCreateUpdate37Guards access to APIs that create or update published Roblox assets.
Capture38Guards access to CaptureService APIs that take screenshots and record video.
SensitiveInput39Guards access to sensitive user input APIs such as those that can read raw keyboard or mouse data beyond normal game input.
Monetization40Guards access to in-experience purchase and monetization APIs such as MarketplaceService.
LoadOwnedAsset41Allows a script to load assets that are owned by the experience's creator using InsertService or LuaGlobals.require().
Social42Guards access to social APIs such as SocialService, FriendPages, and ExperienceInviteOptions.
ServerCommunication43Guards access to server-to-server messaging APIs such as MessagingService.
Logging44Guards access to LogService and logging-related APIs.
PromptExternalPurchase45Guards access to APIs that initiate external (non-Roblox) purchase prompts.
Groups46Guards access to group-related APIs such as GroupService.
Teleport47Guards access to teleportation APIs such as TeleportService, TeleportOptions, and TeleportAsyncResult.
Consequences48Guards access to moderation and player-consequence APIs such as Players:BanAsync() and ModerationService.
Material49Guards access to MaterialService, MaterialVariant, and custom material APIs.
AvatarBehavior50Guards access to APIs that control avatar locomotion and behavior at runtime.
AvatarAppearance51Guards access to APIs that read or modify avatar appearance, such as HumanoidDescription.
LoadUnownedAsset52Allows a script to LuaGlobals.require() asset IDs or call InsertService:LoadAsset() for assets not owned by the creator.

RunClientScript

Indicates that a script container is permitted to execute scripts on the client (LocalScript).

FieldValue
value0

RunServerScript

Indicates that a script container is permitted to execute scripts on the server (Script).

FieldValue
value1

AccessOutsideWrite

Grants a script read-write access to instances that live outside its sandboxed container.

FieldValue
value2

AssetRequire

Deprecated. Use SecurityCapability.LoadUnownedAsset instead.

Deprecated. Use SecurityCapability.LoadUnownedAsset instead.

FieldValue
value3
tags["Deprecated"]

LoadString

Allows a script to use the loadstring() Luau built-in to compile and execute a string as code.

FieldValue
value4

ScriptGlobals

Allows a script to access the shared and _G shared global variable tables.

FieldValue
value5

CreateInstances

Allows a script to create new Instance objects using Instance.new().

FieldValue
value6

Basic

Guards access to a broad set of general-purpose engine APIs that do not belong to a more specific capability category.

FieldValue
value7

Audio

Guards access to audio engine APIs such as Sound, AudioPlayer, and related classes.

FieldValue
value8

DataStore

Guards access to data store APIs such as DataStoreService and its associated objects.

FieldValue
value9

Network

Guards access to low-level networking APIs such as HttpService.

FieldValue
value10

Physics

Guards access to physics engine APIs such as Constraint classes and BasePart physics properties.

FieldValue
value11

UI

Guards access to UI engine APIs such as ScreenGui, Frame, and other GuiObject classes.

FieldValue
value12

CSG

Guards access to Constructive Solid Geometry (CSG) APIs such as UnionOperation and NegateOperation.

FieldValue
value13

Chat

Guards access to chat engine APIs such as TextChatService and related chat classes.

FieldValue
value14

Animation

Guards access to animation engine APIs such as AnimationController and related classes.

FieldValue
value15

Avatar

Deprecated. Use SecurityCapability.AvatarAppearance instead.

Deprecated. Use SecurityCapability.AvatarAppearance instead.

FieldValue
value16
tags["Deprecated"]

Input

Guards access to user input APIs such as UserInputService and ContextActionService.

FieldValue
value17

Environment

Guards access to environment and world-setting APIs such as Lighting and Atmosphere.

FieldValue
value18

RemoteEvent

Guards access to remote event and function APIs such as RemoteEvent and RemoteFunction.

FieldValue
value19

LegacySound

Guards access to the legacy Sound and pre-VoiceChatService.UseAudioApi sound stack APIs.

FieldValue
value20

Players

Guards access to Players service APIs that query or manage connected players.

FieldValue
value21

CapabilityControl

Guards access to the Instance.Capabilities and Instance.Sandboxed properties that configure script sandboxing.

FieldValue
value22

Plugin

Mirrors the legacy Plugin permission level, granting access to Studio plugin APIs.

FieldValue
value23

LocalUser

Mirrors the legacy LocalUser permission level, granting access to IDE-only and Studio-level APIs.

FieldValue
value24

WritePlayer

Mirrors the legacy WritePlayer permission level, granting the ability to modify player identity properties such as name and UserId.

FieldValue
value25

RobloxScript

Mirrors the legacy RobloxScript permission level, granting access to CoreScript APIs.

FieldValue
value26

RobloxEngine

Mirrors the legacy RobloxEngine permission level, granting access to internal engine-level APIs.

FieldValue
value27

Unassigned

The default capability assigned to API members that have not been explicitly assigned to any other capability category.

FieldValue
value28

InternalTest

Restricts access to non-sensitive APIs that are intentionally kept internal.

FieldValue
value29

PluginOrOpenCloud

Restricts access to APIs callable only from Studio plugin or Open Cloud Luau execution sessions.

FieldValue
value30

Assistant

Restricts access to APIs that may only be called from Studio Assistant execution contexts.

FieldValue
value31

RemoteCommand

Restricts access to APIs that are executable only from Studio's RemoteCommandService in Team Create sessions.

FieldValue
value32

AssetRead

Guards access to APIs that read or query asset metadata from the Roblox catalog.

FieldValue
value33

AssetManagement

Guards access to asset management APIs such as ContentProvider:PreloadAsync() and encryption-key registration.

FieldValue
value34

DynamicGeneration

Guards access to procedural and AI-driven content generation APIs such as EditableMesh and AvatarCreationService.

FieldValue
value35

PlatformAvatarEditing

Guards access to platform-level avatar editing APIs provided by AvatarEditorService.

FieldValue
value36

AssetCreateUpdate

Guards access to APIs that create or update published Roblox assets.

FieldValue
value37

Capture

Guards access to CaptureService APIs that take screenshots and record video.

FieldValue
value38

SensitiveInput

Guards access to sensitive user input APIs such as those that can read raw keyboard or mouse data beyond normal game input.

FieldValue
value39

Monetization

Guards access to in-experience purchase and monetization APIs such as MarketplaceService.

FieldValue
value40

LoadOwnedAsset

Allows a script to load assets that are owned by the experience's creator using InsertService or LuaGlobals.require().

FieldValue
value41

Social

Guards access to social APIs such as SocialService, FriendPages, and ExperienceInviteOptions.

FieldValue
value42

ServerCommunication

Guards access to server-to-server messaging APIs such as MessagingService.

FieldValue
value43

Logging

Guards access to LogService and logging-related APIs.

FieldValue
value44

PromptExternalPurchase

Guards access to APIs that initiate external (non-Roblox) purchase prompts.

FieldValue
value45

Groups

Guards access to group-related APIs such as GroupService.

FieldValue
value46

Teleport

Guards access to teleportation APIs such as TeleportService, TeleportOptions, and TeleportAsyncResult.

FieldValue
value47

Consequences

Guards access to moderation and player-consequence APIs such as Players:BanAsync() and ModerationService.

FieldValue
value48

Material

Guards access to MaterialService, MaterialVariant, and custom material APIs.

FieldValue
value49

AvatarBehavior

Guards access to APIs that control avatar locomotion and behavior at runtime.

FieldValue
value50

AvatarAppearance

Guards access to APIs that read or modify avatar appearance, such as HumanoidDescription.

FieldValue
value51

LoadUnownedAsset

Allows a script to LuaGlobals.require() asset IDs or call InsertService:LoadAsset() for assets not owned by the creator.

FieldValue
value52