Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.
SecurityCapability
SecurityCapability is a bitmask-based permission system that controls which engine APIs and Luau language features are accessible to scripts running inside sandboxed containers. Each value represents one capability bit that can be granted or restricted.
When an Instance has its Sandboxed property enabled, the engine intersects the capabilities of all ancestor containers to determine the effective permission set of any script that executes within that container. API members, classes, and Luau built-ins are each annotated with one or more SecurityCapability values; a script's thread must hold every required capability to call them.
Items
| Name | Value | Description |
|---|---|---|
| RunClientScript | 0 | Indicates that a script container is permitted to execute scripts on the client (LocalScript). |
| RunServerScript | 1 | Indicates that a script container is permitted to execute scripts on the server (Script). |
| AccessOutsideWrite | 2 | Grants a script read-write access to instances that live outside its sandboxed container. |
| AssetRequire | 3 | Deprecated. Use SecurityCapability.LoadUnownedAsset instead. |
| LoadString | 4 | Allows a script to use the loadstring() Luau built-in to compile and execute a string as code. |
| ScriptGlobals | 5 | Allows a script to access the shared and _G shared global variable tables. |
| CreateInstances | 6 | Allows a script to create new Instance objects using Instance.new(). |
| Basic | 7 | Guards access to a broad set of general-purpose engine APIs that do not belong to a more specific capability category. |
| Audio | 8 | Guards access to audio engine APIs such as Sound, AudioPlayer, and related classes. |
| DataStore | 9 | Guards access to data store APIs such as DataStoreService and its associated objects. |
| Network | 10 | Guards access to low-level networking APIs such as HttpService. |
| Physics | 11 | Guards access to physics engine APIs such as Constraint classes and BasePart physics properties. |
| UI | 12 | Guards access to UI engine APIs such as ScreenGui, Frame, and other GuiObject classes. |
| CSG | 13 | Guards access to Constructive Solid Geometry (CSG) APIs such as UnionOperation and NegateOperation. |
| Chat | 14 | Guards access to chat engine APIs such as TextChatService and related chat classes. |
| Animation | 15 | Guards access to animation engine APIs such as AnimationController and related classes. |
| Avatar | 16 | Deprecated. Use SecurityCapability.AvatarAppearance instead. |
| Input | 17 | Guards access to user input APIs such as UserInputService and ContextActionService. |
| Environment | 18 | Guards access to environment and world-setting APIs such as Lighting and Atmosphere. |
| RemoteEvent | 19 | Guards access to remote event and function APIs such as RemoteEvent and RemoteFunction. |
| LegacySound | 20 | Guards access to the legacy Sound and pre-VoiceChatService.UseAudioApi sound stack APIs. |
| Players | 21 | Guards access to Players service APIs that query or manage connected players. |
| CapabilityControl | 22 | Guards access to the Instance.Capabilities and Instance.Sandboxed properties that configure script sandboxing. |
| Plugin | 23 | Mirrors the legacy Plugin permission level, granting access to Studio plugin APIs. |
| LocalUser | 24 | Mirrors the legacy LocalUser permission level, granting access to IDE-only and Studio-level APIs. |
| WritePlayer | 25 | Mirrors the legacy WritePlayer permission level, granting the ability to modify player identity properties such as name and UserId. |
| RobloxScript | 26 | Mirrors the legacy RobloxScript permission level, granting access to CoreScript APIs. |
| RobloxEngine | 27 | Mirrors the legacy RobloxEngine permission level, granting access to internal engine-level APIs. |
| Unassigned | 28 | The default capability assigned to API members that have not been explicitly assigned to any other capability category. |
| InternalTest | 29 | Restricts access to non-sensitive APIs that are intentionally kept internal. |
| PluginOrOpenCloud | 30 | Restricts access to APIs callable only from Studio plugin or Open Cloud Luau execution sessions. |
| Assistant | 31 | Restricts access to APIs that may only be called from Studio Assistant execution contexts. |
| RemoteCommand | 32 | Restricts access to APIs that are executable only from Studio's RemoteCommandService in Team Create sessions. |
| AssetRead | 33 | Guards access to APIs that read or query asset metadata from the Roblox catalog. |
| AssetManagement | 34 | Guards access to asset management APIs such as ContentProvider:PreloadAsync() and encryption-key registration. |
| DynamicGeneration | 35 | Guards access to procedural and AI-driven content generation APIs such as EditableMesh and AvatarCreationService. |
| PlatformAvatarEditing | 36 | Guards access to platform-level avatar editing APIs provided by AvatarEditorService. |
| AssetCreateUpdate | 37 | Guards access to APIs that create or update published Roblox assets. |
| Capture | 38 | Guards access to CaptureService APIs that take screenshots and record video. |
| SensitiveInput | 39 | Guards access to sensitive user input APIs such as those that can read raw keyboard or mouse data beyond normal game input. |
| Monetization | 40 | Guards access to in-experience purchase and monetization APIs such as MarketplaceService. |
| LoadOwnedAsset | 41 | Allows a script to load assets that are owned by the experience's creator using InsertService or LuaGlobals.require(). |
| Social | 42 | Guards access to social APIs such as SocialService, FriendPages, and ExperienceInviteOptions. |
| ServerCommunication | 43 | Guards access to server-to-server messaging APIs such as MessagingService. |
| Logging | 44 | Guards access to LogService and logging-related APIs. |
| PromptExternalPurchase | 45 | Guards access to APIs that initiate external (non-Roblox) purchase prompts. |
| Groups | 46 | Guards access to group-related APIs such as GroupService. |
| Teleport | 47 | Guards access to teleportation APIs such as TeleportService, TeleportOptions, and TeleportAsyncResult. |
| Consequences | 48 | Guards access to moderation and player-consequence APIs such as Players:BanAsync() and ModerationService. |
| Material | 49 | Guards access to MaterialService, MaterialVariant, and custom material APIs. |
| AvatarBehavior | 50 | Guards access to APIs that control avatar locomotion and behavior at runtime. |
| AvatarAppearance | 51 | Guards access to APIs that read or modify avatar appearance, such as HumanoidDescription. |
| LoadUnownedAsset | 52 | Allows a script to LuaGlobals.require() asset IDs or call InsertService:LoadAsset() for assets not owned by the creator. |
RunClientScript
Indicates that a script container is permitted to execute scripts on the client (LocalScript).
| Field | Value |
|---|---|
| value | 0 |
RunServerScript
Indicates that a script container is permitted to execute scripts on the server (Script).
| Field | Value |
|---|---|
| value | 1 |
AccessOutsideWrite
Grants a script read-write access to instances that live outside its sandboxed container.
| Field | Value |
|---|---|
| value | 2 |
AssetRequire
Deprecated. Use SecurityCapability.LoadUnownedAsset instead.
Deprecated. Use SecurityCapability.LoadUnownedAsset instead.
| Field | Value |
|---|---|
| value | 3 |
| tags | ["Deprecated"] |
LoadString
Allows a script to use the loadstring() Luau built-in to compile and execute a string as code.
| Field | Value |
|---|---|
| value | 4 |
ScriptGlobals
Allows a script to access the shared and _G shared global variable tables.
| Field | Value |
|---|---|
| value | 5 |
CreateInstances
Allows a script to create new Instance objects using Instance.new().
| Field | Value |
|---|---|
| value | 6 |
Basic
Guards access to a broad set of general-purpose engine APIs that do not belong to a more specific capability category.
| Field | Value |
|---|---|
| value | 7 |
Audio
Guards access to audio engine APIs such as Sound, AudioPlayer, and related classes.
| Field | Value |
|---|---|
| value | 8 |
DataStore
Guards access to data store APIs such as DataStoreService and its associated objects.
| Field | Value |
|---|---|
| value | 9 |
Network
Guards access to low-level networking APIs such as HttpService.
| Field | Value |
|---|---|
| value | 10 |
Physics
Guards access to physics engine APIs such as Constraint classes and BasePart physics properties.
| Field | Value |
|---|---|
| value | 11 |
UI
Guards access to UI engine APIs such as ScreenGui, Frame, and other GuiObject classes.
| Field | Value |
|---|---|
| value | 12 |
CSG
Guards access to Constructive Solid Geometry (CSG) APIs such as UnionOperation and NegateOperation.
| Field | Value |
|---|---|
| value | 13 |
Chat
Guards access to chat engine APIs such as TextChatService and related chat classes.
| Field | Value |
|---|---|
| value | 14 |
Animation
Guards access to animation engine APIs such as AnimationController and related classes.
| Field | Value |
|---|---|
| value | 15 |
Avatar
Deprecated. Use SecurityCapability.AvatarAppearance instead.
Deprecated. Use SecurityCapability.AvatarAppearance instead.
| Field | Value |
|---|---|
| value | 16 |
| tags | ["Deprecated"] |
Input
Guards access to user input APIs such as UserInputService and ContextActionService.
| Field | Value |
|---|---|
| value | 17 |
Environment
Guards access to environment and world-setting APIs such as Lighting and Atmosphere.
| Field | Value |
|---|---|
| value | 18 |
RemoteEvent
Guards access to remote event and function APIs such as RemoteEvent and RemoteFunction.
| Field | Value |
|---|---|
| value | 19 |
LegacySound
Guards access to the legacy Sound and pre-VoiceChatService.UseAudioApi sound stack APIs.
| Field | Value |
|---|---|
| value | 20 |
Players
Guards access to Players service APIs that query or manage connected players.
| Field | Value |
|---|---|
| value | 21 |
CapabilityControl
Guards access to the Instance.Capabilities and Instance.Sandboxed properties that configure script sandboxing.
| Field | Value |
|---|---|
| value | 22 |
Plugin
Mirrors the legacy Plugin permission level, granting access to Studio plugin APIs.
| Field | Value |
|---|---|
| value | 23 |
LocalUser
Mirrors the legacy LocalUser permission level, granting access to IDE-only and Studio-level APIs.
| Field | Value |
|---|---|
| value | 24 |
WritePlayer
Mirrors the legacy WritePlayer permission level, granting the ability to modify player identity properties such as name and UserId.
| Field | Value |
|---|---|
| value | 25 |
RobloxScript
Mirrors the legacy RobloxScript permission level, granting access to CoreScript APIs.
| Field | Value |
|---|---|
| value | 26 |
RobloxEngine
Mirrors the legacy RobloxEngine permission level, granting access to internal engine-level APIs.
| Field | Value |
|---|---|
| value | 27 |
Unassigned
The default capability assigned to API members that have not been explicitly assigned to any other capability category.
| Field | Value |
|---|---|
| value | 28 |
InternalTest
Restricts access to non-sensitive APIs that are intentionally kept internal.
| Field | Value |
|---|---|
| value | 29 |
PluginOrOpenCloud
Restricts access to APIs callable only from Studio plugin or Open Cloud Luau execution sessions.
| Field | Value |
|---|---|
| value | 30 |
Assistant
Restricts access to APIs that may only be called from Studio Assistant execution contexts.
| Field | Value |
|---|---|
| value | 31 |
RemoteCommand
Restricts access to APIs that are executable only from Studio's RemoteCommandService in Team Create sessions.
| Field | Value |
|---|---|
| value | 32 |
AssetRead
Guards access to APIs that read or query asset metadata from the Roblox catalog.
| Field | Value |
|---|---|
| value | 33 |
AssetManagement
Guards access to asset management APIs such as ContentProvider:PreloadAsync() and encryption-key registration.
| Field | Value |
|---|---|
| value | 34 |
DynamicGeneration
Guards access to procedural and AI-driven content generation APIs such as EditableMesh and AvatarCreationService.
| Field | Value |
|---|---|
| value | 35 |
PlatformAvatarEditing
Guards access to platform-level avatar editing APIs provided by AvatarEditorService.
| Field | Value |
|---|---|
| value | 36 |
AssetCreateUpdate
Guards access to APIs that create or update published Roblox assets.
| Field | Value |
|---|---|
| value | 37 |
Capture
Guards access to CaptureService APIs that take screenshots and record video.
| Field | Value |
|---|---|
| value | 38 |
SensitiveInput
Guards access to sensitive user input APIs such as those that can read raw keyboard or mouse data beyond normal game input.
| Field | Value |
|---|---|
| value | 39 |
Monetization
Guards access to in-experience purchase and monetization APIs such as MarketplaceService.
| Field | Value |
|---|---|
| value | 40 |
LoadOwnedAsset
Allows a script to load assets that are owned by the experience's creator using InsertService or LuaGlobals.require().
| Field | Value |
|---|---|
| value | 41 |
Social
Guards access to social APIs such as SocialService, FriendPages, and ExperienceInviteOptions.
| Field | Value |
|---|---|
| value | 42 |
ServerCommunication
Guards access to server-to-server messaging APIs such as MessagingService.
| Field | Value |
|---|---|
| value | 43 |
Logging
Guards access to LogService and logging-related APIs.
| Field | Value |
|---|---|
| value | 44 |
PromptExternalPurchase
Guards access to APIs that initiate external (non-Roblox) purchase prompts.
| Field | Value |
|---|---|
| value | 45 |
Groups
Guards access to group-related APIs such as GroupService.
| Field | Value |
|---|---|
| value | 46 |
Teleport
Guards access to teleportation APIs such as TeleportService, TeleportOptions, and TeleportAsyncResult.
| Field | Value |
|---|---|
| value | 47 |
Consequences
Guards access to moderation and player-consequence APIs such as Players:BanAsync() and ModerationService.
| Field | Value |
|---|---|
| value | 48 |
Material
Guards access to MaterialService, MaterialVariant, and custom material APIs.
| Field | Value |
|---|---|
| value | 49 |
AvatarBehavior
Guards access to APIs that control avatar locomotion and behavior at runtime.
| Field | Value |
|---|---|
| value | 50 |
AvatarAppearance
Guards access to APIs that read or modify avatar appearance, such as HumanoidDescription.
| Field | Value |
|---|---|
| value | 51 |
LoadUnownedAsset
Allows a script to LuaGlobals.require() asset IDs or call InsertService:LoadAsset() for assets not owned by the creator.
| Field | Value |
|---|---|
| value | 52 |