6 min read

Source: Roblox Creator Hub · CC BY 4.0 · View source · Code samples: MIT Imported 2026-10-03. Formatting adapted for this site.

In-game HTTP requests

You can use HttpService to send generic HTTP requests to third-party web services for use cases like analytics, data storage, or error logging. HttpService also supports certain Open Cloud endpoints.

Enable HTTP requests

The HttpService:GetAsync(), HttpService:PostAsync(), and HttpService:RequestAsync() methods aren't enabled by default. To send requests, you must Allow HTTP Requests under File ⟩ Experience Settings ⟩ Security in Studio.

Use in plugins

You can use HttpService in Studio plugins to check for updates, download content, or other business logic. The first time a plugin attempts to use the service, the user might be prompted to give the plugin permission to communicate with the particular web address. Users can accept, deny, and revoke these permissions at any time through the Plugin Management window.

Plugins can also communicate with other software running on the same computer through the localhost and 127.0.0.1 hosts. By running programs compatible with such plugins, you can extend the functionality of your plugin beyond the normal capabilities of Studio, such as interacting with your computer's file system. Beware that such software must be distributed separately from the plugin itself and can pose security risks.

Use with Open Cloud

HttpService can currently call a subset of the Open Cloud endpoints. You can call these endpoints the same way that you'd call any other endpoint via HttpService. The only difference is that you must include an Open Cloud API key in the request:

  1. Create an Open Cloud API key.
  2. Save the API key to your secrets store.
  3. Make the request.

The following code sample demonstrates how to update a user's group membership from within a game:

local HttpService = game:GetService("HttpService")

local groupId = "your_group_id"
local membershipId = "your_membership_id"
local roleId = "your_role_id"

local function request()
	local response = HttpService:RequestAsync({
		Url = `https://apis.roblox.com/cloud/v2/groups/{groupId}/memberships/{membershipId}`,
		Method = "PATCH",
		Headers = {
			["Content-Type"] = "application/json", -- When sending JSON, set this!
			["x-api-key"] = HttpService:GetSecret("APIKey"), -- Set in Creator Hub
		},
		Body = HttpService:JSONEncode({ role = `groups/{groupId}/roles/{roleId}` }),
	})

	if response.Success then
		print("The response was successful:", response.StatusCode, response.StatusMessage)
	else
		print("The response returned an error:", response.StatusCode, response.StatusMessage)
	end
	print("Response body:\n", response.Body)
	print("Response headers:\n", HttpService:JSONEncode(response.Headers))
end

-- Wrap the function in pcall() for safety
local success, errorMessage = pcall(request)
if not success then
	print("The HTTP request failed to send:", errorMessage)
end

Supported Open Cloud endpoints

The following endpoints are supported. Due to current limitations on HttpService, the .. string is not allowed in URL path parameters to Roblox domains. This means, for example, that data stores and entries containing this string are currently inaccessible from HttpService.

Assets

Bans and blocks

Configs

Creator Store

Developer products

Game passes

Data and memory stores

Data stores:

Memory stores:

Ordered data stores:

Groups

Inventories

Luau execution

Notifications

Places

Universes

Users

Limitations

Rate limits

For each Roblox game server, there is a limit of 2500 Open Cloud requests per minute. Exceeding this can cause request-sending methods to stall for around 30 seconds. Your LuaGlobals.pcall() may also fail with a message of Number of Open Cloud requests exceeded limit.

For detailed information about Open Cloud rate limits, authentication-based rate limiting, and best practices, see Rate Limits.

Best practices

To optimize your HttpService usage and avoid exceeding the limits, apply the following best practices:

Observability

The Observability Dashboard provides insights and analytics for monitoring and troubleshooting your HttpService usage. The dashboard features two primary charts: Request Count which tracks the volume of HttpService requests from your game, and Response Time which measures the latency for endpoints to respond.

The available dimensions for filtering and breakdown are defined as follows:

Request Type

Status

The Response Time chart is not correlated with status data. If you select "Status" as a breakdown or filter, this chart will not display data.

Additional considerations