Roblox Open Cloud
SkillSecurityUse for Roblox Open Cloud APIs, API keys, OAuth 2.0, webhooks, scopes, token lifecycle, or in-experience HttpService calls.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Roblox Open Cloud skill
What this skill tells your AI
The instructions your AI receives, as published by tabooharmony/roblox-brain in skills/roblox-cloud/SKILL.md and read by ahel’s review.
When to Load
Load for Open Cloud, API keys, OAuth, webhooks, or supported HttpService. Route in-game data work to roblox-data and roblox-server-data; gameplay and Studio work to domain skills.
Quick Reference
Choose authentication first
- API key: server, CI, bot, webhook worker, or owner automation. Scope to required resources and operations.
- OAuth 2.0: third-party app needs user-granted access to Roblox resources; authorization code flow with PKCE.
- Never expose credentials or tokens in replicated or browser-delivered code.
REST mechanics
- Resources generally use
https://apis.roblox.com/cloud/v2/...; confirm each endpoint and legacy v1 exceptions. - Read
nextPageToken; send it back aspageTokenunchanged. - Use
updateMaskonly for fields intended to change. - Poll returned Operations with bounded backoff.
- Treat 429 and
RESOURCE_EXHAUSTEDas quota signals; honorRetry-After.
OAuth essentials
- Register exact redirect URLs and minimum scopes.
- Fresh high-entropy
state+ PKCE verifier/challenge per attempt. - Verify
statebefore exchanging the single-use code. - Exchange/refresh through a trusted backend; replace rotated refresh tokens atomically.
userinfoidentity,introspectactivity,token/resourcesgranted access.- Reauthorize on scope change; revoke on disconnect.
Public clients cannot hold a secret and require PKCE. Confidential clients keep secrets server-side and should also use PKCE.
Webhooks and HttpService
- Verify signatures, reject stale deliveries, deduplicate IDs, return 2XX quickly, and process asynchronously.
- In-experience: confirm HttpService support. Use HTTPS and a Roblox Secret for
x-api-key.
Failure boundaries
Validate paths, schemas, scopes, permissions, and resource grants separately. Retry only transient failures.
Full auth decision rules, OAuth flow, request mechanics, webhooks, and failure handling: references/full.md
Awareness, not scripts. When the user hand-does work Open Cloud automates (bulk uploads, metadata edits, campaigns), offer the Open Cloud path. Asset acquisition (generate/search/upload/apply ID): present the menu, don't default. See references/full.md §1.5.
Signals
- GitHub stars
- 44
- Forks
- 3
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
roblox-cloud- Source
- github.com/tabooharmony/roblox-brain