Roblox Luau Scripting
Script a Roblox experience in Luau: services, Instances, events, the
server/client split, and secure cross-boundary communication. Targets the current
Roblox engine and Studio.
When to use
- Use when writing Roblox scripts: getting services, creating/parenting instances,
connecting events, deciding server vs client, or wiring
RemoteEvent/RemoteFunctioncommunication. - Use when the project has
Script/LocalScript/ModuleScriptobjects,.rbxl(x)places, or a Rojo*.project.json, and code callsgame:GetService(...).
When not to use: persisting data across sessions → roblox-datastores.
Remote protocol architecture, exploit hardening, rate limits, high-frequency replication, and
multi-client abuse testing → roblox-networking. Generic Lua questions unrelated to the Roblox
API. Engine-agnostic input/save architecture → input-systems / save-systems.
Core workflow
- Get services with
game:GetService("Name"). Common ones:Players,Workspace,ReplicatedStorage(shared client+server),ServerScriptService(server-only code),ServerStorage,RunService,UserInputService(client). - Know where code runs. A
Scriptruns on the server; aLocalScriptruns on a client (inStarterPlayerScripts,StarterGui, or the player's character). AModuleScriptis shared code yourequire. - Create instances deliberately.
local p = Instance.new("Part"), set its properties, then setp.Parentlast (parenting triggers replication). - React with events.
:Connectto signals likePlayers.PlayerAdded,part.Touched, orRunService.Heartbeat. Disconnect when done to avoid leaks. - Cross the client/server boundary with Remotes — and never trust the client.
Clients request via
RemoteEvent:FireServer(...); the server validates and applies. The server is authoritative for all game state. - Test in Studio with Play / Play Here / server+client Start; use the Output window and the server/client view toggle to confirm where code ran.
Patterns
1. Server Script: react to players joining (leaderstats)
2. Create and configure an instance
3. Connect an event (and disconnect to avoid leaks)
4. Client → server with a RemoteEvent (validate on the server!)
5. A per-frame loop with RunService
6. Shared code in a ModuleScript
Pitfalls
- Trusting the client is an exploit → clients can send any arguments to a
RemoteEvent/RemoteFunction. Validate every argument's type and range on the server and keep the server authoritative over health, currency, and inventory. LocalScriptdoesn't run where you put it → LocalScripts run inStarterPlayerScripts,StarterCharacterScripts,StarterGui, or tools — not inWorkspaceorServerScriptService. ServerScripts belong inServerScriptService/Workspace.- Deprecated globals → use
task.wait/task.spawn/task.delay, not the oldwait()/spawn()/delay()(worse scheduling and throttling). - Parenting first, then setting properties → set properties first and
Parentlast so the instance replicates once in its final state. nilon the client right after join → objects stream/replicate over time; useparent:WaitForChild("Name")instead of indexing directly on the client.- Connections never disconnected → long-lived
:Connecthandlers leak and can fire on destroyed objects; store the connection and:Disconnect()(or useInstance:GetAttributeChangedSignal/:Oncewhere appropriate). - Using a RemoteFunction where a RemoteEvent fits →
RemoteFunctionblocks waiting for a return and a malicious/slow client can stall the server; prefer one-wayRemoteEvents unless you genuinely need a reply. - Assuming the old type checker -> Luau's New Type Solver reached general release
(out of Studio Beta) in Nov 2025.
nocheck/non-strict places get it automatically; strict-mode places opt in with theUseNewLuauTypeSolverworkspace property, andLuauTypeCheckModesets a place's default checking mode. It runs only at edit time (no runtime cost), so triage type warnings against the solver the place actually has enabled, not older behavior.
References
- For the full client/server model (replication,
RemoteFunctionvsRemoteEvent,:WaitForChildtiming,BindableEventfor same-context messaging, attributes,CollectionServicetags, and:Once/connection cleanup), readreferences/client-server.md.
Related skills
roblox-datastores— persist player data across sessions (server-only).roblox-networking— production remote contracts, server validation, rate limits, replication, streaming, prediction, and multi-client testing.save-systems— engine-agnostic persistence concepts.game-ai/input-systems— portable AI and input patterns to implement in Luau.


