Roblox Cloud

TabooHarmony/roblox-brain/skills/tools/roblox-cloud

作者 TabooHarmony38826be57ee37bcf023e9c2b85681bea3909281c无许可证收录于 2026年10月9日更新于 2026年10月9日

Use for Roblox Open Cloud APIs, API keys, OAuth 2.0, webhooks, scopes, token lifecycle, or in-experience HttpService calls.

AI 生成的概览

关于 Roblox Open Cloud API 的参考指南,涵盖 API 密钥、OAuth 2.0、Webhook、作用域、令牌生命周期和 HttpService。

功能
提供 Roblox Open Cloud 的参考指导,包括在 API 密钥与 OAuth 2.0 之间做选择、REST 请求机制(如分页和更新掩码)、OAuth 注册与令牌处理、Webhook 验证,以及体验内 HttpService 调用。还涉及失败边界与重试行为。该技能仅为说明文档,不生成文件或脚本。
适用场景
适用于处理 Roblox Open Cloud API、API 密钥、OAuth 2.0 流程、Webhook、作用域、令牌生命周期或体验内 HttpService 调用时。当用户手动完成 Open Cloud 本可自动化的操作(如批量上传或元数据编辑)时也适用。
运行要求
无需脚本或软件包,仅为说明型技能。它引用随附的参考文档,并在执行所述调用时需要访问 Roblox Open Cloud 端点的网络连接。

Roblox Open Cloud

When to Load

Load for Open Cloud, OAuth, webhooks, HttpService, or teleport handoffs. In-game data: roblox-data and roblox-server-data.

Quick Reference

Choose authentication first

  • API key: server, CI, bot, webhook worker, or owner automation. Scope to required resources and operations.
  • OAuth 2.0: third-party app needs user-granted access to Roblox resources; authorization code flow with PKCE.
  • Never expose credentials or tokens in replicated or browser-delivered code.

REST mechanics

  • Resources generally use https://apis.roblox.com/cloud/v2/...; confirm each endpoint and legacy v1 exceptions.
  • Read nextPageToken; send it back as pageToken unchanged.
  • Use updateMask only for fields intended to change.
  • Poll returned Operations with bounded backoff.
  • Treat 429 and RESOURCE_EXHAUSTED as quota signals; honor Retry-After.

OAuth essentials

  1. Register exact redirect URLs and minimum scopes.
  2. Fresh high-entropy state + PKCE verifier/challenge per attempt.
  3. Verify state before exchanging the single-use code.
  4. Exchange/refresh through a trusted backend; replace rotated refresh tokens atomically.
  5. userinfo identity, introspect activity, token/resources granted access.
  6. Reauthorize on scope change; revoke on disconnect.

Public clients cannot hold a secret and require PKCE. Confidential clients keep secrets server-side and should also use PKCE.

Webhooks and HttpService

  • Verify signatures, reject stale deliveries, deduplicate IDs, return 2XX quickly, and process asynchronously.
  • In-experience: confirm HttpService support. Use HTTPS and a Roblox Secret for x-api-key.

Failure boundaries

Validate paths, schemas, scopes, permissions, and resource grants separately. Retry only transient failures.

Auth and handoff workflows: references/full.md [blocked]

Awareness, not scripts. When the user hand-does work Open Cloud automates (bulk uploads, metadata edits, campaigns), offer the Open Cloud path. Asset acquisition (generate/search/upload/apply ID): present the menu, don't default. See references/full.md §1.5.

来源与署名

来源:TabooHarmony/roblox-brain位于skills/tools/roblox-cloud提交38826be

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架