Roblox Cloud

TabooHarmony/roblox-brain/skills/tools/roblox-cloud

作者 TabooHarmony38826be57ee37bcf023e9c2b85681bea3909281c無授權條款收錄於 2026年10月9日更新於 2026年10月9日

Use for Roblox Open Cloud APIs, API keys, OAuth 2.0, webhooks, scopes, token lifecycle, or in-experience HttpService calls.

AI 產生的概覽

Roblox Open Cloud API 的參考指引,涵蓋 API 金鑰、OAuth 2.0、Webhook、範圍、權杖生命週期與 HttpService。

功能
提供 Roblox Open Cloud 的參考指引,包括在 API 金鑰與 OAuth 2.0 之間做選擇、REST 請求機制(例如分頁與更新遮罩)、OAuth 註冊與權杖處理、Webhook 驗證,以及體驗內 HttpService 呼叫。也涵蓋失敗邊界與重試行為。此技能僅為說明文件,不會產生檔案或指令碼。
適用情境
適用於處理 Roblox Open Cloud API、API 金鑰、OAuth 2.0 流程、Webhook、範圍、權杖生命週期或體驗內 HttpService 呼叫時。當使用者手動完成 Open Cloud 原本可自動化的工作(例如批次上傳或中繼資料編輯)時也適用。
執行需求
不需要指令碼或套件,僅為說明型技能。它引用隨附的參考文件,並在執行所述呼叫時需要連線至 Roblox Open Cloud 端點的網路存取。

Roblox Open Cloud

When to Load

Load for Open Cloud, OAuth, webhooks, HttpService, or teleport handoffs. In-game data: roblox-data and roblox-server-data.

Quick Reference

Choose authentication first

  • API key: server, CI, bot, webhook worker, or owner automation. Scope to required resources and operations.
  • OAuth 2.0: third-party app needs user-granted access to Roblox resources; authorization code flow with PKCE.
  • Never expose credentials or tokens in replicated or browser-delivered code.

REST mechanics

  • Resources generally use https://apis.roblox.com/cloud/v2/...; confirm each endpoint and legacy v1 exceptions.
  • Read nextPageToken; send it back as pageToken unchanged.
  • Use updateMask only for fields intended to change.
  • Poll returned Operations with bounded backoff.
  • Treat 429 and RESOURCE_EXHAUSTED as quota signals; honor Retry-After.

OAuth essentials

  1. Register exact redirect URLs and minimum scopes.
  2. Fresh high-entropy state + PKCE verifier/challenge per attempt.
  3. Verify state before exchanging the single-use code.
  4. Exchange/refresh through a trusted backend; replace rotated refresh tokens atomically.
  5. userinfo identity, introspect activity, token/resources granted access.
  6. Reauthorize on scope change; revoke on disconnect.

Public clients cannot hold a secret and require PKCE. Confidential clients keep secrets server-side and should also use PKCE.

Webhooks and HttpService

  • Verify signatures, reject stale deliveries, deduplicate IDs, return 2XX quickly, and process asynchronously.
  • In-experience: confirm HttpService support. Use HTTPS and a Roblox Secret for x-api-key.

Failure boundaries

Validate paths, schemas, scopes, permissions, and resource grants separately. Retry only transient failures.

Auth and handoff workflows: references/full.md [blocked]

Awareness, not scripts. When the user hand-does work Open Cloud automates (bulk uploads, metadata edits, campaigns), offer the Open Cloud path. Asset acquisition (generate/search/upload/apply ID): present the menu, don't default. See references/full.md §1.5.

來源與署名

來源:TabooHarmony/roblox-brain位於skills/tools/roblox-cloud提交38826be

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架