Skip to content

Set up Roblox

Your game needs two settings to call Rolink, a Roblox OAuth app so players can sign in on your linking page, and two more settings if you want live events.

SettingWhereNeeded for
HTTP requestsStudio: File > Experience Settings > SecurityEverything
rolink_api_key SecretCreator Dashboard > your experience > Secrets, plus Local Secrets in StudioEverything
Roblox OAuth appCreator Dashboard > OAuth 2.0 Apps, then the Rolink dashboardWallet linking
Open Cloud API keyCreator Dashboard > Open Cloud > API Keys, then the Rolink dashboardLive events (optional)
Universe IDCreator Dashboard, then the Rolink dashboardLive events (optional)

In Studio, open File > Experience Settings > Security and turn on Allow HTTP Requests. The SDK sends every call through HttpService. If the setting is unavailable, publish the place first.

Roblox allows about 500 HTTP requests per minute per server. The SDK caches wallet lookups and fetches them in bulk, which helps you stay under it. Balance, token and asset reads aren’t cached on the game server, so each call is one request, plus retries. How it works has the details.

Game servers authenticate with an API key from your project’s API keys page in the dashboard. Keys start with rlk_live_. Keep yours in a Roblox Secret, not in a script.

  1. In Creator Dashboard, open your experience, then Secrets, and create a secret named rolink_api_key.
  2. Set its value to the API key.
  3. Set its domain to api.rolink.tech. The secret can then only be sent to Rolink.

Read it on the server and pass it to the SDK:

local HttpService = game:GetService("HttpService")
local Rolink = require(game:GetService("ServerScriptService").Rolink)
local rolink = Rolink.new({
apiKey = HttpService:GetSecret("rolink_api_key"),
})

A Secret can be sent in a request but never read back, so the key never appears in your place file. Rolink.new refuses to run on the client, which keeps the key on your servers.

For Studio, add the same secret under File > Experience Settings > Security > Local Secrets, with the same domain. Studio sessions use Local Secrets, not the ones in Creator Dashboard. You can give Studio its own key, so you can revoke one without touching the other.

To rotate a key:

  1. Create a new key in the dashboard.
  2. Update the rolink_api_key Secret with the new value.
  3. Once your servers have restarted with the new Secret, revoke the old key. Servers still using a revoked key are refused within 30 seconds.

A project can have up to 10 active keys at a time.

Players sign in with Roblox on your linking page through your game’s own OAuth 2.0 app. Rolink has no Roblox app of its own, so you create one under your name, and Roblox reviews it.

  1. In Creator Dashboard, open OAuth 2.0 Apps and create an app for your game.
  2. Add the redirect URL https://api.rolink.tech/auth/roblox/callback. It’s the same for every game, and it must match exactly.
  3. Allow the openid and profile scopes.
  4. In the Rolink dashboard, open your project’s Settings, then Roblox sign-in. Paste the app’s client ID and client secret, and save.

Rolink encrypts the client secret at rest with AES-256-GCM, and the dashboard never shows it again. Until Roblox reviews the app, it works for up to 10 users, which is enough to test. Get it reviewed before launch. Link wallets covers what players see.

Live events tell every running server when a player links or unlinks a wallet, when a transaction from the managed wallet finishes, and when a watched address has new activity. Rolink publishes them to your experience through Open Cloud MessagingService, with an Open Cloud key that you create and own. The SDK receives them with MessagingService:SubscribeAsync.

  1. Create the key. In Creator Dashboard, open Open Cloud > API Keys and create a key.

  2. Grant one permission. Under access permissions, add the messaging-service API system with the universe-messaging-service:publish operation, scoped to your experience. Rolink needs nothing else.

  3. Check its restrictions. If you restrict the key’s accepted IP addresses, the restriction has to allow Rolink’s requests, otherwise Roblox refuses them. If you set an expiration date, note it: when the key expires, events stop until you paste a new one.

  4. Copy your universe ID. It’s the ID of the experience as a whole, not the place ID in your experience’s URL. Creator Dashboard shows it for each experience.

  5. Enter both in Rolink. In the dashboard, open your project’s Settings, then Live events. Paste the universe ID and the Open Cloud key, keep the event topic as rolink unless you have a reason to change it, and save.

  6. Send a test event. Use Send test event on the same page. Rolink publishes a ping message with your settings and tells you whether Roblox accepted it. A refusal comes with Roblox’s HTTP status and a hint, such as checking the key’s permission or the universe ID.

Rolink encrypts the Open Cloud key at rest with AES-256-GCM and decrypts it only to publish your events. The dashboard never shows it again.

Once both values are saved, rolink:GetProject().events returns true.

Rolink publishes to your project’s event topic, and the SDK subscribes to its topic option. Both default to rolink. If you change one, change the other:

local rolink = Rolink.new({
apiKey = HttpService:GetSecret("rolink_api_key"),
topic = "rolink", -- must match the event topic in the dashboard
})

Without the Open Cloud key, everything except live events still works. Servers see a new link on their first lookup after their wallet cache expires (walletCacheSeconds, 60 by default). MessagingService is best-effort even when it’s on, so read the API when you need the authoritative state. See Live events.

Players link their wallet at your project’s hosted page, in a browser:

https://api.rolink.tech/link/<project-slug>

The dashboard shows the exact URL on the project’s Overview page, and rolink:GetProject().linkUrl returns it in game. Roblox restricts which off-platform links an experience can show, so check the current rules before you show this URL in your game. Use Rolink responsibly covers what to check.

From a server script, GetProject shows which project the key belongs to and whether live events are configured:

local ok, project = pcall(rolink.GetProject, rolink)
if ok then
print(project.name, project.cluster, project.linkUrl, project.events)
else
warn(project) -- "[Rolink] unauthorized: ..." means the key is wrong or revoked
end

From a terminal, the same route answers with JSON:

Terminal window
curl -H "x-api-key: <your API key>" https://api.rolink.tech/v1/project

walletAddress is your project’s managed wallet once you create it, and events is true once the universe ID and Open Cloud key are saved.