Set up Roblox
Your game needs two settings to call Rolink, a Roblox OAuth app so players can sign in on your linking page, and two more settings if you want live events.
| Setting | Where | Needed for |
|---|---|---|
| HTTP requests | Studio: File > Experience Settings > Security | Everything |
rolink_api_key Secret | Creator Dashboard > your experience > Secrets, plus Local Secrets in Studio | Everything |
| Roblox OAuth app | Creator Dashboard > OAuth 2.0 Apps, then the Rolink dashboard | Wallet linking |
| Open Cloud API key | Creator Dashboard > Open Cloud > API Keys, then the Rolink dashboard | Live events (optional) |
| Universe ID | Creator Dashboard, then the Rolink dashboard | Live events (optional) |
Allow HTTP requests
Section titled “Allow HTTP requests”In Studio, open File > Experience Settings > Security and turn on Allow HTTP Requests. The SDK sends every call through HttpService. If the setting is unavailable, publish the place first.
Roblox allows about 500 HTTP requests per minute per server. The SDK caches wallet lookups and fetches them in bulk, which helps you stay under it. Balance, token and asset reads aren’t cached on the game server, so each call is one request, plus retries. How it works has the details.
Store the API key as a Secret
Section titled “Store the API key as a Secret”Game servers authenticate with an API key from your project’s API keys page in the dashboard. Keys start with rlk_live_. Keep yours in a Roblox Secret, not in a script.
- In Creator Dashboard, open your experience, then Secrets, and create a secret named
rolink_api_key. - Set its value to the API key.
- Set its domain to
api.rolink.tech. The secret can then only be sent to Rolink.
Read it on the server and pass it to the SDK:
local HttpService = game:GetService("HttpService")local Rolink = require(game:GetService("ServerScriptService").Rolink)
local rolink = Rolink.new({ apiKey = HttpService:GetSecret("rolink_api_key"),})A Secret can be sent in a request but never read back, so the key never appears in your place file. Rolink.new refuses to run on the client, which keeps the key on your servers.
For Studio, add the same secret under File > Experience Settings > Security > Local Secrets, with the same domain. Studio sessions use Local Secrets, not the ones in Creator Dashboard. You can give Studio its own key, so you can revoke one without touching the other.
To rotate a key:
- Create a new key in the dashboard.
- Update the
rolink_api_keySecret with the new value. - Once your servers have restarted with the new Secret, revoke the old key. Servers still using a revoked key are refused within 30 seconds.
A project can have up to 10 active keys at a time.
Create an OAuth app for player sign-in
Section titled “Create an OAuth app for player sign-in”Players sign in with Roblox on your linking page through your game’s own OAuth 2.0 app. Rolink has no Roblox app of its own, so you create one under your name, and Roblox reviews it.
- In Creator Dashboard, open OAuth 2.0 Apps and create an app for your game.
- Add the redirect URL
https://api.rolink.tech/auth/roblox/callback. It’s the same for every game, and it must match exactly. - Allow the
openidandprofilescopes. - In the Rolink dashboard, open your project’s Settings, then Roblox sign-in. Paste the app’s client ID and client secret, and save.
Rolink encrypts the client secret at rest with AES-256-GCM, and the dashboard never shows it again. Until Roblox reviews the app, it works for up to 10 users, which is enough to test. Get it reviewed before launch. Link wallets covers what players see.
Add an Open Cloud key for live events
Section titled “Add an Open Cloud key for live events”Live events tell every running server when a player links or unlinks a wallet, when a transaction from the managed wallet finishes, and when a watched address has new activity. Rolink publishes them to your experience through Open Cloud MessagingService, with an Open Cloud key that you create and own. The SDK receives them with MessagingService:SubscribeAsync.
-
Create the key. In Creator Dashboard, open Open Cloud > API Keys and create a key.
-
Grant one permission. Under access permissions, add the
messaging-serviceAPI system with theuniverse-messaging-service:publishoperation, scoped to your experience. Rolink needs nothing else. -
Check its restrictions. If you restrict the key’s accepted IP addresses, the restriction has to allow Rolink’s requests, otherwise Roblox refuses them. If you set an expiration date, note it: when the key expires, events stop until you paste a new one.
-
Copy your universe ID. It’s the ID of the experience as a whole, not the place ID in your experience’s URL. Creator Dashboard shows it for each experience.
-
Enter both in Rolink. In the dashboard, open your project’s Settings, then Live events. Paste the universe ID and the Open Cloud key, keep the event topic as
rolinkunless you have a reason to change it, and save. -
Send a test event. Use Send test event on the same page. Rolink publishes a
pingmessage with your settings and tells you whether Roblox accepted it. A refusal comes with Roblox’s HTTP status and a hint, such as checking the key’s permission or the universe ID.
Rolink encrypts the Open Cloud key at rest with AES-256-GCM and decrypts it only to publish your events. The dashboard never shows it again.
Once both values are saved, rolink:GetProject().events returns true.
Keep the topic in sync
Section titled “Keep the topic in sync”Rolink publishes to your project’s event topic, and the SDK subscribes to its topic option. Both default to rolink. If you change one, change the other:
local rolink = Rolink.new({ apiKey = HttpService:GetSecret("rolink_api_key"), topic = "rolink", -- must match the event topic in the dashboard})Without the Open Cloud key, everything except live events still works. Servers see a new link on their first lookup after their wallet cache expires (walletCacheSeconds, 60 by default). MessagingService is best-effort even when it’s on, so read the API when you need the authoritative state. See Live events.
Point players to the linking page
Section titled “Point players to the linking page”Players link their wallet at your project’s hosted page, in a browser:
https://api.rolink.tech/link/<project-slug>The dashboard shows the exact URL on the project’s Overview page, and rolink:GetProject().linkUrl returns it in game. Roblox restricts which off-platform links an experience can show, so check the current rules before you show this URL in your game. Use Rolink responsibly covers what to check.
Check your setup
Section titled “Check your setup”From a server script, GetProject shows which project the key belongs to and whether live events are configured:
local ok, project = pcall(rolink.GetProject, rolink)if ok then print(project.name, project.cluster, project.linkUrl, project.events)else warn(project) -- "[Rolink] unauthorized: ..." means the key is wrong or revokedendFrom a terminal, the same route answers with JSON:
curl -H "x-api-key: <your API key>" https://api.rolink.tech/v1/projectwalletAddress is your project’s managed wallet once you create it, and events is true once the universe ID and Open Cloud key are saved.
