# Roblox Oauth

> OAuth 2.0 flows, PKCE, authorization code, token lifecycle, scope selection, Open Cloud auth.

- **Type:** Skill
- **Install:** `agentstack add skill-tabooharmony-roblox-brain-roblox-oauth`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [TabooHarmony](https://agentstack.voostack.com/s/tabooharmony)
- **Installs:** 0
- **Category:** [Security](https://agentstack.voostack.com/c/security)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [TabooHarmony](https://github.com/TabooHarmony)
- **Source:** https://github.com/TabooHarmony/roblox-brain/tree/main/skills/roblox-oauth

## Install

```sh
agentstack add skill-tabooharmony-roblox-brain-roblox-oauth
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# roblox-oauth

## When to Load

Load this skill when the task centers on Roblox OAuth 2.0 delegated authorization for Open Cloud — app registration, authorization code flow with PKCE, token exchange/refresh/revocation, scope selection, or OAuth-specific error debugging. Skip it for API-key automation, in-experience scripting, or general Open Cloud endpoint work (use `roblox-cloud` instead).

## Quick Reference

### Flow Selection
- **Auth Code + PKCE** — required for public clients (browser/mobile), recommended for all.
- **Confidential** — backend holds `client_secret`; never expose in frontend code.
- **Public** — no secret; PKCE mandatory.

### PKCE Essentials
- Generate `code_verifier` (43–128 char random) + `code_challenge` (SHA-256, base64url).
- Send `code_challenge` + `code_challenge_method=S256` in authorize; send `code_verifier` in token exchange.
- One verifier per authorization attempt.

### Authorization URL
`GET https://apis.roblox.com/oauth/v1/authorize`
Params: `client_id`, `redirect_uri`, `scope`, `response_type=code`, `code_challenge`, `code_challenge_method=S256`, `state`, optional `nonce`.

### Token Exchange
`POST /oauth/v1/token` — `application/x-www-form-urlencoded`
Params: `grant_type=authorization_code`, `code`, `client_id`, `code_verifier` (public) or `client_secret` (confidential).

### Token Lifecycle
- **Auth code** — seconds, single-use; exchange immediately.
- **Access token** — ~15 min; use as Bearer.
- **Refresh token** — ~90 days; single-use per refresh. Replace stored token atomically after each refresh.
- **Revoke**: `POST /oauth/v1/token/revoke` on disconnect.

### Scope Selection
- Minimum scopes matching actual endpoint needs.
- `openid` → ID token; `profile` only if profile claims needed.
- Medium/high/critical risk = least-privilege review signal.
- Changing scopes requires reauthorization.

### Validation Endpoints
- `GET /oauth/v1/userinfo` — identity claims.
- `POST /oauth/v1/token/introspect` — token activity (not resource auth).
- `POST /oauth/v1/token/resources` — resource-level access.

### Key Rules
- Verify `state` before using returned code.
- Refresh tokens: server-side only.
- PKCE even for confidential clients.
- Don't mix API keys and OAuth.
**Need more detail?** Load `references/full.md` for the complete reference with code examples, API tables, and edge cases.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [TabooHarmony](https://github.com/TabooHarmony)
- **Source:** [TabooHarmony/roblox-brain](https://github.com/TabooHarmony/roblox-brain)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-tabooharmony-roblox-brain-roblox-oauth
- Seller: https://agentstack.voostack.com/s/tabooharmony
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
