Complete Roblox account linking
curl --request GET \
--url http://localhost:3000/api/auth/roblox/callback \
--cookie __Host-argus-session=import requests
url = "http://localhost:3000/api/auth/roblox/callback"
headers = {"cookie": "__Host-argus-session="}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {cookie: '__Host-argus-session='}};
fetch('http://localhost:3000/api/auth/roblox/callback', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_PORT => "3000",
CURLOPT_URL => "http://localhost:3000/api/auth/roblox/callback",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_COOKIE => "__Host-argus-session=",
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "http://localhost:3000/api/auth/roblox/callback"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("cookie", "__Host-argus-session=")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("http://localhost:3000/api/auth/roblox/callback")
.header("cookie", "__Host-argus-session=")
.asString();require 'uri'
require 'net/http'
url = URI("http://localhost:3000/api/auth/roblox/callback")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Get.new(url)
request["cookie"] = '__Host-argus-session='
response = http.request(request)
puts response.read_body{
"error": {
"code": "INVALID_OAUTH_STATE",
"message": "Authentication state is invalid or expired."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "UNAUTHENTICATED",
"message": "Sign in to continue."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "IDENTITY_MISMATCH",
"message": "Sign in to the original Argus account before linking."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "IDENTITY_ALREADY_LINKED",
"message": "This Argus account already has a different Roblox identity."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "RATE_LIMITED",
"message": "Too many requests."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "OAUTH_PROVIDER_ERROR",
"message": "The identity provider could not complete authentication. Please try signing in again."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "INTERNAL_ERROR",
"message": "The request could not be completed."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}Authentication
Complete Roblox account linking
Permission: None beyond being signed in.
Access: Browser session only.
Roblox redirects the browser here. The session must belong to the user who started the flow. On success the verified Roblox identity is linked and audited as identity.roblox.verified.
Unknown query parameters are ignored.
GET
/
auth
/
roblox
/
callback
Complete Roblox account linking
curl --request GET \
--url http://localhost:3000/api/auth/roblox/callback \
--cookie __Host-argus-session=import requests
url = "http://localhost:3000/api/auth/roblox/callback"
headers = {"cookie": "__Host-argus-session="}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {cookie: '__Host-argus-session='}};
fetch('http://localhost:3000/api/auth/roblox/callback', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_PORT => "3000",
CURLOPT_URL => "http://localhost:3000/api/auth/roblox/callback",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_COOKIE => "__Host-argus-session=",
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "http://localhost:3000/api/auth/roblox/callback"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("cookie", "__Host-argus-session=")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("http://localhost:3000/api/auth/roblox/callback")
.header("cookie", "__Host-argus-session=")
.asString();require 'uri'
require 'net/http'
url = URI("http://localhost:3000/api/auth/roblox/callback")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Get.new(url)
request["cookie"] = '__Host-argus-session='
response = http.request(request)
puts response.read_body{
"error": {
"code": "INVALID_OAUTH_STATE",
"message": "Authentication state is invalid or expired."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "UNAUTHENTICATED",
"message": "Sign in to continue."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "IDENTITY_MISMATCH",
"message": "Sign in to the original Argus account before linking."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "IDENTITY_ALREADY_LINKED",
"message": "This Argus account already has a different Roblox identity."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "RATE_LIMITED",
"message": "Too many requests."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "OAUTH_PROVIDER_ERROR",
"message": "The identity provider could not complete authentication. Please try signing in again."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "INTERNAL_ERROR",
"message": "The request could not be completed."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}Authorizations
The opaque session cookie set by Discord sign-in. Named argus-session outside production. HttpOnly, so scripts cannot read it; same-origin requests send it automatically. Requests other than GET must also carry an Origin header equal to the application's own origin.
Query Parameters
The state Argus issued.
Maximum string length:
100Authorisation code from Roblox.
Required string length:
1 - 2048Set by Roblox when the user cancels.
Response
Redirects to: The application root (APP_URL/). Clears the flow cookie.