Record a warning
curl --request POST \
--url http://localhost:3000/api/moderation/warnings \
--header 'Content-Type: application/json' \
--header 'Idempotency-Key: <idempotency-key>' \
--cookie __Host-argus-session= \
--data '
{
"targetRobloxId": "123456",
"reason": "Repeated disruption"
}
'import requests
url = "http://localhost:3000/api/moderation/warnings"
payload = {
"targetRobloxId": "123456",
"reason": "Repeated disruption"
}
headers = {
"cookie": "__Host-argus-session=",
"Idempotency-Key": "<idempotency-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
cookie: '__Host-argus-session=',
'Idempotency-Key': '<idempotency-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({targetRobloxId: '123456', reason: 'Repeated disruption'})
};
fetch('http://localhost:3000/api/moderation/warnings', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_PORT => "3000",
CURLOPT_URL => "http://localhost:3000/api/moderation/warnings",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'targetRobloxId' => '123456',
'reason' => 'Repeated disruption'
]),
CURLOPT_COOKIE => "__Host-argus-session=",
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"Idempotency-Key: <idempotency-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "http://localhost:3000/api/moderation/warnings"
payload := strings.NewReader("{\n \"targetRobloxId\": \"123456\",\n \"reason\": \"Repeated disruption\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("cookie", "__Host-argus-session=")
req.Header.Add("Idempotency-Key", "<idempotency-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("http://localhost:3000/api/moderation/warnings")
.header("cookie", "__Host-argus-session=")
.header("Idempotency-Key", "<idempotency-key>")
.header("Content-Type", "application/json")
.body("{\n \"targetRobloxId\": \"123456\",\n \"reason\": \"Repeated disruption\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("http://localhost:3000/api/moderation/warnings")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Post.new(url)
request["cookie"] = '__Host-argus-session='
request["Idempotency-Key"] = '<idempotency-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"targetRobloxId\": \"123456\",\n \"reason\": \"Repeated disruption\"\n}"
response = http.request(request)
puts response.read_body{
"data": {
"id": "cmg5y4pun0007l508pun00001",
"targetRobloxId": "123456",
"targetUsername": null,
"moderatorId": "cmg5x1k2a0000l508a1b2c3d4",
"serviceId": null,
"type": "warn",
"reason": "Repeated disruption",
"evidence": "https://example.org/evidence/123",
"createdAt": "2026-10-06T19:30:00.000Z",
"updatedAt": "2026-10-06T19:30:00.000Z",
"delivery": "RECORDED",
"errorCode": null
},
"meta": {
"replayed": true
}
}{
"data": {
"id": "cmg5y4pun0007l508pun00001",
"targetRobloxId": "123456",
"targetUsername": null,
"moderatorId": "cmg5x1k2a0000l508a1b2c3d4",
"serviceId": null,
"type": "warn",
"reason": "Repeated disruption",
"evidence": "https://example.org/evidence/123",
"createdAt": "2026-10-06T19:30:00.000Z",
"updatedAt": "2026-10-06T19:30:00.000Z",
"delivery": "RECORDED",
"errorCode": null
},
"meta": {
"replayed": false
}
}{
"error": {
"code": "INVALID_INPUT",
"message": "Request validation failed.",
"details": [
{
"path": [
"targetRobloxId"
],
"message": "Invalid input"
}
]
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "UNAUTHENTICATED",
"message": "Sign in to continue."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "FORBIDDEN",
"message": "Permission required: moderation.warn."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "IDEMPOTENCY_CONFLICT",
"message": "This key was already used for a different request."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "RATE_LIMITED",
"message": "Too many requests."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "INTERNAL_ERROR",
"message": "The request could not be completed."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}Moderation
Record a warning
Permission: moderation.warn.
Access: Browser session, or a service credential holding the permission as a scope.
Saves a warning against a Roblox ID. Nothing is sent to the game, so delivery is RECORDED. The target need not have an Argus account. A repeated request with the same key and body returns the original record with meta.replayed: true.
POST
/
moderation
/
warnings
Record a warning
curl --request POST \
--url http://localhost:3000/api/moderation/warnings \
--header 'Content-Type: application/json' \
--header 'Idempotency-Key: <idempotency-key>' \
--cookie __Host-argus-session= \
--data '
{
"targetRobloxId": "123456",
"reason": "Repeated disruption"
}
'import requests
url = "http://localhost:3000/api/moderation/warnings"
payload = {
"targetRobloxId": "123456",
"reason": "Repeated disruption"
}
headers = {
"cookie": "__Host-argus-session=",
"Idempotency-Key": "<idempotency-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
cookie: '__Host-argus-session=',
'Idempotency-Key': '<idempotency-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({targetRobloxId: '123456', reason: 'Repeated disruption'})
};
fetch('http://localhost:3000/api/moderation/warnings', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_PORT => "3000",
CURLOPT_URL => "http://localhost:3000/api/moderation/warnings",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'targetRobloxId' => '123456',
'reason' => 'Repeated disruption'
]),
CURLOPT_COOKIE => "__Host-argus-session=",
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"Idempotency-Key: <idempotency-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "http://localhost:3000/api/moderation/warnings"
payload := strings.NewReader("{\n \"targetRobloxId\": \"123456\",\n \"reason\": \"Repeated disruption\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("cookie", "__Host-argus-session=")
req.Header.Add("Idempotency-Key", "<idempotency-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("http://localhost:3000/api/moderation/warnings")
.header("cookie", "__Host-argus-session=")
.header("Idempotency-Key", "<idempotency-key>")
.header("Content-Type", "application/json")
.body("{\n \"targetRobloxId\": \"123456\",\n \"reason\": \"Repeated disruption\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("http://localhost:3000/api/moderation/warnings")
http = Net::HTTP.new(url.host, url.port)
request = Net::HTTP::Post.new(url)
request["cookie"] = '__Host-argus-session='
request["Idempotency-Key"] = '<idempotency-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"targetRobloxId\": \"123456\",\n \"reason\": \"Repeated disruption\"\n}"
response = http.request(request)
puts response.read_body{
"data": {
"id": "cmg5y4pun0007l508pun00001",
"targetRobloxId": "123456",
"targetUsername": null,
"moderatorId": "cmg5x1k2a0000l508a1b2c3d4",
"serviceId": null,
"type": "warn",
"reason": "Repeated disruption",
"evidence": "https://example.org/evidence/123",
"createdAt": "2026-10-06T19:30:00.000Z",
"updatedAt": "2026-10-06T19:30:00.000Z",
"delivery": "RECORDED",
"errorCode": null
},
"meta": {
"replayed": true
}
}{
"data": {
"id": "cmg5y4pun0007l508pun00001",
"targetRobloxId": "123456",
"targetUsername": null,
"moderatorId": "cmg5x1k2a0000l508a1b2c3d4",
"serviceId": null,
"type": "warn",
"reason": "Repeated disruption",
"evidence": "https://example.org/evidence/123",
"createdAt": "2026-10-06T19:30:00.000Z",
"updatedAt": "2026-10-06T19:30:00.000Z",
"delivery": "RECORDED",
"errorCode": null
},
"meta": {
"replayed": false
}
}{
"error": {
"code": "INVALID_INPUT",
"message": "Request validation failed.",
"details": [
{
"path": [
"targetRobloxId"
],
"message": "Invalid input"
}
]
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "UNAUTHENTICATED",
"message": "Sign in to continue."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "FORBIDDEN",
"message": "Permission required: moderation.warn."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "IDEMPOTENCY_CONFLICT",
"message": "This key was already used for a different request."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "RATE_LIMITED",
"message": "Too many requests."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}{
"error": {
"code": "INTERNAL_ERROR",
"message": "The request could not be completed."
},
"requestId": "3f1c9d5e-7a42-4f0b-9c1e-8b6d2a4e5f70"
}Authorizations
sessionCookieserviceCredential
The opaque session cookie set by Discord sign-in. Named argus-session outside production. HttpOnly, so scripts cannot read it; same-origin requests send it automatically. Requests other than GET must also carry an Origin header equal to the application's own origin.
Headers
Generate one per deliberate action and reuse it when retrying the same request. Scoped to the caller.
Required string length:
16 - 128Pattern:
^[A-Za-z0-9_-]+$Body
application/json