Roblox Security
When to Load
Load for exploit audits and hardening: authority models, remote abuse, economy, DataStore flows, native bans, sandboxing. Use roblox-networking for validation and rate limiting.
Quick Reference
Core: Client is always compromised. The server remains the source of truth, but the implementation depends on the authority model.
Authority Models
- Classic replication: validate client requests against server state. Never trust client damage, currency, inventory, permissions, or positions.
- Server Authority:
Workspace.AuthorityMode = Server: the server owns core simulation while clients predict and recover from misprediction. UseBindToSimulation()(needsUseFixedSimulation), not blanketHeartbeatcorrection. Cheap for stock characters, rewrite-scale for authored simulation (full.md). - Both: validate attacks, purchases, teleports, permissions, and custom remotes at the server boundary.
Audit Checklist
CRITICAL: Server-authoritative state · Documented authority model · Validate all arg types · Rate limit remotes · Session-lock DataStore · No client currency mutations · ProcessReceipt verification · No secrets in client code
HIGH: Validate custom movement and action transitions · BindToClose protection · Atomic trading · Never trust client values · Use InputActions for simulation input in Server Authority projects · Validate ProximityPrompt/ClickDetector/DragDetector like remotes
MEDIUM: Server cooldowns · server-computed leaderboards · anti-AFK reward checks · TextService filtering · Script sandboxing for third-party code
Enforcement
Enforcement is a product decision with appeal implications, not an automatic response. The native ban API is server-only (Players:BanAsync / UnbanAsync / GetBanHistoryAsync; Players.BanningEnabled must be on). Duration -1 is permanent, 0 and other negatives are invalid; DisplayReason max 400 chars (filtered); PrivateReason max 1000, never client-shared; ApplyDeviceBlock lasts 24 hours and only UnbanAsync lifts it. Escalate via ban history; pcall every call (throttled HTTP). Config field table is in full.md.
Anti-Patterns
Don't obfuscate client code, use _G for security, kick without logging, over-validate movement, or rely on client anti-cheat.
See references/full.md for detailed examples.