API documentation

Windows · macOS · Android · home

This server watches the Roblox client on Windows, macOS, Android around the clock, records every version it sees — including builds that have not reached production yet — keeps a copy of the files, and publishes offsets. The API below is how another program asks it five questions:

  • What is the current Roblox version, and when was it released?
  • What is coming next?
  • Which files do you actually hold?
  • Give me that file.
  • Give me the offsets for it — and are they verified?

Base URL

https://rbxoffsets.com

All paths below are relative to it. Responses are JSON (application/json; charset=utf-8) unless stated otherwise, and every JSON endpoint sends Access-Control-Allow-Origin: *, so a browser page can call it directly.

Platforms

Almost every route takes a platform segment. This deployment answers for windows, macos, android; mac is accepted as a synonym for macos.

GET /api/v1/{platform}/version
GET /download/{platform}/{version}
GET /api/v1/{platform}/offsets/{version}/{format}

An unrecognised platform answers 400 unknown_platform and lists the valid ones, so a client never has to guess the spelling.

Authentication

Every read endpoint on this site is open: no key, no header, no account. Only the routes under /internal/ require a token, and those exist for the operator rather than for clients.

Versions are not the same shape on every platform

Read this before you write anything. Android versions are the dotted numbers you already know. Windows and macOS builds are identified by an opaque content hash — that is what Roblox keys every CDN path and every offsets dump by — and the dotted version comes along beside it as a separate field.

Platformversion (identity)displayVersion
Windowsversion-c5aecda2245e4fae0.738.0.7381397
macOSversion-5b15515e806240950.738.0.7381393
Android2.738.13972.738.1397
  • version is the identity. Build URLs from it. It is unique.
  • displayVersion is for humans. It is not unique: the macOS player and macOS Studio have shipped the same dotted version as two different builds.
  • On Android the two are identical, which is why old clients that only ever saw version keep working.

The 30-second version

Everything, in one call:

curl -s https://rbxoffsets.com/api/v1/platforms

What is live on one platform:

curl -s https://rbxoffsets.com/api/v1/windows/version

What is downloadable, and then download it:

curl -s https://rbxoffsets.com/api/v1/windows/files
curl -L -o RobloxApp.zip https://rbxoffsets.com/download/windows/latest

What is coming:

curl -s https://rbxoffsets.com/api/v1/windows/upcoming

The newest Windows offsets, as a C++ header — verified when a verified set exists:

curl -sL -o offsets.hpp https://rbxoffsets.com/api/v1/windows/offsets/latest/hpp
curl -sL -o offsets.hpp "https://rbxoffsets.com/api/v1/windows/offsets/latest/hpp?tier=verified"   # verified or nothing

-L matters on both downloads. They are redirects to Cloudflare storage; without it you save the redirect instead of the file. The same tasks in PowerShell and cmd are on Command line.

Contents

Start here

  1. Command line
    Every common task in PowerShell, cmd, bash, zsh and the macOS terminal, ready to paste.
  2. OpenAPI
    The machine-readable description of this API, and how to import it into your tools.

Reference

  1. Endpoints
    Every URL, what it returns, and what each field means.
  2. Upcoming builds
    How builds ahead of production are detected, what the sources are, and what upcoming does not promise.
  3. Offsets
    Verified and default offsets, every file in a dump, and how to fetch the right one.
  4. Downloading files
    How /download works, why it redirects to Cloudflare, and how to verify what you got.
  5. Failures and edge cases
    Every error code, which states only look like errors, and what is safe to retry.
  6. Offset tiers
    Verified against default: which one you get, how to demand verified, and what a set records.
  7. FFlags and dump files
    Every file a dump can contain, what is inside each one, and how to fetch it.
  8. Events and feeds
    Every event type, its payload, the Atom feeds and the Discord alerts built on them.

Guides

  1. Writing a client
    A working updater in eight languages, plus the mistakes worth avoiding.
  2. Git and CI
    Keep verified offsets in your own repository and publish them from your own pipeline.

Operating this server

  1. Changelog
    What changed in this API, what was added, and what is deprecated.

What this server will not do

  • It does not serve any version it has not stored. Ask /api/v1/{platform}/files first, or accept a 404.
  • It does not pass off a default offsets set as verified. Every response says which tier it served, and ?tier=verified never substitutes.
  • It does not treat an upcoming build as a promise. Roblox pulls pre-release builds, and when that happens it says so with upcoming_withdrawn.
  • It has only partial Windows and macOS history from before it started watching. Roblox redacted the build hashes from DeployHistory.txt, so desktop history accumulates from this server's first poll — plus, where the operator turns on the backfill, the builds theo's offsets listing still names.
  • It does not track any Android ABI other than x86_64. An abi parameter naming a different one is rejected rather than answered with something that will not install.
  • It does not modify files. Bytes are copied from upstream unchanged, and the published sha256 is of the exact file you receive.