Downloading files
Windows · macOS · Android · home
One route, on every platform:
GET /download/{platform}/{version}
Examples, all valid:
https://rbxoffsets.com/download/windows/version-c5aecda2245e4fae
https://rbxoffsets.com/download/macos/version-5b15515e80624095
https://rbxoffsets.com/download/android/2.738.1397
https://rbxoffsets.com/download/android/2.738.1397.apk
https://rbxoffsets.com/download/windows/latest
latest means the newest usable build this server holds for
that platform, which is not necessarily the newest one it holds. On Android it is the newest
stored build carrying x86_64. Roblox ships arm-only
releases regularly; those are archived and downloadable by explicit version, but
latest never returns one, because handing back a package that cannot install is
worse than handing back a slightly older one that can. The
X-Roblox-Version header on the response says exactly what you are getting, so you
never have to guess.
A bare /download/{version} with no platform still works and still
means Android. That was the only form when this API was first published and it will keep
answering; new clients should name the platform.
What you get, per platform
| Platform | File | What it is |
|---|---|---|
| Windows | RobloxApp.zip | Exactly four files: RobloxPlayerBeta.exe, RobloxPlayerBeta.dll, RobloxCrashHandler.exe and COPYRIGHT.txt — everything needed to run or dump the client. The other 21 packages in Roblox's manifest are content, shaders, fonts and the installer. |
| macOS | RobloxPlayer.zip | The entire application. macOS ships as one zip rather than a package set. |
| Android | roblox-<version>.apk or .apks | A universal APK, or a split bundle. Check kind. |
Extra Windows packages
A deployment can keep more of a Windows build than RobloxApp.zip
(ARCHIVE_WINDOWS_PACKAGES: this one keeps only the primary package). Each is verified against Roblox's MD5 before it is stored, listed under
packages on /api/v1/windows/files/{version}, and downloaded the same
way:
curl -L -o RobloxPlayerInstaller.exe https://rbxoffsets.com/download/windows/latest/RobloxPlayerInstaller.exe
Upcoming builds
When this deployment archives upcoming builds, /download/{platform}/{version}
works for them before they go live. /api/v1/{platform}/upcoming says whether one is
stored.
It is a redirect, and that is deliberate
The response is 302 with a Location pointing at Cloudflare R2,
where the file actually lives. The bytes come from Cloudflare's network, never through this
server: a 134 MB client zip does not pass through a small hosting plan on every request,
and the transfer runs at Cloudflare's speed rather than this box's.
Practically, that means your client must follow redirects:
curl -L -o RobloxApp.zip https://rbxoffsets.com/download/windows/latest # -L is required
wget --content-disposition https://rbxoffsets.com/download/windows/latest # follows by default
python: requests.get(url, allow_redirects=True, stream=True)
The redirect target is signed and expires (about 60 minutes). Follow it immediately. Never store it, never put it in a config file, never
hand it to a queue that might run tomorrow — request the /download/ path again
instead. The path never expires; the URL it points at always does.
Headers on the redirect
| Header | Value |
|---|---|
X-Roblox-Platform | windows, mac or android. |
X-Roblox-Version | The version identity being served, e.g. version-c5aecda2245e4fae. |
X-Roblox-Display-Version | The dotted version, when it differs from the identity. |
X-Roblox-Version-Code | Android versionCode, when known. |
X-Roblox-Kind | apk, xapk or zip. |
X-Roblox-Sha256 | Hex sha256 of the file you are about to receive. |
X-Roblox-Size-Bytes | Exact size, for a progress bar or a disk-space check. |
X-Roblox-Filename | Suggested name, e.g. RobloxApp.zip. |
Use HEAD to read all of that without downloading anything:
curl -sI https://rbxoffsets.com/download/windows/latest
Getting the URL instead of the redirect
Add ?json=1 to be told where the file is rather than being sent there. Useful
when the downloader is a separate process from the thing deciding what to download.
curl -s "https://rbxoffsets.com/download/windows/latest?json=1"
Verify the hash
Every stored file has a real sha256, computed by this project while copying the bytes. Neither the Android mirror nor Roblox's CDN publishes one, so that copy is the only moment one can be learned — which is exactly why it is worth checking.
sha256sum RobloxApp.zip
# compare against X-Roblox-Sha256, or .files[0].sha256
A mismatch means a truncated download far more often than anything sinister. Delete and retry; do not use it.
Windows has a second, independent check. Roblox publishes an MD5 per package in
<version>-rbxPkgManifest.txt, and this project verifies the download
against it before storing anything — so a Windows object in the bucket has been
checked against a digest we did not compute ourselves. The manifest is archived beside the zip
if you want to repeat that check. macOS publishes no digest at all, which is why its files are
pinned only by our own sha256.
apk and xapk are not interchangeable
apk— one universal file containing every ABI.pm installoradb installtakes it directly.xapk— a zip of split APKs (a base plus per-ABI and per-density parts). It must be installed as a set: unzip it and useadb install-multiple base.apk config.x86_64.apk .... Handing the bundle to a plaininstallfails.
Check kind before you install. It is the one field that silently breaks an
automated flow if ignored.