Roblox Will Cut Web API Rate Limits by 99 Percent
Starting October 19, 2026, developers must migrate to Open Cloud endpoints to avoid significant traffic throttling.
Updated on Oct. 1, 2026 in Data Centers

Live Poll
Will Roblox's new API limits effectively force third-party developers to reduce platform utility for users?
Roblox announced on September 30, 2026, that it will slash rate limits for several legacy web API endpoints, reducing throughput from 10,000 to 100 requests per minute. This change forces a transition for developers still using older cookie-based authentication methods.
Why it matters
This move accelerates the platform-wide migration toward stable Open Cloud endpoints, which offer more secure authentication via API keys or OAuth 2.0. The policy shift pressures developers to modernize their back-end infrastructure to maintain application functionality.
The new cap of 100 requests per minute applies to legacy web APIs covering thumbnails, badges, inventory, user data, game persistence, and data stores. This 99% reduction mandates that developers implement caching layers or request queues to stay within the new throughput constraints.
The players
Roblox
A global gaming platform providing a development environment for user-created 3D experiences, currently transitioning its infrastructure toward more secure, modern API standards.
The details
Legacy web APIs on the Roblox platform currently rely on cookie-based authentication, which presents security risks compared to modern standards. To manage the lower request volume, developers are encouraged to monitor traffic levels using response headers and reset windows to throttle their own outgoing requests. Roblox is instead steering development toward its Open Cloud suite, which supports secure, credentialed access through API keys or OAuth 2.0 — an industry-standard framework for authorization.
Timeline
September 30, 2026: Roblox announced the upcoming API rate-limit changes.
October 19, 2026: The new reduced API request limits take effect.
The Tech Race
This policy change aligns Roblox with broader industry shifts toward enforcing OAuth 2.0 across high-traffic platforms to improve security and endpoint stability. It marks a decisive move to retire legacy web architectures in favor of a strictly defined Open Cloud environment.
Developers currently relying on legacy web APIs for inventory, badges, or game persistence will see their service functionality break if request volumes exceed the new 100-per-minute threshold. To maintain service uptime after October 19, 2026, teams must refactor their integration logic to use Open Cloud equivalents or implement aggressive client-side caching.
The takeaway
Developers should immediately audit their API dependencies to identify which services are affected by the 99% capacity reduction. Track the migration status of any legacy endpoints still lacking an Open Cloud counterpart as the October 19 deadline approaches.
Further reading
Find more updates regarding backend stability and migration trends in Data Centers.
Source note: This article includes information reported by TalkEsport.
Live Poll
Will Roblox's new API limits effectively force third-party developers to reduce platform utility for users?






