Tripwire
made by alibolly
An MCP server that gives an AI coding agent real control of Roblox Studio and Roblox Open Cloud, with a test-and-security layer no other Studio MCP has.
Tripwire lets an assistant read, write, and edit the data model, drive playtests with simulated input, run tests-as-code headlessly in the real engine, flag client-trust exploits in game code, and call the Open Cloud APIs (DataStores, MessagingService, Memory Stores, and more). The Studio tools need no API key; the headless test, asset, and Open Cloud tools use an Open Cloud key.
Requirements
- An MCP client: Claude Code, Codex, Gemini, or any client that speaks MCP over stdio.
- Roblox Studio, for the Studio tools. These need no API key.
- Node.js, only if you run the server with
npx. The prebuilt binary needs no Node. - For the headless test, asset, and Open Cloud tools: a published place and a Roblox Open Cloud API key. See Open Cloud setup.
Quickstart
Tripwire is for Roblox developers who drive Studio through an AI coding agent.
- Wire the server into your MCP client (one command or a small config block, see Install below).
- Install the Studio plugin so the Studio tools can reach Studio (see the plugin step in Install).
- Open your place in Studio, turn on Game Settings > Security > Allow HTTP Requests, then click the Tripwire toolbar button and press Connect in the panel. The panel shows Connected and the Output prints
[Tripwire v...] connected. - Ask your agent to run
studio_status. A connected Studio confirms the bridge works. - Optional: add an Open Cloud key for the headless test, asset, and Open Cloud tools (see Open Cloud setup).
Install
Tripwire's server is a single binary. The easiest way to run it is with npx, which fetches the
prebuilt binary for your platform, so there is no Rust toolchain to install. Prefer a manual binary
or a source build? See the Alternatives at the end of this section.
Claude Code
One command:
claude mcp add --transport stdio tripwire -- npx -y tripwire-roblox
Or add it to a project .mcp.json (or ~/.claude.json):
{
"mcpServers": {
"tripwire": {
"type": "stdio",
"command": "npx",
"args": ["-y", "tripwire-roblox"]
}
}
}
Codex
Add to ~/.codex/config.toml:
[mcp_servers.tripwire]
command = "npx"
args = ["-y", "tripwire-roblox"]
Or: codex mcp add tripwire -- npx -y tripwire-roblox
Gemini
Add to ~/.gemini/settings.json (or a project .gemini/settings.json):
{
"mcpServers": {
"tripwire": {
"command": "npx",
"args": ["-y", "tripwire-roblox"]
}
}
}
Or: gemini mcp add tripwire npx -y tripwire-roblox
Other MCP clients
Any client that speaks MCP over stdio can run it:
command: npx
args: ["-y", "tripwire-roblox"]
Alternatives: prebuilt binary, or build from source
Prebuilt binary (no Node). Download the archive for your platform from the
Releases page (for example
tripwire-server-vX.Y.Z-aarch64-apple-darwin.tar.gz), extract it, and point your client's
command at the extracted tripwire-server with empty args.
Build from source (needs Rust):
git clone https://github.com/aliboIly/Tripwire.git
cd Tripwire/server
cargo build --release # produces server/target/release/tripwire-server
Then point your client's command at that binary path.
Studio plugin (required for the Studio tools)
The Studio tools reach Studio through a small plugin that long-polls the local server. Grab
Tripwire.rbxmx from the Releases page, or build it:
cd Tripwire/plugin
npm install
npx rbxtsc
rojo build --output Tripwire.rbxmx
cp Tripwire.rbxmx ~/Documents/Roblox/Plugins/ # macOS; Windows: %LOCALAPPDATA%\Roblox\Plugins
Restart Studio, enable Game Settings > Security > Allow HTTP Requests, then click the
Tripwire toolbar button and press Connect in the panel. The panel shows Connected and
the Output prints [Tripwire v...] connected.
Open Cloud key (for headless tests, assets, and Open Cloud tools)
The Studio tools need no key. The Open Cloud tools do. See Open Cloud setup below for the full walkthrough.
Open Cloud setup
Most of Tripwire needs no credentials. These tools do, because they call Roblox Open Cloud:
run_luau, the headless tests (run_tests, run_test_file, list_tests), and every tool in the
Open Cloud sections below (assets, publishing, data stores, messaging, memory, universe and
servers, the Engine Instance API, moderation, secrets, monetization, Creator Store, groups,
analytics, platform, and open_cloud_request). They authenticate with a Roblox Open Cloud API key.
Use at your own risk. An Open Cloud key is a real credential with real power over your experience. Depending on the scopes you grant it, it can read and overwrite your live DataStores, publish new versions of your place, upload assets to your account, and message your servers. Treat it like a password: grant only the scopes you actually use, restrict it to your own IP, never commit it, and revoke it if it leaks. You are responsible for what you do with it. Tripwire is not affiliated with or endorsed by Roblox.
1. Create the key
- Go to create.roblox.com/dashboard/credentials and sign in.
- Click Create API Key and name it (for example
Tripwire). - Under Access Permissions, add only the API systems for the tools you want, and grant each the operation it needs, scoped to your experience. Every system the dashboard offers has a tool; the map is in Permissions to tools below. The short version:
- Luau Execution (write):
run_luauand the headless tests. - universe-places (write):
publish_place. - Assets (read + write) and Asset Permissions: the asset tools.
- DataStores and Ordered DataStores: the data-store tools.
- Messaging Service (publish) and Memory Stores: those tools.
- Universe, Place, Instance, User Restrictions, Secrets, Analytics: the universe, server, instance, moderation, secrets, and analytics tools.
- Developer Products, Game Passes, Creator Store: the monetization and store tools.
- User/Group/Inventory/Subscription/Notification: the platform, group, and engagement tools.
- Anything else (the legacy and experimental systems):
open_cloud_request.
- Luau Execution (write):
- Under Security, set Accepted IP Addresses to your machine's IP, or
0.0.0.0/0to allow any (simplest for local use). Set an expiration if you want. - Click Save & Generate Key and copy the key string. It is shown only once.
2. Find your universe and place IDs
In the Studio command bar (View, then Command Bar), run:
print("universe", game.GameId, "place", game.PlaceId)
GameId is your ROBLOX_UNIVERSE_ID; PlaceId is your ROBLOX_PLACE_ID. The place must be
published to Roblox for Open Cloud to act on it.
3. Give Tripwire the credentials
Create a .env at the repo root. It is gitignored and the server loads it automatically:
ROBLOX_OPEN_CLOUD_KEY=paste_the_key_here
ROBLOX_UNIVERSE_ID=000000
ROBLOX_PLACE_ID=000000
ROBLOX_CREATOR_USER_ID=000000 # only for upload_asset (your user id)
Or put the same variables in your MCP client's env block instead (those take precedence).
Reconnect the MCP server after changing either. Each tool works when the key grants its scope and
returns Roblox's own error if a scope is missing, so you can add scopes as you go.
Tools
Connection
studio_status
Whether a Studio is connected, the active place, and any other connected studios.ping_studio
Round-trip a ping through the plugin to confirm the live bridge works.list_studios
List every connected (or recently seen) Studio: place, whether it is active, last-seen, and playtest state.set_active_studio
Choose which connected Studio the tools target (by id, id prefix, or place name). Automatic with one Studio.Read and inspect
get_file_tree
List the instance tree from a path (default the whole game), bounded by depth.get_instance_children
List the direct children (name and class) of an instance.get_instance_properties
Read an instance's name, class, full path, attributes, and a curated set of common engine properties (Position, Size, Color, Material, Anchored, Text, and so on).search_objects
Find instances whose name contains a query, optionally filtered by exact class or by class-and-subclasses (isA).search_by_property
Find instances whose property equals a value, optionally filtered by exact class or by class-and-subclasses (isA).get_script_source
Read the source of a Script, LocalScript, or ModuleScript.grep_scripts
Search script sources for a substring; returns path, line number, and line.get_output_log
Recent Studio Output entries (message, type, timestamp).get_selection
The instances currently selected in Studio.get_class_info
Look up a Roblox class's members (properties, methods, events) with their types, inherited members folded in. Answered from a bundled API reflection dump, so it needs no Studio and no key.Spatial (read-only)
raycast
Cast a ray and report the first hit (instance, position, normal, material, distance) or no hit, with an optional excluded subtree.get_bounding_box
The world-space bounding box (center and size) of a Model or BasePart.find_spawns
List the SpawnLocations under a path: position, whether each is enabled, and whether it is neutral.capture_screenshot
Capture the Studio viewport as a JPEG image so the agent can see the scene. Needs the plugin connected and Allow Mesh / Image APIs enabled (Game Settings, Security). Edit mode only.Edit (each is one undo step)
create_instance
Create an instance of a class with an optional name and initial properties.delete_instance
Destroy an instance and its descendants.set_property
Set one typed property (primitive, Vector3, Color3, UDim2, CFrame, EnumItem, or an instance reference).update_script_source
Replace a script's source through the script editor (the supported write path).insert_model
Insert an asset by id, with optional reposition or unpack.mass_create
Create many instances in one undo step (atomic, or best-effort with per-item results).mass_set_property
Set one property on many instances in one undo step (atomic or best-effort).Playtest and input
start_playtest
Start an F5 playtest (server and client DataModels with a player); injects the in-play runner.stop_playtest
Stop the F5 playtest (best-effort; F5 teardown can outlast the confirmation).start_simulation
Start an F8 run (server-only simulation, no client or player).stop_simulation
Stop the F8 run (clean).simulate_mouse_input
Click or move the mouse at screen coordinates during an F5 playtest.simulate_keyboard_input
Press a key (tap/press/release) or type text during an F5 playtest.character_navigation
Walk the local character toward a world position; reports whether it reached the goal.get_playtest_output
The running playtest's output log, aggregated across the server and client peers. Pass the cursor from the previous call as since to get only new lines; the buffer is bounded so long sessions do not freeze it.reset_playtest_output
Clear the playtest's output buffers so the next read starts fresh, without restarting Studio.run_luau_live
Evaluate Luau in the live F5 playtest server and return the result, so you can inspect the running game (a Humanoid's state, an NPC's position, a path's waypoints) without adding a print and replaying. Needs an active playtest and ServerScriptService.LoadStringEnabled on in the test place. Distinct from run_luau, which is headless against the published place.Tests and headless execution (Open Cloud)
run_luau
Run a Luau script headlessly in the published place; returns the results and logs.run_tests
Run the headless test suite in the published place and report passed/failed with messages.run_test_file
Run a single spec by name, headlessly.list_tests
List the spec files and their cases discovered in the published place.write_test
Write a roblox-ts test spec to disk; rebuild and publish, then run_tests picks it up.Security review (static analysis, no key)
review_security
Review the game source for client-trust and unvalidated-remote issues, each with a suggested server-side fix.scan_remotes
List server remote handlers and the client-controlled parameters of each.scan_client_trust
Flag server handlers that use client-supplied values without validating them.Assets and publishing (Open Cloud)
upload_asset
Upload a local file as a Roblox asset (Decal, Audio, Model, Animation, or Video); returns the assetId.get_asset
An asset's metadata: type, name, description, moderation state, current revision.update_asset
Change an asset's name or description, or (Models) upload new content as a new version.list_asset_versions
An asset's versions with their moderation state.rollback_asset_version
Roll an asset back to an earlier version.archive_asset / restore_asset
Hide an asset from the site and experiences, or bring it back.list_asset_quotas
Your upload quotas and how much of each is used.download_asset
Download an asset's content (a model, image, or place file) to a local path.grant_asset_permissions
Grant a user, group, roleset, universe, or everyone a permission (Use, Edit, Download) on assets you own.publish_place
Publish a local place file (.rbxl/.rbxlx) as a new version of the experience.DataStores (Open Cloud)
list_datastores
List the standard data stores in the universe.list_datastore_entries
List entry keys in a data store. Optional scope; - lists every scope.get_datastore_entry
Read an entry's value and metadata, or an older revision of it.set_datastore_entry
Create or overwrite an entry (value plus optional users/attributes).delete_datastore_entry
Soft-delete an entry (purged after 30 days).increment_datastore_entry
Atomically add an integer to a numeric entry.list_datastore_entry_revisions
An entry's revision history, newest first.delete_datastore / undelete_datastore
Schedule a whole data store for deletion in 30 days, or cancel that.snapshot_datastores
Snapshot every data store so the next write to each key keeps a versioned backup. Run it before a migration.list_ordered_entries
List ordered data store entries by value, ascending or descending.get_ordered_entry
Read one ordered data store entry.set_ordered_entry
Set (upsert) an ordered data store entry to a non-negative integer.increment_ordered_entry
Atomically add to an ordered data store entry.delete_ordered_entry
Delete an ordered data store entry.Messaging and memory (Open Cloud)
publish_message
Publish a message to a MessagingService topic (reaches running production servers).memory_sorted_map_set
Set (upsert) a Memory Store sorted-map item, with TTL and sort keys.memory_sorted_map_get
Read a Memory Store sorted-map item.memory_sorted_map_list
List sorted-map items in sort order.memory_sorted_map_delete
Delete a sorted-map item.memory_queue_add
Add an item to a Memory Store queue, with priority and TTL.memory_queue_read
Read items from a queue; returns a readId for the discard call.memory_queue_discard
Permanently remove a read batch by its readId.flush_memory_store
Wipe every Memory Store structure in the universe (LIVE or TEST scope) and wait for it.Universe, place, and servers (Open Cloud)
get_universe
The configured universe's metadata.update_universe
Voice chat, private server price, and per-platform join toggles.get_place
The configured place's metadata.update_place
The place's name, description, or server size.restart_servers
Move live servers to the newest published version, outdated ones only by default, with an optional bleed-off.list_game_servers
The live servers running a place version: players, uptime, job ids.get_game_server_logs
A live server's log lines by job id. The production counterpart of get_playtest_output.translate_text
Translate text into one or more languages with Roblox's translation service.Engine Instance API (Open Cloud, no Studio needed)
cloud_list_instance_children
List an instance's children in the published place. Start from root.cloud_get_instance
Read an instance's details in the published place.cloud_update_instance
Rename an instance or set a script's Source, Enabled, or RunContext in the published place.Moderation (Open Cloud)
list_user_restrictions
Users who have ever been banned from the universe or a place.get_user_restriction
One user's ban state and reasons.set_user_restriction
Ban (permanent or timed, with reasons, optionally not extended to alts) or unban a user. Kicks them from live servers.list_user_restriction_logs
The audit log of ban and unban changes.Secrets (Open Cloud)
list_secrets
The universe's secrets, metadata only.create_secret / update_secret
Store a value for HttpService:GetSecret. It is sealed with the universe's public key on your machine before upload.delete_secret
Permanently delete a secret.Monetization and Creator Store (Open Cloud)
list_developer_products / get_developer_product
Developer products with prices and sale state.create_developer_product / update_developer_product
Create or edit a developer product: name, description, Robux price, sale state, icon.list_game_passes / get_game_pass
Game passes with prices and sale state.create_game_pass / update_game_pass
Create or edit a game pass.search_creator_store
Search the Creator Store for models, plugins, audio, decals, meshes, video, or fonts; returns asset ids for insert_model.get_creator_store_asset
A store listing's creator, votes, price, and asset details.get_creator_store_product
One of your own store products: prices, published state, restrictions.Groups (Open Cloud)
get_group
A group's metadata.list_group_memberships
A group's members and their roles, filterable by user or role.list_group_roles
A group's roles and ranks.list_group_join_requests / resolve_group_join_request
Pending join requests, and accept or decline one.set_group_role
Assign a role to a member, or remove one.Platform, engagement, and analytics (Open Cloud)
get_user
A user's public profile.generate_user_thumbnail
A user's avatar headshot as an image URL.list_inventory
A user's inventory items, filterable by type or id.send_notification
Send an experience notification to a user (from a Creator Dashboard template).get_subscription
Read a user's subscription to a subscription product.query_analytics
A metric (DAU, sessions, revenue, and so on) over a time range, broken down and filtered by dimension; or the values a dimension can take.Everything else (Open Cloud)
open_cloud_request
Call any endpoint under apis.roblox.com with the key attached: method, host-relative path, query, JSON body. This is how the legacy and experimental systems are reached (badges, localization tables, Team Create, game events, thumbnails, ads, place version history, creator store products). The key is only ever sent to that host.Permissions to tools
Every API system you can add to a key on the Creator Dashboard, and the tools that use it. Scope names are the ones the dashboard and Roblox's error messages use.
| Permission (scope) | Tools |
|---|---|
Luau Execution (universe.place.luau-execution-session) | run_luau, run_tests, run_test_file, list_tests |
Places (universe-places:write, universe.place) | publish_place, update_place, get_place |
Universe (universe:read, universe:write) | update_universe, restart_servers, translate_text, list_game_servers, get_game_server_logs |
Instance (universe.place.instance) | cloud_list_instance_children, cloud_get_instance, cloud_update_instance |
Data Stores (universe-datastores.control, .objects, .versions) | the DataStores section: entries, revisions, store delete, snapshot |
Ordered Data Stores (universe.ordered-data-store.scope.entry) | list/get/set/increment/delete_ordered_entry |
Memory Stores (memory-store.sorted-map, .queue, :flush) | the sorted-map and queue tools, flush_memory_store |
Messaging Service (universe-messaging-service:publish) | publish_message |
User Restrictions (universe.user-restriction) | list/get/set_user_restriction, list_user_restriction_logs |
Secrets (universe.secret) | list/create/update/delete_secret |
Assets (asset:read, asset:write) | upload_asset, get_asset, update_asset, list_asset_versions, rollback_asset_version, archive_asset, restore_asset, list_asset_quotas |
Asset Permissions (asset-permissions:write) | grant_asset_permissions |
Legacy Assets (legacy-asset:manage) | download_asset |
Developer Products (developer-product) | list/get/create/update_developer_product |
Game Passes (game-pass) | list/get/create/update_game_pass |
Creator Store (creator-store-product) | search_creator_store, get_creator_store_asset, get_creator_store_product; create and update via open_cloud_request |
Groups (group:read, group:write) | get_group, list_group_memberships, list_group_roles, list_group_join_requests, resolve_group_join_request, set_group_role |
Users and Inventory (user.advanced:read, user.social:read, user.inventory-item:read) | get_user, generate_user_thumbnail, list_inventory |
Notifications (user.user-notification:write) | send_notification |
Subscriptions (universe.subscription-product.subscription:read) | get_subscription |
Analytics (universe.analytics:read) | query_analytics |
| Everything else: Ads, Game Events, Thumbnails, Creator Store saves, Legacy Badges, Legacy Develop, Legacy Followings, Legacy Game Internationalization, Legacy Groups, Legacy Localization Tables, Legacy Publish, Legacy Team Collaboration, Legacy Users | open_cloud_request |
What you can do
- Build scenes from a prompt. Create and mass-create instances, set typed properties, insert models, and write scripts, each as a clean undo step.
- Test gameplay in CI. Write specs, run them headlessly in the real engine through Open Cloud, and gate pull requests on the results.
- Catch exploits before they ship. The security reviewer flags server handlers that trust client input and suggests the server-side fix; the same check runs automatically on every PR.
- Drive a real playtest. Enter Play mode, send keyboard and mouse input, walk the character to a spot, read the combined server/client output, then stop.
- Inspect a live place. Read the instance tree, search by name or property, read and grep scripts, and pull the Output log.
- Automate Open Cloud. Seed DataStores for test fixtures, publish a place, broadcast a MessagingService topic, or look up users, groups, and inventory.
Known limits
These are platform limits, not bugs. They are written down here so you know going in.
- F5 playtest stop is best-effort.
stop_playtestmay not take, because the plugin and the running game are separate DataModels.stop_simulation(F8) stops cleanly. If an F5 playtest will not stop, press Stop in Studio. - In-play actions go through an injected runner. Input, runtime state, and stop during a playtest are relayed over the bridge, not called directly on the plugin.
- Headless tests run a server context. Open Cloud runs your published place on a server, where
RunService:IsStudio()is false and plugin APIs are absent. Use it for server and gameplay logic and the security tests, not for Studio-plugin or client-input behaviour. - Tool parity with Roblox's built-in Assistant is maintained by hand.
- Several Open Cloud systems are beta or experimental on Roblox's side (the Instance API, user restrictions, secrets, game servers, analytics, and everything behind
open_cloud_request). Their shapes can move, andopen_cloud_requestgives you the raw response, not a tidied one.
Tripwire is maintained by one person in spare time. Issues and pull requests usually get a reply within about a week. A slow reply is not a no.
Troubleshooting
The Studio tools time out or report no connected Studio. The plugin is not connected. Install Tripwire.rbxmx, restart Studio, click the Tripwire toolbar button, and press Connect in the panel. The panel status and the Output line [Tripwire v...] connected both confirm it.
The plugin reports that HTTP is blocked. Turn on Game Settings > Security > Allow HTTP Requests on the open place. This is the most common setup failure. Studio cannot reach the local bridge without it.
The Output shows a version mismatch between the plugin and the server. The installed .rbxmx is stale. Rebuild it (npx rbxtsc && rojo build --output Tripwire.rbxmx), copy it into your Plugins folder, and restart Studio. The plugin prints its compiled version, so the prefix tells you what is actually installed; the panel header shows the same version.
An Open Cloud tool returns 401 Invalid API Key. The key itself is not accepted: it was regenerated, expired, or pasted incompletely. Every tool fails the same way. Create or copy the key again on the Creator Dashboard, replace ROBLOX_OPEN_CLOUD_KEY, and reconnect the MCP server.
An Open Cloud tool returns a 403 or scope error. The key is missing the scope that tool needs, the universe or place id is wrong, or the place is not published. Add the scope on the Creator Dashboard (the tool description names it), confirm the ids, and reconnect the MCP server. The error text is Roblox's own, so it names what is missing.
run_tests does not see your latest change. It reads the published place. Publish first; rojo serve only updates the live edit session, not what Open Cloud runs.
npx cannot fetch the server. You have no Node.js, or no network for the first download. Install Node, or use the prebuilt binary from the Releases page and point command at it (see Alternatives under Install).
The server says the bridge port is busy. A previous server is still holding port 44331. Close the old MCP session or the stale process, then reconnect.
Prior art
The Studio runtime approach (a plugin that long-polls a local server, an injected in-play runner) follows ideas from boshyxd/robloxstudio-mcp and Chrrxs/robloxstudio-mcp. Tripwire is an independent, from-scratch implementation; the headless test harness, the CI security reviewer, and the Open Cloud tooling are its own.
Contributing
Bug reports, feature ideas, and patches are welcome. See CONTRIBUTING.md for the setup, the build gates, and the branch and commit rules, and ARCHITECTURE.md for how the pieces fit together. By taking part you agree to the Code of Conduct.
Found a security issue? Do not open a public issue. See SECURITY.md for the private disclosure path.
Changelog
Release notes for each version are on the Releases page.
License
MIT. See LICENSE.