Odel
Tripwire

Tripwire

Local
@aliboily3RustMITUpdated 1w ago

MCP for Roblox Studio and Open Cloud: drive Studio, run headless tests, and review game security.

Tripwire

made by alibolly

npm CI MCP Registry License: MIT

An MCP server that gives an AI coding agent real control of Roblox Studio and Roblox Open Cloud, with a test-and-security layer no other Studio MCP has.

Tripwire lets an assistant read, write, and edit the data model, drive playtests with simulated input, run tests-as-code headlessly in the real engine, flag client-trust exploits in game code, and call the Open Cloud APIs (DataStores, MessagingService, Memory Stores, and more). The Studio tools need no API key; the headless test, asset, and Open Cloud tools use an Open Cloud key.


Requirements

  • An MCP client: Claude Code, Codex, Gemini, or any client that speaks MCP over stdio.
  • Roblox Studio, for the Studio tools. These need no API key.
  • Node.js, only if you run the server with npx. The prebuilt binary needs no Node.
  • For the headless test, asset, and Open Cloud tools: a published place and a Roblox Open Cloud API key. See Open Cloud setup.

Quickstart

Tripwire is for Roblox developers who drive Studio through an AI coding agent.

  1. Wire the server into your MCP client (one command or a small config block, see Install below).
  2. Install the Studio plugin so the Studio tools can reach Studio (see the plugin step in Install).
  3. Open your place in Studio, turn on Game Settings > Security > Allow HTTP Requests, then click the Tripwire toolbar button and press Connect in the panel. The panel shows Connected and the Output prints [Tripwire v...] connected.
  4. Ask your agent to run studio_status. A connected Studio confirms the bridge works.
  5. Optional: add an Open Cloud key for the headless test, asset, and Open Cloud tools (see Open Cloud setup).

Install

Tripwire's server is a single binary. The easiest way to run it is with npx, which fetches the prebuilt binary for your platform, so there is no Rust toolchain to install. Prefer a manual binary or a source build? See the Alternatives at the end of this section.

Claude Code

One command:

claude mcp add --transport stdio tripwire -- npx -y tripwire-roblox

Or add it to a project .mcp.json (or ~/.claude.json):

{
  "mcpServers": {
    "tripwire": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "tripwire-roblox"]
    }
  }
}
Codex

Add to ~/.codex/config.toml:

[mcp_servers.tripwire]
command = "npx"
args = ["-y", "tripwire-roblox"]

Or: codex mcp add tripwire -- npx -y tripwire-roblox

Gemini

Add to ~/.gemini/settings.json (or a project .gemini/settings.json):

{
  "mcpServers": {
    "tripwire": {
      "command": "npx",
      "args": ["-y", "tripwire-roblox"]
    }
  }
}

Or: gemini mcp add tripwire npx -y tripwire-roblox

Other MCP clients

Any client that speaks MCP over stdio can run it:

command: npx
args:    ["-y", "tripwire-roblox"]
Alternatives: prebuilt binary, or build from source

Prebuilt binary (no Node). Download the archive for your platform from the Releases page (for example tripwire-server-vX.Y.Z-aarch64-apple-darwin.tar.gz), extract it, and point your client's command at the extracted tripwire-server with empty args.

Build from source (needs Rust):

git clone https://github.com/aliboIly/Tripwire.git
cd Tripwire/server
cargo build --release   # produces server/target/release/tripwire-server

Then point your client's command at that binary path.

Studio plugin (required for the Studio tools)

The Studio tools reach Studio through a small plugin that long-polls the local server. Grab Tripwire.rbxmx from the Releases page, or build it:

cd Tripwire/plugin
npm install
npx rbxtsc
rojo build --output Tripwire.rbxmx
cp Tripwire.rbxmx ~/Documents/Roblox/Plugins/   # macOS; Windows: %LOCALAPPDATA%\Roblox\Plugins

Restart Studio, enable Game Settings > Security > Allow HTTP Requests, then click the Tripwire toolbar button and press Connect in the panel. The panel shows Connected and the Output prints [Tripwire v...] connected.

Open Cloud key (for headless tests, assets, and Open Cloud tools)

The Studio tools need no key. The Open Cloud tools do. See Open Cloud setup below for the full walkthrough.


Open Cloud setup

Most of Tripwire needs no credentials. These tools do, because they call Roblox Open Cloud: run_luau, the headless tests (run_tests, run_test_file, list_tests), and every tool in the Open Cloud sections below (assets, publishing, data stores, messaging, memory, universe and servers, the Engine Instance API, moderation, secrets, monetization, Creator Store, groups, analytics, platform, and open_cloud_request). They authenticate with a Roblox Open Cloud API key.

Use at your own risk. An Open Cloud key is a real credential with real power over your experience. Depending on the scopes you grant it, it can read and overwrite your live DataStores, publish new versions of your place, upload assets to your account, and message your servers. Treat it like a password: grant only the scopes you actually use, restrict it to your own IP, never commit it, and revoke it if it leaks. You are responsible for what you do with it. Tripwire is not affiliated with or endorsed by Roblox.

1. Create the key

  1. Go to create.roblox.com/dashboard/credentials and sign in.
  2. Click Create API Key and name it (for example Tripwire).
  3. Under Access Permissions, add only the API systems for the tools you want, and grant each the operation it needs, scoped to your experience. Every system the dashboard offers has a tool; the map is in Permissions to tools below. The short version:
    • Luau Execution (write): run_luau and the headless tests.
    • universe-places (write): publish_place.
    • Assets (read + write) and Asset Permissions: the asset tools.
    • DataStores and Ordered DataStores: the data-store tools.
    • Messaging Service (publish) and Memory Stores: those tools.
    • Universe, Place, Instance, User Restrictions, Secrets, Analytics: the universe, server, instance, moderation, secrets, and analytics tools.
    • Developer Products, Game Passes, Creator Store: the monetization and store tools.
    • User/Group/Inventory/Subscription/Notification: the platform, group, and engagement tools.
    • Anything else (the legacy and experimental systems): open_cloud_request.
  4. Under Security, set Accepted IP Addresses to your machine's IP, or 0.0.0.0/0 to allow any (simplest for local use). Set an expiration if you want.
  5. Click Save & Generate Key and copy the key string. It is shown only once.

2. Find your universe and place IDs

In the Studio command bar (View, then Command Bar), run:

print("universe", game.GameId, "place", game.PlaceId)

GameId is your ROBLOX_UNIVERSE_ID; PlaceId is your ROBLOX_PLACE_ID. The place must be published to Roblox for Open Cloud to act on it.

3. Give Tripwire the credentials

Create a .env at the repo root. It is gitignored and the server loads it automatically:

ROBLOX_OPEN_CLOUD_KEY=paste_the_key_here
ROBLOX_UNIVERSE_ID=000000
ROBLOX_PLACE_ID=000000
ROBLOX_CREATOR_USER_ID=000000   # only for upload_asset (your user id)

Or put the same variables in your MCP client's env block instead (those take precedence). Reconnect the MCP server after changing either. Each tool works when the key grants its scope and returns Roblox's own error if a scope is missing, so you can add scopes as you go.


Tools

Connection

studio_statusWhether a Studio is connected, the active place, and any other connected studios.
ping_studioRound-trip a ping through the plugin to confirm the live bridge works.
list_studiosList every connected (or recently seen) Studio: place, whether it is active, last-seen, and playtest state.
set_active_studioChoose which connected Studio the tools target (by id, id prefix, or place name). Automatic with one Studio.

Read and inspect

get_file_treeList the instance tree from a path (default the whole game), bounded by depth.
get_instance_childrenList the direct children (name and class) of an instance.
get_instance_propertiesRead an instance's name, class, full path, attributes, and a curated set of common engine properties (Position, Size, Color, Material, Anchored, Text, and so on).
search_objectsFind instances whose name contains a query, optionally filtered by exact class or by class-and-subclasses (isA).
search_by_propertyFind instances whose property equals a value, optionally filtered by exact class or by class-and-subclasses (isA).
get_script_sourceRead the source of a Script, LocalScript, or ModuleScript.
grep_scriptsSearch script sources for a substring; returns path, line number, and line.
get_output_logRecent Studio Output entries (message, type, timestamp).
get_selectionThe instances currently selected in Studio.
get_class_infoLook up a Roblox class's members (properties, methods, events) with their types, inherited members folded in. Answered from a bundled API reflection dump, so it needs no Studio and no key.

Spatial (read-only)

raycastCast a ray and report the first hit (instance, position, normal, material, distance) or no hit, with an optional excluded subtree.
get_bounding_boxThe world-space bounding box (center and size) of a Model or BasePart.
find_spawnsList the SpawnLocations under a path: position, whether each is enabled, and whether it is neutral.
capture_screenshotCapture the Studio viewport as a JPEG image so the agent can see the scene. Needs the plugin connected and Allow Mesh / Image APIs enabled (Game Settings, Security). Edit mode only.

Edit (each is one undo step)

create_instanceCreate an instance of a class with an optional name and initial properties.
delete_instanceDestroy an instance and its descendants.
set_propertySet one typed property (primitive, Vector3, Color3, UDim2, CFrame, EnumItem, or an instance reference).
update_script_sourceReplace a script's source through the script editor (the supported write path).
insert_modelInsert an asset by id, with optional reposition or unpack.
mass_createCreate many instances in one undo step (atomic, or best-effort with per-item results).
mass_set_propertySet one property on many instances in one undo step (atomic or best-effort).

Playtest and input

start_playtestStart an F5 playtest (server and client DataModels with a player); injects the in-play runner.
stop_playtestStop the F5 playtest (best-effort; F5 teardown can outlast the confirmation).
start_simulationStart an F8 run (server-only simulation, no client or player).
stop_simulationStop the F8 run (clean).
simulate_mouse_inputClick or move the mouse at screen coordinates during an F5 playtest.
simulate_keyboard_inputPress a key (tap/press/release) or type text during an F5 playtest.
character_navigationWalk the local character toward a world position; reports whether it reached the goal.
get_playtest_outputThe running playtest's output log, aggregated across the server and client peers. Pass the cursor from the previous call as since to get only new lines; the buffer is bounded so long sessions do not freeze it.
reset_playtest_outputClear the playtest's output buffers so the next read starts fresh, without restarting Studio.
run_luau_liveEvaluate Luau in the live F5 playtest server and return the result, so you can inspect the running game (a Humanoid's state, an NPC's position, a path's waypoints) without adding a print and replaying. Needs an active playtest and ServerScriptService.LoadStringEnabled on in the test place. Distinct from run_luau, which is headless against the published place.

Tests and headless execution (Open Cloud)

run_luauRun a Luau script headlessly in the published place; returns the results and logs.
run_testsRun the headless test suite in the published place and report passed/failed with messages.
run_test_fileRun a single spec by name, headlessly.
list_testsList the spec files and their cases discovered in the published place.
write_testWrite a roblox-ts test spec to disk; rebuild and publish, then run_tests picks it up.

Security review (static analysis, no key)

review_securityReview the game source for client-trust and unvalidated-remote issues, each with a suggested server-side fix.
scan_remotesList server remote handlers and the client-controlled parameters of each.
scan_client_trustFlag server handlers that use client-supplied values without validating them.

Assets and publishing (Open Cloud)

upload_assetUpload a local file as a Roblox asset (Decal, Audio, Model, Animation, or Video); returns the assetId.
get_assetAn asset's metadata: type, name, description, moderation state, current revision.
update_assetChange an asset's name or description, or (Models) upload new content as a new version.
list_asset_versionsAn asset's versions with their moderation state.
rollback_asset_versionRoll an asset back to an earlier version.
archive_asset / restore_assetHide an asset from the site and experiences, or bring it back.
list_asset_quotasYour upload quotas and how much of each is used.
download_assetDownload an asset's content (a model, image, or place file) to a local path.
grant_asset_permissionsGrant a user, group, roleset, universe, or everyone a permission (Use, Edit, Download) on assets you own.
publish_placePublish a local place file (.rbxl/.rbxlx) as a new version of the experience.

DataStores (Open Cloud)

list_datastoresList the standard data stores in the universe.
list_datastore_entriesList entry keys in a data store. Optional scope; - lists every scope.
get_datastore_entryRead an entry's value and metadata, or an older revision of it.
set_datastore_entryCreate or overwrite an entry (value plus optional users/attributes).
delete_datastore_entrySoft-delete an entry (purged after 30 days).
increment_datastore_entryAtomically add an integer to a numeric entry.
list_datastore_entry_revisionsAn entry's revision history, newest first.
delete_datastore / undelete_datastoreSchedule a whole data store for deletion in 30 days, or cancel that.
snapshot_datastoresSnapshot every data store so the next write to each key keeps a versioned backup. Run it before a migration.
list_ordered_entriesList ordered data store entries by value, ascending or descending.
get_ordered_entryRead one ordered data store entry.
set_ordered_entrySet (upsert) an ordered data store entry to a non-negative integer.
increment_ordered_entryAtomically add to an ordered data store entry.
delete_ordered_entryDelete an ordered data store entry.

Messaging and memory (Open Cloud)

publish_messagePublish a message to a MessagingService topic (reaches running production servers).
memory_sorted_map_setSet (upsert) a Memory Store sorted-map item, with TTL and sort keys.
memory_sorted_map_getRead a Memory Store sorted-map item.
memory_sorted_map_listList sorted-map items in sort order.
memory_sorted_map_deleteDelete a sorted-map item.
memory_queue_addAdd an item to a Memory Store queue, with priority and TTL.
memory_queue_readRead items from a queue; returns a readId for the discard call.
memory_queue_discardPermanently remove a read batch by its readId.
flush_memory_storeWipe every Memory Store structure in the universe (LIVE or TEST scope) and wait for it.

Universe, place, and servers (Open Cloud)

get_universeThe configured universe's metadata.
update_universeVoice chat, private server price, and per-platform join toggles.
get_placeThe configured place's metadata.
update_placeThe place's name, description, or server size.
restart_serversMove live servers to the newest published version, outdated ones only by default, with an optional bleed-off.
list_game_serversThe live servers running a place version: players, uptime, job ids.
get_game_server_logsA live server's log lines by job id. The production counterpart of get_playtest_output.
translate_textTranslate text into one or more languages with Roblox's translation service.

Engine Instance API (Open Cloud, no Studio needed)

cloud_list_instance_childrenList an instance's children in the published place. Start from root.
cloud_get_instanceRead an instance's details in the published place.
cloud_update_instanceRename an instance or set a script's Source, Enabled, or RunContext in the published place.

Moderation (Open Cloud)

list_user_restrictionsUsers who have ever been banned from the universe or a place.
get_user_restrictionOne user's ban state and reasons.
set_user_restrictionBan (permanent or timed, with reasons, optionally not extended to alts) or unban a user. Kicks them from live servers.
list_user_restriction_logsThe audit log of ban and unban changes.

Secrets (Open Cloud)

list_secretsThe universe's secrets, metadata only.
create_secret / update_secretStore a value for HttpService:GetSecret. It is sealed with the universe's public key on your machine before upload.
delete_secretPermanently delete a secret.

Monetization and Creator Store (Open Cloud)

list_developer_products / get_developer_productDeveloper products with prices and sale state.
create_developer_product / update_developer_productCreate or edit a developer product: name, description, Robux price, sale state, icon.
list_game_passes / get_game_passGame passes with prices and sale state.
create_game_pass / update_game_passCreate or edit a game pass.
search_creator_storeSearch the Creator Store for models, plugins, audio, decals, meshes, video, or fonts; returns asset ids for insert_model.
get_creator_store_assetA store listing's creator, votes, price, and asset details.
get_creator_store_productOne of your own store products: prices, published state, restrictions.

Groups (Open Cloud)

get_groupA group's metadata.
list_group_membershipsA group's members and their roles, filterable by user or role.
list_group_rolesA group's roles and ranks.
list_group_join_requests / resolve_group_join_requestPending join requests, and accept or decline one.
set_group_roleAssign a role to a member, or remove one.

Platform, engagement, and analytics (Open Cloud)

get_userA user's public profile.
generate_user_thumbnailA user's avatar headshot as an image URL.
list_inventoryA user's inventory items, filterable by type or id.
send_notificationSend an experience notification to a user (from a Creator Dashboard template).
get_subscriptionRead a user's subscription to a subscription product.
query_analyticsA metric (DAU, sessions, revenue, and so on) over a time range, broken down and filtered by dimension; or the values a dimension can take.

Everything else (Open Cloud)

open_cloud_requestCall any endpoint under apis.roblox.com with the key attached: method, host-relative path, query, JSON body. This is how the legacy and experimental systems are reached (badges, localization tables, Team Create, game events, thumbnails, ads, place version history, creator store products). The key is only ever sent to that host.

Permissions to tools

Every API system you can add to a key on the Creator Dashboard, and the tools that use it. Scope names are the ones the dashboard and Roblox's error messages use.

Permission (scope)Tools
Luau Execution (universe.place.luau-execution-session)run_luau, run_tests, run_test_file, list_tests
Places (universe-places:write, universe.place)publish_place, update_place, get_place
Universe (universe:read, universe:write)update_universe, restart_servers, translate_text, list_game_servers, get_game_server_logs
Instance (universe.place.instance)cloud_list_instance_children, cloud_get_instance, cloud_update_instance
Data Stores (universe-datastores.control, .objects, .versions)the DataStores section: entries, revisions, store delete, snapshot
Ordered Data Stores (universe.ordered-data-store.scope.entry)list/get/set/increment/delete_ordered_entry
Memory Stores (memory-store.sorted-map, .queue, :flush)the sorted-map and queue tools, flush_memory_store
Messaging Service (universe-messaging-service:publish)publish_message
User Restrictions (universe.user-restriction)list/get/set_user_restriction, list_user_restriction_logs
Secrets (universe.secret)list/create/update/delete_secret
Assets (asset:read, asset:write)upload_asset, get_asset, update_asset, list_asset_versions, rollback_asset_version, archive_asset, restore_asset, list_asset_quotas
Asset Permissions (asset-permissions:write)grant_asset_permissions
Legacy Assets (legacy-asset:manage)download_asset
Developer Products (developer-product)list/get/create/update_developer_product
Game Passes (game-pass)list/get/create/update_game_pass
Creator Store (creator-store-product)search_creator_store, get_creator_store_asset, get_creator_store_product; create and update via open_cloud_request
Groups (group:read, group:write)get_group, list_group_memberships, list_group_roles, list_group_join_requests, resolve_group_join_request, set_group_role
Users and Inventory (user.advanced:read, user.social:read, user.inventory-item:read)get_user, generate_user_thumbnail, list_inventory
Notifications (user.user-notification:write)send_notification
Subscriptions (universe.subscription-product.subscription:read)get_subscription
Analytics (universe.analytics:read)query_analytics
Everything else: Ads, Game Events, Thumbnails, Creator Store saves, Legacy Badges, Legacy Develop, Legacy Followings, Legacy Game Internationalization, Legacy Groups, Legacy Localization Tables, Legacy Publish, Legacy Team Collaboration, Legacy Usersopen_cloud_request

What you can do

  • Build scenes from a prompt. Create and mass-create instances, set typed properties, insert models, and write scripts, each as a clean undo step.
  • Test gameplay in CI. Write specs, run them headlessly in the real engine through Open Cloud, and gate pull requests on the results.
  • Catch exploits before they ship. The security reviewer flags server handlers that trust client input and suggests the server-side fix; the same check runs automatically on every PR.
  • Drive a real playtest. Enter Play mode, send keyboard and mouse input, walk the character to a spot, read the combined server/client output, then stop.
  • Inspect a live place. Read the instance tree, search by name or property, read and grep scripts, and pull the Output log.
  • Automate Open Cloud. Seed DataStores for test fixtures, publish a place, broadcast a MessagingService topic, or look up users, groups, and inventory.

Known limits

These are platform limits, not bugs. They are written down here so you know going in.

  • F5 playtest stop is best-effort. stop_playtest may not take, because the plugin and the running game are separate DataModels. stop_simulation (F8) stops cleanly. If an F5 playtest will not stop, press Stop in Studio.
  • In-play actions go through an injected runner. Input, runtime state, and stop during a playtest are relayed over the bridge, not called directly on the plugin.
  • Headless tests run a server context. Open Cloud runs your published place on a server, where RunService:IsStudio() is false and plugin APIs are absent. Use it for server and gameplay logic and the security tests, not for Studio-plugin or client-input behaviour.
  • Tool parity with Roblox's built-in Assistant is maintained by hand.
  • Several Open Cloud systems are beta or experimental on Roblox's side (the Instance API, user restrictions, secrets, game servers, analytics, and everything behind open_cloud_request). Their shapes can move, and open_cloud_request gives you the raw response, not a tidied one.

Tripwire is maintained by one person in spare time. Issues and pull requests usually get a reply within about a week. A slow reply is not a no.


Troubleshooting

The Studio tools time out or report no connected Studio. The plugin is not connected. Install Tripwire.rbxmx, restart Studio, click the Tripwire toolbar button, and press Connect in the panel. The panel status and the Output line [Tripwire v...] connected both confirm it.

The plugin reports that HTTP is blocked. Turn on Game Settings > Security > Allow HTTP Requests on the open place. This is the most common setup failure. Studio cannot reach the local bridge without it.

The Output shows a version mismatch between the plugin and the server. The installed .rbxmx is stale. Rebuild it (npx rbxtsc && rojo build --output Tripwire.rbxmx), copy it into your Plugins folder, and restart Studio. The plugin prints its compiled version, so the prefix tells you what is actually installed; the panel header shows the same version.

An Open Cloud tool returns 401 Invalid API Key. The key itself is not accepted: it was regenerated, expired, or pasted incompletely. Every tool fails the same way. Create or copy the key again on the Creator Dashboard, replace ROBLOX_OPEN_CLOUD_KEY, and reconnect the MCP server.

An Open Cloud tool returns a 403 or scope error. The key is missing the scope that tool needs, the universe or place id is wrong, or the place is not published. Add the scope on the Creator Dashboard (the tool description names it), confirm the ids, and reconnect the MCP server. The error text is Roblox's own, so it names what is missing.

run_tests does not see your latest change. It reads the published place. Publish first; rojo serve only updates the live edit session, not what Open Cloud runs.

npx cannot fetch the server. You have no Node.js, or no network for the first download. Install Node, or use the prebuilt binary from the Releases page and point command at it (see Alternatives under Install).

The server says the bridge port is busy. A previous server is still holding port 44331. Close the old MCP session or the stale process, then reconnect.


Prior art

The Studio runtime approach (a plugin that long-polls a local server, an injected in-play runner) follows ideas from boshyxd/robloxstudio-mcp and Chrrxs/robloxstudio-mcp. Tripwire is an independent, from-scratch implementation; the headless test harness, the CI security reviewer, and the Open Cloud tooling are its own.


Contributing

Bug reports, feature ideas, and patches are welcome. See CONTRIBUTING.md for the setup, the build gates, and the branch and commit rules, and ARCHITECTURE.md for how the pieces fit together. By taking part you agree to the Code of Conduct.

Found a security issue? Do not open a public issue. See SECURITY.md for the private disclosure path.

Changelog

Release notes for each version are on the Releases page.


License

MIT. See LICENSE.