Syntax
-- ServerScriptService: server rules
-- ReplicatedStorage: shared modules and remotes
-- StarterPlayerScripts: local presentationExamples
Publish a small piece of state
Script in ServerScriptService. The server creates a replicated folder with a display attribute. Clients can read it; this is not a secure place for a secret or an authorization rule.
local ReplicatedStorage = game:GetService("ReplicatedStorage")
local status = Instance.new("Folder")
status.Name = "LessonStatus"
status:SetAttribute("Title", "Welcome")
status.Parent = ReplicatedStorageRead it on the client
LocalScript in StarterPlayerScripts, paired with the server example. Wait for replication before using the object. The client reads display data without requesting access to server-only modules.
local ReplicatedStorage = game:GetService("ReplicatedStorage")
local status = ReplicatedStorage:WaitForChild("LessonStatus")
print(status:GetAttribute("Title"))Best practices
- Do not put secrets in replicated scripts or attributes; hiding a UI does not hide its data.
- Test with Studio server and multiple clients so you can see which changes replicate.
- Keep inventory, purchases and rewards authoritative on the server even when the client predicts visuals.
At a glance
- Purpose
- Typed scripting and Roblox development
- File extension
- .luau
- Runs in
- Luau host; Roblox engine examples require Roblox Studio
- Usually used with
- Roblox APIs and Studio
Specifications & further reading
Related Luau documentation
Script, LocalScript and ModuleScript placement
The same code can behave differently depending on where it runs. These lessons use server Scripts in ServerScriptService and LocalScripts in StarterPlayerScripts or StarterGui. A ModuleScript runs when required. Script RunContext also affects execution, so inspect it when a script appears silent.RemoteEvent requests and notifications
RemoteEvent sends a message without waiting for a return value. A client calls FireServer; Roblox supplies the sending Player to OnServerEvent. The server can target one client with FireClient or broadcast with FireAllClients. This example requests a fixed help message, not a reward.Server authority, validation and rate limits
A valid-looking remote call can still be an impossible game action. Validate both the shape of a request and whether the sender may perform it now. This example lets a nearby living player request a visual switch; it does not trust a client position, target Instance or reward.game, workspace and storage services
game is the root DataModel and workspace holds the active 3D world. GetService obtains engine services by class name. ReplicatedStorage is visible to both sides; ServerStorage holds objects clients should not receive until the server places them into a replicated location.
The same code can behave differently depending on where it runs. These lessons use server Scripts in ServerScriptService and LocalScripts in StarterPlayerScripts or StarterGui. A ModuleScript runs when required. Script RunContext also affects execution, so inspect it when a script appears silent.RemoteEvent requests and notifications
RemoteEvent sends a message without waiting for a return value. A client calls FireServer; Roblox supplies the sending Player to OnServerEvent. The server can target one client with FireClient or broadcast with FireAllClients. This example requests a fixed help message, not a reward.Server authority, validation and rate limits
A valid-looking remote call can still be an impossible game action. Validate both the shape of a request and whether the sender may perform it now. This example lets a nearby living player request a visual switch; it does not trust a client position, target Instance or reward.game, workspace and storage services
game is the root DataModel and workspace holds the active 3D world. GetService obtains engine services by class name. ReplicatedStorage is visible to both sides; ServerStorage holds objects clients should not receive until the server places them into a replicated location.