Codectionary / Developer documentation / Luau

Client/server boundaries and project structure

A server owns shared game decisions while each client handles its own input, camera and presentation. Treat client messages as requests. Put private rules in server containers and expose only the data and operations the client actually needs.

Syntax

-- ServerScriptService: server rules
-- ReplicatedStorage: shared modules and remotes
-- StarterPlayerScripts: local presentation

Examples

Publish a small piece of state

Script in ServerScriptService. The server creates a replicated folder with a display attribute. Clients can read it; this is not a secure place for a secret or an authorization rule.

local ReplicatedStorage = game:GetService("ReplicatedStorage")
local status = Instance.new("Folder")
status.Name = "LessonStatus"
status:SetAttribute("Title", "Welcome")
status.Parent = ReplicatedStorage

Read it on the client

LocalScript in StarterPlayerScripts, paired with the server example. Wait for replication before using the object. The client reads display data without requesting access to server-only modules.

local ReplicatedStorage = game:GetService("ReplicatedStorage")
local status = ReplicatedStorage:WaitForChild("LessonStatus")
print(status:GetAttribute("Title"))

Best practices

  • Do not put secrets in replicated scripts or attributes; hiding a UI does not hide its data.
  • Test with Studio server and multiple clients so you can see which changes replicate.
  • Keep inventory, purchases and rewards authoritative on the server even when the client predicts visuals.

At a glance

Purpose
Typed scripting and Roblox development
File extension
.luau
Runs in
Luau host; Roblox engine examples require Roblox Studio
Usually used with
Roblox APIs and Studio

Specifications & further reading

Related Luau documentation