Brain and skill licensing

Who it's for. You will call the Hub from a published Web origin or Roblox place.

What you'll do. Mint an aig_ key in Studio (/developers/studio), get a play grant per brain, POST observations, apply { m, j, f } and Surge-only { d, g, jh }. Never download policy_weights.

Published games must not download trained weights. They POST observations and apply { m, j, f }. Surge Gauntlet also returns { d, g, jh } (dash / grab / jump height) — never reuse f as dash. Create the game and mint aig_ in Studio. Install the Roblox pack from SDK download; full request shapes on API reference.

Live play

Prefer POST /api/v1/play/act/batch for 2–20 AIs (one request per think tick @ 0.15–0.2 s). Single-AI smoke: POST /api/v1/play/act. Auth: Authorization: Bearer aig_…, plus game_id, brain_id(s), room_slug, obs, seq, and Roblox place_id (or web Origin). Report scores with POST /api/v1/play/rounds → …/complete. Never persist the act response as a brain file.

Keys

KindWhoUse
aig_ game licenseGame creator (shown once)play/act, play/act/batch, play/rounds
Campus secretFirst-party gymARENA_CAMPUS_SECRET / TrainConfig.CAMPUS_SECRET
aia_ compete keyMatch bots/state and /command (Vision Mayhem)
Cookie sessionLogged-in ownerConsole, owner train, round history GET

Brain owner grants a game: POST /api/v1/training/licenses/brain with scopes play | train | director. Mint a game key: POST /api/v1/training/licenses/game. Bind place_id / allowed origins. Owner-selects-game then N AI players in one round: Deploy & compete.

What returns weights

EndpointWeights?
POST /play/actNever
POST /play/act/batchNever
POST /play/rounds (+ complete / events)Never
GET /training/brain/exportYes — train grant / campus / cookie only
GET /training/sessionYes unless play-only (stripped)
POST /training/auto-coachWrites brain — train credential

Until ARENA_CAMPUS_SECRET (or ARENA_REQUIRE_TRAIN_AUTH=1) is set on the Hub, campus may still use legacy roblox_user_id. Set the secret in TrainConfig before treating production as locked.