Skip to main content

POST (/system/strings/validate)

Accepts an array of strings for validation and returns an array of results of equal size. The domain for these URIs is client-strings.xboxlive.com.

Remarks

Each result indicates whether the corresponding string is acceptable on XBOX LIVE, and contains the offending string if applicable. Identical strings will always give identical results. If you receive a non-successful result, analyze the result and modify the string accordingly.
Note:
The resulting VerifyStringResult will only report the first offending word in the string. There might be additional offending words within the string. If you plan to replace the offending words to make the string usable, you should replace the offending word or substring and then re-verify the string to look for additional offending substrings.

Required Request Headers

| Header| Description| | --- | --- | --- | | Authorization| Authentication Token. Example: XBL3.0 x=[hash];[token].| | x-xbl-contract-version| Integer API contract version. Must be 1 or 2 for this API.|

Request body

The request body is an array of strings, with no limits on the size of the array, and 512 characters per string.

Sample request

HTTP status codes

The service returns one of the status codes in this section in response to a request made with this method on this resource. For a complete list of standard HTTP status codes used with XBOX Live Services, see Standard HTTP status codes. | Code| Reason phrase| Description| | --- | --- | --- | --- | --- | --- | | 200| OK| All strings were processed successfully. This does not necessarily mean all strings had positive HResults.| | 401| Unauthorized| The request requires user authentication.| | 403| Forbidden| The request is not allowed for the user or service.| | 406| Not Acceptable| Missing Content-type: application/json header.| | 408| Request Timeout| Service could not understand malformed request. Typically an invalid parameter.|

Response body

Returns an array of VerifyStringResult (JSON), of the same size as the request array.

See also

Parent
/system/strings/validate
Last modified on August 20, 2026