Developer API v0.7.25
View .mdBuild catalog browsing, natural-language search, availability displays, branded guest accounts, editable pages, and configurable software with Kismet. Developer API v0.7.25 with the inline email-signup extension documents 77 operations, including Google guest sign-in, verified email signup, events and webhook destinations, software settings and account panels, and 18 early-access content operations. Request preview access before integrating early-access features; production content promotion requires its own registered channel and explicit publication grant.
Authorized collection administrators and developers can create scoped TEST and LIVE applications, installations, and credentials from the collection’s Kismet settings. Guest preferences support TEST rehearsal and LIVE membership and email double opt-in with Kismet-hosted confirmation.
API base URL: https://api.ksmt.app/v1
Operation families
Section titled “Operation families”| Family | Operations | Current contract |
|---|---|---|
| Catalog | 4 | Read groups and group details; query dated availability and undated stay estimates |
| Credential inspection | 1 | Read the credential’s own installation scope |
| Published rentals and manager content | 5 | Read-only, collection/resource grants |
| Natural-language search | 1 | Ranked BookableProduct discovery; not availability, quotes, or booking |
| Calendar and collection availability | 2 | Synced commercial reads; indicative, not quotes |
| Articles | 2 | Published Kismet block content only |
| Content (preview) | 15 | Define page fields, import or edit drafts, review changes, and publish to staging |
| Fixture registry | 2 | Manifest metadata; installable public package is separate |
| Booking requests | 1 | TEST only; no charge or production reservation |
| Branded guest authentication | 7 | Email-code and hosted Google sign-in; server-key, same-origin BFF, CSRF protected |
| Guest account and saves | 4 | Signed-in, collection-filtered self-service |
| Guest contact | 3 | Signed-in contact updates and verified email changes |
| Guest wallet | 2 | Wallet summaries and trusted capture preparation; not charge authority |
| Guest preferences | 2 | Independent membership and email preferences; TEST simulation or LIVE double opt-in |
| Events and webhooks | 7 | Early access: installation-scoped history, signed destinations, delivery status and replay |
| Software | 7 | Early access: revisioned settings, assigned visits, engagement receipts, aggregate performance, and manager-panel render authorization |
The signed-in booking flow uses the existing booking-request operation with a BFF-held guest token; it is not a second endpoint.
The event and webhook extension is available for integration review; production event delivery is not yet enabled. Request access and prepare a receiver.
Preview a catalog before publication
Section titled “Preview a catalog before publication”Group list/detail and rental list/detail accept an explicit view=staging for
TEST installations with manager-approved preview access. The view can include
eligible unpublished content without publishing it or granting booking authority.
The source-pinned SDK exposes the same four reads. Follow Staging catalog
previews to configure access, build a directory and
room-preview drawer, and handle independent approval expiry. API deployment and
SDK installation must both support the extension.
Authentication and authorization
Section titled “Authentication and authorization”Every operation uses Authorization: Bearer …. Kismet resolves the application, installation environment, positive collection/resource grants, and capabilities server-side. URL identifiers narrow a request; they never expand authority.
- Publishable keys are for explicitly browser-safe read surfaces and authorized origins.
- Restricted server keys are required for guest auth, guest account operations, and writes.
- TEST and LIVE are installation properties. TEST bookings and telemetry remain sandboxed even when they use real CMS content.
Pricing and booking semantics
Section titled “Pricing and booking semantics”Group availability and pricing returns explicit fee/tax
inclusions and freshness. Its base-calendar adapter does not prove all-plan
coverage: use lowestStay only when populated, otherwise show Check availability.
Observed estimates are not checkout quotes. Fixture wiring is separate.
Catalog pricing currently supports static groups classified as buildings, with neighborhood parents as selection filters. Other group classifications and dynamic groups are not yet supported by these two pricing operations. General catalog group reads have a broader scope; see the guide before choosing an operation.
Calendar rates, pricing.nightlyFrom, and availability display fields come from Kismet’s synchronized calendar plane. They are indicative display values, not quotes. They carry no taxes, final total, payment authority, expiry, or booking action.
createVacationRentalBookingRequest records a sandbox reservation in TEST, including guestbook, journey, and telemetry activity. It does not charge a payment method or create a production reservation. A LIVE installation receives SANDBOX_ONLY from this operation.
SDK and Developer MCP
Section titled “SDK and Developer MCP”The REST API is the application contract, and the SDK is its typed runtime client. The Developer MCP helps coding agents find recipes, inspect operations and Fixture coverage, and plan and validate integrations. Sign in with Kismet to manage developer access and Fixtures within your collection roles; use a suitably scoped server API key to inspect or configure telemetry. See Authentication and access for the separate requirements.
The Developer MCP does not replace your site’s guest APIs or accept Kismet guest tokens. Generated sites call the SDK or REST API through the documented browser/BFF boundaries. Agents without an MCP client can use llms.txt and the Markdown twin linked from each operation page.
Install Kismet Developer in Claude or Codex, or connect it in Lovable.
Reference formats
Section titled “Reference formats”- OpenAPI v0.7.25 JSON
- Generated HTML pages in the API reference navigation
- A Markdown twin linked from every operation page
llms.txtfor coding agents
Integration boundaries
Section titled “Integration boundaries”- Access is collection-scoped. TEST and LIVE use separate installations and credentials. Browser-safe reads may use an origin-bound publishable key; guest operations and writes need a restricted server key behind a same-origin BFF. Set up and manage credentials.
- Discovery and display prices are not checkout offers. Search returns candidates, and calendar/group pricing returns estimates with coverage and freshness. Use the configured managed checkout for an authoritative offer and payment. Understand group pricing.
- Developer API booking requests are TEST-only. They cannot charge or create a production reservation. Managed Fixture checkout is a separate integration, as described above.
- Choose a shipped Fixture installation target. WordPress plugin delivery and supported embeds are available. The public
@kismet-tech/fixturesnpm package is not published; a manifest is not proof that an npm artifact exists. Compare installation methods. - Builder access and guest sign-in are different. Developer MCP sign-in authorizes setup work for a Kismet account. Your visitors sign in through the site’s guest-account integration. Choose an authentication mode.
For integration help, contact [email protected].