---
title: "Capture an offer and request its email"
description: "On explicit guest submission, award the configured offer and send one real email with [STAGING] in the subject. Requires a TEST server key with offers.write and an exact registered STAGING origin. The recipient must be registered unless an unexpired, manager-enabled requested-offer-email participation policy covers this installation and exact verified staging origin. Does not authenticate the guest, enroll membership or change LIVE marketing consent. Reuse the idempotency key on retry. A recipient receives at most one email per offer and installation, including across different keys. accepted means provider acceptance, not inbox delivery; pending or unknown must not be shown as sent and must not trigger a new send."
---

`POST /v1/developer/collections/{collection}/offers/{offerId}/captures`

**Operation ID:** `captureDeveloperOffer`

On explicit guest submission, award the configured offer and send one real email with [STAGING] in the subject. Requires a TEST server key with offers.write and an exact registered STAGING origin. The recipient must be registered unless an unexpired, manager-enabled requested-offer-email participation policy covers this installation and exact verified staging origin. Does not authenticate the guest, enroll membership or change LIVE marketing consent. Reuse the idempotency key on retry. A recipient receives at most one email per offer and installation, including across different keys. accepted means provider acceptance, not inbox delivery; pending or unknown must not be shown as sent and must not trigger a new send.

## Contract status

| Field | Value |
| --- | --- |
| Maturity | `preview` |
| Required capability | `offers.write` |
| Freshness class | `authenticated-state` |
| Quota cost | `1` |

All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential's installation grants; identifiers in the URL never grant access.

## Request parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `collection` | path | string | yes |  |
| `offerId` | path | string | yes |  |
| `origin` | header | string | yes |  |

## Request body

The request body is JSON. The canonical schema is:

```json
{
  "type": "object",
  "additionalProperties": false,
  "required": [
    "email",
    "origin",
    "idempotencyKey",
    "consent"
  ],
  "properties": {
    "email": {
      "type": "string",
      "format": "email",
      "maxLength": 254
    },
    "origin": {
      "type": "string",
      "minLength": 8,
      "maxLength": 255
    },
    "idempotencyKey": {
      "type": "string",
      "minLength": 16,
      "maxLength": 200,
      "pattern": "^[A-Za-z0-9_-]+$"
    },
    "consent": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "accepted",
        "disclosureHash"
      ],
      "properties": {
        "accepted": {
          "type": "boolean",
          "enum": [
            true
          ]
        },
        "disclosureHash": {
          "type": "string",
          "pattern": "^[a-f0-9]{64}$"
        }
      }
    },
    "attribution": {
      "type": [
        "object",
        "null"
      ],
      "additionalProperties": false,
      "required": [
        "enrollmentId",
        "sessionId"
      ],
      "properties": {
        "enrollmentId": {
          "type": "string",
          "format": "uuid"
        },
        "sessionId": {
          "type": "string",
          "minLength": 8,
          "maxLength": 255
        },
        "verificationProof": {
          "type": [
            "string",
            "null"
          ],
          "maxLength": 256,
          "description": "Server-only proof from portable email verification. sessionId remains the destination browser. The API resolves the original source session solely for enrollment attribution, preserving ownership checks."
        }
      }
    }
  }
}
```

Minimal example:

```json
{
  "email": "developer-test@example.com",
  "origin": "https://staging.example.com",
  "idempotencyKey": "offer-submission-0001",
  "consent": {
    "accepted": true,
    "disclosureHash": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
  }
}
```

## cURL

Set `KISMET_API_ORIGIN=https://api.ksmt.app` and configure `KISMET_DEVELOPER_API_KEY` in your environment. Run server-credential requests from your backend, not browser code.

```sh
curl --request POST \
  "$KISMET_API_ORIGIN/v1/developer/collections/example-collection/offers/{offerId}/captures" \
  --header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \
  --header "Accept: application/json" \
  --header "origin: $KISMET_SITE_ORIGIN" \
  --header "Content-Type: application/json" \
  --data '{"email":"developer-test@example.com","origin":"https://staging.example.com","idempotencyKey":"offer-submission-0001","consent":{"accepted":true,"disclosureHash":"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"}}'
```

## Responses

| Status | Meaning |
| --- | --- |
| 200 | Success. |
| 400 | Invalid request parameters or body. |
| 401 | Missing, invalid, expired, or inappropriate credential/session. |
| 403 | Credential lacks the required grant/capability, or an origin/CSRF check failed. |
| 404 | The authorized resource was not found. |
| 409 | Request conflicts with the installation environment or current state. |
| 429 | Rate limit or quota exceeded; inspect response metadata before retrying. |
| 503 | A required Kismet dependency is temporarily unavailable. |

### 200 response example

```json
{
  "captureId": "22222222-2222-4222-8222-222222222222",
  "environment": "TEST",
  "offer": {
    "id": "11111111-1111-4111-8111-111111111111",
    "status": "issued"
  },
  "email": {
    "status": "accepted",
    "acceptedAt": "2026-09-29T03:00:00.000Z"
  },
  "replayed": false
}
```

### 200 response schema

Content type: `application/json`. Required fields, nullable values, and nested structures are defined below.

<details>
<summary>View complete response schema</summary>

```json
{
  "type": "object",
  "additionalProperties": false,
  "required": [
    "captureId",
    "environment",
    "offer",
    "email",
    "replayed"
  ],
  "properties": {
    "captureId": {
      "type": "string",
      "format": "uuid"
    },
    "environment": {
      "type": "string",
      "enum": [
        "TEST"
      ]
    },
    "offer": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "id",
        "status"
      ],
      "properties": {
        "id": {
          "type": "string"
        },
        "status": {
          "type": "string",
          "enum": [
            "issued",
            "pending",
            "unavailable"
          ]
        }
      }
    },
    "email": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "status",
        "acceptedAt"
      ],
      "properties": {
        "status": {
          "type": "string",
          "enum": [
            "not_sent",
            "pending",
            "accepted",
            "unknown",
            "failed"
          ]
        },
        "acceptedAt": {
          "type": [
            "null",
            "string"
          ],
          "format": "date-time"
        }
      }
    },
    "replayed": {
      "type": "boolean"
    }
  }
}
```

</details>

## Machine-readable sources

- [This page as Markdown](/api/reference/capture-developer-offer.md)
- [Developer API OpenAPI v0.7.25](/openapi.json)
