Capture an offer and request its email
View .mdPOST /v1/developer/collections/{collection}/offers/{offerId}/captures
Operation ID: captureDeveloperOffer
On explicit guest submission, award the configured offer and send one real email with [STAGING] in the subject. Requires a TEST server key with offers.write and an exact registered STAGING origin. The recipient must be registered unless an unexpired, manager-enabled requested-offer-email participation policy covers this installation and exact verified staging origin. Does not authenticate the guest, enroll membership or change LIVE marketing consent. Reuse the idempotency key on retry. A recipient receives at most one email per offer and installation, including across different keys. accepted means provider acceptance, not inbox delivery; pending or unknown must not be shown as sent and must not trigger a new send.
Contract status
Section titled “Contract status”| Field | Value |
|---|---|
| Maturity | preview |
| Required capability | offers.write |
| Freshness class | authenticated-state |
| Quota cost | 1 |
All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential’s installation grants; identifiers in the URL never grant access.
Request parameters
Section titled “Request parameters”| Name | In | Type | Required | Description |
|---|---|---|---|---|
collection |
path | string | yes | |
offerId |
path | string | yes | |
origin |
header | string | yes |
Request body
Section titled “Request body”The request body is JSON. The canonical schema is:
{ "type": "object", "additionalProperties": false, "required": [ "email", "origin", "idempotencyKey", "consent" ], "properties": { "email": { "type": "string", "format": "email", "maxLength": 254 }, "origin": { "type": "string", "minLength": 8, "maxLength": 255 }, "idempotencyKey": { "type": "string", "minLength": 16, "maxLength": 200, "pattern": "^[A-Za-z0-9_-]+$" }, "consent": { "type": "object", "additionalProperties": false, "required": [ "accepted", "disclosureHash" ], "properties": { "accepted": { "type": "boolean", "enum": [ true ] }, "disclosureHash": { "type": "string", "pattern": "^[a-f0-9]{64}$" } } }, "attribution": { "type": [ "object", "null" ], "additionalProperties": false, "required": [ "enrollmentId", "sessionId" ], "properties": { "enrollmentId": { "type": "string", "format": "uuid" }, "sessionId": { "type": "string", "minLength": 8, "maxLength": 255 }, "verificationProof": { "type": [ "string", "null" ], "maxLength": 256, "description": "Server-only proof from portable email verification. sessionId remains the destination browser. The API resolves the original source session solely for enrollment attribution, preserving ownership checks." } } } }}Minimal example:
{ "origin": "https://staging.example.com", "idempotencyKey": "offer-submission-0001", "consent": { "accepted": true, "disclosureHash": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" }}Set KISMET_API_ORIGIN=https://api.ksmt.app and configure KISMET_DEVELOPER_API_KEY in your environment. Run server-credential requests from your backend, not browser code.
curl --request POST \ "$KISMET_API_ORIGIN/v1/developer/collections/example-collection/offers/{offerId}/captures" \ --header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \ --header "Accept: application/json" \ --header "origin: $KISMET_SITE_ORIGIN" \ --header "Content-Type: application/json" \ --data '{"email":"[email protected]","origin":"https://staging.example.com","idempotencyKey":"offer-submission-0001","consent":{"accepted":true,"disclosureHash":"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"}}'Responses
Section titled “Responses”| Status | Meaning |
|---|---|
| 200 | Success. |
| 400 | Invalid request parameters or body. |
| 401 | Missing, invalid, expired, or inappropriate credential/session. |
| 403 | Credential lacks the required grant/capability, or an origin/CSRF check failed. |
| 404 | The authorized resource was not found. |
| 409 | Request conflicts with the installation environment or current state. |
| 429 | Rate limit or quota exceeded; inspect response metadata before retrying. |
| 503 | A required Kismet dependency is temporarily unavailable. |
200 response example
Section titled “200 response example”{ "captureId": "22222222-2222-4222-8222-222222222222", "environment": "TEST", "offer": { "id": "11111111-1111-4111-8111-111111111111", "status": "issued" }, "email": { "status": "accepted", "acceptedAt": "2026-09-29T03:00:00.000Z" }, "replayed": false}200 response schema
Section titled “200 response schema”Content type: application/json. Required fields, nullable values, and nested structures are defined below.
View complete response schema
{ "type": "object", "additionalProperties": false, "required": [ "captureId", "environment", "offer", "email", "replayed" ], "properties": { "captureId": { "type": "string", "format": "uuid" }, "environment": { "type": "string", "enum": [ "TEST" ] }, "offer": { "type": "object", "additionalProperties": false, "required": [ "id", "status" ], "properties": { "id": { "type": "string" }, "status": { "type": "string", "enum": [ "issued", "pending", "unavailable" ] } } }, "email": { "type": "object", "additionalProperties": false, "required": [ "status", "acceptedAt" ], "properties": { "status": { "type": "string", "enum": [ "not_sent", "pending", "accepted", "unknown", "failed" ] }, "acceptedAt": { "type": [ "null", "string" ], "format": "date-time" } } }, "replayed": { "type": "boolean" } }}