---
title: "Enroll a visit in software"
description: "Installation-scoped custom software. Requires a server credential. Collection, application and TEST/LIVE environment come from the credential. Settings are revisioned; engagement is client-reported, not consent or booking authority. Canonical outcome attribution is currently unavailable. Browser components use their same-origin server boundary; never expose the server credential."
---

`POST /v1/developer/collections/{collection}/software/{module}/enrollments`

**Operation ID:** `enrollDeveloperSoftwareVisit`

Installation-scoped custom software. Requires a server credential. Collection, application and TEST/LIVE environment come from the credential. Settings are revisioned; engagement is client-reported, not consent or booking authority. Canonical outcome attribution is currently unavailable. Browser components use their same-origin server boundary; never expose the server credential.

## Contract status

| Field | Value |
| --- | --- |
| Maturity | `beta` |
| Required capability | `telemetry.write` |
| Freshness class | `authenticated-state` |
| Quota cost | `1` |

All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential's installation grants; identifiers in the URL never grant access.

## Request parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `collection` | path | string | yes |  |
| `module` | path | string | yes |  |

## Request body

The request body is JSON. The canonical schema is:

```json
{
  "type": "object",
  "properties": {
    "sessionId": {
      "type": "string",
      "minLength": 8,
      "maxLength": 255
    },
    "pageUrl": {
      "type": "string",
      "format": "uri",
      "maxLength": 2048
    },
    "pageEnvironment": {
      "type": "string",
      "enum": [
        "production",
        "staging",
        "development",
        "preview",
        "local"
      ]
    },
    "userAgent": {
      "type": "string",
      "maxLength": 1024,
      "nullable": true
    }
  },
  "required": [
    "sessionId",
    "pageUrl",
    "pageEnvironment",
    "userAgent"
  ],
  "additionalProperties": false
}
```

Minimal example:

```json
{
  "sessionId": "string",
  "pageUrl": "string",
  "pageEnvironment": "production",
  "userAgent": "string"
}
```

## cURL

Set `KISMET_API_ORIGIN=https://api.ksmt.app` and configure `KISMET_DEVELOPER_API_KEY` in your environment. Run server-credential requests from your backend, not browser code.

```sh
curl --request POST \
  "$KISMET_API_ORIGIN/v1/developer/collections/example-collection/software/{module}/enrollments" \
  --header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \
  --header "Accept: application/json" \
  --header "Content-Type: application/json" \
  --data '{"sessionId":"string","pageUrl":"string","pageEnvironment":"production","userAgent":"string"}'
```

## Responses

| Status | Meaning |
| --- | --- |
| 200 | Success. |
| 400 | Invalid request parameters or body. |
| 401 | Missing, invalid, expired, or inappropriate credential/session. |
| 403 | Credential lacks the required grant/capability, or an origin/CSRF check failed. |
| 404 | The authorized resource was not found. |
| 409 | Request conflicts with the installation environment or current state. |
| 429 | Rate limit or quota exceeded; inspect response metadata before retrying. |
| 503 | A required Kismet dependency is temporarily unavailable. |

### 200 response example

```json
{
  "id": "22222222-2222-4222-8222-222222222222",
  "moduleId": "welcome-offer",
  "revision": 1,
  "assignmentUnit": "session",
  "variant": {
    "id": "first-page",
    "settings": {
      "eligiblePage": 1
    }
  },
  "enrolledAt": "2026-09-01T01:00:00.000Z",
  "expiresAt": "2026-09-02T01:00:00.000Z"
}
```

### 200 response schema

Content type: `application/json`. Required fields, nullable values, and nested structures are defined below.

<details>
<summary>View complete response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "format": "uuid"
    },
    "moduleId": {
      "type": "string",
      "pattern": "^[a-z][a-z0-9-]{0,63}$"
    },
    "revision": {
      "type": "integer",
      "minimum": 1
    },
    "assignmentUnit": {
      "type": "string",
      "enum": [
        "session"
      ]
    },
    "variant": {
      "type": "object",
      "properties": {
        "id": {
          "type": "string",
          "pattern": "^[a-z][a-z0-9-]{0,63}$"
        },
        "settings": {
          "type": "object",
          "additionalProperties": {
            "anyOf": [
              {
                "type": "string",
                "maxLength": 100
              },
              {
                "type": "number"
              },
              {
                "type": "boolean"
              }
            ]
          }
        }
      },
      "required": [
        "id",
        "settings"
      ],
      "additionalProperties": false
    },
    "enrolledAt": {
      "type": "string",
      "format": "date-time"
    },
    "expiresAt": {
      "type": "string",
      "format": "date-time"
    }
  },
  "required": [
    "id",
    "moduleId",
    "revision",
    "assignmentUnit",
    "variant",
    "enrolledAt",
    "expiresAt"
  ],
  "additionalProperties": false
}
```

</details>

## Machine-readable sources

- [This page as Markdown](/api/reference/enroll-developer-software-visit.md)
- [Developer API OpenAPI v0.7.25](/openapi.json)
