---
title: "Read guest preferences and current disclosures"
description: "Returns marketing and membership separately for the authenticated guest and installed collection. TEST is installation-isolated rehearsal with no real effects. LIVE reads canonical collection preferences and membership. Requires a verified guest and explicit guest_preferences.write grant. Discovery does not enroll or subscribe the guest."
---

`GET /v1/developer/guest/me/preferences`

**Operation ID:** `getDeveloperGuestPreferences`

Returns marketing and membership separately for the authenticated guest and installed collection. TEST is installation-isolated rehearsal with no real effects. LIVE reads canonical collection preferences and membership. Requires a verified guest and explicit guest_preferences.write grant. Discovery does not enroll or subscribe the guest.

## Contract status

| Field | Value |
| --- | --- |
| Maturity | `beta` |
| Required capability | `guest_preferences.write` |
| Freshness class | `authenticated-state` |
| Quota cost | `1` |

All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential's installation grants; identifiers in the URL never grant access.

## Request parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `x-kismet-guest-token` | header | string | yes | Verified guest access token held by your same-origin BFF, never browser JavaScript. |

## Request body

This operation has no JSON request body.

## cURL

Set `KISMET_API_ORIGIN=https://api.ksmt.app` and configure `KISMET_DEVELOPER_API_KEY` in your environment. Run server-credential requests from your backend, not browser code.

Guest access tokens come from the signed-in guest session held by your backend. Forward a CSRF proof only after your same-origin backend validates it. If shown, `KISMET_SITE_ORIGIN` is the authorized origin of your site. Do not substitute a guest ID or an invented token.

```sh
curl --request GET \
  "$KISMET_API_ORIGIN/v1/developer/guest/me/preferences" \
  --header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \
  --header "Accept: application/json" \
  --header "x-kismet-guest-token: $GUEST_ACCESS_TOKEN"
```

## Responses

| Status | Meaning |
| --- | --- |
| 200 | Success. |
| 400 | Invalid request parameters or body. |
| 401 | Missing, invalid, expired, or inappropriate credential/session. |
| 403 | Credential lacks the required grant/capability, or an origin/CSRF check failed. |
| 404 | The authorized resource was not found. |
| 409 | Request conflicts with the installation environment or current state. |
| 429 | Rate limit or quota exceeded; inspect response metadata before retrying. |
| 503 | A required Kismet dependency is temporarily unavailable. |

### 200 response schema

Content type: `application/json`. Required fields, nullable values, and nested structures are defined below.

<details>
<summary>View complete response schema</summary>

```json
{
  "type": "object",
  "additionalProperties": false,
  "required": [
    "disclosure",
    "disclosureHash",
    "state"
  ],
  "properties": {
    "disclosure": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "version",
        "collection",
        "membership",
        "emailMarketing",
        "privacyUrl",
        "notice"
      ],
      "properties": {
        "version": {
          "type": "string"
        },
        "collection": {
          "type": "object",
          "additionalProperties": false,
          "required": [
            "id",
            "slug",
            "name"
          ],
          "properties": {
            "id": {
              "type": "string"
            },
            "slug": {
              "type": "string"
            },
            "name": {
              "type": "string"
            }
          }
        },
        "membership": {
          "type": "object",
          "additionalProperties": false,
          "required": [
            "available",
            "name",
            "termsUrl"
          ],
          "properties": {
            "available": {
              "type": "boolean"
            },
            "name": {
              "type": "string"
            },
            "termsUrl": {
              "type": "string",
              "format": "uri"
            }
          }
        },
        "emailMarketing": {
          "type": "object",
          "additionalProperties": false,
          "required": [
            "channel",
            "confirmation",
            "text"
          ],
          "properties": {
            "channel": {
              "type": "string",
              "enum": [
                "email"
              ]
            },
            "confirmation": {
              "type": "string",
              "enum": [
                "double_opt_in"
              ]
            },
            "text": {
              "type": "string"
            }
          }
        },
        "privacyUrl": {
          "type": "string",
          "format": "uri"
        },
        "notice": {
          "type": "string"
        }
      }
    },
    "disclosureHash": {
      "type": "string"
    },
    "state": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "environment",
        "revision",
        "emailMarketing",
        "membership",
        "deliveries"
      ],
      "properties": {
        "environment": {
          "type": "string",
          "enum": [
            "TEST",
            "LIVE"
          ]
        },
        "revision": {
          "type": "integer",
          "minimum": 0
        },
        "emailMarketing": {
          "type": "string",
          "enum": [
            "NEVER_SUBSCRIBED",
            "PENDING",
            "SUBSCRIBED",
            "UNSUBSCRIBED"
          ]
        },
        "membership": {
          "type": "object",
          "additionalProperties": false,
          "required": [
            "status",
            "joinedAt"
          ],
          "properties": {
            "status": {
              "type": "string",
              "enum": [
                "NOT_JOINED",
                "ACTIVE"
              ]
            },
            "joinedAt": {
              "type": [
                "null",
                "string"
              ],
              "format": "date-time"
            }
          }
        },
        "deliveries": {
          "type": "string",
          "enum": [
            "SIMULATED",
            "LIVE"
          ]
        }
      }
    }
  }
}
```

</details>

## Machine-readable sources

- [This page as Markdown](/api/reference/get-developer-guest-preferences.md)
- [Developer API OpenAPI v0.7.25](/openapi.json)
