Read guest preferences and current disclosures
View .mdGET /v1/developer/guest/me/preferences
Operation ID: getDeveloperGuestPreferences
Returns marketing and membership separately for the authenticated guest and installed collection. TEST is installation-isolated rehearsal with no real effects. LIVE reads canonical collection preferences and membership. Requires a verified guest and explicit guest_preferences.write grant. Discovery does not enroll or subscribe the guest.
Contract status
Section titled “Contract status”| Field | Value |
|---|---|
| Maturity | beta |
| Required capability | guest_preferences.write |
| Freshness class | authenticated-state |
| Quota cost | 1 |
All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential’s installation grants; identifiers in the URL never grant access.
Request parameters
Section titled “Request parameters”| Name | In | Type | Required | Description |
|---|---|---|---|---|
x-kismet-guest-token |
header | string | yes | Verified guest access token held by your same-origin BFF, never browser JavaScript. |
Request body
Section titled “Request body”This operation has no JSON request body.
Set KISMET_API_ORIGIN=https://api.ksmt.app and configure KISMET_DEVELOPER_API_KEY in your environment. Run server-credential requests from your backend, not browser code.
Guest access tokens come from the signed-in guest session held by your backend. Forward a CSRF proof only after your same-origin backend validates it. If shown, KISMET_SITE_ORIGIN is the authorized origin of your site. Do not substitute a guest ID or an invented token.
curl --request GET \ "$KISMET_API_ORIGIN/v1/developer/guest/me/preferences" \ --header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \ --header "Accept: application/json" \ --header "x-kismet-guest-token: $GUEST_ACCESS_TOKEN"Responses
Section titled “Responses”| Status | Meaning |
|---|---|
| 200 | Success. |
| 400 | Invalid request parameters or body. |
| 401 | Missing, invalid, expired, or inappropriate credential/session. |
| 403 | Credential lacks the required grant/capability, or an origin/CSRF check failed. |
| 404 | The authorized resource was not found. |
| 409 | Request conflicts with the installation environment or current state. |
| 429 | Rate limit or quota exceeded; inspect response metadata before retrying. |
| 503 | A required Kismet dependency is temporarily unavailable. |
200 response schema
Section titled “200 response schema”Content type: application/json. Required fields, nullable values, and nested structures are defined below.
View complete response schema
{ "type": "object", "additionalProperties": false, "required": [ "disclosure", "disclosureHash", "state" ], "properties": { "disclosure": { "type": "object", "additionalProperties": false, "required": [ "version", "collection", "membership", "emailMarketing", "privacyUrl", "notice" ], "properties": { "version": { "type": "string" }, "collection": { "type": "object", "additionalProperties": false, "required": [ "id", "slug", "name" ], "properties": { "id": { "type": "string" }, "slug": { "type": "string" }, "name": { "type": "string" } } }, "membership": { "type": "object", "additionalProperties": false, "required": [ "available", "name", "termsUrl" ], "properties": { "available": { "type": "boolean" }, "name": { "type": "string" }, "termsUrl": { "type": "string", "format": "uri" } } }, "emailMarketing": { "type": "object", "additionalProperties": false, "required": [ "channel", "confirmation", "text" ], "properties": { "channel": { "type": "string", "enum": [ "email" ] }, "confirmation": { "type": "string", "enum": [ "double_opt_in" ] }, "text": { "type": "string" } } }, "privacyUrl": { "type": "string", "format": "uri" }, "notice": { "type": "string" } } }, "disclosureHash": { "type": "string" }, "state": { "type": "object", "additionalProperties": false, "required": [ "environment", "revision", "emailMarketing", "membership", "deliveries" ], "properties": { "environment": { "type": "string", "enum": [ "TEST", "LIVE" ] }, "revision": { "type": "integer", "minimum": 0 }, "emailMarketing": { "type": "string", "enum": [ "NEVER_SUBSCRIBED", "PENDING", "SUBSCRIBED", "UNSUBSCRIBED" ] }, "membership": { "type": "object", "additionalProperties": false, "required": [ "status", "joinedAt" ], "properties": { "status": { "type": "string", "enum": [ "NOT_JOINED", "ACTIVE" ] }, "joinedAt": { "type": [ "null", "string" ], "format": "date-time" } } }, "deliveries": { "type": "string", "enum": [ "SIMULATED", "LIVE" ] } } } }}