---
title: "List the signed-in guest's saved cards"
description: "The guest's Kismet wallet: cards saved for future charges across the Kismet network, one wallet per guest. LIVE returns the chargeable cards. TEST returns the cards captured by this sandbox in Stripe test mode, never the live wallet."
---

`GET /v1/developer/guest/me/wallet`

**Operation ID:** `listDeveloperGuestWallet`

The guest's Kismet wallet: cards saved for future charges across the Kismet network, one wallet per guest. LIVE returns the chargeable cards. TEST returns the cards captured by this sandbox in Stripe test mode, never the live wallet.

## Contract status

| Field | Value |
| --- | --- |
| Maturity | `beta` |
| Required capability | `guest_auth.write` |
| Freshness class | `authenticated-state` |
| Quota cost | `1` |

All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential's installation grants; identifiers in the URL never grant access.

## Request parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `x-kismet-guest-token` | header | string | yes | Server-only Kismet guest access token held by the same-origin BFF. Never expose it to browser JavaScript. |

## Request body

This operation has no JSON request body.

## cURL

Set `KISMET_API_ORIGIN=https://api.ksmt.app` and configure `KISMET_DEVELOPER_API_KEY` in your environment. Run server-credential requests from your backend, not browser code.

Guest access tokens come from the signed-in guest session held by your backend. Forward a CSRF proof only after your same-origin backend validates it. If shown, `KISMET_SITE_ORIGIN` is the authorized origin of your site. Do not substitute a guest ID or an invented token.

```sh
curl --request GET \
  "$KISMET_API_ORIGIN/v1/developer/guest/me/wallet" \
  --header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \
  --header "Accept: application/json" \
  --header "x-kismet-guest-token: $GUEST_ACCESS_TOKEN"
```

## Responses

| Status | Meaning |
| --- | --- |
| 200 | Success. |
| 400 | Invalid request parameters or body. |
| 401 | Missing, invalid, expired, or inappropriate credential/session. |
| 403 | Credential lacks the required grant/capability, or an origin/CSRF check failed. |
| 404 | The authorized resource was not found. |
| 429 | Rate limit or quota exceeded; inspect response metadata before retrying. |
| 503 | A required Kismet dependency is temporarily unavailable. |

### 200 response example

```json
{
  "livemode": false,
  "hasPaymentOnFile": true,
  "paymentMethods": [
    {
      "id": "99999999-9999-4999-8999-999999999999",
      "brand": "visa",
      "last4": "4242",
      "expMonth": 12,
      "expYear": 2031,
      "isDefault": false,
      "addedAt": "2026-09-23T00:00:00.000Z"
    }
  ]
}
```

### 200 response schema

Content type: `application/json`. Required fields, nullable values, and nested structures are defined below.

<details>
<summary>View complete response schema</summary>

```json
{
  "type": "object",
  "additionalProperties": false,
  "required": [
    "livemode",
    "hasPaymentOnFile",
    "paymentMethods"
  ],
  "properties": {
    "livemode": {
      "type": "boolean",
      "description": "False for a TEST installation: the list is the sandbox test captures, not the live wallet."
    },
    "hasPaymentOnFile": {
      "type": "boolean",
      "description": "LIVE: Kismet can charge the guest off-session now. TEST: a test card was captured."
    },
    "paymentMethods": {
      "type": "array",
      "items": {
        "type": "object",
        "additionalProperties": false,
        "required": [
          "id",
          "brand",
          "last4",
          "expMonth",
          "expYear",
          "isDefault",
          "addedAt"
        ],
        "properties": {
          "id": {
            "type": "string"
          },
          "brand": {
            "type": [
              "null",
              "string"
            ]
          },
          "last4": {
            "type": [
              "null",
              "string"
            ]
          },
          "expMonth": {
            "type": [
              "null",
              "integer"
            ]
          },
          "expYear": {
            "type": [
              "null",
              "integer"
            ]
          },
          "isDefault": {
            "type": "boolean",
            "description": "Display preference only. Never decides which card Kismet charges."
          },
          "addedAt": {
            "type": "string",
            "format": "date-time"
          }
        }
      }
    }
  }
}
```

</details>

## Machine-readable sources

- [This page as Markdown](/api/reference/list-developer-guest-wallet.md)
- [Developer API OpenAPI v0.7.25](/openapi.json)
