Skip to content
KismetKismetDevelopers
llms.txt

Open a Kismet-hosted preference confirmation

View .md

POST /v1/developer/guest/me/preferences/captures

Operation ID: prepareDeveloperGuestPreferenceCapture

Prepares a confirmation URL valid for at most ten minutes, bound to this guest, installation, collection, registered website origin and disclosure. Open it as a standalone popup or tab. Do not collect consent in your own form. TEST simulates double opt-in with no real effects. LIVE independently records optional free membership and marketing choices; subscriptions remain pending until the guest confirms the code emailed to their verified address. Existing suppression is preserved.

Field Value
Maturity beta
Required capability guest_preferences.write
Freshness class authenticated-state
Quota cost 1

All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential’s installation grants; identifiers in the URL never grant access.

Name In Type Required Description
x-kismet-guest-token header string yes Verified guest access token held by your same-origin BFF, never browser JavaScript.
x-kismet-csrf header string yes CSRF proof validated by the same-origin BFF before forwarding.

The request body is JSON. The canonical schema is:

{
"type": "object",
"additionalProperties": false,
"required": [
"parentOrigin"
],
"properties": {
"parentOrigin": {
"type": "string",
"minLength": 8,
"maxLength": 255,
"description": "Exact registered website origin; HTTPS except local development. Empty origin allowlists do not authorize capture."
}
}
}

Minimal example:

{
"parentOrigin": "string"
}

Set KISMET_API_ORIGIN=https://api.ksmt.app and configure KISMET_DEVELOPER_API_KEY in your environment. Run server-credential requests from your backend, not browser code.

Guest access tokens come from the signed-in guest session held by your backend. Forward a CSRF proof only after your same-origin backend validates it. If shown, KISMET_SITE_ORIGIN is the authorized origin of your site. Do not substitute a guest ID or an invented token.

Terminal window
curl --request POST \
"$KISMET_API_ORIGIN/v1/developer/guest/me/preferences/captures" \
--header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \
--header "Accept: application/json" \
--header "x-kismet-guest-token: $GUEST_ACCESS_TOKEN" \
--header "x-kismet-csrf: $VALIDATED_CSRF_TOKEN" \
--header "Content-Type: application/json" \
--data '{"parentOrigin":"string"}'
Status Meaning
200 Success.
400 Invalid request parameters or body.
401 Missing, invalid, expired, or inappropriate credential/session.
403 Credential lacks the required grant/capability, or an origin/CSRF check failed.
404 The authorized resource was not found.
409 Request conflicts with the installation environment or current state.
429 Rate limit or quota exceeded; inspect response metadata before retrying.
503 A required Kismet dependency is temporarily unavailable.

Content type: application/json. Required fields, nullable values, and nested structures are defined below.

View complete response schema
{
"type": "object",
"additionalProperties": false,
"required": [
"captureId",
"confirmationUrl",
"expiresAt",
"environment"
],
"properties": {
"captureId": {
"type": "string",
"format": "uuid"
},
"confirmationUrl": {
"type": "string",
"format": "uri"
},
"expiresAt": {
"type": "string",
"format": "date-time"
},
"environment": {
"type": "string",
"enum": [
"TEST",
"LIVE"
]
}
}
}