Start saving a card for the signed-in guest
View .mdPOST /v1/developer/guest/me/wallet/capture
Operation ID: prepareDeveloperGuestWalletCapture
Creates a Kismet platform SetupIntent for the guest and returns a single-use, Kismet-hosted capture page URL that your page frames from parentOrigin. The guest enters the card there; on success Kismet attaches it to the guest’s wallet for future off-session charges and the frame posts kismet:guest-wallet:complete to parentOrigin. The card details and the Stripe client secret never reach your page. LIVE installations save a real card; TEST installations capture in Stripe test mode (use 4242 4242 4242 4242) and never write the live wallet.
Contract status
Section titled “Contract status”| Field | Value |
|---|---|
| Maturity | beta |
| Required capability | guest_auth.write |
| Freshness class | authenticated-state |
| Quota cost | 1 |
All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential’s installation grants; identifiers in the URL never grant access.
Request parameters
Section titled “Request parameters”| Name | In | Type | Required | Description |
|---|---|---|---|---|
x-kismet-guest-token |
header | string | yes | Server-only Kismet guest access token held by the same-origin BFF. Never expose it to browser JavaScript. |
x-kismet-csrf |
header | string | yes | Opaque CSRF proof validated by the same-origin host BFF before it calls Kismet. |
Request body
Section titled “Request body”The request body is JSON. The canonical schema is:
{ "type": "object", "additionalProperties": false, "required": [ "parentOrigin" ], "properties": { "parentOrigin": { "type": "string", "minLength": 8, "maxLength": 255, "description": "The origin of the page that will frame the capture (scheme + host + optional port). Must be https, or http on localhost. When the credential carries an origin allowlist it must be one of those origins." } }}Minimal example:
{ "parentOrigin": "string"}Set KISMET_API_ORIGIN=https://api.ksmt.app and configure KISMET_DEVELOPER_API_KEY in your environment. Run server-credential requests from your backend, not browser code.
Guest access tokens come from the signed-in guest session held by your backend. Forward a CSRF proof only after your same-origin backend validates it. If shown, KISMET_SITE_ORIGIN is the authorized origin of your site. Do not substitute a guest ID or an invented token.
curl --request POST \ "$KISMET_API_ORIGIN/v1/developer/guest/me/wallet/capture" \ --header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \ --header "Accept: application/json" \ --header "x-kismet-guest-token: $GUEST_ACCESS_TOKEN" \ --header "x-kismet-csrf: $VALIDATED_CSRF_TOKEN" \ --header "Content-Type: application/json" \ --data '{"parentOrigin":"string"}'Responses
Section titled “Responses”| Status | Meaning |
|---|---|
| 201 | Created successfully. |
| 400 | Invalid request parameters or body. |
| 401 | Missing, invalid, expired, or inappropriate credential/session. |
| 403 | Credential lacks the required grant/capability, or an origin/CSRF check failed. |
| 404 | The authorized resource was not found. |
| 409 | Request conflicts with the installation environment or current state. |
| 429 | Rate limit or quota exceeded; inspect response metadata before retrying. |
| 503 | A required Kismet dependency is temporarily unavailable. |
201 response example
Section titled “201 response example”{ "captureUrl": "https://kismet.travel/embed/guest-wallet?request=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa", "expiresAt": "2026-09-23T00:10:00.000Z", "livemode": false}201 response schema
Section titled “201 response schema”Content type: application/json. Required fields, nullable values, and nested structures are defined below.
View complete response schema
{ "type": "object", "additionalProperties": false, "required": [ "captureUrl", "expiresAt", "livemode" ], "properties": { "captureUrl": { "type": "string", "description": "Kismet-hosted capture page (an https URL on kismet.travel). Embed it in an iframe from parentOrigin, or open it in a dialog. Single use; the card details never touch your page." }, "expiresAt": { "type": "string", "format": "date-time" }, "livemode": { "type": "boolean", "description": "False for a TEST installation: the capture runs in Stripe test mode." } }}