Skip to content
KismetKismetDevelopers
llms.txt

Start saving a card for the signed-in guest

View .md

POST /v1/developer/guest/me/wallet/capture

Operation ID: prepareDeveloperGuestWalletCapture

Creates a Kismet platform SetupIntent for the guest and returns a single-use, Kismet-hosted capture page URL that your page frames from parentOrigin. The guest enters the card there; on success Kismet attaches it to the guest’s wallet for future off-session charges and the frame posts kismet:guest-wallet:complete to parentOrigin. The card details and the Stripe client secret never reach your page. LIVE installations save a real card; TEST installations capture in Stripe test mode (use 4242 4242 4242 4242) and never write the live wallet.

Field Value
Maturity beta
Required capability guest_auth.write
Freshness class authenticated-state
Quota cost 1

All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential’s installation grants; identifiers in the URL never grant access.

Name In Type Required Description
x-kismet-guest-token header string yes Server-only Kismet guest access token held by the same-origin BFF. Never expose it to browser JavaScript.
x-kismet-csrf header string yes Opaque CSRF proof validated by the same-origin host BFF before it calls Kismet.

The request body is JSON. The canonical schema is:

{
"type": "object",
"additionalProperties": false,
"required": [
"parentOrigin"
],
"properties": {
"parentOrigin": {
"type": "string",
"minLength": 8,
"maxLength": 255,
"description": "The origin of the page that will frame the capture (scheme + host + optional port). Must be https, or http on localhost. When the credential carries an origin allowlist it must be one of those origins."
}
}
}

Minimal example:

{
"parentOrigin": "string"
}

Set KISMET_API_ORIGIN=https://api.ksmt.app and configure KISMET_DEVELOPER_API_KEY in your environment. Run server-credential requests from your backend, not browser code.

Guest access tokens come from the signed-in guest session held by your backend. Forward a CSRF proof only after your same-origin backend validates it. If shown, KISMET_SITE_ORIGIN is the authorized origin of your site. Do not substitute a guest ID or an invented token.

Terminal window
curl --request POST \
"$KISMET_API_ORIGIN/v1/developer/guest/me/wallet/capture" \
--header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \
--header "Accept: application/json" \
--header "x-kismet-guest-token: $GUEST_ACCESS_TOKEN" \
--header "x-kismet-csrf: $VALIDATED_CSRF_TOKEN" \
--header "Content-Type: application/json" \
--data '{"parentOrigin":"string"}'
Status Meaning
201 Created successfully.
400 Invalid request parameters or body.
401 Missing, invalid, expired, or inappropriate credential/session.
403 Credential lacks the required grant/capability, or an origin/CSRF check failed.
404 The authorized resource was not found.
409 Request conflicts with the installation environment or current state.
429 Rate limit or quota exceeded; inspect response metadata before retrying.
503 A required Kismet dependency is temporarily unavailable.
{
"captureUrl": "https://kismet.travel/embed/guest-wallet?request=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
"expiresAt": "2026-09-23T00:10:00.000Z",
"livemode": false
}

Content type: application/json. Required fields, nullable values, and nested structures are defined below.

View complete response schema
{
"type": "object",
"additionalProperties": false,
"required": [
"captureUrl",
"expiresAt",
"livemode"
],
"properties": {
"captureUrl": {
"type": "string",
"description": "Kismet-hosted capture page (an https URL on kismet.travel). Embed it in an iframe from parentOrigin, or open it in a dialog. Single use; the card details never touch your page."
},
"expiresAt": {
"type": "string",
"format": "date-time"
},
"livemode": {
"type": "boolean",
"description": "False for a TEST installation: the capture runs in Stripe test mode."
}
}
}