Skip to content
KismetKismetDevelopers
llms.txt

Complete hosted Google guest sign-in

View .md

POST /v1/developer/guest-auth/google/authorizations/redeem

Operation ID: redeemDeveloperGuestGoogleAuthorization

Redeems a single-use, 60-second return code using the originating BFF’s PKCE verifier and canonical kidSid. Re-authorizes the installation, environment, origin and guest_auth.write grant. Returns guest session tokens only to the server. TEST requires a registered identity or an unexpired real-Google staging participation policy for this installation and exact verified staging origin. This operation never sends email or enrolls the guest in an offer; deterministic TEST email-code authentication remains restricted.

Field Value
Maturity preview
Required capability guest_auth.write
Freshness class authenticated-state
Quota cost 1

All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential’s installation grants; identifiers in the URL never grant access.

Name In Type Required Description
x-kismet-csrf header string yes
origin header string yes

The request body is JSON. The canonical schema is:

{
"type": "object",
"additionalProperties": false,
"required": [
"code",
"codeVerifier",
"kidSid"
],
"properties": {
"code": {
"type": "string",
"pattern": "^[a-zA-Z0-9_-]{43}$"
},
"kidSid": {
"type": "string",
"pattern": "^kid_[A-Za-z0-9]{8}$"
},
"codeVerifier": {
"type": "string",
"pattern": "^[A-Za-z0-9._~-]{43,128}$"
}
}
}

Minimal example:

{
"code": "042817",
"kidSid": "kid_Ab12Cd34",
"codeVerifier": "string"
}

Set KISMET_API_ORIGIN=https://api.ksmt.app and configure KISMET_DEVELOPER_API_KEY in your environment. Run server-credential requests from your backend, not browser code.

Guest access tokens come from the signed-in guest session held by your backend. Forward a CSRF proof only after your same-origin backend validates it. If shown, KISMET_SITE_ORIGIN is the authorized origin of your site. Do not substitute a guest ID or an invented token.

Terminal window
curl --request POST \
"$KISMET_API_ORIGIN/v1/developer/guest-auth/google/authorizations/redeem" \
--header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \
--header "Accept: application/json" \
--header "x-kismet-csrf: $VALIDATED_CSRF_TOKEN" \
--header "origin: $KISMET_SITE_ORIGIN" \
--header "Content-Type: application/json" \
--data '{"code":"042817","kidSid":"kid_Ab12Cd34","codeVerifier":"string"}'
Status Meaning
200 Success.
400 Invalid request parameters or body.
401 Missing, invalid, expired, or inappropriate credential/session.
403 Credential lacks the required grant/capability, or an origin/CSRF check failed.
409 Request conflicts with the installation environment or current state.
410 The single-use authentication challenge is no longer valid.
429 Rate limit or quota exceeded; inspect response metadata before retrying.
503 A required Kismet dependency is temporarily unavailable.
{
"kidSid": "kid_AbCdEf12",
"guest": {
"id": "77777777-7777-4777-8777-777777777777",
"email": "[email protected]",
"guestProfileId": "88888888-8888-4888-8888-888888888888"
},
"session": {
"accessToken": "<server-only-access-token>",
"refreshToken": "<server-only-refresh-token>",
"expiresAt": "2026-10-27T18:00:00.000Z"
}
}

Content type: application/json. Required fields, nullable values, and nested structures are defined below.

View complete response schema
{
"type": "object",
"additionalProperties": false,
"required": [
"kidSid",
"guest",
"session"
],
"properties": {
"kidSid": {
"type": "string",
"pattern": "^kid_[A-Za-z0-9]{8}$"
},
"guest": {
"type": "object",
"required": [
"id",
"email",
"guestProfileId"
],
"properties": {
"id": {
"type": "string"
},
"email": {
"type": "string"
},
"guestProfileId": {
"type": "string"
}
}
},
"session": {
"type": "object",
"required": [
"accessToken",
"refreshToken",
"expiresAt"
],
"properties": {
"accessToken": {
"type": "string"
},
"refreshToken": {
"type": "string"
},
"expiresAt": {
"type": "string",
"format": "date-time"
}
}
}
}
}