---
title: "Authorize rendering a manager panel"
description: "Server-only page-render authorization. Redeem the one-use, 30-second code issued by the signed-in Kismet Software dashboard before rendering the registered panel HTML. Requires the matching installation server credential with telemetry.read. Rechecks the current manager collection role, installation, grants and exact registered panel URL. Returns no manager identity, session or data capability. Expired, reused or mismatched codes are refused; manager data remains protected by the account bridge. Never cache this response or expose the server credential in browser code."
---

`POST /v1/developer/collections/{collection}/software/{module}/panel-launches/redeem`

**Operation ID:** `redeemDeveloperSoftwarePanelLaunch`

Server-only page-render authorization. Redeem the one-use, 30-second code issued by the signed-in Kismet Software dashboard before rendering the registered panel HTML. Requires the matching installation server credential with telemetry.read. Rechecks the current manager collection role, installation, grants and exact registered panel URL. Returns no manager identity, session or data capability. Expired, reused or mismatched codes are refused; manager data remains protected by the account bridge. Never cache this response or expose the server credential in browser code.

## Contract status

| Field | Value |
| --- | --- |
| Maturity | `preview` |
| Required capability | `telemetry.read` |
| Freshness class | `authenticated-state` |
| Quota cost | `1` |

All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential's installation grants; identifiers in the URL never grant access.

## Request parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `collection` | path | string | yes |  |
| `module` | path | string | yes |  |

## Request body

The request body is JSON. The canonical schema is:

```json
{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "pattern": "^kspl_[A-Za-z0-9_-]{43}$"
    },
    "panelUrl": {
      "type": "string",
      "format": "uri",
      "maxLength": 2048
    }
  },
  "required": [
    "code",
    "panelUrl"
  ],
  "additionalProperties": false
}
```

Minimal example:

```json
{
  "code": "kspl_aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
  "panelUrl": "https://staging.example.com/our/software/welcome-offer/panel"
}
```

## cURL

Set `KISMET_API_ORIGIN=https://api.ksmt.app` and configure `KISMET_DEVELOPER_API_KEY` in your environment. Run server-credential requests from your backend, not browser code.

```sh
curl --request POST \
  "$KISMET_API_ORIGIN/v1/developer/collections/example-collection/software/{module}/panel-launches/redeem" \
  --header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \
  --header "Accept: application/json" \
  --header "Content-Type: application/json" \
  --data '{"code":"kspl_aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa","panelUrl":"https://staging.example.com/our/software/welcome-offer/panel"}'
```

## Responses

| Status | Meaning |
| --- | --- |
| 200 | Success. |
| 400 | Invalid request parameters or body. |
| 401 | Missing, invalid, expired, or inappropriate credential/session. |
| 403 | Credential lacks the required grant/capability, or an origin/CSRF check failed. |
| 404 | The authorized resource was not found. |
| 409 | Request conflicts with the installation environment or current state. |
| 429 | Rate limit or quota exceeded; inspect response metadata before retrying. |
| 503 | A required Kismet dependency is temporarily unavailable. |

### 200 response example

```json
{
  "purpose": "software-panel-render",
  "moduleId": "welcome-offer",
  "applicationId": "10000000-0000-4000-8000-000000000001",
  "installationId": "10000000-0000-4000-8000-000000000003",
  "collectionId": "10000000-0000-4000-8000-000000000002",
  "environment": "TEST",
  "panelUrl": "https://staging.example.com/our/welcome-offer",
  "expiresAt": "2026-09-28T12:00:30.000Z"
}
```

### 200 response schema

Content type: `application/json`. Required fields, nullable values, and nested structures are defined below.

<details>
<summary>View complete response schema</summary>

```json
{
  "type": "object",
  "properties": {
    "purpose": {
      "type": "string",
      "enum": [
        "software-panel-render"
      ]
    },
    "moduleId": {
      "type": "string",
      "pattern": "^[a-z][a-z0-9-]{0,63}$"
    },
    "applicationId": {
      "type": "string",
      "format": "uuid"
    },
    "installationId": {
      "type": "string",
      "format": "uuid"
    },
    "collectionId": {
      "type": "string",
      "format": "uuid"
    },
    "environment": {
      "type": "string",
      "enum": [
        "TEST",
        "LIVE"
      ]
    },
    "panelUrl": {
      "type": "string",
      "format": "uri"
    },
    "expiresAt": {
      "type": "string",
      "format": "date-time"
    }
  },
  "required": [
    "purpose",
    "moduleId",
    "applicationId",
    "installationId",
    "collectionId",
    "environment",
    "panelUrl",
    "expiresAt"
  ],
  "additionalProperties": false
}
```

</details>

## Machine-readable sources

- [This page as Markdown](/api/reference/redeem-developer-software-panel-launch.md)
- [Developer API OpenAPI v0.7.25](/openapi.json)
