Skip to content
KismetKismetDevelopers
llms.txt

Save a vacation rental for the signed-in guest

View .md

PUT /v1/developer/guest/me/saves/{vacationRentalSlug}

Operation ID: saveDeveloperGuestVacationRental

Save a vacation rental for the signed-in guest

Field Value
Maturity beta
Required capability guest_auth.write
Freshness class authenticated-state
Quota cost 1

All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential’s installation grants; identifiers in the URL never grant access.

Name In Type Required Description
vacationRentalSlug path string yes
x-kismet-guest-token header string yes Server-only Kismet guest access token held by the same-origin BFF. Never expose it to browser JavaScript.
x-kismet-csrf header string yes Opaque CSRF proof validated by the same-origin host BFF before it calls Kismet.

This operation has no JSON request body.

Set KISMET_API_ORIGIN=https://api.ksmt.app and configure KISMET_DEVELOPER_API_KEY in your environment. Run server-credential requests from your backend, not browser code.

Guest access tokens come from the signed-in guest session held by your backend. Forward a CSRF proof only after your same-origin backend validates it. If shown, KISMET_SITE_ORIGIN is the authorized origin of your site. Do not substitute a guest ID or an invented token.

Terminal window
curl --request PUT \
"$KISMET_API_ORIGIN/v1/developer/guest/me/saves/sand-sea-110" \
--header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \
--header "Accept: application/json" \
--header "x-kismet-guest-token: $GUEST_ACCESS_TOKEN" \
--header "x-kismet-csrf: $VALIDATED_CSRF_TOKEN"
Status Meaning
200 Success.
400 Invalid request parameters or body.
401 Missing, invalid, expired, or inappropriate credential/session.
403 Credential lacks the required grant/capability, or an origin/CSRF check failed.
404 The authorized resource was not found.
429 Rate limit or quota exceeded; inspect response metadata before retrying.
503 A required Kismet dependency is temporarily unavailable.
{
"saved": true,
"vacationRentalSlug": "sandbox-chalet"
}

Content type: application/json. Required fields, nullable values, and nested structures are defined below.

View complete response schema
{
"type": "object",
"additionalProperties": false,
"required": [
"saved",
"vacationRentalSlug"
],
"properties": {
"saved": {
"type": "boolean"
},
"vacationRentalSlug": {
"type": "string"
}
}
}