---
title: "Edit the authenticated guest contact information"
description: "LIVE identities only. Email replacement requires codes to both the existing verified email and the new email. Guest selection comes exclusively from the authenticated guest token. TEST requests fail closed because identities are shared."
---

`POST /v1/developer/guest/me/email-change`

**Operation ID:** `startDeveloperGuestEmailChange`

LIVE identities only. Email replacement requires codes to both the existing verified email and the new email. Guest selection comes exclusively from the authenticated guest token. TEST requests fail closed because identities are shared.

## Contract status

| Field | Value |
| --- | --- |
| Maturity | `beta` |
| Required capability | `guest_auth.write` |
| Freshness class | `authenticated-state` |
| Quota cost | `1` |

All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential's installation grants; identifiers in the URL never grant access.

## Request parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `x-kismet-guest-token` | header | string | yes | Server-only Kismet guest access token held by the same-origin BFF. Never expose it to browser JavaScript. |
| `x-kismet-csrf` | header | string | yes | Opaque CSRF proof validated by the same-origin host BFF before it calls Kismet. |

## Request body

The request body is JSON. The canonical schema is:

```json
{
  "type": "object",
  "additionalProperties": false,
  "required": [
    "email"
  ],
  "properties": {
    "email": {
      "type": "string",
      "format": "email",
      "maxLength": 254
    }
  }
}
```

Minimal example:

```json
{
  "email": "developer-test@example.com"
}
```

## cURL

Set `KISMET_API_ORIGIN=https://api.ksmt.app` and configure `KISMET_DEVELOPER_API_KEY` in your environment. Run server-credential requests from your backend, not browser code.

Guest access tokens come from the signed-in guest session held by your backend. Forward a CSRF proof only after your same-origin backend validates it. If shown, `KISMET_SITE_ORIGIN` is the authorized origin of your site. Do not substitute a guest ID or an invented token.

```sh
curl --request POST \
  "$KISMET_API_ORIGIN/v1/developer/guest/me/email-change" \
  --header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \
  --header "Accept: application/json" \
  --header "x-kismet-guest-token: $GUEST_ACCESS_TOKEN" \
  --header "x-kismet-csrf: $VALIDATED_CSRF_TOKEN" \
  --header "Content-Type: application/json" \
  --data '{"email":"developer-test@example.com"}'
```

## Responses

| Status | Meaning |
| --- | --- |
| 200 | Success. |
| 400 | Invalid request parameters or body. |
| 401 | Missing, invalid, expired, or inappropriate credential/session. |
| 403 | Credential lacks the required grant/capability, or an origin/CSRF check failed. |
| 409 | Request conflicts with the installation environment or current state. |
| 429 | Rate limit or quota exceeded; inspect response metadata before retrying. |
| 503 | A required Kismet dependency is temporarily unavailable. |

### 200 response schema

Content type: `application/json`. Required fields, nullable values, and nested structures are defined below.

<details>
<summary>View complete response schema</summary>

```json
{
  "type": "object",
  "additionalProperties": false,
  "properties": {
    "challengeId": {
      "type": "string",
      "format": "uuid"
    },
    "stage": {
      "type": "string",
      "enum": [
        "current",
        "new",
        "complete"
      ]
    },
    "expiresAt": {
      "type": "string",
      "format": "date-time"
    },
    "identity": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "id",
        "guestProfileId",
        "email",
        "phone",
        "firstName",
        "lastName",
        "displayName",
        "avatarUrl",
        "emailVerified",
        "phoneVerified"
      ],
      "properties": {
        "id": {
          "type": "string"
        },
        "guestProfileId": {
          "type": "string"
        },
        "email": {
          "type": [
            "null",
            "string"
          ]
        },
        "phone": {
          "type": [
            "null",
            "string"
          ]
        },
        "firstName": {
          "type": [
            "null",
            "string"
          ]
        },
        "lastName": {
          "type": [
            "null",
            "string"
          ]
        },
        "displayName": {
          "type": [
            "null",
            "string"
          ]
        },
        "avatarUrl": {
          "type": [
            "null",
            "string"
          ]
        },
        "emailVerified": {
          "type": "boolean"
        },
        "phoneVerified": {
          "type": "boolean"
        }
      }
    }
  }
}
```

</details>

## Machine-readable sources

- [This page as Markdown](/api/reference/start-developer-guest-email-change.md)
- [Developer API OpenAPI v0.7.25](/openapi.json)
