---
title: "Record explicit inline marketing signup after verification"
description: "Requires guest_preferences.write, a verified guest token, CSRF proof and registered parentOrigin. Display current signup terms before the action; preserve the explicit choice through Google or email-link verification. No additional confirmation email and no membership enrollment. TEST stores an isolated rehearsal receipt, never LIVE marketing permission. Replays return current preference without undoing later withdrawal. Offer-email consent is separate."
---

`POST /v1/developer/guest/me/email-subscriptions`

**Operation ID:** `subscribeDeveloperGuestEmail`

Requires guest_preferences.write, a verified guest token, CSRF proof and registered parentOrigin. Display current signup terms before the action; preserve the explicit choice through Google or email-link verification. No additional confirmation email and no membership enrollment. TEST stores an isolated rehearsal receipt, never LIVE marketing permission. Replays return current preference without undoing later withdrawal. Offer-email consent is separate.

## Contract status

| Field | Value |
| --- | --- |
| Maturity | `preview` |
| Required capability | `guest_preferences.write` |
| Freshness class | `authenticated-state` |
| Quota cost | `1` |

All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential's installation grants; identifiers in the URL never grant access.

## Request parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `x-kismet-guest-token` | header | string | yes | Verified guest access token held by your same-origin BFF, never browser JavaScript. |
| `x-kismet-csrf` | header | string | yes |  |

## Request body

The request body is JSON. The canonical schema is:

```json
{
  "type": "object",
  "properties": {
    "accepted": {
      "type": "boolean",
      "enum": [
        true
      ]
    },
    "expectedGuestId": {
      "type": "string",
      "minLength": 1,
      "maxLength": 128
    },
    "disclosureVersion": {
      "type": "string",
      "minLength": 1,
      "maxLength": 40
    },
    "disclosureHash": {
      "type": "string",
      "pattern": "^[a-f0-9]{64}$"
    },
    "idempotencyKey": {
      "type": "string",
      "minLength": 16,
      "maxLength": 100,
      "pattern": "^[A-Za-z0-9_-]+$"
    },
    "parentOrigin": {
      "type": "string",
      "format": "uri"
    }
  },
  "required": [
    "accepted",
    "expectedGuestId",
    "disclosureVersion",
    "disclosureHash",
    "idempotencyKey",
    "parentOrigin"
  ],
  "additionalProperties": false
}
```

Minimal example:

```json
{
  "accepted": true,
  "expectedGuestId": "string",
  "disclosureVersion": "string",
  "disclosureHash": "string",
  "idempotencyKey": "string",
  "parentOrigin": "string"
}
```

## cURL

Set `KISMET_API_ORIGIN=https://api.ksmt.app` and configure `KISMET_DEVELOPER_API_KEY` in your environment. Run server-credential requests from your backend, not browser code.

Guest access tokens come from the signed-in guest session held by your backend. Forward a CSRF proof only after your same-origin backend validates it. If shown, `KISMET_SITE_ORIGIN` is the authorized origin of your site. Do not substitute a guest ID or an invented token.

```sh
curl --request POST \
  "$KISMET_API_ORIGIN/v1/developer/guest/me/email-subscriptions" \
  --header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \
  --header "Accept: application/json" \
  --header "x-kismet-guest-token: $GUEST_ACCESS_TOKEN" \
  --header "x-kismet-csrf: $VALIDATED_CSRF_TOKEN" \
  --header "Content-Type: application/json" \
  --data '{"accepted":true,"expectedGuestId":"string","disclosureVersion":"string","disclosureHash":"string","idempotencyKey":"string","parentOrigin":"string"}'
```

## Responses

| Status | Meaning |
| --- | --- |
| 200 | Success. |
| 400 | Invalid request parameters or body. |
| 401 | Missing, invalid, expired, or inappropriate credential/session. |
| 403 | Credential lacks the required grant/capability, or an origin/CSRF check failed. |
| 404 | The authorized resource was not found. |
| 409 | Request conflicts with the installation environment or current state. |
| 429 | Rate limit or quota exceeded; inspect response metadata before retrying. |
| 503 | A required Kismet dependency is temporarily unavailable. |

### 200 response schema

Content type: `application/json`. Required fields, nullable values, and nested structures are defined below.

<details>
<summary>View complete response schema</summary>

```json
{
  "type": "object",
  "additionalProperties": false,
  "required": [
    "receiptId",
    "environment",
    "emailMarketing",
    "replayed"
  ],
  "properties": {
    "receiptId": {
      "type": "string",
      "format": "uuid"
    },
    "environment": {
      "type": "string",
      "enum": [
        "TEST",
        "LIVE"
      ]
    },
    "emailMarketing": {
      "type": "string",
      "enum": [
        "NEVER_SUBSCRIBED",
        "PENDING",
        "SUBSCRIBED",
        "UNSUBSCRIBED"
      ]
    },
    "replayed": {
      "type": "boolean"
    }
  }
}
```

</details>

## Machine-readable sources

- [This page as Markdown](/api/reference/subscribe-developer-guest-email.md)
- [Developer API OpenAPI v0.7.25](/openapi.json)
