Skip to content
KismetKismetDevelopers
llms.txt

Record explicit inline marketing signup after verification

View .md

POST /v1/developer/guest/me/email-subscriptions

Operation ID: subscribeDeveloperGuestEmail

Requires guest_preferences.write, a verified guest token, CSRF proof and registered parentOrigin. Display current signup terms before the action; preserve the explicit choice through Google or email-link verification. No additional confirmation email and no membership enrollment. TEST stores an isolated rehearsal receipt, never LIVE marketing permission. Replays return current preference without undoing later withdrawal. Offer-email consent is separate.

Field Value
Maturity preview
Required capability guest_preferences.write
Freshness class authenticated-state
Quota cost 1

All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential’s installation grants; identifiers in the URL never grant access.

Name In Type Required Description
x-kismet-guest-token header string yes Verified guest access token held by your same-origin BFF, never browser JavaScript.
x-kismet-csrf header string yes

The request body is JSON. The canonical schema is:

{
"type": "object",
"properties": {
"accepted": {
"type": "boolean",
"enum": [
true
]
},
"expectedGuestId": {
"type": "string",
"minLength": 1,
"maxLength": 128
},
"disclosureVersion": {
"type": "string",
"minLength": 1,
"maxLength": 40
},
"disclosureHash": {
"type": "string",
"pattern": "^[a-f0-9]{64}$"
},
"idempotencyKey": {
"type": "string",
"minLength": 16,
"maxLength": 100,
"pattern": "^[A-Za-z0-9_-]+$"
},
"parentOrigin": {
"type": "string",
"format": "uri"
}
},
"required": [
"accepted",
"expectedGuestId",
"disclosureVersion",
"disclosureHash",
"idempotencyKey",
"parentOrigin"
],
"additionalProperties": false
}

Minimal example:

{
"accepted": true,
"expectedGuestId": "string",
"disclosureVersion": "string",
"disclosureHash": "string",
"idempotencyKey": "string",
"parentOrigin": "string"
}

Set KISMET_API_ORIGIN=https://api.ksmt.app and configure KISMET_DEVELOPER_API_KEY in your environment. Run server-credential requests from your backend, not browser code.

Guest access tokens come from the signed-in guest session held by your backend. Forward a CSRF proof only after your same-origin backend validates it. If shown, KISMET_SITE_ORIGIN is the authorized origin of your site. Do not substitute a guest ID or an invented token.

Terminal window
curl --request POST \
"$KISMET_API_ORIGIN/v1/developer/guest/me/email-subscriptions" \
--header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \
--header "Accept: application/json" \
--header "x-kismet-guest-token: $GUEST_ACCESS_TOKEN" \
--header "x-kismet-csrf: $VALIDATED_CSRF_TOKEN" \
--header "Content-Type: application/json" \
--data '{"accepted":true,"expectedGuestId":"string","disclosureVersion":"string","disclosureHash":"string","idempotencyKey":"string","parentOrigin":"string"}'
Status Meaning
200 Success.
400 Invalid request parameters or body.
401 Missing, invalid, expired, or inappropriate credential/session.
403 Credential lacks the required grant/capability, or an origin/CSRF check failed.
404 The authorized resource was not found.
409 Request conflicts with the installation environment or current state.
429 Rate limit or quota exceeded; inspect response metadata before retrying.
503 A required Kismet dependency is temporarily unavailable.

Content type: application/json. Required fields, nullable values, and nested structures are defined below.

View complete response schema
{
"type": "object",
"additionalProperties": false,
"required": [
"receiptId",
"environment",
"emailMarketing",
"replayed"
],
"properties": {
"receiptId": {
"type": "string",
"format": "uuid"
},
"environment": {
"type": "string",
"enum": [
"TEST",
"LIVE"
]
},
"emailMarketing": {
"type": "string",
"enum": [
"NEVER_SUBSCRIBED",
"PENDING",
"SUBSCRIBED",
"UNSUBSCRIBED"
]
},
"replayed": {
"type": "boolean"
}
}
}