Record explicit inline marketing signup after verification
View .mdPOST /v1/developer/guest/me/email-subscriptions
Operation ID: subscribeDeveloperGuestEmail
Requires guest_preferences.write, a verified guest token, CSRF proof and registered parentOrigin. Display current signup terms before the action; preserve the explicit choice through Google or email-link verification. No additional confirmation email and no membership enrollment. TEST stores an isolated rehearsal receipt, never LIVE marketing permission. Replays return current preference without undoing later withdrawal. Offer-email consent is separate.
Contract status
Section titled “Contract status”| Field | Value |
|---|---|
| Maturity | preview |
| Required capability | guest_preferences.write |
| Freshness class | authenticated-state |
| Quota cost | 1 |
All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential’s installation grants; identifiers in the URL never grant access.
Request parameters
Section titled “Request parameters”| Name | In | Type | Required | Description |
|---|---|---|---|---|
x-kismet-guest-token |
header | string | yes | Verified guest access token held by your same-origin BFF, never browser JavaScript. |
x-kismet-csrf |
header | string | yes |
Request body
Section titled “Request body”The request body is JSON. The canonical schema is:
{ "type": "object", "properties": { "accepted": { "type": "boolean", "enum": [ true ] }, "expectedGuestId": { "type": "string", "minLength": 1, "maxLength": 128 }, "disclosureVersion": { "type": "string", "minLength": 1, "maxLength": 40 }, "disclosureHash": { "type": "string", "pattern": "^[a-f0-9]{64}$" }, "idempotencyKey": { "type": "string", "minLength": 16, "maxLength": 100, "pattern": "^[A-Za-z0-9_-]+$" }, "parentOrigin": { "type": "string", "format": "uri" } }, "required": [ "accepted", "expectedGuestId", "disclosureVersion", "disclosureHash", "idempotencyKey", "parentOrigin" ], "additionalProperties": false}Minimal example:
{ "accepted": true, "expectedGuestId": "string", "disclosureVersion": "string", "disclosureHash": "string", "idempotencyKey": "string", "parentOrigin": "string"}Set KISMET_API_ORIGIN=https://api.ksmt.app and configure KISMET_DEVELOPER_API_KEY in your environment. Run server-credential requests from your backend, not browser code.
Guest access tokens come from the signed-in guest session held by your backend. Forward a CSRF proof only after your same-origin backend validates it. If shown, KISMET_SITE_ORIGIN is the authorized origin of your site. Do not substitute a guest ID or an invented token.
curl --request POST \ "$KISMET_API_ORIGIN/v1/developer/guest/me/email-subscriptions" \ --header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \ --header "Accept: application/json" \ --header "x-kismet-guest-token: $GUEST_ACCESS_TOKEN" \ --header "x-kismet-csrf: $VALIDATED_CSRF_TOKEN" \ --header "Content-Type: application/json" \ --data '{"accepted":true,"expectedGuestId":"string","disclosureVersion":"string","disclosureHash":"string","idempotencyKey":"string","parentOrigin":"string"}'Responses
Section titled “Responses”| Status | Meaning |
|---|---|
| 200 | Success. |
| 400 | Invalid request parameters or body. |
| 401 | Missing, invalid, expired, or inappropriate credential/session. |
| 403 | Credential lacks the required grant/capability, or an origin/CSRF check failed. |
| 404 | The authorized resource was not found. |
| 409 | Request conflicts with the installation environment or current state. |
| 429 | Rate limit or quota exceeded; inspect response metadata before retrying. |
| 503 | A required Kismet dependency is temporarily unavailable. |
200 response schema
Section titled “200 response schema”Content type: application/json. Required fields, nullable values, and nested structures are defined below.
View complete response schema
{ "type": "object", "additionalProperties": false, "required": [ "receiptId", "environment", "emailMarketing", "replayed" ], "properties": { "receiptId": { "type": "string", "format": "uuid" }, "environment": { "type": "string", "enum": [ "TEST", "LIVE" ] }, "emailMarketing": { "type": "string", "enum": [ "NEVER_SUBSCRIBED", "PENDING", "SUBSCRIBED", "UNSUBSCRIBED" ] }, "replayed": { "type": "boolean" } }}