Skip to content
KismetKismetDevelopers
llms.txt

Edit the authenticated guest contact information

View .md

POST /v1/developer/guest/me/contact

Operation ID: updateDeveloperGuestContact

LIVE identities only. Email replacement requires codes to both the existing verified email and the new email. Guest selection comes exclusively from the authenticated guest token. TEST requests fail closed because identities are shared.

Field Value
Maturity beta
Required capability guest_auth.write
Freshness class authenticated-state
Quota cost 1

All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential’s installation grants; identifiers in the URL never grant access.

Name In Type Required Description
x-kismet-guest-token header string yes Server-only Kismet guest access token held by the same-origin BFF. Never expose it to browser JavaScript.
x-kismet-csrf header string yes Opaque CSRF proof validated by the same-origin host BFF before it calls Kismet.

The request body is JSON. The canonical schema is:

{
"type": "object",
"additionalProperties": false,
"required": [
"firstName",
"lastName",
"phone"
],
"properties": {
"firstName": {
"type": "string",
"minLength": 1,
"maxLength": 100
},
"lastName": {
"type": "string",
"maxLength": 100
},
"phone": {
"type": [
"string",
"null"
],
"maxLength": 16,
"pattern": "^\\+[1-9]\\d{1,14}$",
"description": "Valid international phone in E.164 format (+ and country code, digits only), or null to clear. Normalize local input with an explicit country before sending. Extensions are not supported. This does not verify phone ownership."
}
}
}

Minimal example:

{
"firstName": "Taylor",
"lastName": "Guest",
"phone": "+15555550123"
}

Set KISMET_API_ORIGIN=https://api.ksmt.app and configure KISMET_DEVELOPER_API_KEY in your environment. Run server-credential requests from your backend, not browser code.

Guest access tokens come from the signed-in guest session held by your backend. Forward a CSRF proof only after your same-origin backend validates it. If shown, KISMET_SITE_ORIGIN is the authorized origin of your site. Do not substitute a guest ID or an invented token.

Terminal window
curl --request POST \
"$KISMET_API_ORIGIN/v1/developer/guest/me/contact" \
--header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \
--header "Accept: application/json" \
--header "x-kismet-guest-token: $GUEST_ACCESS_TOKEN" \
--header "x-kismet-csrf: $VALIDATED_CSRF_TOKEN" \
--header "Content-Type: application/json" \
--data '{"firstName":"Taylor","lastName":"Guest","phone":"+15555550123"}'
Status Meaning
200 Success.
400 Invalid request parameters or body.
401 Missing, invalid, expired, or inappropriate credential/session.
403 Credential lacks the required grant/capability, or an origin/CSRF check failed.
409 Request conflicts with the installation environment or current state.
429 Rate limit or quota exceeded; inspect response metadata before retrying.
503 A required Kismet dependency is temporarily unavailable.

Content type: application/json. Required fields, nullable values, and nested structures are defined below.

View complete response schema
{
"type": "object",
"additionalProperties": false,
"properties": {
"challengeId": {
"type": "string",
"format": "uuid"
},
"stage": {
"type": "string",
"enum": [
"current",
"new",
"complete"
]
},
"expiresAt": {
"type": "string",
"format": "date-time"
},
"identity": {
"type": "object",
"additionalProperties": false,
"required": [
"id",
"guestProfileId",
"email",
"phone",
"firstName",
"lastName",
"displayName",
"avatarUrl",
"emailVerified",
"phoneVerified"
],
"properties": {
"id": {
"type": "string"
},
"guestProfileId": {
"type": "string"
},
"email": {
"type": [
"null",
"string"
]
},
"phone": {
"type": [
"null",
"string"
]
},
"firstName": {
"type": [
"null",
"string"
]
},
"lastName": {
"type": [
"null",
"string"
]
},
"displayName": {
"type": [
"null",
"string"
]
},
"avatarUrl": {
"type": [
"null",
"string"
]
},
"emailVerified": {
"type": "boolean"
},
"phoneVerified": {
"type": "boolean"
}
}
}
}
}