---
title: "Verify Google sign-in for a branded guest"
description: "Exchanges a Google authorization code with PKCE and nonce verification on an explicitly configured installation callback, resolves the canonical guest, and returns tokens only to the host BFF. Requires a server credential, CSRF proof and authorized branded origin. TEST and LIVE callbacks are configured separately; unsupported installations fail closed."
---

`POST /v1/developer/guest-auth/google/verify`

**Operation ID:** `verifyDeveloperGuestGoogleAuth`

Exchanges a Google authorization code with PKCE and nonce verification on an explicitly configured installation callback, resolves the canonical guest, and returns tokens only to the host BFF. Requires a server credential, CSRF proof and authorized branded origin. TEST and LIVE callbacks are configured separately; unsupported installations fail closed.

## Contract status

| Field | Value |
| --- | --- |
| Maturity | `beta` |
| Required capability | `guest_auth.write` |
| Freshness class | `sandbox-write` |
| Quota cost | `1` |

All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential's installation grants; identifiers in the URL never grant access.

## Request parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `x-kismet-csrf` | header | string | yes | Opaque CSRF proof validated by the same-origin host BFF before it calls Kismet. Never a Kismet credential. |
| `origin` | header | string | no | Original branded browser origin forwarded by the same-origin BFF. Must match Collection.authorizedDomains. |
| `x-forwarded-host` | header | string | no | Original branded host fallback for server route handlers that do not forward Origin. Must match Collection.authorizedDomains. |

## Request body

The request body is JSON. The canonical schema is:

```json
{
  "type": "object",
  "additionalProperties": false,
  "required": [
    "code",
    "codeVerifier",
    "nonce",
    "kidSid"
  ],
  "properties": {
    "code": {
      "type": "string",
      "minLength": 1,
      "maxLength": 4096
    },
    "codeVerifier": {
      "type": "string",
      "pattern": "^[a-zA-Z0-9_-]{43,128}$"
    },
    "nonce": {
      "type": "string",
      "pattern": "^[a-zA-Z0-9_-]{43}$"
    },
    "kidSid": {
      "type": "string",
      "pattern": "^kid_[A-Za-z0-9]{8}$"
    }
  }
}
```

Minimal example:

```json
{
  "code": "042817",
  "codeVerifier": "string",
  "nonce": "string",
  "kidSid": "kid_Ab12Cd34"
}
```

## cURL

Set `KISMET_API_ORIGIN=https://api.ksmt.app` and configure `KISMET_DEVELOPER_API_KEY` in your environment. Run server-credential requests from your backend, not browser code.

Guest access tokens come from the signed-in guest session held by your backend. Forward a CSRF proof only after your same-origin backend validates it. If shown, `KISMET_SITE_ORIGIN` is the authorized origin of your site. Do not substitute a guest ID or an invented token.

```sh
curl --request POST \
  "$KISMET_API_ORIGIN/v1/developer/guest-auth/google/verify" \
  --header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \
  --header "Accept: application/json" \
  --header "x-kismet-csrf: $VALIDATED_CSRF_TOKEN" \
  --header "origin: $KISMET_SITE_ORIGIN" \
  --header "Content-Type: application/json" \
  --data '{"code":"042817","codeVerifier":"string","nonce":"string","kidSid":"kid_Ab12Cd34"}'
```

## Responses

| Status | Meaning |
| --- | --- |
| 200 | Success. |
| 400 | Invalid request parameters or body. |
| 401 | Missing, invalid, expired, or inappropriate credential/session. |
| 403 | Credential lacks the required grant/capability, or an origin/CSRF check failed. |
| 409 | Request conflicts with the installation environment or current state. |
| 410 | The single-use authentication challenge is no longer valid. |
| 429 | Rate limit or quota exceeded; inspect response metadata before retrying. |
| 503 | A required Kismet dependency is temporarily unavailable. |

### 200 response example

```json
{
  "kidSid": "kid_AbCdEf12",
  "guest": {
    "id": "77777777-7777-4777-8777-777777777777",
    "email": "developer-test@example.com",
    "guestProfileId": "88888888-8888-4888-8888-888888888888"
  },
  "session": {
    "accessToken": "<server-only-access-token>",
    "refreshToken": "<server-only-refresh-token>",
    "expiresAt": "2026-09-17T18:00:00.000Z"
  }
}
```

### 200 response schema

Content type: `application/json`. Required fields, nullable values, and nested structures are defined below.

<details>
<summary>View complete response schema</summary>

```json
{
  "type": "object",
  "additionalProperties": false,
  "required": [
    "kidSid",
    "guest",
    "session"
  ],
  "properties": {
    "kidSid": {
      "type": "string"
    },
    "guest": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "id",
        "email",
        "guestProfileId"
      ],
      "properties": {
        "id": {
          "type": "string"
        },
        "email": {
          "type": "string"
        },
        "guestProfileId": {
          "type": "string"
        }
      }
    },
    "session": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "accessToken",
        "refreshToken",
        "expiresAt"
      ],
      "properties": {
        "accessToken": {
          "type": "string"
        },
        "refreshToken": {
          "type": "string"
        },
        "expiresAt": {
          "type": "string",
          "format": "date-time"
        }
      }
    }
  }
}
```

</details>

## Machine-readable sources

- [This page as Markdown](/api/reference/verify-developer-guest-google-auth.md)
- [Developer API OpenAPI v0.7.25](/openapi.json)
