Verify Google sign-in for a branded guest
View .mdPOST /v1/developer/guest-auth/google/verify
Operation ID: verifyDeveloperGuestGoogleAuth
Exchanges a Google authorization code with PKCE and nonce verification on an explicitly configured installation callback, resolves the canonical guest, and returns tokens only to the host BFF. Requires a server credential, CSRF proof and authorized branded origin. TEST and LIVE callbacks are configured separately; unsupported installations fail closed.
Contract status
Section titled “Contract status”| Field | Value |
|---|---|
| Maturity | beta |
| Required capability | guest_auth.write |
| Freshness class | sandbox-write |
| Quota cost | 1 |
All operations require a Kismet Developer Bearer credential. Collection and resource authority is resolved from the credential’s installation grants; identifiers in the URL never grant access.
Request parameters
Section titled “Request parameters”| Name | In | Type | Required | Description |
|---|---|---|---|---|
x-kismet-csrf |
header | string | yes | Opaque CSRF proof validated by the same-origin host BFF before it calls Kismet. Never a Kismet credential. |
origin |
header | string | no | Original branded browser origin forwarded by the same-origin BFF. Must match Collection.authorizedDomains. |
x-forwarded-host |
header | string | no | Original branded host fallback for server route handlers that do not forward Origin. Must match Collection.authorizedDomains. |
Request body
Section titled “Request body”The request body is JSON. The canonical schema is:
{ "type": "object", "additionalProperties": false, "required": [ "code", "codeVerifier", "nonce", "kidSid" ], "properties": { "code": { "type": "string", "minLength": 1, "maxLength": 4096 }, "codeVerifier": { "type": "string", "pattern": "^[a-zA-Z0-9_-]{43,128}$" }, "nonce": { "type": "string", "pattern": "^[a-zA-Z0-9_-]{43}$" }, "kidSid": { "type": "string", "pattern": "^kid_[A-Za-z0-9]{8}$" } }}Minimal example:
{ "code": "042817", "codeVerifier": "string", "nonce": "string", "kidSid": "kid_Ab12Cd34"}Set KISMET_API_ORIGIN=https://api.ksmt.app and configure KISMET_DEVELOPER_API_KEY in your environment. Run server-credential requests from your backend, not browser code.
Guest access tokens come from the signed-in guest session held by your backend. Forward a CSRF proof only after your same-origin backend validates it. If shown, KISMET_SITE_ORIGIN is the authorized origin of your site. Do not substitute a guest ID or an invented token.
curl --request POST \ "$KISMET_API_ORIGIN/v1/developer/guest-auth/google/verify" \ --header "Authorization: Bearer $KISMET_DEVELOPER_API_KEY" \ --header "Accept: application/json" \ --header "x-kismet-csrf: $VALIDATED_CSRF_TOKEN" \ --header "origin: $KISMET_SITE_ORIGIN" \ --header "Content-Type: application/json" \ --data '{"code":"042817","codeVerifier":"string","nonce":"string","kidSid":"kid_Ab12Cd34"}'Responses
Section titled “Responses”| Status | Meaning |
|---|---|
| 200 | Success. |
| 400 | Invalid request parameters or body. |
| 401 | Missing, invalid, expired, or inappropriate credential/session. |
| 403 | Credential lacks the required grant/capability, or an origin/CSRF check failed. |
| 409 | Request conflicts with the installation environment or current state. |
| 410 | The single-use authentication challenge is no longer valid. |
| 429 | Rate limit or quota exceeded; inspect response metadata before retrying. |
| 503 | A required Kismet dependency is temporarily unavailable. |
200 response example
Section titled “200 response example”{ "kidSid": "kid_AbCdEf12", "guest": { "id": "77777777-7777-4777-8777-777777777777", "guestProfileId": "88888888-8888-4888-8888-888888888888" }, "session": { "accessToken": "<server-only-access-token>", "refreshToken": "<server-only-refresh-token>", "expiresAt": "2026-09-17T18:00:00.000Z" }}200 response schema
Section titled “200 response schema”Content type: application/json. Required fields, nullable values, and nested structures are defined below.
View complete response schema
{ "type": "object", "additionalProperties": false, "required": [ "kidSid", "guest", "session" ], "properties": { "kidSid": { "type": "string" }, "guest": { "type": "object", "additionalProperties": false, "required": [ "id", "email", "guestProfileId" ], "properties": { "id": { "type": "string" }, "email": { "type": "string" }, "guestProfileId": { "type": "string" } } }, "session": { "type": "object", "additionalProperties": false, "required": [ "accessToken", "refreshToken", "expiresAt" ], "properties": { "accessToken": { "type": "string" }, "refreshToken": { "type": "string" }, "expiresAt": { "type": "string", "format": "date-time" } } } }}