Guest contact forms
View .mdUse the contact-editing SDK build paired with Developer API 0.7.7. These additions require the matching API deployment; an older installed SDK does not expose them.
Use the SDK helper before submitting a contact update. Local input requires an
explicit ISO country selected by the guest; do not infer it from the partner’s
address, browser locale or IP. A full + number takes precedence over that country.
import { normalizeGuestPhoneNumber, GuestContactInputSchema } from '@kismet-tech/sdk/contracts';
const phone = normalizeGuestPhoneNumber('(201) 555-0123', 'US'); // +12015550123const input = GuestContactInputSchema.parse({ firstName: 'Taylor', lastName: '', phone });await guest.contact.update(input);// A UK form can use normalizeGuestPhoneNumber('020 7946 0018', 'GB').REST equivalent: POST /v1/developer/guest/me/contact with JSON
{"firstName":"Taylor","lastName":"","phone":"+12015550123"}, using the existing
server-only developer credential, verified guest token and CSRF proof. Keep those
credentials in the BFF; browser forms call the same-origin SDK guest route.
The wire contract is + plus country code and digits only (E.164, at most 15
digits), or null to clear. Empty form input normalizes to null. Local strings,
spaces, invalid country/number combinations and extensions are rejected before
SDK transport and validated again by the API. The API never guesses a country or
silently removes an extension. Surface helper/schema errors beside the input;
API validation errors return HTTP 400. Format validity does not prove ownership
or grant SMS consent. Changed numbers remain unverified; identity/journey linking
continues through the existing authenticated identity authority.
npm run sdk:contract checks the generated API’s phone constraints. SDK tests
exercise the public contracts entry point, normalization for multiple countries,
and rejection before network calls. This applies to guest contact editing; legacy
read responses and other resource families retain their existing contracts.
Contact editing requires guest_auth.write, the authenticated guest session and
CSRF protection. The caller cannot select a guest/profile ID or set verification
flags. TEST installations reject these writes with TEST_CONTACT_EDIT_UNAVAILABLE
because guest identity is shared. A manager’s API key alone cannot edit a guest.