Skip to content
KismetKismetDevelopers
llms.txt

Guest contact forms

View .md

Use the contact-editing SDK build paired with Developer API 0.7.7. These additions require the matching API deployment; an older installed SDK does not expose them.

Use the SDK helper before submitting a contact update. Local input requires an explicit ISO country selected by the guest; do not infer it from the partner’s address, browser locale or IP. A full + number takes precedence over that country.

import { normalizeGuestPhoneNumber, GuestContactInputSchema } from '@kismet-tech/sdk/contracts';
const phone = normalizeGuestPhoneNumber('(201) 555-0123', 'US'); // +12015550123
const input = GuestContactInputSchema.parse({ firstName: 'Taylor', lastName: '', phone });
await guest.contact.update(input);
// A UK form can use normalizeGuestPhoneNumber('020 7946 0018', 'GB').

REST equivalent: POST /v1/developer/guest/me/contact with JSON {"firstName":"Taylor","lastName":"","phone":"+12015550123"}, using the existing server-only developer credential, verified guest token and CSRF proof. Keep those credentials in the BFF; browser forms call the same-origin SDK guest route.

The wire contract is + plus country code and digits only (E.164, at most 15 digits), or null to clear. Empty form input normalizes to null. Local strings, spaces, invalid country/number combinations and extensions are rejected before SDK transport and validated again by the API. The API never guesses a country or silently removes an extension. Surface helper/schema errors beside the input; API validation errors return HTTP 400. Format validity does not prove ownership or grant SMS consent. Changed numbers remain unverified; identity/journey linking continues through the existing authenticated identity authority.

npm run sdk:contract checks the generated API’s phone constraints. SDK tests exercise the public contracts entry point, normalization for multiple countries, and rejection before network calls. This applies to guest contact editing; legacy read responses and other resource families retain their existing contracts.

Contact editing requires guest_auth.write, the authenticated guest session and CSRF protection. The caller cannot select a guest/profile ID or set verification flags. TEST installations reject these writes with TEST_CONTACT_EDIT_UNAVAILABLE because guest identity is shared. A manager’s API key alone cannot edit a guest.