> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. /api/company/v1 and /api/v1/... paths are documented in no spec here and must never be used (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/auth-v0.yaml covers the unversioned auth surface (/api/... paths — authentication, MFA, social auth, and token exchange); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.

# Home > Live "Activity" card (recent event stream)

> Returns up to 7 newest-first events across four source
kinds — order, first_sale (buyer's first order), share
(share.copied on analytics_events), and subscription
(successful billing event). No milestone / viral yet;
those land in a follow-up once product locks their
signals.




## OpenAPI

````yaml /api-reference/analytics-v2026-04.yaml get /api/v202604/analytics/dashboard/live_activity
openapi: 3.1.0
info:
  title: Fluid Analytics Dashboard v2026-04 API
  version: v2026-04
  description: |
    Endpoints backing the fluid-admin Analytics section
    (Home / Traffic / Brand Buzz). One endpoint per card on each tab;
    the frontend polls independently so each card can have its own
    refresh cadence.

    Every endpoint is gated by the `ANALYTICS_DASHBOARD` feature flag
    on the requesting company. When the flag is off the endpoint
    returns 404 — the fluid-admin sidebar hides the section too, so
    the flag-gated 404 only shows up when someone hits the URL
    directly.
  contact:
    email: support@fluid.app
  license:
    name: Proprietary
    identifier: LicenseRef-Proprietary
servers:
  - url: https://api.fluid.app
  - url: https://{company}.fluid.app
    description: Production server with company subdomain
    variables:
      company:
        default: myco
        description: Company subdomain
security:
  - bearer_auth: []
tags:
  - name: analytics_dashboard_home_overview
    description: |
      Home > Overview tab cards. Card 1 (header tiles) is served here;
      cards 2-11 land in subsequent PRs.
  - name: analytics_dashboard_home_live
    description: |
      Home > Live tab cards. Card 1 (header tiles) is served here;
      cards 2-6 land in subsequent PRs.
  - name: analytics_dashboard_home_field
    description: |
      Home > Field tab cards. Card 1 (field momentum header) is served
      here; cards 2-5 land in subsequent PRs.
paths:
  /api/v202604/analytics/dashboard/live_activity:
    get:
      tags:
        - analytics_dashboard_home_live
      summary: Home > Live "Activity" card (recent event stream)
      description: |
        Returns up to 7 newest-first events across four source
        kinds — order, first_sale (buyer's first order), share
        (share.copied on analytics_events), and subscription
        (successful billing event). No milestone / viral yet;
        those land in a follow-up once product locks their
        signals.
      operationId: getAnalyticsDashboardLiveActivity
      parameters:
        - $ref: '#/components/parameters/CountryQueryParam'
      responses:
        '200':
          description: Activity feed payload
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DashboardLiveActivityResponse'
        '400':
          $ref: '#/components/responses/InvalidCountry'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '422':
          $ref: '#/components/responses/Unprocessable'
components:
  parameters:
    CountryQueryParam:
      name: country
      in: query
      required: false
      description: |
        ISO alpha-2 code of one of the requesting company's configured
        countries (see `GET /countries`). When present, every service
        on this endpoint filters its data to that country and reports
        money in the country's own currency. Omit (or send `"all"`)
        for the aggregate-across-countries view, which is the default
        and matches pre-Phase-004 behavior. Unknown ISO codes or ones
        the company is not configured for return `400`.
      schema:
        type: string
        example: US
  schemas:
    DashboardLiveActivityResponse:
      type: object
      description: |
        Home > Live "Activity" card (Card 4). Up to 7 newest-first
        events across four source kinds: order, first_sale, share,
        subscription. Milestone / viral event kinds from felipe's
        design mock land in a follow-up once product locks their
        signals.
      properties:
        events:
          type: array
          items:
            $ref: '#/components/schemas/DashboardLiveActivityEvent'
          maxItems: 7
        currency:
          $ref: '#/components/schemas/Currency'
        meta:
          $ref: '#/components/schemas/Meta'
      required:
        - events
        - currency
    DashboardLiveActivityEvent:
      type: object
      description: |
        One entry in the Live > Activity feed. `kind` drives the
        icon + tint on the FE; `amount` is nil for shares (no
        money moved) and present for orders / first-sales /
        subscription rebills, always in the top-level `currency`.
      properties:
        id:
          type: string
          description: '`{kind}-{primary_key}` — stable react key.'
        kind:
          type: string
          enum:
            - order
            - first_sale
            - share
            - subscription
        occurred_at:
          type: string
          format: date-time
        actor:
          type: string
        text:
          type: string
        amount:
          oneOf:
            - $ref: '#/components/schemas/Money'
            - type: 'null'
        location:
          type:
            - string
            - 'null'
        via_rep:
          type:
            - string
            - 'null'
      required:
        - id
        - kind
        - occurred_at
        - actor
        - text
        - amount
        - location
        - via_rep
    Currency:
      type: string
      description: ISO 4217 three-letter code (uppercase).
      example: USD
      minLength: 3
      maxLength: 3
    Meta:
      type: object
      properties:
        request_id:
          type:
            - string
            - 'null'
        timestamp:
          type: string
          format: date-time
      required:
        - timestamp
    ErrorResponse:
      type: object
      properties:
        error:
          type: object
          properties:
            message:
              type: string
            details:
              type: object
              additionalProperties: true
          required:
            - message
        meta:
          $ref: '#/components/schemas/Meta'
      required:
        - error
    LegacyUnauthorizedResponse:
      type: object
      properties:
        message:
          type: string
      required:
        - message
    LegacyForbiddenResponse:
      type: object
      properties:
        message:
          type: string
        error:
          type: string
      minProperties: 1
    Money:
      type: string
      description: |
        Decimal amount, expressed as a string to preserve arbitrary
        precision across the wire. Parsed to Number on the client and
        formatted with `Intl.NumberFormat`. Once the in-flight
        money-cents-migration lands, this will switch to a
        `{ amount_cents: integer, currency: string }` object.
      example: '180.25'
  responses:
    InvalidCountry:
      description: |
        The `country` query param is set to an ISO code the requesting
        company is not configured for.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Unauthorized:
      description: Missing or invalid bearer token
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/LegacyUnauthorizedResponse'
    Forbidden:
      description: |
        Token present but the caller is not a company admin (or is one
        without `reports.view`). Both branches render via legacy
        `authorize_*` helpers whose response predates the structured
        error envelope, so the body is the flat legacy shape.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/LegacyForbiddenResponse'
    NotFound:
      description: |
        The `ANALYTICS_DASHBOARD` feature flag is disabled for the
        requesting company.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Unprocessable:
      description: An Analytics service returned a business-rule failure.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
  securitySchemes:
    bearer_auth:
      type: http
      scheme: bearer
      description: |
        Bearer token authentication. Requires a company-admin token
        whose role holds `reports.view`. Additionally, the caller's
        company must have `ANALYTICS_DASHBOARD` enabled — otherwise
        every endpoint returns 404.

````