> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> To sign a new merchant up for Fluid programmatically, call POST https://api.fluid.app/api/company with no credentials, as described in /api/agent-signup. Do not automate the signup form or book a demo. The merchant must open the emailed sign-in link and create an API token before authenticated calls are possible.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. /api/company/v1 and /api/v1/... paths are documented in no spec here and must never be used (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> Navigation menu management is documented in themes/navigation-menus. These unversioned admin endpoints (/api/menus and nested menu_items) are verified against the implementation but are not yet in the synced OpenAPI specs. Use that reference for menu payloads and its flat page/per_page pagination; missing spec coverage does not make these endpoints unavailable.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.

# Start company bank-account setup

> Reserve a durable setup attempt after the authenticated company admin
accepts the current variable-amount ACH authorization and submits its exact
frontend wording for fingerprint verification. Returns the
Stripe client secret used by Stripe-rendered bank account collection.
The optional existing-bank fields select a company-owned encrypted
account for server-side Stripe tokenization; all three must be sent
together. Bank and routing numbers are never accepted by this endpoint.




## OpenAPI

````yaml /api-reference/settings-v0.yaml post /api/settings/billing/instrument-setup
openapi: 3.1.0
info:
  title: Fluid Settings API
  version: v0
  contact:
    email: support@fluid.app
  license:
    name: Proprietary
    identifier: LicenseRef-Proprietary
servers:
  - url: https://api.fluid.app
security: []
paths:
  /api/settings/billing/instrument-setup:
    post:
      tags:
        - billing
      summary: Start company bank-account setup
      description: >
        Reserve a durable setup attempt after the authenticated company admin

        accepts the current variable-amount ACH authorization and submits its
        exact

        frontend wording for fingerprint verification. Returns the

        Stripe client secret used by Stripe-rendered bank account collection.

        The optional existing-bank fields select a company-owned encrypted

        account for server-side Stripe tokenization; all three must be sent

        together. Bank and routing numbers are never accepted by this endpoint.
      operationId: settings_v0_create_billing_instrument_setup
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              additionalProperties: false
              required:
                - instrument_setup
              properties:
                instrument_setup:
                  type: object
                  additionalProperties: false
                  required:
                    - billing_name
                    - billing_email
                    - authorization_version
                    - authorization_text
                    - accepted
                  dependentRequired:
                    bank_account_id:
                      - bank_account_type
                      - account_holder_type
                    bank_account_type:
                      - bank_account_id
                      - account_holder_type
                    account_holder_type:
                      - bank_account_id
                      - bank_account_type
                  if:
                    required:
                      - instrument_type
                    properties:
                      instrument_type:
                        const: card
                  then:
                    properties:
                      bank_account_id: false
                      bank_account_type: false
                      account_holder_type: false
                  properties:
                    instrument_type:
                      type: string
                      enum:
                        - us_bank_account
                        - card
                      default: us_bank_account
                      description: >-
                        Rail to set up. A card takes no bank account fields, and
                        is refused while the card agreement is not approved.
                    billing_name:
                      type: string
                      minLength: 1
                      maxLength: 255
                      pattern: \S
                    billing_email:
                      type: string
                      format: email
                    authorization_version:
                      type: string
                      minLength: 1
                      pattern: \S
                    authorization_text:
                      type: string
                      minLength: 1
                      maxLength: 20000
                      description: >-
                        Exact frontend agreement accepted; the server verifies
                        its approved SHA-256 fingerprint.
                    accepted:
                      type: boolean
                      const: true
                    bank_account_id:
                      type: integer
                      minimum: 1
                      description: >-
                        Existing bank account owned by the authenticated
                        company.
                    bank_account_type:
                      type: string
                      enum:
                        - checking
                        - savings
                    account_holder_type:
                      type: string
                      const: company
            example:
              instrument_setup:
                instrument_type: us_bank_account
                billing_name: Dunder Mifflin Paper Company
                billing_email: angela.martin@dundermifflin.com
                authorization_version: fluid-ach-v1
                authorization_text: >-
                  MERCHANT BANK ACCOUNT DEBIT AUTHORIZATION AND PLATFORM FEE
                  AGREEMENT


                  By creating and maintaining a merchant profile on Fluid and
                  providing the bank account information requested by Fluid (the
                  “Platform”), Merchant authorizes the Platform and its
                  designated payment processor, financial institution, or
                  payment service provider to initiate electronic debits
                  (including ACH debits, where applicable) from the bank account
                  designated by Merchant for amounts that Merchant owes to the
                  Platform under the Platform’s applicable Merchant Agreement,
                  Terms of Service, fee schedule, or other agreement governing
                  Merchant’s use of the Platform (collectively, the “Platform
                  Fees”).


                  This authorization is provided voluntarily and constitutes
                  Merchant’s authorization for the Platform, through its payment
                  processor or financial institution, to debit the designated
                  bank account for Platform Fees and other amounts expressly
                  authorized under Merchant’s agreement with the Platform.


                  Merchant represents and warrants that it is authorized to use
                  the designated bank account and to authorize electronic debits
                  from that account. Merchant agrees that the bank-account
                  information provided to the Platform is accurate and complete
                  and will promptly update that information if the account
                  changes, is closed, or is no longer authorized for such
                  debits.


                  Amount of Debits. Debits may be made for Platform Fees and
                  other amounts that are due and payable by Merchant under the
                  applicable Merchant Agreement. Where the amount of a debit is
                  not a fixed amount, the amount will be determined in
                  accordance with the Platform’s then-current fee schedule and
                  the transaction activity or other applicable charges
                  associated with Merchant’s use of the Platform.


                  Authorization Duration. This authorization will remain in
                  effect for as long as Merchant maintains an account with the
                  Platform and has amounts payable to the Platform, unless and
                  until Merchant properly revokes the authorization as described
                  below. Revocation does not relieve Merchant of any payment
                  obligation incurred before revocation or otherwise terminate
                  Merchant’s obligations under the applicable Merchant
                  Agreement.


                  How to Revoke Authorization. Merchant may revoke this
                  authorization by providing written notice to
                  finance@fluid.app. To allow reasonable time to process the
                  revocation and prevent additional authorized debits, Merchant
                  should submit the revocation notice at least 15 business days
                  before the date of any debit Merchant wishes to prevent.
                  Revocation will become effective after the Platform has had a
                  reasonable opportunity to process the request. Revocation of
                  this authorization does not cancel, waive, or otherwise affect
                  Platform Fees or other amounts already owed by Merchant.


                  Merchant acknowledges that it has read and understands this
                  authorization and agrees that submitting the bank-account
                  information and accepting these terms constitutes its
                  authorization for the Platform and its designated payment
                  processor to initiate the debits described above.
                accepted: true
                bank_account_id: 3187
                bank_account_type: checking
                account_holder_type: company
      responses:
        '201':
          description: SetupIntent created or safely replayed.
          headers:
            Cache-Control:
              description: Prevents storage of the one-response SetupIntent client secret.
              schema:
                type: string
                const: no-store
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BillingInstrumentSetupCreateResponse'
              example:
                instrument_setup:
                  id: 5823
                  instrument_type: us_bank_account
                  status: pending
                  provider: stripe
                  billing_email: angela.martin@dundermifflin.com
                  authorization_version: fluid-ach-v1
                  authorization_accepted_at: '2026-09-30T14:05:11Z'
                  failure_code: null
                  created_at: '2026-09-30T14:05:11Z'
                authorization:
                  version: fluid-ach-v1
                  digest: >-
                    b624e6f9fe13a72526ed0cde8e2dbb492933a7bbb528ba98aa3eaef9269f0fc1
                authorizations:
                  us_bank_account:
                    version: fluid-ach-v1
                    digest: >-
                      b624e6f9fe13a72526ed0cde8e2dbb492933a7bbb528ba98aa3eaef9269f0fc1
                  card:
                    version: fluid-card-v1
                    digest: >-
                      28454951345cf4fe2b43b180fa751686d63bc996cf02b96542ee917267e43857
                allowed_instrument_types:
                  - us_bank_account
                  - card
                publishable_key: pk_live_51Nf3kQHx8Zr2VbTmY4cPq7WdLs0aE6uJ9gKtR1oBnXhCzMvDw
                authorized_bank_account_ids:
                  - 3187
                saved_cards:
                  - id: 5610
                    brand: visa
                    last4: '4242'
                    exp_month: 11
                    exp_year: 2028
                client_secret: >-
                  seti_1Q8wLmHx8Zr2VbTm4cPq7WdL_secret_R3kD9fXq2VnBz7YtMw1sLp0aE6uJgKh
                status: 201
                meta:
                  request_uuid: 7c2e9a41-3b8d-4f62-a1c5-9d0e6f2b8a37
                  timestamp: '2026-09-30T14:05:11Z'
        '401':
          description: Authentication is required.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardUnauthorizedResponse'
        '403':
          description: The caller lacks billing update permission.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardErrorResponse'
        '404':
          description: Billing is not set up for this company (no billing profile).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardErrorResponse'
        '409':
          description: >-
            The accepted authorization version or wording does not match the
            approved agreement.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardErrorResponse'
        '422':
          description: Input or domain validation failed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardErrorResponse'
        '503':
          description: Stripe billing configuration is unavailable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardErrorResponse'
      security:
        - bearer_auth: []
components:
  schemas:
    BillingInstrumentSetupCreateResponse:
      type: object
      additionalProperties: false
      required:
        - instrument_setup
        - authorization
        - authorizations
        - allowed_instrument_types
        - publishable_key
        - authorized_bank_account_ids
        - saved_cards
        - client_secret
        - status
        - meta
      properties:
        instrument_setup:
          $ref: '#/components/schemas/BillingInstrumentSetup'
        authorization:
          $ref: '#/components/schemas/BillingAchAuthorization'
        authorizations:
          $ref: '#/components/schemas/BillingInstrumentAuthorizations'
        allowed_instrument_types:
          $ref: '#/components/schemas/BillingAllowedInstrumentTypes'
        publishable_key:
          type: string
        authorized_bank_account_ids:
          $ref: '#/components/schemas/BillingAuthorizedBankAccountIds'
        saved_cards:
          $ref: '#/components/schemas/BillingSavedCards'
        client_secret:
          type: string
        status:
          type: integer
          const: 201
        meta:
          $ref: '#/components/schemas/BillingTargetMeta'
    StandardUnauthorizedResponse:
      description: Common legacy unauthorized response envelope.
      allOf:
        - $ref: '#/components/schemas/StandardErrorResponse'
    StandardErrorResponse:
      description: >-
        Common legacy error response envelope. Older endpoints may return one or
        more of these fields depending on the controller path.
      type: object
      properties:
        message:
          type: string
        error:
          $ref: '#/components/schemas/ErrorMessage'
        error_message:
          $ref: '#/components/schemas/ErrorMessage'
        errors:
          $ref: '#/components/schemas/ErrorBag'
        meta:
          $ref: '#/components/schemas/Meta'
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
    BillingInstrumentSetup:
      type: object
      additionalProperties: false
      required:
        - id
        - instrument_type
        - status
        - provider
        - billing_email
        - authorization_version
        - authorization_accepted_at
        - created_at
      properties:
        id:
          type: integer
        instrument_type:
          type: string
          enum:
            - us_bank_account
            - card
          description: The rail this setup is for.
        status:
          type: string
          enum:
            - pending
            - usable
            - failed
            - canceled
            - expired
        provider:
          type: string
          const: stripe
        billing_email:
          type: string
          format: email
        authorization_version:
          type: string
        authorization_accepted_at:
          type: string
          format: date-time
        failure_code:
          type:
            - string
            - 'null'
        created_at:
          type: string
          format: date-time
    BillingAchAuthorization:
      type: object
      additionalProperties: false
      required:
        - version
        - digest
      properties:
        version:
          type: string
        digest:
          type: string
          pattern: ^[a-f0-9]{64}$
    BillingInstrumentAuthorizations:
      type: object
      additionalProperties: false
      description: >-
        The approved agreement for each rail offered, by version and
        fingerprint. Every company is offered every rail with an approved
        agreement.
      properties:
        us_bank_account:
          $ref: '#/components/schemas/BillingAchAuthorization'
        card:
          $ref: '#/components/schemas/BillingAchAuthorization'
    BillingAllowedInstrumentTypes:
      type: array
      description: >-
        The rails this company can set up now, which is every rail with an
        approved agreement.
      items:
        type: string
        enum:
          - us_bank_account
          - card
    BillingAuthorizedBankAccountIds:
      type: array
      description: >-
        Saved company bank accounts whose earlier ACH authorization still
        applies. Switching debits onto one of these needs no new acceptance.
      items:
        type: integer
        minimum: 1
    BillingSavedCards:
      type: array
      description: >-
        Saved cards other than the one in use, newest first. Their earlier card
        authorization still applies, so switching onto one needs no new
        acceptance. The expiry is the one recorded at setup; the switch asks
        Stripe whether the card can still be charged.
      items:
        type: object
        additionalProperties: false
        required:
          - id
          - brand
          - last4
          - exp_month
          - exp_year
        properties:
          id:
            type: integer
            minimum: 1
            description: >-
              The card's instrument setup, sent back as instrument_setup_id to
              switch onto it.
          brand:
            type:
              - string
              - 'null'
          last4:
            type:
              - string
              - 'null'
          exp_month:
            type:
              - integer
              - 'null'
          exp_year:
            type:
              - integer
              - 'null'
    BillingTargetMeta:
      type: object
      additionalProperties: true
      required:
        - request_uuid
        - timestamp
      properties:
        request_uuid:
          type:
            - string
            - 'null'
        timestamp:
          type: string
          format: date-time
    ErrorMessage:
      description: An API error message represented as text or structured JSON.
      anyOf:
        - type: string
        - $ref: '#/components/schemas/ErrorBag'
        - type: 'null'
    ErrorBag:
      description: >-
        Validation errors keyed by field, a list of errors, a single error
        message, or null when no structured error details are available.
      anyOf:
        - type: string
        - type: array
          items:
            $ref: '#/components/schemas/ErrorValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/ErrorValue'
        - type: 'null'
    Meta:
      type: object
      properties:
        request_id:
          type:
            - string
            - 'null'
        timestamp:
          type: string
          format: date-time
    JsonValue:
      description: >-
        Any valid JSON value for provider, integration, theme, metadata, or
        other dynamic payloads whose keys are not fixed by the API contract.
      anyOf:
        - type: string
        - type: number
        - type: boolean
        - type: 'null'
        - type: array
          items:
            $ref: '#/components/schemas/JsonValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
    ErrorValue:
      description: A validation or API error value.
      anyOf:
        - type: string
        - type: array
          items:
            type: string
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
  securitySchemes:
    bearer_auth:
      type: http
      scheme: bearer
      description: Bearer token authentication

````