> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> To sign a new merchant up for Fluid programmatically, call POST https://api.fluid.app/api/company with no credentials, as described in /api/agent-signup. Do not automate the signup form or book a demo. The merchant must open the emailed sign-in link and create an API token before authenticated calls are possible.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. /api/company/v1 and /api/v1/... paths are documented in no spec here and must never be used (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> Navigation menu management is documented in themes/navigation-menus. These unversioned admin endpoints (/api/menus and nested menu_items) are verified against the implementation but are not yet in the synced OpenAPI specs. Use that reference for menu payloads and its flat page/per_page pagination; missing spec coverage does not make these endpoints unavailable.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.

# Complete a Fluid OS widget package upload

> Verify uploaded artifacts for a company-owned Fluid OS widget package version and approve the version when verification succeeds. Uploaded manifest.json is verified for matching packageId, matching version, and valid company-owned `company.<package_key>.` widget type prefixes.



## OpenAPI

````yaml /api-reference/fluid-os-v0.yaml post /api/company/fluid_os/widget_package_versions/{version}/complete_upload
openapi: 3.1.0
info:
  title: Fluid Fluid Os API
  version: v0
  contact:
    email: support@fluid.app
  license:
    name: Proprietary
    identifier: LicenseRef-Proprietary
servers:
  - url: https://api.fluid.app
security: []
paths:
  /api/company/fluid_os/widget_package_versions/{version}/complete_upload:
    post:
      tags:
        - fluid-os---widget-package-versions
      summary: Complete a Fluid OS widget package upload
      description: >-
        Verify uploaded artifacts for a company-owned Fluid OS widget package
        version and approve the version when verification succeeds. Uploaded
        manifest.json is verified for matching packageId, matching version, and
        valid company-owned `company.<package_key>.` widget type prefixes.
      operationId: fluid_os_v0_complete_widget_package_version_upload
      parameters:
        - name: version
          in: path
          required: true
          schema:
            type: string
            minLength: 1
            pattern: ^(?!\.\.?$)[A-Za-z0-9._~-]+$
          description: >-
            Non-empty, object-path-safe widget package version identifier to
            verify. Dotted versions such as 1.0.0 are accepted; only exact . or
            .. path segments and characters outside [A-Za-z0-9._~-] are
            rejected.
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/FluidOSWidgetPackageVersionCompleteUploadRequest
              description: Request payload
        required: false
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/FluidOSWidgetPackageVersionCompleteUploadResponse
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardUnauthorizedResponse'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardErrorResponse'
        '404':
          description: Widget package or version not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardErrorResponse'
        '422':
          description: Validation or verification failed
          content:
            application/json:
              schema:
                anyOf:
                  - $ref: >-
                      #/components/schemas/FluidOSWidgetPackageVersionVerificationErrorResponse
                  - $ref: '#/components/schemas/StandardErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardErrorResponse'
      security:
        - bearer_auth: []
components:
  schemas:
    FluidOSWidgetPackageVersionCompleteUploadRequest:
      description: >-
        Request payload for verifying uploaded company-owned Fluid OS widget
        package artifacts. The version path parameter, optional package_key, and
        any supplied artifact metadata must match the stored
        upload-session/package version artifact metadata before the package
        version is approved. If artifacts are supplied, they must include
        exactly the stored upload-session artifact paths. Uploaded manifest.json
        is verified for matching packageId, matching version, and valid
        company-owned `company.<package_key>.` widget type prefixes.
      type: object
      properties:
        package_key:
          type:
            - string
            - 'null'
          minLength: 1
          pattern: ^(?!\.\.?$)[A-Za-z0-9._~-]+$
          description: >-
            Optional non-empty, object-path-safe widget package key. When
            omitted, the company's widget package is used; . and .. are not
            accepted.
        artifacts:
          type: array
          minItems: 1
          description: >-
            Optional artifact metadata to compare with the stored upload
            session. When supplied, the list must include exactly the stored
            upload-session artifact paths; omissions and extras are rejected.
          items:
            $ref: >-
              #/components/schemas/FluidOSWidgetPackageVersionCompletionArtifactInput
    FluidOSWidgetPackageVersionCompleteUploadResponse:
      description: Approved Fluid OS widget package version details.
      type: object
      required:
        - status
        - packageId
        - version
        - scriptUrl
        - cssUrls
        - manifestUrl
      properties:
        status:
          type: string
        packageId:
          type: string
        version:
          type: string
          minLength: 1
          pattern: ^(?!\.\.?$)[A-Za-z0-9._~-]+$
          description: >-
            Non-empty, object-path-safe widget package version identifier.
            Dotted versions such as 1.0.0 are accepted; only exact . or .. path
            segments and characters outside [A-Za-z0-9._~-] are rejected.
        scriptUrl:
          type: string
          format: uri
        cssUrls:
          type: array
          items:
            type: string
            format: uri
        manifestUrl:
          type: string
          format: uri
      additionalProperties: false
    StandardUnauthorizedResponse:
      description: Common legacy unauthorized response envelope.
      allOf:
        - $ref: '#/components/schemas/StandardErrorResponse'
    StandardErrorResponse:
      description: >-
        Common legacy error response envelope. Older endpoints may return one or
        more of these fields depending on the controller path.
      type: object
      properties:
        message:
          type: string
        error:
          $ref: '#/components/schemas/ErrorMessage'
        error_message:
          $ref: '#/components/schemas/ErrorMessage'
        errors:
          $ref: '#/components/schemas/ErrorBag'
        meta:
          $ref: '#/components/schemas/Meta'
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
    FluidOSWidgetPackageVersionVerificationErrorResponse:
      description: >-
        Flat verification failure response returned when uploaded artifacts do
        not match the package manifest or expected metadata.
      type: object
      required:
        - status
        - error_message
        - details
      properties:
        status:
          type: string
          enum:
            - error
        error_message:
          type: string
        details:
          type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
      additionalProperties: false
    FluidOSWidgetPackageVersionCompletionArtifactInput:
      description: >-
        Optional artifact metadata supplied when completing a widget package
        upload. Artifact paths must be unique top-level package artifact
        filenames within the request; accepted names are widget.js,
        manifest.json, *.css, and *.js.map with no slash paths. Accepted content
        types are application/javascript for widget.js, application/json for
        manifest.json and *.js.map, and text/css for *.css. Byte sizes are
        non-negative and checked against configured per-artifact and bundle
        limits; defaults are 5 MiB per artifact and 10 MiB per bundle unless
        environment config changes them. sha256/checksum, bytes/size, and
        contentType/content_type are accepted aliases and must match when both
        aliases are present; supplied artifact metadata is compared with the
        stored upload-session/package version artifact metadata during
        verification. If artifacts are supplied, they must include exactly the
        stored upload-session artifact paths. Manifest verification is separate
        and happens against uploaded artifact content.
      type: object
      allOf:
        - $ref: >-
            #/components/schemas/FluidOSWidgetPackageVersionCompletionArtifactContentTypeConstraint
      required:
        - path
      properties:
        path:
          type: string
          minLength: 1
          pattern: >-
            ^(widget\.js|manifest\.json|[A-Za-z0-9._~-]+\.css|[A-Za-z0-9._~-]+\.js\.map)$
          description: >-
            Top-level package artifact filename. Accepted names are widget.js,
            manifest.json, *.css, or *.js.map; slash paths are not accepted.
        sha256:
          type: string
          minLength: 1
          description: Expected SHA256 checksum for the artifact content.
        checksum:
          type: string
          minLength: 1
          description: Alias for sha256.
        bytes:
          type: integer
          minimum: 0
          description: >-
            Expected artifact size in bytes. Checked against configured
            per-artifact and bundle limits; defaults are 5 MiB per artifact and
            10 MiB per bundle unless environment config changes them.
        size:
          type: integer
          minimum: 0
          description: >-
            Alias for bytes; checked against the same configured per-artifact
            and bundle limits.
        contentType:
          type: string
          minLength: 1
          enum:
            - application/javascript
            - application/json
            - text/css
          description: >-
            MIME content type for the artifact. Accepted values are
            application/javascript for widget.js, application/json for
            manifest.json and *.js.map, and text/css for *.css.
        content_type:
          type: string
          minLength: 1
          enum:
            - application/javascript
            - application/json
            - text/css
          description: Alias for contentType.
    ErrorMessage:
      description: An API error message represented as text or structured JSON.
      anyOf:
        - type: string
        - $ref: '#/components/schemas/ErrorBag'
        - type: 'null'
    ErrorBag:
      description: >-
        Validation errors keyed by field, a list of errors, a single error
        message, or null when no structured error details are available.
      anyOf:
        - type: string
        - type: array
          items:
            $ref: '#/components/schemas/ErrorValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/ErrorValue'
        - type: 'null'
    Meta:
      type: object
      properties:
        request_id:
          type: string
        timestamp:
          type: string
          format: date-time
      required:
        - request_id
        - timestamp
      additionalProperties: false
    JsonValue:
      description: >-
        Any valid JSON value for provider, integration, theme, metadata, or
        other dynamic payloads whose keys are not fixed by the API contract.
      anyOf:
        - type: string
        - type: number
        - type: boolean
        - type: 'null'
        - type: array
          items:
            $ref: '#/components/schemas/JsonValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
    FluidOSWidgetPackageVersionCompletionArtifactContentTypeConstraint:
      description: >-
        Couples each widget package artifact path class with the only accepted
        contentType/content_type alias values when supplied.
      oneOf:
        - title: Widget script artifact
          type: object
          required:
            - path
          properties:
            path:
              const: widget.js
            contentType:
              const: application/javascript
            content_type:
              const: application/javascript
        - title: Widget manifest artifact
          type: object
          required:
            - path
          properties:
            path:
              const: manifest.json
            contentType:
              const: application/json
            content_type:
              const: application/json
        - title: Stylesheet artifact
          type: object
          required:
            - path
          properties:
            path:
              type: string
              pattern: ^[A-Za-z0-9._~-]+\.css$
            contentType:
              const: text/css
            content_type:
              const: text/css
        - title: Source map artifact
          type: object
          required:
            - path
          properties:
            path:
              type: string
              pattern: ^[A-Za-z0-9._~-]+\.js\.map$
            contentType:
              const: application/json
            content_type:
              const: application/json
    ErrorValue:
      description: A validation or API error value.
      anyOf:
        - type: string
        - type: array
          items:
            type: string
        - $ref: '#/components/schemas/JsonValue'
  securitySchemes:
    bearer_auth:
      type: http
      scheme: bearer
      description: Bearer token authentication

````