> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> To sign a new merchant up for Fluid programmatically, call POST https://api.fluid.app/api/company with no credentials, as described in /api/agent-signup. Do not automate the signup form or book a demo. The merchant must open the emailed sign-in link and create an API token before authenticated calls are possible.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. /api/company/v1 and /api/v1/... paths are documented in no spec here and must never be used (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> Navigation menu management is documented in themes/navigation-menus. These unversioned admin endpoints (/api/menus and nested menu_items) are verified against the implementation but are not yet in the synced OpenAPI specs. Use that reference for menu payloads and its flat page/per_page pagination; missing spec coverage does not make these endpoints unavailable.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.

# Create a Fluid OS widget package version

> Start a company-owned Fluid OS widget package publish flow and return signed upload URLs for each artifact.



## OpenAPI

````yaml /api-reference/fluid-os-v0.yaml post /api/company/fluid_os/widget_package_versions
openapi: 3.1.0
info:
  title: Fluid Fluid Os API
  version: v0
  contact:
    email: support@fluid.app
  license:
    name: Proprietary
    identifier: LicenseRef-Proprietary
servers:
  - url: https://api.fluid.app
security: []
paths:
  /api/company/fluid_os/widget_package_versions:
    post:
      tags:
        - fluid-os---widget-package-versions
      summary: Create a Fluid OS widget package version
      description: >-
        Start a company-owned Fluid OS widget package publish flow and return
        signed upload URLs for each artifact.
      operationId: fluid_os_v0_create_widget_package_version
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/FluidOSWidgetPackageVersionCreateRequest'
              description: Request payload
        required: true
      responses:
        '201':
          description: Created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/FluidOSWidgetPackageVersionCreateResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardUnauthorizedResponse'
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardErrorResponse'
        '422':
          description: Validation failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardErrorResponse'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardErrorResponse'
      security:
        - bearer_auth: []
components:
  schemas:
    FluidOSWidgetPackageVersionCreateRequest:
      description: >-
        Request payload for starting a company-owned Fluid OS widget package
        version publish flow. Artifact paths must be unique top-level package
        artifact filenames. The artifacts list must include widget.js and
        manifest.json so the API can issue upload URLs and later verify the
        completed upload.
      type: object
      required:
        - package_key
        - version
        - builder_version
        - cli_version
        - runtime_version
        - manifest_hash
        - manifest
        - artifacts
      properties:
        package_key:
          type: string
          minLength: 1
          pattern: ^(?!\.\.?$)[A-Za-z0-9._~-]+$
          description: >-
            Non-empty, object-path-safe company-owned widget package key. Use
            URL-safe characters only; . and .. are not accepted.
        version:
          type: string
          minLength: 1
          pattern: ^(?!\.\.?$)[A-Za-z0-9._~-]+$
          description: >-
            Non-empty, object-path-safe widget package version identifier
            accepted in the URL and upload path. Dotted versions such as 1.0.0
            are accepted; only exact . or .. path segments and characters
            outside [A-Za-z0-9._~-] are rejected.
        builder_version:
          type: string
          minLength: 1
          description: Fluid OS builder version that produced this package.
        cli_version:
          type: string
          minLength: 1
          description: Fluid OS CLI version that published this package.
        runtime_version:
          type: string
          minLength: 1
          description: Fluid OS runtime version targeted by this package.
        manifest_hash:
          type: string
          minLength: 1
          description: SHA256 checksum of the serialized manifest JSON.
        manifest:
          type: object
          minProperties: 1
          description: >-
            Widget package manifest JSON. It must use the supported widget
            manifest structure, contain at least one extractable widget type,
            and every widget type in that structure must use the company-owned
            prefix `company.<package_key>.`.
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
        artifacts:
          type: array
          minItems: 2
          description: >-
            Top-level package artifacts to upload. The list must include
            widget.js and manifest.json.
          allOf:
            - contains:
                type: object
                required:
                  - path
                properties:
                  path:
                    const: widget.js
            - contains:
                type: object
                required:
                  - path
                properties:
                  path:
                    const: manifest.json
          items:
            $ref: '#/components/schemas/FluidOSWidgetPackageVersionArtifactInput'
        build_metadata:
          type: object
          description: Optional publisher metadata stored with the package version.
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
    FluidOSWidgetPackageVersionCreateResponse:
      description: Upload session details for a pending Fluid OS widget package version.
      type: object
      required:
        - version_id
        - artifact_base_url
        - uploads
      properties:
        version_id:
          type: integer
        artifact_base_url:
          type: string
          format: uri
        uploads:
          type: array
          items:
            $ref: '#/components/schemas/FluidOSWidgetPackageVersionUpload'
        warnings:
          type: array
          description: >-
            Present when a best-effort side effect of the publish failed —
            currently only the widget's Git repo provisioning (scope git_sync).
            The publish itself succeeded, but `fluid widget clone` will not work
            until a later publish re-provisions the repo.
          items:
            $ref: '#/components/schemas/FluidOSWidgetPackageVersionPublishWarning'
      additionalProperties: false
    StandardUnauthorizedResponse:
      description: Common legacy unauthorized response envelope.
      allOf:
        - $ref: '#/components/schemas/StandardErrorResponse'
    StandardErrorResponse:
      description: >-
        Common legacy error response envelope. Older endpoints may return one or
        more of these fields depending on the controller path.
      type: object
      properties:
        message:
          type: string
        error:
          $ref: '#/components/schemas/ErrorMessage'
        error_message:
          $ref: '#/components/schemas/ErrorMessage'
        errors:
          $ref: '#/components/schemas/ErrorBag'
        meta:
          $ref: '#/components/schemas/Meta'
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
    JsonValue:
      description: >-
        Any valid JSON value for provider, integration, theme, metadata, or
        other dynamic payloads whose keys are not fixed by the API contract.
      anyOf:
        - type: string
        - type: number
        - type: boolean
        - type: 'null'
        - type: array
          items:
            $ref: '#/components/schemas/JsonValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
    FluidOSWidgetPackageVersionArtifactInput:
      description: >-
        Artifact metadata required before Fluid OS widget package upload URLs
        can be issued. Artifact paths must be unique within the request, and the
        artifact list must include widget.js and manifest.json before upload
        URLs are issued. Artifact paths are top-level package artifact filenames
        only; accepted names are widget.js, manifest.json, *.css, and *.js.map
        with no slash paths. Accepted content types are application/javascript
        for widget.js, application/json for manifest.json and *.js.map, and
        text/css for *.css. Byte sizes are non-negative and checked against
        configured per-artifact and bundle limits; defaults are 5 MiB per
        artifact and 10 MiB per bundle unless environment config changes them.
      type: object
      allOf:
        - $ref: >-
            #/components/schemas/FluidOSWidgetPackageVersionArtifactContentTypeConstraint
      required:
        - path
        - sha256
        - bytes
        - contentType
      properties:
        path:
          type: string
          pattern: >-
            ^(widget\.js|manifest\.json|[A-Za-z0-9._~-]+\.css|[A-Za-z0-9._~-]+\.js\.map)$
          description: >-
            Top-level package artifact filename. Accepted names are widget.js,
            manifest.json, *.css, or *.js.map; slash paths are not accepted.
        sha256:
          type: string
          minLength: 1
          description: Expected SHA256 checksum for the artifact content.
        bytes:
          type: integer
          minimum: 0
          description: >-
            Expected artifact size in bytes. Checked against configured
            per-artifact and bundle limits; defaults are 5 MiB per artifact and
            10 MiB per bundle unless environment config changes them.
        contentType:
          type: string
          enum:
            - application/javascript
            - application/json
            - text/css
          description: >-
            MIME content type used when uploading the artifact. Accepted values
            are application/javascript for widget.js, application/json for
            manifest.json and *.js.map, and text/css for *.css.
    FluidOSWidgetPackageVersionUpload:
      description: Upload instructions for a widget package artifact.
      type: object
      required:
        - path
        - upload_url
        - public_url
      properties:
        path:
          type: string
          pattern: >-
            ^(widget\.js|manifest\.json|[A-Za-z0-9._~-]+\.css|[A-Za-z0-9._~-]+\.js\.map)$
          description: Top-level package artifact filename.
        upload_url:
          type: string
          format: uri
        public_url:
          type: string
          format: uri
      additionalProperties: false
    FluidOSWidgetPackageVersionPublishWarning:
      description: A best-effort publish side effect that did not complete.
      type: object
      required:
        - scope
        - type
      properties:
        scope:
          type: string
          enum:
            - git_sync
        type:
          type: string
          description: >-
            Machine-readable failure type (e.g. no_org_available,
            adapter_unregistered, repo_invalid, git_sync_error).
        message:
          type:
            - string
            - 'null'
          description: Human-readable failure description.
      additionalProperties: false
    ErrorMessage:
      description: An API error message represented as text or structured JSON.
      anyOf:
        - type: string
        - $ref: '#/components/schemas/ErrorBag'
        - type: 'null'
    ErrorBag:
      description: >-
        Validation errors keyed by field, a list of errors, a single error
        message, or null when no structured error details are available.
      anyOf:
        - type: string
        - type: array
          items:
            $ref: '#/components/schemas/ErrorValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/ErrorValue'
        - type: 'null'
    Meta:
      type: object
      properties:
        request_id:
          type: string
        timestamp:
          type: string
          format: date-time
      required:
        - request_id
        - timestamp
      additionalProperties: false
    FluidOSWidgetPackageVersionArtifactContentTypeConstraint:
      description: >-
        Couples each widget package artifact path class with the only accepted
        contentType value.
      oneOf:
        - title: Widget script artifact
          type: object
          required:
            - path
            - contentType
          properties:
            path:
              const: widget.js
            contentType:
              const: application/javascript
        - title: Widget manifest artifact
          type: object
          required:
            - path
            - contentType
          properties:
            path:
              const: manifest.json
            contentType:
              const: application/json
        - title: Stylesheet artifact
          type: object
          required:
            - path
            - contentType
          properties:
            path:
              type: string
              pattern: ^[A-Za-z0-9._~-]+\.css$
            contentType:
              const: text/css
        - title: Source map artifact
          type: object
          required:
            - path
            - contentType
          properties:
            path:
              type: string
              pattern: ^[A-Za-z0-9._~-]+\.js\.map$
            contentType:
              const: application/json
    ErrorValue:
      description: A validation or API error value.
      anyOf:
        - type: string
        - type: array
          items:
            type: string
        - $ref: '#/components/schemas/JsonValue'
  securitySchemes:
    bearer_auth:
      type: http
      scheme: bearer
      description: Bearer token authentication

````