> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> To sign a new merchant up for Fluid programmatically, call POST https://api.fluid.app/api/company with no credentials, as described in /api/agent-signup. Do not automate the signup form or book a demo. The merchant must open the emailed sign-in link and create an API token before authenticated calls are possible.
> After signup, to launch a merchant's store (back-office sync, payments onboarding, store setup, a theme copied from their current site, and a preview link before billing), follow /api/agent-launch.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. The same applies to /api/company/v1 and /api/v1/... paths: prefer a newer documented equivalent, and use one only when none exists (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> Fluid has three navigation APIs; don't mix them up. Storefront website menus (navigation bars, footers) are /api/menus and nested menu_items, in api-reference/content-v0.yaml (API Reference: Website > Navigation menus), with a how-to in themes/navigation-menus; their list uses flat page/per_page pagination. The Fluid mobile app's navigation is /api/v2/mobile_navigations, in api-reference/mobile-v2.yaml (API Reference: Mobile app > Navigation); its list also uses page/per_page. Portal navigations belong to a portal definition (Fluid OS), in api-reference/fluid-os-v0.yaml (API Reference: Portal > Portal navigation), and each has a platform of web or mobile.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.
> The Help Center (/help/...) is for merchants, admins and reps using Fluid. Its admin pages mirror the admin's routes: the screen at admin.fluid.app/settings/taxes is documented at /help/admin/settings/taxes. Use the Help Center for how-to questions about the admin, and the Developer Platform and API Reference for building integrations.
> Help Center pages describe what a company admin sees. A reader's role can hide screens and actions; admins manage roles on Settings > Roles (/help/admin/settings/roles). If someone can't find a screen or button, their role's permissions are the first thing to check.
> Send people who need Fluid support to /help/getting-help. Don't invent support email addresses, phone numbers or response times.

# Generate a public token

> Gives the form a new public token, replacing any token it already had, so links built on the old token stop working. The token identifies the public form for the share and embed URLs in the response and the Fluid Public SDK API's token-addressed forms operations. The form must be `active`, and its embed settings still apply: a password, allowed domains, an expiry date, a submission limit, and required contact details. Works for any form type. Activating a form through **Update a form** also creates a token when the form has none.



## OpenAPI

````yaml /api-reference/forms-v0.yaml post /api/forms/{id}/generate_token
openapi: 3.1.0
info:
  description: >-
    Manage your company's forms: build them, choose where they appear, share or
    embed them, and read, export, and follow up on their responses.


    A form is either a **post-purchase** form, which enrollment checkout shows
    after payment to buyers in the form's countries, or a **general** form,
    which you share by link, embed on a website, or send by email. Its fields
    are **form elements**. Each submission is a **respondent** that holds one
    **response** per answered element.


    Every operation takes a Bearer token (`Authorization: Bearer <token>`) for
    your company. Reading operations need the forms view permission, and writing
    operations need the forms update permission, except **Respond to a form**,
    which any member of the company can call. Root admins and droplet tokens
    skip these permission checks. **Respond to a form** also accepts
    unauthenticated calls, but those are deprecated: to collect answers from the
    public, generate a public token and use the Fluid Public SDK API's
    token-addressed forms operations, or the hosted share and embed URLs.


    Answers to elements marked sensitive are masked as `********` unless the
    caller holds the forms view-sensitive permission, is a root admin, or uses a
    droplet token.
  title: Fluid Forms API
  version: v0
  contact:
    email: support@fluid.app
  license:
    name: Proprietary
    identifier: LicenseRef-Proprietary
servers:
  - url: https://api.fluid.app
  - url: https://{company}.fluid.app
    description: Production server with company subdomain
    variables:
      company:
        default: myco
        description: Company subdomain
security: []
tags:
  - name: forms
    description: >-
      Build forms, choose where they appear, share or embed them with a public
      token, and read, export, and follow up on their responses.
  - name: form-elements
    description: The fields and layout blocks that make up a form.
paths:
  /api/forms/{id}/generate_token:
    post:
      tags:
        - forms
      summary: Generate a public token
      description: >-
        Gives the form a new public token, replacing any token it already had,
        so links built on the old token stop working. The token identifies the
        public form for the share and embed URLs in the response and the Fluid
        Public SDK API's token-addressed forms operations. The form must be
        `active`, and its embed settings still apply: a password, allowed
        domains, an expiry date, a submission limit, and required contact
        details. Works for any form type. Activating a form through **Update a
        form** also creates a token when the form has none.
      operationId: forms_v0_forms_generate_token_post
      parameters:
        - name: id
          description: ID of the form.
          in: path
          required: true
          schema:
            type: string
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/FormTokenResponse'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UnauthorizedResponse'
        '404':
          description: Not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardErrorResponse'
      security:
        - bearer_auth: []
components:
  schemas:
    FormTokenResponse:
      type: object
      properties:
        form:
          description: The form with its public sharing settings.
          type: object
          properties:
            countries:
              description: The countries the form is for.
              type: array
              items:
                $ref: '#/components/schemas/JsonValue'
            description:
              description: Description of the form.
              type: string
            embed_settings:
              description: >-
                Restrictions on the public form: `allowed_domains`,
                `expires_at`, `max_submissions`, and `require_contact` when set,
                plus `password_protected`. The password itself is never
                returned.
              type: object
              properties:
                password_protected:
                  description: >-
                    Whether visitors must enter a password before they can see
                    or submit the form.
                  type: boolean
              required:
                - password_protected
              additionalProperties: false
            embed_url:
              description: >-
                Link to the hosted form in embed mode, or `null` when the form
                has no public token.
              type: string
            form_components:
              description: >-
                The form's elements as the builder saved them, a JSON-encoded
                array of components.
              type: 'null'
            form_redirect:
              description: >-
                URL the hosted form sends the respondent to after they submit,
                or `null`.
              type: 'null'
            form_respondents_count:
              description: Number of respondents the form has.
              type: integer
            form_styles:
              description: The form's visual styles, or `null` when none are set.
              type: 'null'
            form_type:
              description: >-
                `post_purchase`, `general`, or the retired `pre_purchase`;
                `null` when unset.
              type: 'null'
            id:
              description: ID of the form.
              type: integer
            public_token:
              description: >-
                The form's public token. It identifies the public form for the
                share and embed URLs and the Fluid Public SDK API's
                token-addressed forms operations. The form must be `active`, and
                its embed settings still apply: a password, allowed domains, an
                expiry date, a submission limit, and required contact details.
              type: string
            share_url:
              description: >-
                Link to the hosted form for this token, or `null` when the form
                has no public token.
              type: string
            status:
              description: >-
                `draft` or `active`. The public token serves the form only while
                it is `active`.
              type: string
            title:
              description: Title of the form.
              type: string
            updated_at:
              description: When the form last changed.
              type: string
              format: date-time
          required:
            - countries
            - description
            - embed_settings
            - embed_url
            - form_components
            - form_redirect
            - form_respondents_count
            - form_styles
            - form_type
            - id
            - public_token
            - share_url
            - status
            - title
            - updated_at
          additionalProperties: false
        message:
          description: 'Confirmation message: `Public token generated`.'
          type: string
        meta:
          $ref: '#/components/schemas/Meta'
          description: Request metadata.
      required:
        - form
        - message
        - meta
      additionalProperties: false
    UnauthorizedResponse:
      type: object
      properties:
        message:
          description: Why the request was refused.
          type: string
      required:
        - message
    StandardErrorResponse:
      description: >-
        Common legacy error response envelope. Older endpoints may return one or
        more of these fields depending on the controller path.
      type: object
      properties:
        message:
          description: Human-readable error message, when the endpoint returns one.
          type: string
        error:
          $ref: '#/components/schemas/ErrorMessage'
          description: >-
            Error message or details, when the endpoint returns them under this
            key.
        error_message:
          $ref: '#/components/schemas/ErrorMessage'
          description: >-
            Human-readable summary of the error, such as `Form not found` or
            `Invalid parameters`.
        errors:
          $ref: '#/components/schemas/ErrorBag'
          description: >-
            Error details, usually keyed by field. For example, a request for
            the retired pre-purchase type returns a message under `form_type`.
        meta:
          $ref: '#/components/schemas/Meta'
          description: Request metadata.
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
    JsonValue:
      description: >-
        Any valid JSON value for provider, integration, theme, metadata, or
        other dynamic payloads whose keys are not fixed by the API contract.
      anyOf:
        - type: string
        - type: number
        - type: boolean
        - type: 'null'
        - type: array
          items:
            $ref: '#/components/schemas/JsonValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
    Meta:
      description: Request metadata returned with the response.
      type: object
      properties:
        request_id:
          description: Identifier of this request, for support and log correlation.
          type:
            - string
            - 'null'
        timestamp:
          description: When the server built the response, in ISO 8601.
          type: string
          format: date-time
    ErrorMessage:
      description: An API error message represented as text or structured JSON.
      anyOf:
        - type: string
        - $ref: '#/components/schemas/ErrorBag'
        - type: 'null'
    ErrorBag:
      description: >-
        Validation errors keyed by field, a list of errors, a single error
        message, or null when no structured error details are available.
      anyOf:
        - type: string
        - type: array
          items:
            $ref: '#/components/schemas/ErrorValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/ErrorValue'
        - type: 'null'
    ErrorValue:
      description: A validation or API error value.
      anyOf:
        - type: string
        - type: array
          items:
            type: string
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
  securitySchemes:
    bearer_auth:
      type: http
      scheme: bearer
      description: Bearer token authentication

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.