> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. /api/company/v1 and /api/v1/... paths are documented in no spec here and must never be used (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/auth-v0.yaml covers the unversioned auth surface (/api/... paths — authentication, MFA, social auth, and token exchange); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.

# Disable a gateway for one country

> Removes one country from the gateway's coverage, leaving the rest of its
list untouched. Removing a country the gateway does not serve is a no-op
that returns `200`. Every removal is recorded on the gateway's audit
trail with the acting admin, or the merchant when an API key made the
call.

On this operation a droplet token receives `403` and a JWT needs root
admin or an explicit `gateways.update` or `apm.update` role grant; the
gateway create and update operations keep their own authorization.
Returns `404` for an unknown gateway or a country the company has not
enabled, and `422` when the country code is not a two-letter ISO 3166-1
code.




## OpenAPI

````yaml /api-reference/payment-v2026-04.yaml delete /api/payment/v2026-04/gateways/{id}/countries/{country_code}
openapi: 3.1.0
info:
  title: Fluid Payment API
  version: v2026-04
  description: |
    Payment gateway and transaction management API — the standalone Fluid
    Payments surface for external platforms.

    Two credentials are accepted on every operation:
    - **API keys** (`fp_live_*` / `fp_test_*`), scoped to a payments merchant.
      Live and sandbox keys are separate credentials; `fp_live_*` keys also
      require the merchant's API access to be enabled. Requests authenticated
      with an `fp_test_*` key run in sandbox mode: transactions are created
      with a sandbox source and never move real funds.
    - **JWT bearer tokens** at admin tier (company admin or root admin). A
      non-admin JWT is rejected with `403`.

    Transactions created outside this API (checkout, storefront, admin) are
    not visible to its read endpoints and cannot be captured, voided, or
    credited here. API-key-authenticated operations emit signed webhooks to
    the merchant's configured webhook URL (see the `webhooks` section).
  contact:
    email: support@fluid.app
  license:
    name: Proprietary
    identifier: LicenseRef-Proprietary
servers:
  - url: https://api.fluid.app
security:
  - bearer_auth: []
tags:
  - name: Gateways
    description: >-
      Manage payment gateways and run gateway-level transactions — purchase,
      authorize, and $0 verification.
  - name: Transactions
    description: >-
      Read transactions and run transaction lifecycle operations — capture,
      void, and refund. Scoped to transactions created through this API (live or
      sandbox); transactions from checkout, storefront, or admin flows are not
      visible here.
  - name: Merchant Configuration
    description: >-
      Root-admin-only access to a merchant's VGS, Kount, 3DS acquirer, payout,
      and platform-fee settings.
  - name: Webhooks
    description: >-
      Signed payment-event notifications POSTed to the merchant's configured
      webhook URL. Fired only for transactions created through
      API-key-authenticated requests.
paths:
  /api/payment/v2026-04/gateways/{id}/countries/{country_code}:
    parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
        description: Gateway slug, UUID, or ID
      - name: country_code
        in: path
        required: true
        schema:
          type: string
          minLength: 2
          maxLength: 2
          pattern: ^[A-Za-z]{2}$
        description: ISO 3166-1 alpha-2 code of the country to disable.
    delete:
      tags:
        - Gateways
      summary: Disable a gateway for one country
      description: |
        Removes one country from the gateway's coverage, leaving the rest of its
        list untouched. Removing a country the gateway does not serve is a no-op
        that returns `200`. Every removal is recorded on the gateway's audit
        trail with the acting admin, or the merchant when an API key made the
        call.

        On this operation a droplet token receives `403` and a JWT needs root
        admin or an explicit `gateways.update` or `apm.update` role grant; the
        gateway create and update operations keep their own authorization.
        Returns `404` for an unknown gateway or a country the company has not
        enabled, and `422` when the country code is not a two-letter ISO 3166-1
        code.
      operationId: unlinkGatewayCountry
      responses:
        '200':
          description: Gateway with the country disabled
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GatewayDataResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '422':
          $ref: '#/components/responses/UnprocessableEntity'
components:
  schemas:
    GatewayDataResponse:
      type: object
      required:
        - data
        - meta
      properties:
        data:
          $ref: '#/components/schemas/Gateway'
        meta:
          $ref: '#/components/schemas/Meta'
    Gateway:
      type: object
      required:
        - id
        - name
        - integration_type
        - mode
        - supported_sources
        - country_codes
        - settings
        - created_at
        - updated_at
      properties:
        id:
          type: string
          description: >
            Gateway slug identifier — the stable string used to address this
            gateway

            on `/gateways/{id}` and its transaction sub-routes.
        name:
          type: string
          description: Human-readable display name for the gateway.
        integration_type:
          type: string
          description: >
            Integration class backing the gateway (e.g. `CreditCard`, `PayPal`).
            Selects

            the provider adapter and the credential set used to process
            transactions.
        mode:
          type: string
          enum:
            - live
            - test
            - sandbox
          description: >
            Environment the gateway operates in. `live` moves real funds; `test`
            and

            `sandbox` route to the provider's non-production environment.
        supported_sources:
          type: array
          items:
            type: string
          description: >
            Card brands / payment sources the gateway accepts (e.g. `visa`,

            `mastercard`). Populated only for `CreditCard` gateways with a
            recognized

            provider adapter; `[]` for all other integration types.
        country_codes:
          type: array
          items:
            type: string
          description: ISO 3166-1 alpha-2 country codes the gateway is enabled for.
        settings:
          type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
          description: >
            Provider-specific configuration key/values for the gateway, returned
            as

            stored. The shape varies by `integration_type`. Secrets never appear
            here:

            provider credentials live in the write-only `credentials` request
            field

            and are excluded from every response.
        created_at:
          type: string
          format: date-time
          description: Creation timestamp (ISO 8601).
        updated_at:
          type: string
          format: date-time
          description: Timestamp of the last update to the gateway (ISO 8601).
    Meta:
      type: object
      required:
        - request_id
        - timestamp
      properties:
        request_id:
          type:
            - string
            - 'null'
          description: |
            Unique identifier for this request, echoed on every response for log
            correlation and support; `null` when none was assigned.
        timestamp:
          type: string
          format: date-time
          description: ISO 8601 timestamp (UTC) of when the response was generated.
    UnauthorizedResponse:
      type: object
      required:
        - message
        - meta
      properties:
        message:
          type: string
          description: Human-readable reason the credentials were rejected.
        status:
          type: string
          description: Error status string, when present.
        meta:
          $ref: '#/components/schemas/Meta'
    ForbiddenResponse:
      description: |
        Authenticated but not authorized. Two body shapes occur:
        - a bare `message` when the credential lacks the required role/tier
          (e.g. a non-admin JWT calling an admin endpoint)
        - a `status` + `message` envelope from payment API endpoint gates
      anyOf:
        - type: object
          required:
            - message
            - meta
          properties:
            message:
              type: string
            meta:
              $ref: '#/components/schemas/Meta'
        - type: object
          required:
            - status
            - message
            - meta
          properties:
            status:
              type: string
              enum:
                - error
            message:
              type: string
            meta:
              $ref: '#/components/schemas/Meta'
    ErrorResponse:
      oneOf:
        - type: object
          required:
            - status
            - message
            - meta
          properties:
            status:
              type: string
              enum:
                - error
              description: Always `error` for this envelope.
            message:
              type: string
              description: Human-readable description of what went wrong.
            meta:
              $ref: '#/components/schemas/Meta'
        - type: object
          required:
            - error_message
            - errors
            - meta
          properties:
            error_message:
              type: string
              description: Human-readable summary of the failure.
            errors:
              $ref: '#/components/schemas/ErrorBag'
            meta:
              $ref: '#/components/schemas/Meta'
    JsonValue:
      description: >-
        Any valid JSON value for provider, integration, theme, metadata, or
        other dynamic payloads whose keys are not fixed by the API contract.
      anyOf:
        - type: string
        - type: number
        - type: boolean
        - type: 'null'
        - type: array
          items:
            $ref: '#/components/schemas/JsonValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
    ErrorBag:
      description: >-
        Validation errors keyed by field, a list of errors, a single error
        message, or null when no structured error details are available.
      anyOf:
        - type: string
        - type: array
          items:
            $ref: '#/components/schemas/ErrorValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/ErrorValue'
        - type: 'null'
    ErrorValue:
      description: A validation or API error value.
      anyOf:
        - type: string
        - type: array
          items:
            type: string
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
  responses:
    Unauthorized:
      description: Missing or invalid credentials.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/UnauthorizedResponse'
    Forbidden:
      description: Authenticated but not authorized for this action.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ForbiddenResponse'
    NotFound:
      description: The requested resource was not found.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    UnprocessableEntity:
      description: Validation or business error.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
  securitySchemes:
    bearer_auth:
      type: http
      scheme: bearer
      description: |
        Merchant API key (`fp_live_*` for live, `fp_test_*` for sandbox) or an
        admin-tier JWT (company admin or root admin). Non-admin JWTs are
        rejected with `403`; live API keys additionally require the merchant's
        API access to be enabled.

````