> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> To sign a new merchant up for Fluid programmatically, call POST https://api.fluid.app/api/company with no credentials, as described in /api/agent-signup. Do not automate the signup form or book a demo. The merchant must open the emailed sign-in link and create an API token before authenticated calls are possible.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. /api/company/v1 and /api/v1/... paths are documented in no spec here and must never be used (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> Navigation menu management is documented in themes/navigation-menus. These unversioned admin endpoints (/api/menus and nested menu_items) are verified against the implementation but are not yet in the synced OpenAPI specs. Use that reference for menu payloads and its flat page/per_page pagination; missing spec coverage does not make these endpoints unavailable.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.

# Preview a company genealogy move

> Requires a persisted company admin identity and members.manage (or users.update). Service tokens cannot provide an audited human move actor. Previews do not write or enqueue work. Incomplete previews return validation_incomplete among the violations; submit a move to request deferred validation. The example uses illustrative fixture IDs. Substitute records visible to your authenticated company or member.



## OpenAPI

````yaml /api-reference/genealogy-v2026-10.yaml post /api/company/v2026-10/genealogy/nodes/{id}/move/validate
openapi: 3.1.0
info:
  title: Genealogy trees and recorded history
  version: 2026-10
  description: >-
    Company-owned tree definitions and recorded relationships. A node is one
    member's seat in a tree; a placement records its parent during a half-open
    time interval. The node shows the current relationship, while the placement
    journal supports as-of reads. Member history is always restricted by current
    team scope. Moves take effect at server time: an immediate/no-op outcome
    returns 200, while an approval request or deferred job returns 202 with a
    receipt. Large previews return validation_incomplete until the full check
    runs in a worker; they do not authorize a write. HTTP move submission and
    approval require explicit company admission after migration checks. The
    examples use fixture identities, never usable authentication tokens.
    Outgoing webhook snapshots describe the recorded transition even if a
    receipt changes later.
servers:
  - url: https://api.fluid.app
    description: Fluid API
security:
  - bearerAuth: []
tags:
  - name: Genealogy trees
    description: Configure the company tree registry and explicit ownership declarations.
  - name: Genealogy history
    description: Read recorded relationships under current company or member authorization.
  - name: Genealogy moves
    description: Preview and request current-time genealogy moves.
  - name: Genealogy reads
    description: Read current relationships from existing company-owned nodes.
  - name: Genealogy placement
    description: Place members in binary and matrix trees and manage their holding tank.
paths:
  /api/company/v2026-10/genealogy/nodes/{id}/move/validate:
    post:
      tags:
        - Genealogy moves
      summary: Preview a company genealogy move
      description: >-
        Requires a persisted company admin identity and members.manage (or
        users.update). Service tokens cannot provide an audited human move
        actor. Previews do not write or enqueue work. Incomplete previews return
        validation_incomplete among the violations; submit a move to request
        deferred validation. The example uses illustrative fixture IDs.
        Substitute records visible to your authenticated company or member.
      operationId: validateCompanyGenealogyMove
      parameters:
        - name: id
          in: path
          required: true
          description: >-
            Moving node identifier in the authenticated company and permitted
            team.
          schema:
            type: string
            format: uuid
          example: 01a08945-198e-764a-83a7-ecfdbc3afffb
      requestBody:
        required: true
        description: >-
          An explicit unilevel move proposal. Actor and source are derived from
          authentication.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/MoveProposal'
            example:
              move:
                parent_node_id: 019f0100-0000-7000-8000-000000000002
                reason: Correct the team placement
            examples:
              recorded:
                summary: Preview a company genealogy move
                value:
                  move:
                    parent_node_id: 01a08945-1995-74ba-840d-797584cfe407
                    reason: Correction
      responses:
        '200':
          description: Completed preview.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/MoveValidationResponse'
              examples:
                recorded:
                  summary: Completed preview.
                  value:
                    validation:
                      valid: true
                      approval_required: false
                      deferred: false
                      violations: []
                    status: 200
                    meta:
                      request_uuid: null
                      timestamp: '2026-09-10T03:03:22Z'
        '401':
          description: Missing or invalid member or admin credentials.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthError'
        '403':
          description: Current company admin identity or movement permission is missing.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthError'
        '404':
          description: Node or destination unavailable in the current company/team scope.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '422':
          description: Malformed proposal or current validation violations.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      x-codeSamples:
        - lang: Shell
          label: Preview a company genealogy move
          source: >-
            curl -X POST
            'https://api.fluid.app/api/company/v2026-10/genealogy/nodes/01a08945-198e-764a-83a7-ecfdbc3afffb/move/validate'
            \
              -H 'Authorization: Bearer <company-token>' \
              -H 'Content-Type: application/json' \
              --data \{\"move\":\{\"parent_node_id\":\"01a08945-1995-74ba-840d-797584cfe407\",\"reason\":\"Correction\"\}\}
components:
  schemas:
    MoveProposal:
      type: object
      properties:
        move:
          type: object
          required:
            - parent_node_id
          additionalProperties: false
          properties:
            parent_node_id:
              type:
                - string
                - 'null'
              description: >-
                Explicit proposed parent, or null for a company-authorized root
                move.
              format: uuid
            reason:
              type:
                - string
                - 'null'
              description: Optional explanation, at most 2000 characters.
              maxLength: 2000
            leg:
              type:
                - string
                - 'null'
              description: >-
                The leg under the proposed parent in a binary or matrix tree. It
                is required below a parent (leg_required), must be one of the
                tree's leg_names (leg_unknown) and must be free (leg_full), and
                is null for a root move. Binary and matrix moves need the
                company to be enabled for legged trees
                (legged_trees_not_enabled). Unilevel moves reject a non-null leg
                with leg_unknown.
            effective_at:
              type: string
              description: >-
                Any supplied value is rejected with
                effective_date_not_supported; moves apply only at
                server-recorded current time.
              minLength: 1
      required:
        - move
    MoveValidationResponse:
      type: object
      properties:
        status:
          type: integer
          const: 200
        validation:
          type: object
          properties:
            valid:
              type: boolean
              const: true
            approval_required:
              type: boolean
            deferred:
              type: boolean
              const: false
            violations:
              type: array
              maxItems: 0
              items:
                type: object
          required:
            - valid
            - approval_required
            - deferred
            - violations
          additionalProperties: false
        meta:
          $ref: '#/components/schemas/Meta'
      required:
        - status
        - validation
        - meta
      additionalProperties: false
    AuthError:
      type: object
      description: Existing company authentication or permission denial envelope.
      properties:
        message:
          type: string
        error: {}
      additionalProperties: true
    Error:
      type: object
      properties:
        status:
          type: integer
        error:
          type: object
          properties:
            message:
              type: string
            details:
              type: object
              additionalProperties: true
          required:
            - message
            - details
        meta:
          $ref: '#/components/schemas/Meta'
      required:
        - status
        - error
        - meta
    Meta:
      type: object
      properties:
        request_uuid:
          type:
            - string
            - 'null'
          description: Request correlation identifier.
        timestamp:
          type: string
          description: Response timestamp.
          format: date-time
      required:
        - request_uuid
        - timestamp
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        Company admin or company service token, subject to developer
        permissions.

````