> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> To sign a new merchant up for Fluid programmatically, call POST https://api.fluid.app/api/company with no credentials, as described in /api/agent-signup. Do not automate the signup form or book a demo. The merchant must open the emailed sign-in link and create an API token before authenticated calls are possible.
> After signup, to launch a merchant's store (back-office sync, payments onboarding, store setup, a theme copied from their current site, and a preview link before billing), follow /api/agent-launch.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. The same applies to /api/company/v1 and /api/v1/... paths: prefer a newer documented equivalent, and use one only when none exists (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> Fluid has three navigation APIs; don't mix them up. Storefront website menus (navigation bars, footers) are /api/menus and nested menu_items, in api-reference/content-v0.yaml (API Reference: Website > Navigation menus), with a how-to in themes/navigation-menus; their list uses flat page/per_page pagination. The Fluid mobile app's navigation is /api/v2/mobile_navigations, in api-reference/mobile-v2.yaml (API Reference: Mobile app > Navigation); its list also uses page/per_page. Portal navigations belong to a portal definition (Fluid OS), in api-reference/fluid-os-v0.yaml (API Reference: Portal > Portal navigation), and each has a platform of web or mobile.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.
> The Help Center (/help/...) is for merchants, admins and reps using Fluid. Its admin pages mirror the admin's routes: the screen at admin.fluid.app/settings/taxes is documented at /help/admin/settings/taxes. Use the Help Center for how-to questions about the admin, and the Developer Platform and API Reference for building integrations.
> Help Center pages describe what a company admin sees. A reader's role can hide screens and actions; admins manage roles on Settings > Roles (/help/admin/settings/roles). If someone can't find a screen or button, their role's permissions are the first thing to check.
> Send people who need Fluid support to /help/getting-help. Don't invent support email addresses, phone numbers or response times.

# Save a draft

> Saves the member's own unsent draft in the conversation without sending it. Only the fields
sent change. A submission with no text, no subject, no reply and no attachments removes the
whole draft and answers an empty object. A request with no body is refused rather than read as
an empty submission, so only an explicit empty JSON object clears the draft. Attachments sent
are added to those already saved, and a draft that has attachments needs no text. A file already
on the draft with the same URL and filename is not added again, and a save that would leave the
draft with more than 10 attachments is refused with 422.




## OpenAPI

````yaml /api-reference/member-messaging-v2026-10.yaml put /api/member/v2026-10/messaging/conversations/{id}/draft
openapi: 3.1.0
info:
  title: Fluid Member API v2026-10 — Messaging
  description: |
    The signed-in member's messaging. Every operation acts as the member the
    bearer credential speaks for; the member and their company come from the
    credential alone.

    Messaging follows the rule the legacy messaging API applies: a
    membership with a messaging identity whose member type is the rep type,
    a company admin who holds the messaging view permission, or a root
    admin. A company admin's own credential is not a member credential and
    receives 401, so in practice a rep's or a root admin's membership
    reaches messaging. A customer or preferred-customer
    membership receives 403 from every operation, even when its member type
    grants the rep-eligible capability. A member session JWT, the kind order
    and subscription email links carry, never authenticates a rep, so it also
    receives 403 from every operation.
  contact:
    email: support@fluid.app
  license:
    name: Proprietary
    identifier: LicenseRef-Proprietary
  version: 2026-10
servers:
  - url: https://api.fluid.app
    description: Production API server
  - url: https://api.fluid.test
    description: Local development server
security:
  - MemberBearer: []
tags:
  - name: messaging
    description: The signed-in member's conversations, messages and realtime delivery.
    x-fluid-section: Messaging
paths:
  /api/member/v2026-10/messaging/conversations/{id}/draft:
    parameters:
      - name: id
        in: path
        required: true
        description: Public id of a conversation the member can see.
        schema:
          type: string
          format: uuid
    put:
      tags:
        - messaging
      summary: Save a draft
      description: >
        Saves the member's own unsent draft in the conversation without sending
        it. Only the fields

        sent change. A submission with no text, no subject, no reply and no
        attachments removes the

        whole draft and answers an empty object. A request with no body is
        refused rather than read as

        an empty submission, so only an explicit empty JSON object clears the
        draft. Attachments sent

        are added to those already saved, and a draft that has attachments needs
        no text. A file already

        on the draft with the same URL and filename is not added again, and a
        save that would leave the

        draft with more than 10 attachments is refused with 422.
      operationId: member_messaging_drafts_update
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              additionalProperties: false
              properties:
                text:
                  type:
                    - string
                    - 'null'
                  maxLength: 10000
                subject:
                  type:
                    - string
                    - 'null'
                  maxLength: 255
                reply_to_id:
                  type:
                    - string
                    - 'null'
                  format: uuid
                  description: >-
                    A message in this conversation the member can read; null
                    removes the reply.
                attachments:
                  type: array
                  maxItems: 10
                  description: >-
                    Files the client has uploaded, named by URL, as the legacy
                    composer takes them. They are added to the draft's saved
                    attachments, which hold at most 10 in all. The URL is not
                    checked as an owned upload.
                  items:
                    type: object
                    additionalProperties: false
                    required:
                      - url
                      - filename
                    properties:
                      url:
                        type: string
                        maxLength: 2048
                        pattern: ^https?://\S+$
                      filename:
                        type: string
                        maxLength: 255
                      content_type:
                        type: string
                        maxLength: 255
                      content_size:
                        type: integer
                        minimum: 0
                        maximum: 2147483647
            example:
              text: Running ten minutes late.
              subject: Kickoff
      responses:
        '200':
          description: The saved draft, or an empty object when a blank save cleared it.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DraftEnvelope'
              example:
                status: 200
                data:
                  id: 0199a1b2-c3d4-7e5f-8a9b-0c1d2e3f4a70
                  conversation_id: 0199a1b2-c3d4-7e5f-8a9b-0c1d2e3f4a5b
                  text: Running ten minutes late.
                  subject: Kickoff
                  attachments: []
                  reply_to: null
                  mentioned_recipients: []
                  created_at: '2026-10-01T15:01:59Z'
                  updated_at: '2026-10-01T15:01:59Z'
                meta:
                  request_uuid: 01a0f4fe-de00-75b3-8d8a-b74b0cde8b07
                  timestamp: '2026-10-01T15:04:05Z'
        '401':
          description: >-
            Missing credential, or a credential that is not a usable member
            credential.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '403':
          description: >-
            The credential is read-only, the membership cannot message, or the
            change is not allowed here.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '404':
          description: Nothing with this id is visible to the member.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '422':
          description: >-
            The request has no body, a parameter is invalid or unknown (such as
            an attachment without an http(s) URL or with a size above
            2147483647), or the reply target is not in this conversation.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
components:
  schemas:
    DraftEnvelope:
      type: object
      description: The saved draft, or an empty object after a blank save cleared it.
      required:
        - status
        - data
        - meta
      properties:
        status:
          type: integer
        data:
          oneOf:
            - $ref: '#/components/schemas/Draft'
            - type: object
              additionalProperties: false
        meta:
          $ref: '#/components/schemas/ResponseMeta'
    ErrorEnvelope:
      type: object
      description: Standard error envelope.
      properties:
        status:
          type: integer
          description: HTTP status code (mirrors the response status line).
        error:
          type: object
          properties:
            message:
              type: string
              description: Human-readable error message.
            details:
              type: object
              additionalProperties: true
          required:
            - message
            - details
        meta:
          $ref: '#/components/schemas/ResponseMeta'
      required:
        - status
        - error
        - meta
    Draft:
      type: object
      description: >-
        The member's unsent draft in one conversation. It is never delivered;
        sending is a separate message.
      additionalProperties: false
      required:
        - id
        - conversation_id
        - text
        - subject
        - attachments
        - reply_to
        - mentioned_recipients
        - created_at
        - updated_at
      properties:
        id:
          type: string
          format: uuid
        conversation_id:
          type: string
          format: uuid
        text:
          type: string
          description: The draft text; empty when only a subject or a reply was saved.
        subject:
          type:
            - string
            - 'null'
        attachments:
          type: array
          description: Files attached to the draft.
          items:
            type: object
            additionalProperties: false
            required:
              - url
              - filename
              - content_type
              - kind
              - content_size
            properties:
              url:
                type:
                  - string
                  - 'null'
              filename:
                type:
                  - string
                  - 'null'
              content_type:
                type:
                  - string
                  - 'null'
              kind:
                type:
                  - string
                  - 'null'
                description: The kind of file the server derived, such as `image` or `pdf`.
              content_size:
                type:
                  - integer
                  - 'null'
                description: Size in bytes, when the client sent it.
        reply_to:
          type:
            - object
            - 'null'
          description: >-
            The message this draft replies to, while the member can still read
            it.
          additionalProperties: false
          required:
            - id
            - preview
          properties:
            id:
              type: string
              format: uuid
            preview:
              type: string
              description: Up to 140 characters of its text.
        mentioned_recipients:
          type: array
          description: People mentioned in the text who are still participants.
          items:
            $ref: '#/components/schemas/Identity'
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
    ResponseMeta:
      type: object
      description: Envelope metadata present on every response.
      properties:
        request_uuid:
          type: string
          format: uuid
          description: Server-generated UUIDv7 uniquely identifying this response.
        timestamp:
          type: string
          format: date-time
          description: ISO 8601 timestamp at which the server produced the response.
      required:
        - request_uuid
        - timestamp
      additionalProperties: true
    Identity:
      type: object
      description: >-
        A participant: a member, one of the member's contacts, or another kind
        of recipient such as a bot.
      additionalProperties: false
      required:
        - id
        - kind
        - name
        - avatar_url
      properties:
        id:
          type: string
          format: uuid
          description: >-
            The member's id, the contact's id, or the recipient's own id for
            other kinds.
        kind:
          type: string
          enum:
            - member
            - contact
            - other
          description: What `id` refers to.
        name:
          type:
            - string
            - 'null'
          description: First and last name. Email and phone are never shown in its place.
        avatar_url:
          type:
            - string
            - 'null'
          description: Avatar image, when there is one.
  securitySchemes:
    MemberBearer:
      type: http
      scheme: bearer
      description: |
        A member credential in the `Authorization: Bearer` header: a member
        session JWT, a portal JWT whose login is linked to a membership in
        that company, or a member token. The credential alone
        identifies the member and company.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.