> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> To sign a new merchant up for Fluid programmatically, call POST https://api.fluid.app/api/company with no credentials, as described in /api/agent-signup. Do not automate the signup form or book a demo. The merchant must open the emailed sign-in link and create an API token before authenticated calls are possible.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. /api/company/v1 and /api/v1/... paths are documented in no spec here and must never be used (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> Navigation menu management is documented in themes/navigation-menus. These unversioned admin endpoints (/api/menus and nested menu_items) are verified against the implementation but are not yet in the synced OpenAPI specs. Use that reference for menu payloads and its flat page/per_page pagination; missing spec coverage does not make these endpoints unavailable.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.

# Provision a new Mist

> Creates a Mist app for the current company. The request creates
the app's GitHub repository, Postgres database, API tokens, and
deployment project with its public domain, then returns `201` with
`state: "provisioning"` and the final `public_url`. The first
deployment runs in the background; the Mist moves to `live` when
it finishes. Poll `GET /api/v202604/mists/{id}` to watch the state.

If any provisioning step fails, the steps that already completed
are rolled back and the response is `422` naming the failing step.

The app is created standalone. Attaching it to the Fluid surfaces
it plugs into, such as a droplet, a drop zone, or a mobile embed,
happens separately after creation.

Requires a company admin token with the `mist.create` permission.
Creating a Mist allocates billable infrastructure, so it can be
refused with `402` before anything is allocated.




## OpenAPI

````yaml /api-reference/mist-v2026-04.yaml post /api/v202604/mists
openapi: 3.1.0
info:
  title: Fluid Mist v2026-04 API
  version: v2026-04
  description: |
    Mist is Fluid's lite cloud for hosting droplets, drop zones, and app
    extensions. One API call provisions a GitHub repository, a Postgres
    database, and a deployment behind a Fluid-hosted subdomain.

    The Fluid CLI (`fluid mist ...`) is built on this API, and every
    developer-facing Mist workflow is available through it. All endpoints
    require a company admin Bearer token with the matching `mist.*`
    permission.
  contact:
    email: support@fluid.app
  license:
    name: Proprietary
    identifier: LicenseRef-Proprietary
servers:
  - url: https://api.fluid.app
security: []
tags:
  - name: mists
    description: |
      Provision, list, inspect, rename, delete, and restore Mist apps.
      Deleting a Mist starts a 15-day grace period during which it can be
      restored.
    x-fluid-section: Developers
  - name: mist_env_vars
    description: |
      Read and manage the environment variables on a Mist app's deployment
      project. Variables that Mist provisions itself are listed but read-only.
    x-fluid-section: Developers
  - name: mist_code
    description: |
      Read a Mist app's deployments and its runtime and build logs.
    x-fluid-section: Developers
paths:
  /api/v202604/mists:
    post:
      tags:
        - mists
      summary: Provision a new Mist
      description: |
        Creates a Mist app for the current company. The request creates
        the app's GitHub repository, Postgres database, API tokens, and
        deployment project with its public domain, then returns `201` with
        `state: "provisioning"` and the final `public_url`. The first
        deployment runs in the background; the Mist moves to `live` when
        it finishes. Poll `GET /api/v202604/mists/{id}` to watch the state.

        If any provisioning step fails, the steps that already completed
        are rolled back and the response is `422` naming the failing step.

        The app is created standalone. Attaching it to the Fluid surfaces
        it plugs into, such as a droplet, a drop zone, or a mobile embed,
        happens separately after creation.

        Requires a company admin token with the `mist.create` permission.
        Creating a Mist allocates billable infrastructure, so it can be
        refused with `402` before anything is allocated.
      operationId: mist_create
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - mist
              properties:
                mist:
                  type: object
                  properties:
                    name:
                      type: string
                      maxLength: 255
                      description: Optional display label
                    kind:
                      type: string
                      enum:
                        - next_app
                      default: next_app
                    template:
                      type: string
                      maxLength: 100
                      description: |
                        Slug of the template to generate this app from. Only
                        templates Fluid has approved for your company are
                        accepted; a repository name is not. Omit it to use
                        the default template.

                        A template you cannot use is refused before anything
                        is allocated, as `422` with `error.details.reason` of
                        `unknown_template` (no such slug, or one restricted
                        to another company) or `template_disabled`.

                        A template that fails its checks while the app is
                        generated is refused as `422` from the provisioning
                        step, where the machine-readable code is
                        `error.details.type`, not `reason`:
                        `template_not_usable` (withdrawn between the request
                        and generation), `template_sha_drift` (the template
                        changed since it was reviewed, including during
                        generation), `template_commit_unresolved` (its
                        current version could not be read), or
                        `repo_not_owned` (a repository with the derived name
                        already exists and was not created for this app, so
                        it is refused rather than adopted).
            example:
              mist:
                name: Loyalty rewards
                kind: next_app
                template: rewards-starter
      responses:
        '201':
          description: |
            Mist created. `state` is `provisioning` until the first
            deployment finishes.
          content:
            application/json:
              schema:
                type: object
                properties:
                  mist:
                    $ref: '#/components/schemas/Mist'
                  meta:
                    $ref: '#/components/schemas/Meta'
              example:
                mist:
                  id: 0192f4c1-7a3e-7d52-9b61-3bed85a41c07
                  slug: 3bed85
                  state: provisioning
                  kind: next_app
                  name: Loyalty rewards
                  public_url: https://dunder-mifflin-3bed85.mist.fluid.app
                  provisioned_at: null
                  scheduled_destroy_at: null
                  template: rewards-starter
                  created_at: '2026-04-14T16:21:58Z'
                  updated_at: '2026-04-14T16:22:04Z'
                status: 201
                meta:
                  request_id: 6f1c2a9e-4b7d-4e8a-9c3f-2d5b8a1e7f40
                  timestamp: '2026-04-14T16:22:04Z'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '402':
          $ref: '#/components/responses/PaymentRequired'
        '409':
          $ref: '#/components/responses/Conflict'
        '422':
          $ref: '#/components/responses/Unprocessable'
        '503':
          $ref: '#/components/responses/ServiceUnavailable'
      security:
        - bearer_auth: []
components:
  schemas:
    Mist:
      type: object
      description: >-
        One Mist hosting — the deployed extension with its repo, database, and
        Vercel project.
      properties:
        id:
          type: string
          format: uuid
          description: Unique identifier of the Mist.
        slug:
          type: string
          description: 6-char URL-safe disambiguator drawn from the random tail of the uuid
        state:
          type: string
          enum:
            - provisioning
            - live
            - failed
            - pending_destroy
            - archived
        kind:
          type: string
          enum:
            - next_app
        name:
          type:
            - string
            - 'null'
          description: Optional display label
        public_url:
          type:
            - string
            - 'null'
          format: uri
        provisioned_at:
          type:
            - string
            - 'null'
          format: date-time
        scheduled_destroy_at:
          type:
            - string
            - 'null'
          format: date-time
          description: >
            ISO-8601 timestamp 15 days after

            `DELETE /api/v202604/mists/{id}` was called. Non-null only while
            `state == "pending_destroy"`.

            After this timestamp the Mist's repository, database, and

            deployment are permanently torn down; call

            `POST /api/v202604/mists/{mist_id}/restore` any time before

            then to cancel the deletion.
        template:
          type:
            - string
            - 'null'
          description: |
            Slug of the template this app was generated from, or null when
            it came from the install-wide starter. The repo the slug points
            at and the commit the copy received are internal.
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
    Meta:
      type: object
      properties:
        request_id:
          type:
            - string
            - 'null'
        timestamp:
          type: string
          format: date-time
    ErrorResponse:
      type: object
      required:
        - error
        - status
        - meta
      properties:
        error:
          type: object
          required:
            - message
          properties:
            message:
              type: string
            details:
              type: object
              additionalProperties: true
        status:
          type: integer
        meta:
          $ref: '#/components/schemas/Meta'
  responses:
    BadRequest:
      description: Validation failed
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Unauthorized:
      description: Missing or invalid bearer token
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    PaymentRequired:
      description: >-
        Billing admission refused the operation before any vendor allocation.
        error.details carries the shared billing_unresolved details (tier,
        state, episode_id, condition_id, eligible_since, recovery_path); nothing
        names a bank account, a waiver, or an actor.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Conflict:
      description: >-
        The create collides with earlier work. error.details.reason is
        duplicate_recent_create (a same-name hosting inside the duplicate-guard
        window), operation_in_progress (an identical request under this
        operation key was admitted and has not finished), operation_completed
        (an identical create under the client's operation key already completed;
        error.details.provider_reference names the hosting it recorded),
        operation_uncertain (an identical create started, its outcome is
        unknown, and a hosting it may have allocated still exists), or
        operation_conflict (the operation key already admits a different
        request).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Unprocessable:
      description: Business rule violation or vendor configuration error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    ServiceUnavailable:
      description: >-
        Billing admission could not be recorded, so nothing was allocated. This
        is not a refusal; error.details.reason is admission_unavailable and the
        create may be retried.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
  securitySchemes:
    bearer_auth:
      type: http
      scheme: bearer
      description: |
        Bearer token authentication. Accepts company admin tokens with
        the matching `mist.*` permission:
          - `mist.view` to list and show Mists
          - `mist.create` to create and rename Mists
          - `mist.destroy` to delete and restore Mists
          - `mist.code` for deployments and logs
          - `mist.env_vars` to read and manage environment variables
        Droplet installation tokens are refused.

````