> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> To sign a new merchant up for Fluid programmatically, call POST https://api.fluid.app/api/company with no credentials, as described in /api/agent-signup. Do not automate the signup form or book a demo. The merchant must open the emailed sign-in link and create an API token before authenticated calls are possible.
> After signup, to launch a merchant's store (back-office sync, payments onboarding, store setup, a theme copied from their current site, and a preview link before billing), follow /api/agent-launch.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. The same applies to /api/company/v1 and /api/v1/... paths: prefer a newer documented equivalent, and use one only when none exists (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> Fluid has three navigation APIs; don't mix them up. Storefront website menus (navigation bars, footers) are /api/menus and nested menu_items, in api-reference/content-v0.yaml (API Reference: Website > Navigation menus), with a how-to in themes/navigation-menus; their list uses flat page/per_page pagination. The Fluid mobile app's navigation is /api/v2/mobile_navigations, in api-reference/mobile-v2.yaml (API Reference: Mobile app > Navigation); its list also uses page/per_page. Portal navigations belong to a portal definition (Fluid OS), in api-reference/fluid-os-v0.yaml (API Reference: Portal > Portal navigation), and each has a platform of web or mobile.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.
> The Help Center (/help/...) is for merchants, admins and reps using Fluid. Its admin pages mirror the admin's routes: the screen at admin.fluid.app/settings/taxes is documented at /help/admin/settings/taxes. Use the Help Center for how-to questions about the admin, and the Developer Platform and API Reference for building integrations.
> Help Center pages describe what a company admin sees. A reader's role can hide screens and actions; admins manage roles on Settings > Roles (/help/admin/settings/roles). If someone can't find a screen or button, their role's permissions are the first thing to check.
> Send people who need Fluid support to /help/getting-help. Don't invent support email addresses, phone numbers or response times.

# Confirm a card verification

> Advances the verification after any device fingerprinting or issuer challenge. Returns the saved method once approved (repeating it returns the same method), or the challenge to show. After the challenge is shown, follow it with the verification status route until `state` leaves `pending`, then confirm again to save the card. The verification is bound to the member that started it: another member's verification, or an unknown id, returns 404. Responses carry `Cache-Control: no-store`. Requires a writable member credential.



## OpenAPI

````yaml /api-reference/member-payments-v2026-10.yaml post /api/member/v2026-10/payment-methods/three-ds/confirm
openapi: 3.1.0
info:
  title: Fluid Member API v2026-10 — Payments
  description: >-
    The authenticated member's saved payment methods, public card-vault setup,
    saved-card 3-D Secure verification, current Pro plan and available plan
    offers. The bearer credential determines the member and company. Saved
    methods follow the existing shared-wallet policy; cardholder and billing
    identity use the existing payment API accessors. Card tokens and CVC fields
    are not included in payment-method responses. Vault setup and card-creation
    or verification responses use Cache-Control: no-store. Pro purchases,
    cancellations and company billing remain on their existing surfaces.
  contact:
    email: support@fluid.app
  license:
    name: Proprietary
    identifier: LicenseRef-Proprietary
  version: 2026-10
servers:
  - url: https://api.fluid.app
    description: Production API server
  - url: https://api.fluid.test
    description: Local development server
security:
  - MemberBearer: []
tags:
  - name: plan
    description: >-
      The signed-in member's own Pro plan, the Pro plans their company offers,
      and their paid add-ons.
    x-fluid-section: Payments
  - name: payment-methods
    description: The signed-in member's saved payment methods and card vault setup.
    x-fluid-section: Payments
paths:
  /api/member/v2026-10/payment-methods/three-ds/confirm:
    post:
      tags:
        - payment-methods
      summary: Confirm a card verification
      description: >-
        Advances the verification after any device fingerprinting or issuer
        challenge. Returns the saved method once approved (repeating it returns
        the same method), or the challenge to show. After the challenge is
        shown, follow it with the verification status route until `state` leaves
        `pending`, then confirm again to save the card. The verification is
        bound to the member that started it: another member's verification, or
        an unknown id, returns 404. Responses carry `Cache-Control: no-store`.
        Requires a writable member credential.
      operationId: member_payment_methods_three_ds_confirm
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/VerificationReference'
            example:
              verification_id: 6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13
      responses:
        '200':
          description: The approved method, or the challenge to complete.
          headers:
            Cache-Control:
              $ref: '#/components/headers/CacheControl'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VerificationConfirmationEnvelope'
              example:
                status: 200
                data:
                  id: 6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13
                  status: approved
                  created: true
                  payment_method:
                    id: 0192f501-2b3c-7d4e-8f5a-6b7c8d9e0f1a
                    kind: card
                    brand: visa
                    last4: '5555'
                    expires:
                      month: 3
                      year: 2031
                    card_holder: Casey Brooks
                    default: true
                    billing_address:
                      name: Casey Brooks
                      address1: 742 Evergreen Terrace
                      address2: null
                      city: Springfield
                      state: IL
                      postal_code: '62704'
                      country_code: US
                    created_at: '2026-07-02T19:44:10.000000Z'
                  challenge_form: null
                  challenge_url: null
                meta:
                  request_uuid: 0192f520-1a2b-7c3d-8e4f-5a6b7c8d9e0f
                  timestamp: '2026-09-30T15:20:00Z'
        '400':
          description: The request body is not valid JSON.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '401':
          description: Missing or unusable member credential.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '403':
          description: The member credential can only read.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '404':
          description: No verification of this member has this `verification_id`.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '409':
          description: >-
            A concurrent change interrupted confirmation. Refresh the
            verification status and retry.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '422':
          description: >-
            The `verification_id` is missing, the membership has no payment
            wallet, or verification is denied, failed or pending. Verification
            failures include `error.details.error_code`. An expired verification
            without a linked payment method returns 404. A retry whose linked
            payment method still exists returns that method with 200, even after
            verification expiry.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
components:
  schemas:
    VerificationReference:
      type: object
      additionalProperties: false
      required:
        - verification_id
      properties:
        verification_id:
          type: string
          minLength: 1
          description: >-
            The verification `id` returned by `POST /payment-methods` when
            verification was required. It names the verification for the
            authenticated member only and grants nothing on its own.
          example: 6f1c2a9e-3b7d-4c58-9e21-0a4d8b7c5e13
    VerificationConfirmationEnvelope:
      type: object
      properties:
        status:
          type: integer
        data:
          type: object
          additionalProperties: false
          properties:
            id:
              type: string
              description: The verification id.
            status:
              type: string
              description: >-
                `approved`: the card is saved and returned. `challenge`: the
                shopper must complete the issuer challenge, then confirm again.
              enum:
                - approved
                - challenge
            created:
              type: boolean
              description: >-
                Whether approving this verification saved a new payment method
                (false when it was already saved).
            payment_method:
              oneOf:
                - $ref: '#/components/schemas/PaymentMethod'
                - type: 'null'
            challenge_form:
              type:
                - string
                - 'null'
              description: >-
                The issuer challenge form to render, when `status` is
                `challenge`.
            challenge_url:
              type:
                - string
                - 'null'
              description: The issuer challenge URL, when `status` is `challenge`.
          required:
            - id
            - status
            - created
            - payment_method
            - challenge_form
            - challenge_url
        meta:
          $ref: '#/components/schemas/ResponseMeta'
      required:
        - status
        - data
        - meta
    ErrorEnvelope:
      type: object
      description: Standard error envelope.
      properties:
        status:
          type: integer
          description: HTTP status code (mirrors the response status line).
        error:
          type: object
          properties:
            message:
              type: string
              description: Human-readable error message.
            details:
              type: object
              additionalProperties: true
          required:
            - message
            - details
        meta:
          $ref: '#/components/schemas/ResponseMeta'
      required:
        - status
        - error
        - meta
    PaymentMethod:
      type: object
      description: >-
        A saved payment method with masked card details and the existing payment
        API identity fields.
      additionalProperties: false
      properties:
        id:
          type: string
          format: uuid
          description: The payment method's identifier.
        kind:
          type: string
          description: >-
            A card, a digital wallet (Apple Pay, Google Pay, PayPal), or another
            saved method.
          enum:
            - card
            - wallet
            - other
        brand:
          type:
            - string
            - 'null'
          description: The card network, lowercase; null for a method that is not a card.
          example: visa
        last4:
          type:
            - string
            - 'null'
          description: The last four digits of the card.
          example: '4242'
        expires:
          description: The card's expiry month and year, or null when not known.
          oneOf:
            - type: object
              additionalProperties: false
              properties:
                month:
                  type: integer
                  minimum: 1
                  maximum: 12
                  example: 3
                year:
                  type: integer
                  description: The four-digit calendar year.
                  example: 2031
              required:
                - month
                - year
            - type: 'null'
        card_holder:
          description: The cardholder name returned by the existing payment API.
          type:
            - string
            - 'null'
          example: Casey Brooks
        default:
          type: boolean
          description: Whether this is the member's default payment method.
        billing_address:
          description: >-
            The billing address returned by the existing payment API, including
            its shared-card fallback for non-isolated companies.
          oneOf:
            - $ref: '#/components/schemas/PaymentMethodBillingAddress'
            - type: 'null'
        created_at:
          type:
            - string
            - 'null'
          format: date-time
      required:
        - id
        - kind
        - brand
        - last4
        - expires
        - card_holder
        - default
        - billing_address
        - created_at
    ResponseMeta:
      type: object
      description: Envelope metadata present on every response.
      properties:
        request_uuid:
          type: string
          format: uuid
          description: Server-generated UUIDv7 uniquely identifying this response.
        timestamp:
          type: string
          format: date-time
          description: ISO 8601 timestamp at which the server produced the response.
      required:
        - request_uuid
        - timestamp
      additionalProperties: true
    PaymentMethodBillingAddress:
      type: object
      description: The billing address stored with this payment method.
      additionalProperties: false
      properties:
        name:
          type:
            - string
            - 'null'
          example: Casey Brooks
        address1:
          type:
            - string
            - 'null'
          example: 742 Evergreen Terrace
        address2:
          type:
            - string
            - 'null'
        city:
          type:
            - string
            - 'null'
          example: Springfield
        state:
          type:
            - string
            - 'null'
          example: IL
        postal_code:
          type:
            - string
            - 'null'
          example: '62704'
        country_code:
          type:
            - string
            - 'null'
          example: US
      required:
        - name
        - address1
        - address2
        - city
        - state
        - postal_code
        - country_code
  headers:
    CacheControl:
      description: >-
        Standard HTTP Cache-Control directive. Always private for this surface.
        The plan routes send max-age=0, so a client revalidates every read with
        the ETag.
      schema:
        type: string
        example: max-age=0, private
  securitySchemes:
    MemberBearer:
      type: http
      scheme: bearer
      description: |
        A member credential in the `Authorization: Bearer` header: a member
        session JWT, a portal JWT whose login is linked to a membership in
        that company, or an opaque member token. The credential alone
        identifies the member and company.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.