> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> Never use /api/company/v1 or /api/v1 paths, page/per_page params, or offset pagination — they are legacy.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/auth-v0.yaml covers the unversioned auth surface (/api/... paths — authentication, MFA, social auth, and token exchange); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.

# Get current user via SSO

> Decode a JWT and return user and user-company profile information through the SSO flow.



## OpenAPI

````yaml /api-reference/auth-v0.yaml get /api/single_sign_ons/me
openapi: 3.1.0
info:
  title: Fluid Auth API
  version: v0
  description: >-
    Authentication, MFA, social auth, impersonation, and token exchange
    endpoints.
  contact:
    email: support@fluid.app
  license:
    name: Proprietary
    identifier: LicenseRef-Proprietary
servers:
  - url: https://api.fluid.app
  - url: https://{company}.fluid.app
    description: Production server with company subdomain
    variables:
      company:
        default: myco
        description: Company subdomain
security: []
tags:
  - name: auth-token
    description: Short-lived auth-token minting for the current user company.
  - name: authentication
    description: >-
      Email MFA login, company switching, JWT-based "me" lookups, and public
      company branding.
  - name: confirm-visitor
    description: Visitor token confirmation.
  - name: impersonation
    description: Root-admin company impersonation (start and exit).
  - name: multi-factor-authentications
    description: MFA record creation and verification-code checks.
  - name: single-sign-ons
    description: SSO-flow aliases of the authentication MFA and lookup endpoints.
  - name: social-auth
    description: >-
      Google, Facebook, and Apple OAuth URLs, callback handling, and Apple
      account linking.
  - name: switch-role
    description: Switch the current admin user between admin and rep roles.
  - name: token-exchange
    description: Exchange and refresh JWTs and user-company tokens.
paths:
  /api/single_sign_ons/me:
    get:
      tags:
        - single-sign-ons
      summary: Get current user via SSO
      description: >-
        Decode a JWT and return user and user-company profile information
        through the SSO flow.
      operationId: auth_v0_sso_me
      parameters:
        - name: jwt
          in: query
          required: true
          description: >
            JWT to decode and look up (the SSO-flow alias of `GET
            /api/authentication/me`).

            Returns `422` when omitted and `404` when it does not resolve to a
            user

            company.
          schema:
            type: string
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
                additionalProperties: false
                required:
                  - user
                  - user_company
                properties:
                  user:
                    $ref: '#/components/schemas/UserProfile'
                  user_company:
                    $ref: '#/components/schemas/UserCompanyProfile'
                  meta:
                    $ref: '#/components/schemas/Meta'
        '404':
          description: >-
            The JWT does not resolve to a user company (unknown or rejected
            token).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '422':
          description: Missing JWT parameter
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security: []
components:
  schemas:
    UserProfile:
      description: Authenticated user profile
      type: object
      additionalProperties: false
      required:
        - id
        - first_name
        - last_name
        - email
        - avatar_url
        - root_admin
      properties:
        id:
          description: >-
            Numeric identifier of the user the supplied JWT resolved to; `null`
            when it cannot be resolved.
          type:
            - integer
            - 'null'
        first_name:
          description: User's given name, or `null` when not set.
          type:
            - string
            - 'null'
        last_name:
          description: User's family name, or `null` when not set.
          type:
            - string
            - 'null'
        email:
          description: User's email address, or `null` when not set.
          type:
            - string
            - 'null'
        avatar_url:
          description: URL of the user's avatar image, or `null` when none is set.
          type:
            - string
            - 'null'
        root_admin:
          description: >-
            `true` when the user is a Fluid root admin (able to impersonate
            companies); `null` when unknown.
          type:
            - boolean
            - 'null'
    UserCompanyProfile:
      description: User-company relationship details
      type: object
      additionalProperties: false
      required:
        - id
        - company_id
        - company_name
        - roles
        - user_type
        - logo_url
        - icon_url
        - fluid_shop
        - company_colors
      properties:
        id:
          description: >-
            Identifier of the user-company membership record (the join between
            the user and the company), not the user or company id.
          type: integer
        company_id:
          description: Numeric identifier of the company this membership belongs to.
          type: integer
        company_name:
          description: Display name of the company.
          type: string
        roles:
          description: >-
            Roles the user holds within this company (e.g. `admin`, `rep`),
            which govern what the JWT can do.
          type: array
          items:
            type: string
        user_type:
          description: >-
            Kind of principal this membership represents within the company
            (e.g. `user`, `customer`).
          type: string
        logo_url:
          description: URL of the company logo, or `null` when none is set.
          type:
            - string
            - 'null'
        icon_url:
          description: >-
            URL of the company's square icon/favicon, or `null` when none is
            set.
          type:
            - string
            - 'null'
        fluid_shop:
          description: Fluid shop identifier for the company (its `*.fluid.app` shop name).
          type: string
        company_colors:
          description: Company brand colors used to theme login and portal surfaces.
          type: object
          required:
            - primary_color
            - secondary_color
          properties:
            primary_color:
              description: >-
                Primary brand color as a "#"-prefixed hex string, or `null` when
                unset.
              type:
                - string
                - 'null'
            secondary_color:
              description: >-
                Secondary brand color as a "#"-prefixed hex string, or `null`
                when unset.
              type:
                - string
                - 'null'
    Meta:
      type: object
      properties:
        request_id:
          description: >
            Opaque per-request identifier echoed on the response; `null` when
            the

            request was not assigned one. Quote it when reporting an issue so
            support

            can correlate server-side logs.
          type:
            - string
            - 'null'
        timestamp:
          description: Server time the response was generated, as an ISO 8601 date-time.
          type: string
          format: date-time
    ErrorResponse:
      type: object
      additionalProperties: false
      required:
        - error_message
        - errors
        - meta
      properties:
        error_message:
          description: >-
            Human-readable summary of what went wrong, safe to surface to the
            caller.
          type: string
        errors:
          $ref: '#/components/schemas/ErrorBag'
          description: >-
            Structured per-field or per-issue detail behind `error_message`;
            shape varies (see `ErrorBag`) and is `null` when no structured
            detail is available.
        meta:
          $ref: '#/components/schemas/Meta'
          description: Response metadata (request id and generation timestamp).
    ErrorBag:
      description: >-
        Validation errors keyed by field, a list of errors, a single error
        message, or null when no structured error details are available.
      anyOf:
        - type: string
        - type: array
          items:
            $ref: '#/components/schemas/ErrorValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/ErrorValue'
        - type: 'null'
    ErrorValue:
      description: A validation or API error value.
      anyOf:
        - type: string
        - type: array
          items:
            type: string
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
    JsonValue:
      description: >-
        Any valid JSON value for provider, integration, theme, metadata, or
        other dynamic payloads whose keys are not fixed by the API contract.
      anyOf:
        - type: string
        - type: number
        - type: boolean
        - type: 'null'
        - type: array
          items:
            $ref: '#/components/schemas/JsonValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'

````