> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> To sign a new merchant up for Fluid programmatically, call POST https://api.fluid.app/api/company with no credentials, as described in /api/agent-signup. Do not automate the signup form or book a demo. The merchant must open the emailed sign-in link and create an API token before authenticated calls are possible.
> After signup, to launch a merchant's store (back-office sync, payments onboarding, store setup, a theme copied from their current site, and a preview link before billing), follow /api/agent-launch.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. The same applies to /api/company/v1 and /api/v1/... paths: prefer a newer documented equivalent, and use one only when none exists (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> Navigation menu management is documented in themes/navigation-menus. These unversioned admin endpoints (/api/menus and nested menu_items) are verified against the implementation but are not yet in the synced OpenAPI specs. Use that reference for menu payloads and its flat page/per_page pagination; missing spec coverage does not make these endpoints unavailable.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.
> The Help Center (/help/...) is for merchants, admins and reps using Fluid. Its admin pages mirror the admin's routes: the screen at admin.fluid.app/settings/taxes is documented at /help/admin/settings/taxes. Use the Help Center for how-to questions about the admin, and the Developer Platform and API Reference for building integrations.
> Help Center pages describe what a company admin sees. A reader's role can hide screens and actions; admins manage roles on Settings > Roles (/help/admin/settings/roles). If someone can't find a screen or button, their role's permissions are the first thing to check.
> Send people who need Fluid support to /help/getting-help. Don't invent support email addresses, phone numbers or response times.

# Get the checkout contract for a country

> Public endpoint. Returns everything checkout needs to sell into one country for the store in one cacheable response - the address layout, agreements, payment method order, legal and tax settings, 3DS, customs, ship-from and currency. The company comes from `cart_token`, else the signed-in caller. With a cart that ships to this country, the agreements and currency are the cart's own. The `ETag` equals `contract_digest`. The response is `max-age=0, private, must-revalidate`, because the same `cart_token` URL changes body as the cart changes, so a browser revalidates with the `ETag` before every use and hands the caller the 200 it holds when nothing changed. A browser caller does not send `If-None-Match` itself. An HTTP client that does gets a bodyless 304.



## OpenAPI

````yaml /api-reference/checkout-v2026-04.yaml get /api/checkout/v2026-04/store/contract/{country_code}
openapi: 3.1.0
info:
  title: Fluid Checkout API
  description: >-
    **Fluid Checkout API — for building a checkout directly against REST.**


    Use this surface if you are integrating server-to-server or building your
    own

    checkout UI. It covers the full order lifecycle (cart → address → shipping →

    discount → complete → order) plus the logged-in customer's account: saved

    addresses, saved payment methods, order history, loyalty points, and

    subscription management (pause, resume, skip, cancel, retry).


    **The cart token in the URL scopes cart access** — creating a cart, adding

    items, applying a discount, and completing a cart need no bearer token.

    Among the cart operations, a Bearer token is required for

    `carts/{cart_token}/sync`, `carts/{cart_token}/volume_rep`, and

    `carts/{cart_token}/discount/manual`. It is also required conditionally when

    `PATCH carts/{cart_token}` selects an enrollment target with

    `member_type_id`; profile-only PATCH requests remain public. Off the cart, a

    token is required for everything under `customers/me` and `subscriptions`,

    and for the store and directory lookups (`store/config`, `store/languages`,

    `reps`, `users`) and `subscription_bundles`. `store/countries` accepts a

    token but does not require one — it returns the same list either way.


    **If you are using the `@fluid-app` FairShare SDK in a theme or storefront,

    you are not calling this surface** — the SDK calls the Fluid Public SDK API

    (`public-v2025-06`). Do not mix the two against one cart: they share the
    same

    cart records and services, but their request shapes differ. See

    [Choosing a cart
    surface](https://docs.fluid.app/api/choosing-a-cart-surface)

    for the operation map and boundary.
  version: v2026-04
  contact:
    email: support@fluid.app
  license:
    name: Proprietary
    identifier: LicenseRef-Proprietary
servers:
  - url: https://api.fluid.app
security: []
tags:
  - name: carts
    description: >-
      Create, read, and mutate checkout carts (email, address, country,
      language, shipping, recalculation, completion).
  - name: cart-auth
    description: >-
      Cart-scoped customer authentication — magic-link challenge, verification,
      identity, and logout.
  - name: cart-discount
    description: >-
      Apply, list, and remove cart discount codes, including admin manual
      discounts.
  - name: cart-items
    description: Add, update, and remove line items on a cart.
  - name: cart-points
    description: Apply and remove loyalty points on a cart.
  - name: customers
    description: The authenticated customer's profile and company memberships.
  - name: customer-addresses
    description: The authenticated customer's saved shipping/billing addresses.
  - name: customer-orders
    description: The authenticated customer's order history.
  - name: customer-payment-methods
    description: The authenticated customer's saved payment methods and tokenization.
  - name: customer-points
    description: The authenticated customer's loyalty point balances.
  - name: directory
    description: Company rep and user directory lookups.
  - name: enrollments
    description: >-
      Public enrollment forms — retrieve a form and submit, update, or upload
      field answers.
  - name: orders
    description: Public order lookup by token.
  - name: products
    description: Public product queries for the storefront checkout.
  - name: store
    description: >-
      Store-level checkout configuration — countries, languages, address fields,
      agreements, drop zones, and Apple Pay domain verification.
    x-fluid-section: Checkout
  - name: subscriptions
    description: >-
      Manage subscriptions — pause, resume, skip, cancel, reactivate, retry, and
      failed-cycle waivers.
  - name: subscription-bundles
    description: List and create subscription bundles.
paths:
  /api/checkout/v2026-04/store/contract/{country_code}:
    get:
      tags:
        - store
      summary: Get the checkout contract for a country
      description: >-
        Public endpoint. Returns everything checkout needs to sell into one
        country for the store in one cacheable response - the address layout,
        agreements, payment method order, legal and tax settings, 3DS, customs,
        ship-from and currency. The company comes from `cart_token`, else the
        signed-in caller. With a cart that ships to this country, the agreements
        and currency are the cart's own. The `ETag` equals `contract_digest`.
        The response is `max-age=0, private, must-revalidate`, because the same
        `cart_token` URL changes body as the cart changes, so a browser
        revalidates with the `ETag` before every use and hands the caller the
        200 it holds when nothing changed. A browser caller does not send
        `If-None-Match` itself. An HTTP client that does gets a bodyless 304.
      operationId: checkout_v2026_04_get_store_contract
      parameters:
        - name: country_code
          in: path
          required: true
          description: ISO country code, any case
          example: US
          schema:
            type: string
        - name: cart_token
          in: query
          required: false
          description: The cart whose company the contract is for.
          schema:
            type: string
        - name: language_iso
          in: query
          required: false
          description: >-
            Language for labels and names. Defaults to the cart's language, then
            English.
          schema:
            type: string
      responses:
        '200':
          description: Success
          headers:
            ETag:
              description: The contract digest, quoted.
              schema:
                type: string
            Cache-Control:
              description: '`max-age=0, private, must-revalidate`'
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CheckoutStoreContractResponse'
              example:
                contract:
                  country:
                    iso: US
                    name: United States
                  currency_code: USD
                  requires_3ds: false
                  checkout_requires_terms: true
                  address_fields:
                    - field: first_name
                      label: First name
                      required: true
                      local_label: null
                      placeholder: null
                      visible: true
                      column_width: full
                      order: 1
                    - field: address1
                      label: Address
                      required: true
                      local_label: null
                      placeholder: null
                      visible: true
                      column_width: full
                      order: 2
                    - field: postal_code
                      label: Zip code
                      required: true
                      local_label: null
                      placeholder: null
                      visible: true
                      column_width: half
                      order: 3
                  agreements:
                    - id: 162906953
                      default_checked: false
                      enrollment_pack_id: null
                      required: true
                      show_at_checkout: true
                      show_path: /api/agreements/162906953
                      standalone_on_checkout: false
                      subscription_only: false
                      title: Terms of Sale - United States
                    - id: 320402186
                      default_checked: false
                      enrollment_pack_id: null
                      required: false
                      show_at_checkout: false
                      show_path: /api/agreements/320402186
                      standalone_on_checkout: false
                      subscription_only: false
                      title: Privacy Policy
                  payment_method_priority:
                    - CreditCard
                    - Paypal
                  legal_settings:
                    cooling_off_period_days: null
                    warranty_period_months: null
                    cookie_consent_required: null
                    recurring_subscription_disclosure_required: true
                    order_button_label: null
                    marketing_consent_mode: null
                  tax:
                    tax_name: Sales tax
                    tax_inclusive_pricing: false
                  customs: null
                  ship_from_country_code: US
                  language_iso: en
                  contract_digest: >-
                    81015d2205eb13ad392cb4fb9b83c4f7e372bd4ea2d3007d2799583c2d21a8c9
                meta:
                  request_id: aacf44e1-4dde-4feb-807a-d80a28b50392
                  timestamp: '2026-10-02T12:11:29Z'
        '304':
          description: >-
            The request's `If-None-Match` matches the contract; no body. A
            browser answers its caller with the cached 200 instead.
          headers:
            ETag:
              description: The contract digest, quoted.
              schema:
                type: string
        '401':
          description: Neither a cart token nor a signed-in caller.
        '403':
          description: >-
            A public token (pub-) with an Origin the token's domain_allowlist
            does not permit, for a company enforcing that allowlist.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardForbiddenResponse'
        '404':
          description: >-
            The cart token matches no cart, the signed-in caller has no company,
            or the store does not sell to the country.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '422':
          description: >-
            A query parameter has the wrong shape (for example
            `language_iso[]=en`).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - bearer_auth: []
        - {}
components:
  schemas:
    CheckoutStoreContractResponse:
      type: object
      properties:
        contract:
          $ref: '#/components/schemas/CheckoutStoreContract'
        meta:
          $ref: '#/components/schemas/CheckoutMeta'
      required:
        - contract
        - meta
      additionalProperties: false
    StandardForbiddenResponse:
      description: Common legacy forbidden response envelope.
      allOf:
        - $ref: '#/components/schemas/StandardErrorResponse'
    ErrorResponse:
      type: object
      additionalProperties: false
      required:
        - error_message
        - errors
        - meta
      properties:
        error_message:
          type: string
        errors:
          $ref: '#/components/schemas/ErrorBag'
        meta:
          $ref: '#/components/schemas/CheckoutMeta'
    CheckoutStoreContract:
      description: >-
        Commerce::Checkout::StoreContract#to_h. Every key is present whether or
        not the company country sets its own contract fields.
      type: object
      additionalProperties: false
      required:
        - country
        - currency_code
        - requires_3ds
        - checkout_requires_terms
        - address_fields
        - agreements
        - payment_method_priority
        - legal_settings
        - tax
        - customs
        - ship_from_country_code
        - language_iso
        - contract_digest
      properties:
        country:
          type: object
          additionalProperties: false
          required:
            - iso
            - name
          properties:
            iso:
              type: string
            name:
              type: string
              description: The country's name in `language_iso`.
        currency_code:
          type: string
          description: >-
            The cart's charge currency when a cart that ships here was given,
            else the country's display currency.
        requires_3ds:
          type: boolean
        checkout_requires_terms:
          type: boolean
        address_fields:
          type: array
          description: The fields the store address fields endpoint serves, in order.
          items:
            type: object
            additionalProperties: false
            required:
              - field
              - label
              - required
              - local_label
              - placeholder
              - visible
              - column_width
              - order
            properties:
              field:
                type: string
              label:
                type: string
              required:
                type: boolean
              local_label:
                type:
                  - string
                  - 'null'
              placeholder:
                type:
                  - string
                  - 'null'
              visible:
                type: boolean
              column_width:
                type: string
                enum:
                  - full
                  - half
                  - third
              order:
                type: integer
                minimum: 1
        agreements:
          type: array
          description: >-
            The cart's agreements when a cart that ships here was given, else
            the country's active agreements, serialized as the cart payload
            serializes them.
          items:
            $ref: '#/components/schemas/CheckoutAgreement'
        payment_method_priority:
          type: array
          description: >-
            Integration types in the order checkout ranks them; empty when the
            store sets none.
          items:
            type: string
        legal_settings:
          type: object
          additionalProperties: false
          required:
            - cooling_off_period_days
            - warranty_period_months
            - cookie_consent_required
            - recurring_subscription_disclosure_required
            - order_button_label
            - marketing_consent_mode
          properties:
            cooling_off_period_days:
              type:
                - integer
                - 'null'
              minimum: 0
            warranty_period_months:
              type:
                - integer
                - 'null'
              minimum: 0
            cookie_consent_required:
              type:
                - boolean
                - 'null'
            recurring_subscription_disclosure_required:
              type:
                - boolean
                - 'null'
            order_button_label:
              type:
                - string
                - 'null'
            marketing_consent_mode:
              type:
                - string
                - 'null'
        tax:
          type: object
          additionalProperties: false
          required:
            - tax_name
            - tax_inclusive_pricing
          properties:
            tax_name:
              type:
                - string
                - 'null'
            tax_inclusive_pricing:
              type: boolean
        customs:
          type:
            - string
            - 'null'
          enum:
            - DDP
            - DAP
            - null
        ship_from_country_code:
          type:
            - string
            - 'null'
        language_iso:
          type: string
          description: >-
            The language the contract was rendered in. Compare a cart's
            `contract_digest` only with a contract in the cart's language.
        contract_digest:
          type: string
          description: >-
            SHA-256 of the contract and the context it was resolved in. Equals
            the `ETag`.
    CheckoutMeta:
      type: object
      additionalProperties: false
      required:
        - request_id
        - timestamp
      properties:
        request_id:
          type:
            - string
            - 'null'
        timestamp:
          type: string
          format: date-time
    StandardErrorResponse:
      description: >-
        Common legacy error response envelope. Older endpoints may return one or
        more of these fields depending on the controller path.
      type: object
      properties:
        message:
          type: string
        error:
          $ref: '#/components/schemas/ErrorMessage'
        error_message:
          $ref: '#/components/schemas/ErrorMessage'
        errors:
          $ref: '#/components/schemas/ErrorBag'
        meta:
          $ref: '#/components/schemas/Meta'
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
    ErrorBag:
      description: >-
        Validation errors keyed by field, a list of errors, a single error
        message, or null when no structured error details are available.
      anyOf:
        - type: string
        - type: array
          items:
            $ref: '#/components/schemas/ErrorValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/ErrorValue'
        - type: 'null'
    CheckoutAgreement:
      description: Checkout agreement rendered by AgreementBlueprinter (default view).
      type: object
      additionalProperties: false
      required:
        - id
        - title
        - show_at_checkout
        - default_checked
        - subscription_only
        - standalone_on_checkout
        - show_path
        - enrollment_pack_id
        - required
      properties:
        id:
          type: integer
        title:
          type:
            - string
            - 'null'
        show_at_checkout:
          type: boolean
        default_checked:
          type: boolean
        subscription_only:
          type: boolean
        standalone_on_checkout:
          type: boolean
        show_path:
          type: string
        enrollment_pack_id:
          type:
            - integer
            - 'null'
        required:
          type: boolean
          description: >-
            Whether the agreement must be accepted at checkout (mirrors
            Agreement#required_on_checkout, coerced to a strict boolean).
    ErrorMessage:
      description: An API error message represented as text or structured JSON.
      anyOf:
        - type: string
        - $ref: '#/components/schemas/ErrorBag'
        - type: 'null'
    Meta:
      type: object
      required:
        - request_id
        - timestamp
      properties:
        request_id:
          type:
            - string
            - 'null'
        timestamp:
          type: string
          format: date-time
    JsonValue:
      description: >-
        Any valid JSON value for provider, integration, theme, metadata, or
        other dynamic payloads whose keys are not fixed by the API contract.
      anyOf:
        - type: string
        - type: number
        - type: boolean
        - type: 'null'
        - type: array
          items:
            $ref: '#/components/schemas/JsonValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
    ErrorValue:
      description: A validation or API error value.
      anyOf:
        - type: string
        - type: array
          items:
            type: string
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
  securitySchemes:
    bearer_auth:
      type: http
      scheme: bearer
      description: Bearer token authentication

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.