> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> To sign a new merchant up for Fluid programmatically, call POST https://api.fluid.app/api/company with no credentials, as described in /api/agent-signup. Do not automate the signup form or book a demo. The merchant must open the emailed sign-in link and create an API token before authenticated calls are possible.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. /api/company/v1 and /api/v1/... paths are documented in no spec here and must never be used (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> Navigation menu management is documented in themes/navigation-menus. These unversioned admin endpoints (/api/menus and nested menu_items) are verified against the implementation but are not yet in the synced OpenAPI specs. Use that reference for menu payloads and its flat page/per_page pagination; missing spec coverage does not make these endpoints unavailable.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.

# Create or update a merchant Avalara account slot

> Upserts the credential slot named by environment. Omitted fields keep their stored values; an obfuscated password is ignored. The first slot a company stores activates itself; a later slot stays inactive unless active is true.



## OpenAPI

````yaml /api-reference/settings-v0.yaml put /api/settings/avalara_account
openapi: 3.1.0
info:
  title: Fluid Settings API
  version: v0
  contact:
    email: support@fluid.app
  license:
    name: Proprietary
    identifier: LicenseRef-Proprietary
servers:
  - url: https://api.fluid.app
security: []
paths:
  /api/settings/avalara_account:
    put:
      tags:
        - taxes
      summary: Create or update a merchant Avalara account slot
      description: >-
        Upserts the credential slot named by environment. Omitted fields keep
        their stored values; an obfuscated password is ignored. The first slot a
        company stores activates itself; a later slot stays inactive unless
        active is true.
      operationId: settings_v0_update_avalara_account
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateAvalaraAccountRequest'
            example:
              avalara_account:
                environment: production
                username: accounting@dundermifflin.com
                password: Scr4nton-Paper-2026
                company_code: DUNDERMIFFLIN
                active: true
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AvalaraAccountResponse'
              example:
                avalara_account:
                  environment: production
                  username: '********'
                  password: '********'
                  company_code: DUNDERMIFFLIN
                  active: true
                status: 200
                meta:
                  request_id: c4f1b9e2-7a3d-4e8b-9f21-5d6a0b3e8c47
                  timestamp: '2026-09-14T15:32:08Z'
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardUnauthorizedResponse'
        '403':
          description: Missing companies.update permission
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardErrorResponse'
        '422':
          description: >-
            Invalid Avalara credentials, active set to false, or an
            active-environment switch while Avalara document commits are enabled
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/StandardErrorResponse'
      security:
        - bearer_auth: []
components:
  schemas:
    UpdateAvalaraAccountRequest:
      type: object
      required:
        - avalara_account
      properties:
        avalara_account:
          type: object
          description: >-
            The slot named by environment is created or updated; omitted fields
            keep their stored values.
          required:
            - environment
          properties:
            environment:
              type: string
              description: >-
                The credential slot to create or update. A slot's environment
                never changes; the active environment switches only via the
                active flag.
              enum:
                - sandbox
                - production
            username:
              type: string
              minLength: 1
              description: >-
                Avalara account username. Required when the slot is being
                created; the obfuscation marker is a masked echo and keeps the
                stored username.
            password:
              type: string
              minLength: 1
              description: >-
                Avalara account password. Required when the slot is being
                created; the obfuscation marker is ignored.
            company_code:
              type:
                - string
                - 'null'
              description: AvaTax companyCode; null clears it.
            active:
              type: boolean
              description: >-
                true makes this slot the active environment and deactivates the
                other; the switch is allowed while "avalara" is the selected tax
                class, because moving from the sandbox host to the production
                host is how a proven integration goes live, but is refused while
                any country has Avalara document commits enabled, since
                committed documents can only be voided on the host that filed
                them. Selecting avalara requires some slot to be active, either
                environment. false is refused, because a company with slots
                always has exactly one active slot; deactivate a slot by
                activating the other environment.
          additionalProperties: false
      additionalProperties: false
    AvalaraAccountResponse:
      type: object
      required:
        - avalara_account
        - status
        - meta
      properties:
        avalara_account:
          $ref: '#/components/schemas/AvalaraAccountSlot'
        status:
          type: integer
          enum:
            - 200
        meta:
          $ref: '#/components/schemas/Meta'
      additionalProperties: false
    StandardUnauthorizedResponse:
      description: Common legacy unauthorized response envelope.
      allOf:
        - $ref: '#/components/schemas/StandardErrorResponse'
    StandardErrorResponse:
      description: >-
        Common legacy error response envelope. Older endpoints may return one or
        more of these fields depending on the controller path.
      type: object
      properties:
        message:
          type: string
        error:
          $ref: '#/components/schemas/ErrorMessage'
        error_message:
          $ref: '#/components/schemas/ErrorMessage'
        errors:
          $ref: '#/components/schemas/ErrorBag'
        meta:
          $ref: '#/components/schemas/Meta'
      additionalProperties:
        $ref: '#/components/schemas/JsonValue'
    AvalaraAccountSlot:
      type: object
      description: >-
        One stored Avalara credential slot. The environment is the slot key;
        while any slots exist, exactly one is active and live tax calculation
        authenticates with it.
      required:
        - environment
        - username
        - password
        - company_code
        - active
      properties:
        environment:
          type: string
          description: >-
            Which AvaTax host the credentials authenticate against. Also the
            slot key; a company stores at most one slot per environment.
          enum:
            - sandbox
            - production
        username:
          type: string
          description: >-
            Always the obfuscation marker, never the stored username; identify a
            slot by its environment and company_code.
          enum:
            - '********'
          example: '********'
        password:
          type: string
          description: Always the obfuscation marker, never the stored password.
          enum:
            - '********'
        company_code:
          type:
            - string
            - 'null'
          description: >-
            AvaTax companyCode targeting one company on a multi-company Avalara
            account.
        active:
          type: boolean
          description: >-
            Whether this slot is the active environment. A company with slots
            always has exactly one active slot.
      additionalProperties: false
    Meta:
      type: object
      properties:
        request_id:
          type:
            - string
            - 'null'
        timestamp:
          type: string
          format: date-time
    ErrorMessage:
      description: An API error message represented as text or structured JSON.
      anyOf:
        - type: string
        - $ref: '#/components/schemas/ErrorBag'
        - type: 'null'
    ErrorBag:
      description: >-
        Validation errors keyed by field, a list of errors, a single error
        message, or null when no structured error details are available.
      anyOf:
        - type: string
        - type: array
          items:
            $ref: '#/components/schemas/ErrorValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/ErrorValue'
        - type: 'null'
    JsonValue:
      description: >-
        Any valid JSON value for provider, integration, theme, metadata, or
        other dynamic payloads whose keys are not fixed by the API contract.
      anyOf:
        - type: string
        - type: number
        - type: boolean
        - type: 'null'
        - type: array
          items:
            $ref: '#/components/schemas/JsonValue'
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
    ErrorValue:
      description: A validation or API error value.
      anyOf:
        - type: string
        - type: array
          items:
            type: string
        - type: object
          additionalProperties:
            $ref: '#/components/schemas/JsonValue'
  securitySchemes:
    bearer_auth:
      type: http
      scheme: bearer
      description: Bearer token authentication

````