> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> To sign a new merchant up for Fluid programmatically, call POST https://api.fluid.app/api/company with no credentials, as described in /api/agent-signup. Do not automate the signup form or book a demo. The merchant must open the emailed sign-in link and create an API token before authenticated calls are possible.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. /api/company/v1 and /api/v1/... paths are documented in no spec here and must never be used (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> Navigation menu management is documented in themes/navigation-menus. These unversioned admin endpoints (/api/menus and nested menu_items) are verified against the implementation but are not yet in the synced OpenAPI specs. Use that reference for menu payloads and its flat page/per_page pagination; missing spec coverage does not make these endpoints unavailable.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.

# Narrow or widen what an installation may read

> Changes the grant without moving the version. The list is a full replacement rather than an addition, so omitting it is refused instead of read as an empty one. Narrowing bumps the grant epoch exactly as widening does, because that is what retires cached descriptors.



## OpenAPI

````yaml /api-reference/theme-surfaces-v0.yaml patch /api/company/widget_installations/{id}
openapi: 3.1.0
info:
  title: Fluid Theme Surfaces API
  version: v0
  description: >-
    The admin seam over a theme's release lifecycle. A release freezes the
    theme's currently-resolved bindings into an immutable artifact; activating
    one is what the storefront and the member account zone then serve, and
    rolling back moves that pointer rather than re-rendering anything.


    Every operation resolves the theme from the authenticated company. No
    operation accepts a theme id, so a release cannot be published onto, or
    activated for, another merchant's theme by supplying one.
  contact:
    email: support@fluid.app
  license:
    name: Proprietary
    identifier: LicenseRef-Proprietary
servers:
  - url: https://api.fluid.app
security:
  - bearer_auth: []
tags:
  - name: theme-surfaces
    description: Routable slots and the templates bound into them
  - name: theme-audiences
    description: Who sees which structure
  - name: theme-releases
    description: Publish, activate and roll back a theme's releases
  - name: members-sites
    description: >-
      The storefront Members scope's sites: an access rule and the page set it
      governs, as a builder edits them
  - name: members-pages
    description: The pages inside a member site, as a builder edits them
paths:
  /api/company/widget_installations/{id}:
    parameters:
      - name: id
        in: path
        required: true
        description: >-
          The installation, which is always read within the authenticated
          company.
        schema:
          type: integer
    patch:
      tags:
        - widget-installations
      summary: Narrow or widen what an installation may read
      description: >-
        Changes the grant without moving the version. The list is a full
        replacement rather than an addition, so omitting it is refused instead
        of read as an empty one. Narrowing bumps the grant epoch exactly as
        widening does, because that is what retires cached descriptors.
      operationId: theme_surfaces_v0_modify_widget_installation
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/WidgetInstallationUpdateRequest'
            example:
              granted_capabilities:
                - orders@1
      responses:
        '200':
          description: The installation and the company's new grant epoch
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/WidgetInstallationEnvelope'
              example:
                widget_installation:
                  id: 2318
                  state: active
                  package_key: company.account-essentials
                  owner_kind: company
                  version: 1.2.0
                  widget_package_version_id: 9147
                  granted:
                    - orders@1
                  created_at: '2026-09-03T15:12:44Z'
                  updated_at: '2026-09-29T08:14:03Z'
                grant_epoch: 16
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '422':
          $ref: '#/components/responses/Unprocessable'
components:
  schemas:
    WidgetInstallationUpdateRequest:
      type: object
      description: Changes the grant without moving the version.
      additionalProperties: false
      required:
        - granted_capabilities
      properties:
        granted_capabilities:
          type: array
          description: >-
            A full replacement rather than an addition, so an omitted or
            malformed list is refused rather than read as an empty one.
          items:
            type: string
    WidgetInstallationEnvelope:
      type: object
      additionalProperties: false
      required:
        - widget_installation
        - grant_epoch
      properties:
        widget_installation:
          $ref: '#/components/schemas/WidgetInstallation'
        grant_epoch:
          type: integer
          description: >-
            The company's grant epoch after this write. Descriptors are cached
            by (version, company, epoch), so a bumped epoch is what retires
            every cached descriptor at once.
    WidgetInstallation:
      type: object
      description: >-
        A company's adoption of a published widget package version. `granted` is
        the merchant's decision and is stored apart from the manifest's own
        declaration, so narrowing a grant never edits an artifact: the effective
        set is the intersection, computed per request, which is why a revocation
        takes effect on the next call rather than at the next publish.
      additionalProperties: false
      required:
        - id
        - state
        - package_key
        - owner_kind
        - version
        - widget_package_version_id
        - granted
        - created_at
        - updated_at
      properties:
        id:
          type: integer
        state:
          type: string
          description: >-
            A disabled installation is not deleted, so the grant survives a
            pause and does not have to be re-entered on resume.
          enum:
            - active
            - disabled
        package_key:
          type: string
          examples:
            - company.account-essentials
        owner_kind:
          type: string
          enum:
            - company
            - droplet
        version:
          type: string
          examples:
            - 1.0.0
        widget_package_version_id:
          type: integer
        granted:
          type: array
          description: >-
            The capabilities the merchant granted, as fused name@version
            strings.
          items:
            type: string
          examples:
            - - orders@1
              - rewards@1
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
    AuthError:
      type: object
      description: >-
        The shared API authentication and authorization refusal, which carries a
        message and no machine-readable code. Described as the framework
        actually answers rather than as this API would have chosen, because
        neither status is produced by this controller.
      additionalProperties: true
      required:
        - message
      properties:
        message:
          type: string
    Error:
      type: object
      additionalProperties: false
      required:
        - error
        - message
      properties:
        error:
          type: string
        message:
          type: string
        details:
          type: object
          additionalProperties: true
  responses:
    Unauthorized:
      description: No or invalid credentials
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/AuthError'
    Forbidden:
      description: Authenticated, but not permitted to manage themes
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/AuthError'
    NotFound:
      description: The company has no active theme, or no such release
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Unprocessable:
      description: The request was understood and refused
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearer_auth:
      type: http
      scheme: bearer
      description: Bearer token authentication

````