Skip to main content
An AI agent or script can sign a merchant up for Fluid without the signup form. POST /api/company creates a company and its first admin user in one request, and it takes no credentials — the merchant has no token yet. This is the supported programmatic path. Use it instead of automating the signup form or booking a demo.
The request, response, and error schemas are on the generated reference page: Create a company. This guide covers the flow around that call.

Before you start

If you are an agent acting for a person, check these with them first:
  • Get their consent. The request sends their name and email address to Fluid and creates a real company. Ask before you send it.
  • Use a mailbox they control. Fluid emails the sign-in link to the address you send. Someone with access to that mailbox has to open it.
  • Don’t accept agreements for them. This endpoint accepts none. Later steps that need agreement are the merchant’s to complete.
You can do everything up to the sign-in email, and everything after the merchant creates an API token. The sign-in itself needs the person.

Finding this flow

Fluid publishes machine-readable pointers to this endpoint: Request these on fluid.app or docs.fluid.app. The API host, api.fluid.app, does not serve them.

Sign a merchant up

1

Choose a subdomain

The subdomain becomes the store’s address: <subdomain>.fluid.app. Subdomains are unique across Fluid.Send a value that is already clean: lowercase letters, digits, and hyphens, no leading or trailing hyphen, and at most 63 characters. Fluid normalizes the value you send rather than rejecting it, and a value that only becomes a duplicate after normalization fails in a way that doesn’t name the subdomain. Sending the clean form avoids both problems.
2

Create the company

Send the admin user and the company in one request to https://api.fluid.app/api/company, with no Authorization header:
user.first_name, user.last_name, user.email, company.name, and company.subdomain are required. company.color (a 3- or 6-digit hex brand colour) and company.onboarding_info are optional.Send only the fields documented on the reference page. The signup form sends extra fields for its own browser checks; an API caller should not.onboarding_info stores the merchant’s onboarding answers. The admin signup form sends usage_type (business or employee) and website_setup (fluid-theme, import, current-site, or unsure). A new business with nothing to import sends website_setup: "unsure". If you have no answers, leave onboarding_info out — an empty object is rejected.
3

Keep the company details from the response

A successful request returns 200:
Store company.id and company.fluid_shop. Read company.subdomain from the response rather than reusing what you sent — it is the value that went live.
4

The merchant signs in

Fluid emails a sign-in link to user.email. Fluid accounts have no password.Which email arrives depends on whether the address already belongs to a Fluid user. A new address gets a signup confirmation. An address already in use for another company can also get an admin invitation for the new company. Either link signs the merchant in. The response is the same 200 in every case, so don’t promise the merchant a specific email.If no email arrives, the merchant can sign in at https://admin.fluid.app with the same address.
5

The merchant creates an API token

Once signed in, the merchant opens Settings → API Tokens at https://admin.fluid.app/settings/tokens and creates a token. See Authentication for token types and scopes.
6

Make authenticated calls

Send the token as a Bearer token to https://api.fluid.app:
Every authenticated call acts on the company the token belongs to.

Handle errors

A 422 takes one of these forms:
  • errors names the field (for example errors.user.email or errors.company.subdomain). A required field is missing or malformed, or the subdomain is already taken. Fix that field and retry. A taken subdomain is the most common failure: pick another.
  • errors.company.base. Setup failed for another reason, such as an invalid colour or a subdomain that collides after normalization. The message text is not stable, so don’t parse it.
  • errors.base. The request was rejected by a check that applies to browser signups. Remove any fields that are not documented on the reference page.
A 422 can arrive after the company was created, when a late setup step fails. Before retrying with a new subdomain, retry once with the same one. If that returns errors.company.subdomain with is taken, the first request created the company. Don’t create another.

Next steps