> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> To sign a new merchant up for Fluid programmatically, call POST https://api.fluid.app/api/company with no credentials, as described in /api/agent-signup. Do not automate the signup form or book a demo. The merchant must open the emailed sign-in link and create an API token before authenticated calls are possible.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. /api/company/v1 and /api/v1/... paths are documented in no spec here and must never be used (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> Navigation menu management is documented in themes/navigation-menus. These unversioned admin endpoints (/api/menus and nested menu_items) are verified against the implementation but are not yet in the synced OpenAPI specs. Use that reference for menu payloads and its flat page/per_page pagination; missing spec coverage does not make these endpoints unavailable.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.

# Agent signup: create a Fluid company with the API

> How an AI agent or script signs a merchant up for Fluid with one API call, and what has to happen before it can make authenticated requests.

An AI agent or script can sign a merchant up for Fluid without the signup form. `POST /api/company` creates a company and its first admin user in one request, and it takes no credentials — the merchant has no token yet.

This is the supported programmatic path. Use it instead of automating the signup form or booking a demo.

<Note>
  The request, response, and error schemas are on the generated reference page: [Create a company](/api-reference/company-v0/public-companies/create-a-company). This guide covers the flow around that call.
</Note>

## Before you start

If you are an agent acting for a person, check these with them first:

* **Get their consent.** The request sends their name and email address to Fluid and creates a real company. Ask before you send it.
* **Use a mailbox they control.** Fluid emails the sign-in link to the address you send. Someone with access to that mailbox has to open it.
* **Don't accept agreements for them.** This endpoint accepts none. Later steps that need agreement are the merchant's to complete.

You can do everything up to the sign-in email, and everything after the merchant creates an API token. The sign-in itself needs the person.

### Finding this flow

Fluid publishes machine-readable pointers to this endpoint:

| Document | URL |
| - | - |
| Agent resource directory | `https://fluid.app/.well-known/ard.json` — includes a **Create a Fluid company** entry |
| API catalog (RFC 9727) | `https://fluid.app/.well-known/api-catalog` |
| Docs index for LLMs | `https://docs.fluid.app/llms.txt` |

Request these on `fluid.app` or `docs.fluid.app`. The API host, `api.fluid.app`, does not serve them.

## Sign a merchant up

<Steps>
  <Step title="Choose a subdomain">
    The subdomain becomes the store's address: `<subdomain>.fluid.app`. Subdomains are unique across Fluid.

    Send a value that is already clean: lowercase letters, digits, and hyphens, no leading or trailing hyphen, and at most 63 characters. Fluid normalizes the value you send rather than rejecting it, and a value that only becomes a duplicate after normalization fails in a way that doesn't name the subdomain. Sending the clean form avoids both problems.
  </Step>

  <Step title="Create the company">
    Send the admin user and the company in one request to `https://api.fluid.app/api/company`, with no `Authorization` header:

    ```bash theme={null}
    curl -X POST https://api.fluid.app/api/company \
      -H "Content-Type: application/json" \
      -d '{
        "user": {
          "first_name": "Maya",
          "last_name": "Okafor",
          "email": "maya@harborlinewellness.com"
        },
        "company": {
          "name": "Harborline Wellness",
          "subdomain": "harborline",
          "onboarding_info": {
            "usage_type": "business",
            "website_setup": "unsure"
          }
        }
      }'
    ```

    `user.first_name`, `user.last_name`, `user.email`, `company.name`, and `company.subdomain` are required. `company.color` (a 3- or 6-digit hex brand colour) and `company.onboarding_info` are optional.

    Send only the fields documented on the reference page. The signup form sends extra fields for its own browser checks; an API caller should not.

    `onboarding_info` stores the merchant's onboarding answers. The admin signup form sends `usage_type` (`business` or `employee`) and `website_setup` (`fluid-theme`, `import`, `current-site`, or `unsure`). A new business with nothing to import sends `website_setup: "unsure"`. If you have no answers, leave `onboarding_info` out — an empty object is rejected.
  </Step>

  <Step title="Keep the company details from the response">
    A successful request returns `200`:

    ```json theme={null}
    {
      "company": {
        "id": 318204,
        "name": "Harborline Wellness",
        "subdomain": "harborline",
        "fluid_shop": "harborline.fluid.app"
      },
      "user_company": {
        "id": 902771,
        "email": "maya@harborlinewellness.com"
      },
      "meta": {
        "request_id": "3b1f6c0e-8d2a-4f57-9c1e-5a7d2e9b4c10",
        "timestamp": "2026-09-29T16:04:12Z"
      }
    }
    ```

    Store `company.id` and `company.fluid_shop`. Read `company.subdomain` from the response rather than reusing what you sent — it is the value that went live.
  </Step>

  <Step title="The merchant signs in">
    Fluid emails a sign-in link to `user.email`. Fluid accounts have no password.

    Which email arrives depends on whether the address already belongs to a Fluid user. A new address gets a signup confirmation. An address already in use for another company can also get an admin invitation for the new company. Either link signs the merchant in. The response is the same `200` in every case, so don't promise the merchant a specific email.

    If no email arrives, the merchant can sign in at `https://admin.fluid.app` with the same address.
  </Step>

  <Step title="The merchant creates an API token">
    Once signed in, the merchant opens **Settings → API Tokens** at `https://admin.fluid.app/settings/tokens` and creates a token. See [Authentication](/api/authentication) for token types and scopes.
  </Step>

  <Step title="Make authenticated calls">
    Send the token as a Bearer token to `https://api.fluid.app`:

    ```bash theme={null}
    curl https://api.fluid.app/api/v202604/company/products \
      -H "Authorization: Bearer <token>"
    ```

    Every authenticated call acts on the company the token belongs to.
  </Step>
</Steps>

## Handle errors

| Status | What it means | What to do |
| - | - | - |
| `422` | The request was rejected. The body is `{ "error_message": ..., "errors": { ... }, "meta": { ... } }`. | See below. |
| `403` | The request was refused. | Don't retry. Contact Fluid support. |
| `429` | Too many signup requests. The body carries `retry_after`, in seconds. | Wait `retry_after` seconds before trying again. |

A `422` takes one of these forms:

* **`errors` names the field** (for example `errors.user.email` or `errors.company.subdomain`). A required field is missing or malformed, or the subdomain is already taken. Fix that field and retry. A taken subdomain is the most common failure: pick another.
* **`errors.company.base`**. Setup failed for another reason, such as an invalid colour or a subdomain that collides after normalization. The message text is not stable, so don't parse it.
* **`errors.base`**. The request was rejected by a check that applies to browser signups. Remove any fields that are not documented on the reference page.

<Warning>
  A `422` can arrive **after** the company was created, when a late setup step fails. Before retrying with a new subdomain, retry once with the same one. If that returns `errors.company.subdomain` with `is taken`, the first request created the company. Don't create another.
</Warning>

## Next steps

* [Authentication](/api/authentication) — token types, scopes, and how to pass a token.
* [API overview](/api/overview) — base URLs, the response envelope, and pagination.
* [Create a company](/api-reference/company-v0/public-companies/create-a-company) — the generated request and response reference.
