A third group of endpoints — public storefront reads and checkout — takes no company or member credential at all.
Company APIs
Company endpoints act for the company the credential belongs to. Only three kinds of caller can use them:- A company admin whose role grants the permission — through a company token or the admin’s own sign-in. An admin whose role lacks the permission gets
403. - A partner token, which acts with the role it was created with.
- A droplet installation token, limited to the scopes granted to the droplet’s installation.
pub-) token reaches only the few endpoints its scopes cover, such as product reads and DAM uploads. Within what its role or scopes allow, a caller can reach any record of that company. See Authentication for the token types.
Company endpoints can manage members too — for example, listing members or changing a member’s type. They do that as the company, on any member it chooses.
Member APIs
Member endpoints act as the member. Two rules follow from that:- They are scoped to the member. The JWT identifies the member and their company. No path, query, or body parameter names a member, so a member can only ever reach their own profile, memberships, and team.
- They use that member’s JWT. Send the member’s own credential as a Bearer token. A company, partner, public (
pub-), or droplet installation token is refused with401— even though it can see far more data, it doesn’t speak for a member. A company admin’s credential is refused as well.
403.
Choosing one
- Your code runs for the company — a sync job, a droplet, an admin tool: use company endpoints with an admin’s token (with the right role), a partner token, or a droplet installation token.
- Your code runs for a signed-in member — they should see and change only their own data: use member endpoints with that member’s JWT.
- Never hand a company token to a member’s browser or app to fetch “their” data. It can read every member’s data. Use the member’s own JWT so Fluid enforces the scope for you.