Skip to main content
Every authenticated Fluid endpoint acts for one of two callers: a company or a member. The caller decides which endpoints you use, which credential you send, and what data you can reach. A third group of endpoints — public storefront reads and checkout — takes no company or member credential at all.

Company APIs

Company endpoints act for the company the credential belongs to. Only three kinds of caller can use them:
  • A company admin whose role grants the permission — through a company token or the admin’s own sign-in. An admin whose role lacks the permission gets 403.
  • A partner token, which acts with the role it was created with.
  • A droplet installation token, limited to the scopes granted to the droplet’s installation.
Members and shoppers can’t call company endpoints. A public (pub-) token reaches only the few endpoints its scopes cover, such as product reads and DAM uploads. Within what its role or scopes allow, a caller can reach any record of that company. See Authentication for the token types. Company endpoints can manage members too — for example, listing members or changing a member’s type. They do that as the company, on any member it chooses.

Member APIs

Member endpoints act as the member. Two rules follow from that:
  • They are scoped to the member. The JWT identifies the member and their company. No path, query, or body parameter names a member, so a member can only ever reach their own profile, memberships, and team.
  • They use that member’s JWT. Send the member’s own credential as a Bearer token. A company, partner, public (pub-), or droplet installation token is refused with 401 — even though it can see far more data, it doesn’t speak for a member. A company admin’s credential is refused as well.
A member credential is a member session JWT, a portal JWT whose login is linked to a membership in that company, or a member token. A JWT that can also travel in a URL is read-only: a write with it returns 403.

Choosing one

  • Your code runs for the company — a sync job, a droplet, an admin tool: use company endpoints with an admin’s token (with the right role), a partner token, or a droplet installation token.
  • Your code runs for a signed-in member — they should see and change only their own data: use member endpoints with that member’s JWT.
  • Never hand a company token to a member’s browser or app to fetch “their” data. It can read every member’s data. Use the member’s own JWT so Fluid enforces the scope for you.
See Member APIs for every member endpoint.