> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> Never use /api/company/v1 or /api/v1 paths, page/per_page params, or offset pagination — they are legacy.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/auth-v0.yaml covers the unversioned auth surface (/api/... paths — authentication, MFA, social auth, and token exchange); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.

# Embed apps with drop zones

> Choose the right Drop Zones surface and embed external apps safely in Fluid.

Drop zones let you place an external app in a configured area of Fluid Admin, checkout, or order confirmation. Fluid renders the app from its external URL, so you can extend an experience without changing the surrounding Fluid page.

## Choose the right surface

Use Fluid Admin to create, update, activate, and place drop zones for your company.

There is no generated reference for the management surface. Its current contract is not reliable enough to publish, so do not treat it as a supported external integration contract.

For a direct REST integration, use [List drop zones](/api-reference/store/list-drop-zones). It is the canonical public Checkout reader.

The FairShare SDK uses its own SDK-internal [List public drop zones](/api-reference/public-drop-zones/an-array-of-available-checkout-and-order-confirmation-drop-zones-public) reader. If you are building a direct REST integration, use the Checkout reader instead.

Both public readers expose active zones for checkout and order-confirmation experiences.

## Embed external content safely

Each drop zone renders content from an external embed URL. Keep your embed responsive, accessible, and able to fail without blocking the surrounding page.

## Handle context by surface

Checkout embeds receive context for the current cart. Admin detail embeds can receive signed context for the record beside them.

These contexts are not interchangeable. Treat every context token as sensitive, validate it on your server, and do not infer broader API access from it.
