> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> To sign a new merchant up for Fluid programmatically, call POST https://api.fluid.app/api/company with no credentials, as described in /api/agent-signup. Do not automate the signup form or book a demo. The merchant must open the emailed sign-in link and create an API token before authenticated calls are possible.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. /api/company/v1 and /api/v1/... paths are documented in no spec here and must never be used (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> Navigation menu management is documented in themes/navigation-menus. These unversioned admin endpoints (/api/menus and nested menu_items) are verified against the implementation but are not yet in the synced OpenAPI specs. Use that reference for menu payloads and its flat page/per_page pagination; missing spec coverage does not make these endpoints unavailable.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.

# Webhooks

> Create, edit, pause or delete webhooks that send store events, such as new orders, to your other systems.

Each webhook watches one event on one resource and delivers it to a URL you choose. The **Webhooks** screen lists your webhooks and shows whether each one is active.

## Where to find it

In the admin, click the **Settings** gear in the top bar. In the Settings sidebar, under **System**, select **Webhooks**.

You can also click the **Developer Hub** code icon in the top bar, then select **Webhooks** in the Developer Hub sidebar.

## The webhooks list

Click **Create Webhook** at the top of the screen to add a webhook. To see deliveries, click **View Webhook Logs** in the banner below the page title. [Webhook Logs](/help/admin/settings/webhook-logs) shows each delivery's status and response code, and lets you retrigger events that failed.

* The **All**, **Active** and **Inactive** tabs filter the list by status.
* Use the search box above the list to find a webhook by its URL, resource or event.

The list has these columns:

* **Resource**: the kind of record the webhook watches, such as **Order** or **Product**.
* **Event**: the change that triggers a delivery, such as **Created** or **Updated**.
* **URL**: the address that receives the events.
* **Status**: **Active** or **Inactive**. Fluid sends events only to active webhooks.

Click a row to open the webhook. Each row's three-dot menu has **Edit** and **Delete**.

<Note>
  To create, open, edit or delete webhooks, your role needs **Full access** to **Developer**, or its **Manage webhooks and API configuration** switch turned on. With **View only**, you can see the list but not change it. See [Roles](/help/admin/settings/roles).
</Note>

## The webhook panel

**Create Webhook** opens a side panel with these fields. Opening an existing webhook shows the same fields in the **Edit Webhook** panel.

* **Resource**: the kind of record to watch. Required.
* **Event**: the change that triggers a delivery. The list fills in after you choose a **Resource**. Required.
* **Destination URL**: the address that receives the events. Required. The URL must use HTTPS and can't point to a private or internal address. You can register a URL only once for the same event.
* **HTTP Method**: the request method Fluid uses for each delivery. Choose **POST** (the default) or **PUT**, whichever your endpoint expects. The list also shows **PATCH** and **DELETE**, but Fluid doesn't accept them, so the webhook isn't saved. See [Why do I see both an error and a success message?](#error-and-success-message)
* **Authentication Token (optional)**: a secret your endpoint expects. Fluid sends it with each delivery and uses it to sign the delivery, so your endpoint can check that the request came from Fluid. If you create the secret yourself, make it long and random. See [Verify a delivery](/api/guides/webhooks#verify-a-delivery).
* **Timeout (seconds)**: Fluid doesn't save this value, so you can leave it blank.
* **Active**: whether the webhook receives events. It's on by default for a new webhook.

If **Resource**, **Event** or **Destination URL** is empty when you click **Save**, the admin asks you to fill in all required fields.

## Create a webhook

<Steps>
  <Step title="Open the panel">
    On the **Webhooks** screen, click **Create Webhook**.
  </Step>

  <Step title="Choose what to watch">
    Choose a **Resource**, then an **Event**.
  </Step>

  <Step title="Enter the destination">
    Enter the **Destination URL**. If your endpoint expects **PUT**, change **HTTP Method** to **PUT**. If your endpoint checks deliveries, enter the secret it uses in **Authentication Token (optional)**.
  </Step>

  <Step title="Save">
    Leave **Active** on so the webhook starts receiving events, then click **Save**. To check that it's listed, search for its URL in the search box.
  </Step>
</Steps>

## Edit a webhook

<Steps>
  <Step title="Open the webhook">
    Click the webhook's row, or choose **Edit** from its three-dot menu. The **Edit Webhook** panel opens.
  </Step>

  <Step title="Make your changes">
    Change the **Destination URL**, **HTTP Method**, **Authentication Token (optional)** or **Active** setting.
  </Step>

  <Step title="Save">
    Click **Save**. To confirm your change, search for the webhook's URL, or open the webhook again.
  </Step>
</Steps>

<Note>
  * The admin doesn't save changes to **Resource** or **Event**. To send a different event to the same URL, create a new webhook, then delete the old one if you no longer need it.
  * Clearing **Authentication Token (optional)** doesn't remove a token that's already saved. To remove it, delete the webhook, then create it again without a token.
  * If a webhook was set to `GET` through the API, saving it here changes it to **POST**.
</Note>

## Pause or resume a webhook

<Steps>
  <Step title="Open the webhook">
    Click the webhook's row, or choose **Edit** from its three-dot menu.
  </Step>

  <Step title="Turn Active off or on">
    Turn **Active** off to stop deliveries, or on to start them again.
  </Step>

  <Step title="Save">
    Click **Save**. The webhook's **Status** changes to **Inactive** or **Active**.
  </Step>
</Steps>

Turning a webhook back on doesn't resend events it missed while it was off.

## Delete a webhook

<Warning>
  **Delete** has no confirmation step, and you can't undo it. To stop deliveries for now, turn off **Active** instead.
</Warning>

In the list, choose **Delete** from the webhook's three-dot menu. Check that the webhook is gone from the list.

## FAQ

<AccordionGroup>
  <Accordion title="Why do I see both an error and a success message?" id="error-and-success-message">
    If you see an error message after you click **Save** or **Delete**, the change didn't go through, even if a success message also appears. After **Save**, the panel closes either way, so click **Create Webhook** or open the webhook again and re-enter your values. Fix the problem, then save again.
  </Accordion>

  <Accordion title="How quickly are events delivered?" id="delivery-timing">
    Fluid queues deliveries. They usually arrive in near real time, but can lag 5 to 10 minutes when the queue is backed up.
  </Accordion>

  <Accordion title="Does Fluid retry a failed delivery?" id="failed-delivery-retry">
    No. Fluid doesn't resend a failed delivery on its own. To resend one yourself, open [Webhook Logs](/help/admin/settings/webhook-logs), find the event on the **All** tab by its red **Failed** badge, and click **Retrigger** in its details. See [Retrigger a failed event](/help/admin/settings/webhook-logs#retrigger-a-failed-event). **Retrigger** sends the event again to every active webhook for that event, not only the one that failed.

    Deliveries that got no response from your endpoint, such as a timeout, show as **Pending** in Webhook Logs and can't be resent.
  </Accordion>

  <Accordion title="What does my endpoint receive?" id="webhook-payloads">
    Each delivery is a JSON request. For the payload format, see [Register and handle webhooks](/api/guides/webhooks).
  </Accordion>
</AccordionGroup>

## Related pages

* [Settings](/help/admin/settings): find the other screens under **Company**, **Commerce**, **Payments** and **System**.
* [Webhook Logs](/help/admin/settings/webhook-logs): check each delivery and retrigger events that failed.
* [Callbacks](/help/admin/settings/callbacks): have Fluid call your endpoint during store events, such as cart tax calculation.
* [Roles](/help/admin/settings/roles): set the permissions this screen needs.
* [Register and handle webhooks](/api/guides/webhooks): the delivery format and how to verify a delivery.
