> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> To sign a new merchant up for Fluid programmatically, call POST https://api.fluid.app/api/company with no credentials, as described in /api/agent-signup. Do not automate the signup form or book a demo. The merchant must open the emailed sign-in link and create an API token before authenticated calls are possible.
> After signup, to launch a merchant's store (back-office sync, payments onboarding, store setup, a theme copied from their current site, and a preview link before billing), follow /api/agent-launch.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. The same applies to /api/company/v1 and /api/v1/... paths: prefer a newer documented equivalent, and use one only when none exists (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> Fluid has three navigation APIs; don't mix them up. Storefront website menus (navigation bars, footers) are /api/menus and nested menu_items, in api-reference/content-v0.yaml (API Reference: Website > Navigation menus), with a how-to in themes/navigation-menus; their list uses flat page/per_page pagination. The Fluid mobile app's navigation is /api/v2/mobile_navigations, in api-reference/mobile-v2.yaml (API Reference: Mobile app > Navigation); its list also uses page/per_page. Portal navigations belong to a portal definition (Fluid OS), in api-reference/fluid-os-v0.yaml (API Reference: Portal > Portal navigation), and each has a platform of web or mobile.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.
> The Help Center (/help/...) is for merchants, admins and reps using Fluid. Its admin pages mirror the admin's routes: the screen at admin.fluid.app/settings/taxes is documented at /help/admin/settings/taxes. Use the Help Center for how-to questions about the admin, and the Developer Platform and API Reference for building integrations.
> Help Center pages describe what a company admin sees. A reader's role can hide screens and actions; admins manage roles on Settings > Roles (/help/admin/settings/roles). If someone can't find a screen or button, their role's permissions are the first thing to check.
> Send people who need Fluid support to /help/getting-help. Don't invent support email addresses, phone numbers or response times.

# Authentication in Mist apps

> How the starter template authenticates webhooks, droplet installs, embedded requests and the person viewing an embedded page, and which parts you must not rebuild yourself.

The starter template already handles authentication between your app and Fluid. This page explains each part, so you can build on it instead of replacing it.

There are four questions your app has to answer:

| Question | How the template answers it |
| - | - |
| Did this webhook really come from Fluid? | An HMAC signature on every webhook. |
| Which company is this, and how do I call the API for it? | The droplet install flow, which stores a droplet installation token for each company. |
| Which installation is this embedded request for? | An installation reference that Fluid adds to the embed's URL. |
| Who is looking at this embedded page? | A short-lived session token that Fluid signs. |

## Webhook signatures

Fluid signs every webhook it sends. The template's `/api/webhooks` route checks the signature before it does anything else.

* Fluid sends `X-Fluid-Signature`, an HMAC-SHA256 of `{timestamp}.{raw body}`, and `X-Fluid-Timestamp`.
* The template rejects a webhook whose timestamp is more than five minutes old, to block replays.
* **Company webhooks**, such as `order.created`, are checked against that company's own webhook secret. The template finds the company from the `X-Fluid-Shop` header.
* **Lifecycle webhooks**, `droplet.installed` and `droplet.uninstalled`, are checked against `FLUID_WEBHOOK_AUTH_TOKEN`, which Fluid sets when you add a droplet.

Every webhook is saved to the `webhooks` table, with tokens and secrets removed from the stored copy. See [Webhooks](/api/guides/webhooks) for the events Fluid sends.

## The droplet install flow

When a company installs your droplet, Fluid sends `droplet.installed` to `/api/webhooks/installed`. The template then:

1. Exchanges the short-lived install token for the company's credentials: a [droplet installation token](/api/authentication#droplet-installation-token), which starts with `dit_`, and a webhook secret.
2. Saves them in the `companies` table, one row per installation.
3. Registers the webhooks, callbacks and drop zones you turned on in `lib/config/droplet.config.ts`.

When the company uninstalls the droplet, the template deactivates the installation, removes what it registered and erases the stored credentials.

Use the installation's token to call the Fluid API for that company:

```ts theme={null}
import { createFluidClientForInstallation } from "@/lib/fluid/client";
import { resolveFluidInstallation } from "@/lib/fluid/installation-context";

const context = await resolveFluidInstallation(request);
const fluid = createFluidClientForInstallation(context.installation);
```

A droplet installation token can do only what its installation's scopes allow. See [Token scopes](/concepts/droplets#token-scopes).

## Installation context for embedded pages

When the Fluid admin opens your droplet, it adds `?dri=dri_…` to your app's URL. That value identifies the company's installation of your droplet.

The template turns it into a server-side tenancy boundary:

1. In the browser, read it once with `readFluidInstallationReference(window.location.href)`.
2. Call your own API routes with `fluidInstallationFetch()`. It sends the reference in the `X-Fluid-Droplet-Installation` header and only to your app's own origin.
3. On the server, call `resolveFluidInstallation(request)` first in every route that reads company data or calls Fluid. It finds the one active installation, or throws.

Scope every query by `context.companyId` or `context.installation`.

<Warning>
  The `dri` value selects an installation. It doesn't prove who is viewing the page. Anyone who has a valid `dri` can call routes that check only the installation. When a route needs to know the viewer, also verify a session token.
</Warning>

## Viewer identity with session tokens

The Fluid admin can also add a `session_token` to the URL. It's a short-lived token, signed with HS256, that names the viewer (`sub`) and the store (`dest`).

`verifySessionToken()` in `lib/fluid/session-token.ts` checks it on the server. It checks the signature, issuer, audience, expiry and store, and allows 30 seconds of clock skew. It reads its keys from `FLUID_SESSION_TOKEN_SIGNING_SECRET`, `FLUID_OAUTH_CLIENT_ID` and `FLUID_SESSION_TOKEN_ISSUER`. Fluid sets them in production only, and verification fails closed when they're missing.

The `/embed/session-example` route shows the full pattern:

1. It resolves the installation from `dri`.
2. It looks up the store with the installation's token. This needs the `settings` scope on the installation.
3. It verifies the `session_token` against that store.
4. It sets its own HttpOnly cookie for 120 seconds, so later pages in the same frame don't need the token again.
5. It removes `session_token` from the browser's address bar.

If the cookie expires or the browser blocks it, the page asks the viewer to reload it from Fluid. A fresh load brings a new session token.

The session token identifies the viewer. It doesn't authorize Fluid API calls. To call Fluid, use the installation's token.

## What you must not build yourself

* **Don't create your own login.** Don't add a password form, an OAuth flow or a second viewer token for pages embedded in Fluid. Use the installation context and the session token.
* **Don't trust what the browser sends about the company.** Never pick the company from a query parameter, the `X-Fluid-Shop` header of a browser request, a shared token or "the only row in the database". Resolve the installation on the server.
* **Don't send tokens to the browser.** Keep droplet installation tokens and `FLUID_COMPANY_PRIVATE_TOKEN` on the server. Never forward a Fluid session token to the Fluid API.
* **Don't skip signature checks.** Don't disable the webhook signature check, even while you test.

## Local development

Locally, nothing signs webhooks or session tokens for you. The home page renders without a viewer, so you can build the UI right away.

To test the install flow locally, copy `.env.example` to `.env.local` and set the lifecycle variables it lists. The session-token variables exist only in production, so verified-viewer routes return `401` locally.

## Related pages

* [Integration points](/mist-apps/integration-points)
* [Authentication](/api/authentication) for every Fluid token type
* [Creating droplets](/guides/creating-droplets)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.