> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> To sign a new merchant up for Fluid programmatically, call POST https://api.fluid.app/api/company with no credentials, as described in /api/agent-signup. Do not automate the signup form or book a demo. The merchant must open the emailed sign-in link and create an API token before authenticated calls are possible.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. /api/company/v1 and /api/v1/... paths are documented in no spec here and must never be used (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> Navigation menu management is documented in themes/navigation-menus. These unversioned admin endpoints (/api/menus and nested menu_items) are verified against the implementation but are not yet in the synced OpenAPI specs. Use that reference for menu payloads and its flat page/per_page pagination; missing spec coverage does not make these endpoints unavailable.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.

# Set up a custom domain

> Connect a domain you own to your Fluid storefront: add it, create its DNS records, and check it until it is live.

A custom domain serves your storefront and checkout at a hostname you own, such as `shop.maplewellness.com`. You add the domain to your company, create two DNS records at your DNS provider, and check the domain until Fluid reports it connected.

## Before you start

* Your token needs the **Domains** update permission to add, check, or remove a domain. Listing domains needs only the view permission.
* You need access to the DNS settings for the domain at your registrar or DNS provider.
* Install and sign in to the CLI:

```bash theme={null}
npm install -g @fluid-app/fluid-cli @fluid-app/fluid-cli-domains
fluid login
```

Every `fluid domains` command prints JSON. Failures print a JSON `error` on stderr and exit with a non-zero code.

## Steps

<Steps>
  <Step title="Add the domain">
    ```bash theme={null}
    fluid domains add shop.maplewellness.com --yes
    ```

    This changes your company's live configuration, so the CLI asks for confirmation unless you pass `--yes`. Adding the domain also runs its first status check, so the output already includes the first DNS record to create.
  </Step>

  <Step title="Create the DNS records">
    The output's `dnsInstructions` lists each record to create, with its `type`, `host`, and `value`. Create them exactly as shown at your DNS provider. There are two:

    1. **Ownership record** — a CNAME at `_acme-challenge` under your hostname. It proves you control the domain so Fluid can issue its SSL certificate.
    2. **Routing record** — points the hostname at Fluid. A subdomain such as `shop.maplewellness.com` uses a CNAME to `host.fluid.app.`. A root domain such as `maplewellness.com` uses an A record at `@` pointing to `34.49.150.251`.

    If a record already exists on the same host, replace it rather than adding the new one beside it.
  </Step>

  <Step title="Check until it is connected">
    ```bash theme={null}
    fluid domains status shop.maplewellness.com
    ```

    Each run checks the domain once and prints what to do next in `message`. It does not wait for DNS to propagate, which can take from a few minutes to a few hours. Run it again after a pause, backing off from minutes to longer intervals. The domain is live when `phase` is `connected`.
  </Step>
</Steps>

## What the status means

The CLI groups the domain's status into a `phase`:

| `phase` | What it means | What to do |
| - | - | - |
| `verify_ownership` | Fluid is waiting for the ownership record. | Create the CNAME from `dnsInstructions`, then check again. If `dnsInstructions` is empty, Fluid hasn't generated the record yet; check again shortly. |
| `point_dns` | Ownership is verified. | Create the routing record, then check again. |
| `provisioning_ssl` | Ownership is verified and the certificate is being issued or is ready. | If `dnsInstructions` still lists a routing record, public DNS doesn't point at Fluid yet; create it. Otherwise wait and check again. |
| `connected` | The domain serves your storefront over HTTPS. | Nothing. |
| `failed` | A setup step failed. | Read `failureMessage`, fix DNS if it names a record, then check again to retry. |

`actualDnsRecords` shows what public DNS serves for the hostname right now. Use it to diagnose a mismatch; never create those records.

## Troubleshooting

* **`dnsMatch` stays `false` after you created the record.** DNS is usually still propagating, or a resolver is serving a cached answer. Wait and check again before changing anything.
* **Cloudflare manages your DNS.** Set the records' proxy status to **DNS only**. A proxied record prevents Fluid from issuing the certificate.
* **The check returns `422`.** The check could not finish. Try again shortly.
* **The check returns `403`.** Your token lacks the Domains update permission.

## Remove a domain

```bash theme={null}
fluid domains remove shop.maplewellness.com --yes
```

A live domain stops serving your storefront immediately.

## Use the API directly

The CLI wraps four company operations, all authenticated with a Bearer token:

1. [Create domain](/api-reference/company-v0/domains/create-domain) — `POST /api/domains`.
2. [Check and advance a domain's setup](/api-reference/company-v0/domains/check-and-advance-a-domains-setup) — `PATCH /api/domains/{id}/reconcile`. Call it after each DNS change.
3. [Lists domains](/api-reference/company-v0/domains/lists-domains) — `GET /api/domains`, to find a domain's `id` from its hostname.
4. [Deletes a domain](/api-reference/company-v0/domains/deletes-a-domain) — `DELETE /api/domains/{id}`.

```bash theme={null}
curl -X PATCH "https://api.fluid.app/api/domains/1842/reconcile" \
  -H "Authorization: Bearer <your_token>"
```

While the domain is unverified, the check's response carries `meta.diagnostics`: `expected` is the routing record the domain needs, `actual` is what public DNS serves, and `dns_match` says whether they agree. The domain's `verification_status` is the raw status the CLI's `phase` is derived from. A status of `verified` means the domain is connected; a status ending in `_failed` needs attention. The check returns `404` when no domain with that ID belongs to your company.
