At a glance
Public endpoints
Public endpoints need no token, so your storefront can call them straight from the browser. Fluid works out which store you mean from the host you call:https://api.fluid.app returns 404, because that host names no store.
What the public side returns:
- Lists show only live content. A draft, scheduled, or switched-off resource never appears in a public list. See Visibility, drafts, and scheduling.
- Looking up a slug is looser. A public show request can return a resource that isn’t live yet, so preview links work. It carries
seo.indexable: falseso search engines skip it. - Missing translations fall back. A field that has no translation in the requested
langreturns its default-language value. - The public side never returns
403. A resource you can’t see is either left out of a list or returns404.
Company endpoints
Company endpoints need a Bearer token and run onhttps://api.fluid.app. The token identifies the store:
- Reads need the
storefront.viewpermission, and writes needstorefront.update. Older per-resource permissions, such asproducts.update, are also accepted. - A droplet installation token needs the
websitescope instead. See Authentication. - Lists return every resource in any state. You can narrow them with
filter[status], and on every resource except products withfilter[active]. The public side ignores both. - Responses add management fields the public side leaves out, such as
custom_slugandseo.id.
Which to use
- Rendering a storefront, or reading as a shopper would — use the public endpoints on the store’s host.
- Managing content, or reading content that isn’t live — use the company endpoints with a token.
- Checking what a shopper will see before you publish — read the resource on the company side, then look it up by slug on the public side.
lang, q, sort, page[cursor], and page[limit] on lists. See Find and create resources.