> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. /api/company/v1 and /api/v1/... paths are documented in no spec here and must never be used (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> Navigation menu management is documented in themes/navigation-menus. These unversioned admin endpoints (/api/menus and nested menu_items) are verified against the implementation but are not yet in the synced OpenAPI specs. Use that reference for menu payloads and its flat page/per_page pagination; missing spec coverage does not make these endpoints unavailable.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/auth-v0.yaml covers the unversioned auth surface (/api/... paths — authentication, MFA, social auth, and token exchange); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.

# Sign in and sign out

> Add cache-safe member authentication links to your storefront and member layouts using your own HTML and styles.

<Warning>
  Member storefront is in a limited pilot. This guide requires the updated storefront authentication release, including the new sign-out route. Confirm that the release is deployed and member storefront is enabled for your company before publishing these links.
</Warning>

Use `member_routes.sign_in` and `member_routes.sign_out` in your theme. Fluid handles authentication and the session; you choose the markup, text, classes, and styles.

## Add links to your navigation

Place ordinary anchors in your storefront header or member layout:

```liquid theme={null}
<nav class="account-actions" aria-label="Account">
  <a class="account-actions__link" href="{{ member_routes.sign_in | escape }}">
    Sign in
  </a>
  <a class="account-actions__link" href="{{ member_routes.sign_out | escape }}">
    Sign out
  </a>
</nav>
```

Replace the example classes with your theme's classes. You can put an icon or other content inside either anchor. No Fluid-specific styling, form tag, logout JavaScript, or CSRF-token variable is required.

Keep these URLs independent of the visitor's session. A cached storefront page can be reused for signed-in and signed-out visitors, so do not use Liquid conditions on `member` to choose which link that page includes. `member` is available only in authorized member-page renders. The existence of `member_routes.sign_out` does not mean a visitor is signed in.

Use the variables instead of hardcoding your company domain, the auth domain, or a callback URL. Local and deployed environments can use different authentication hosts.

## What happens when you sign in

1. On the storefront, the sign-in link starts authentication on the current host and redirects to your company's Fluid sign-in screen. In production, Fluid hosts authentication at `auth.fluid.app`.
2. After successful authentication, the browser returns to the same host's session callback. Fluid verifies the result and creates the member session cookie.
3. The browser returns to the requested local path. If no safe return path is available, it returns to `/` on that host.

Signing in from a storefront returns to that storefront, including a custom domain. Signing in from the account host returns to the account host. Your theme should not generate authentication tokens, store them in browser storage, or build the callback itself.

`member_routes.root` is the root of the current host. It does not switch between the storefront and the account host.

## Sign-in always uses hosted authentication

Both hosts use `/auth/sign_in` to redirect directly to the configured authentication app. It does not render a `members_login` theme template. Your theme does not need a login template or its own password form.

A guest who opens a protected member page also goes directly to hosted authentication and returns to the requested page after signing in.

## What happens when you sign out

Following `member_routes.sign_out` ends the member session on the current host and redirects to that host's root. Fluid also revokes the member's company-scoped real-time connections. If that cleanup fails, sign-out reports a failure and keeps the cookie so the member can retry.

Sessions are currently scoped to the host. Signing in on the storefront does not automatically sign you in on the account host, and signing out does not clear the other host's cookie. It also does not sign you out of the hosted authentication provider. Real-time connection revocation can affect other tabs for the same member and company.

Sign-out uses a GET navigation. A link preview, prefetch, or navigation from another site can therefore sign a visitor out. Keep this as an explicit user-clicked link and do not prefetch or automatically request it. This behavior applies to sign-out; it does not remove protection from other actions.

## Update an older theme

After the updated authentication release is deployed:

1. Replace old `/login` links with `member_routes.sign_in`. Remove unused `members_login` templates.
2. Replace old sign-out forms and references to the retired session-delete route with the anchor above.
3. Remove `member_routes.csrf_token`, hidden method overrides, and custom code used only to submit that old logout form.
4. Keep `content_for_header` in your layout; system screens and other theme features still need the normal header output.
5. Publish or regenerate your theme's HTML so cached storefront pages receive the new links.

## Test your links

* Start signed out on a storefront page, follow **Sign in**, and confirm you return to that storefront page after authentication.
* Follow **Sign out** and confirm the session ends on that host.
* On the account host, sign in, open a protected member page, and sign out. Reopening the protected page should require authentication.
* Follow the sign-in link on the account host and confirm it uses `/auth/sign_in` and redirects directly to hosted authentication.
* Check cached storefront HTML as both a guest and a member. It should contain stable auth links and no private member data or session token.

For the complete field reference, see [Member Liquid variables](/themes/member-storefront/member-variables).
