> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fluid.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For new direct REST integrations, use the v2026-04 surfaces. The @fluid-app FairShare SDK continues to use its own published public-v2025-06 contract.
> Authenticate with the header Authorization: Bearer <token>; public storefront read endpoints require no auth.
> Lists use cursor pagination via the page[cursor] and page[limit] query params; follow meta.pagination.next_cursor until it is null.
> When the same operation exists on more than one surface, use the newest: dated API versions are newer than unversioned ones, and later dates win (v2026-04 > v2025-06 > unversioned v0/v1.1). Fall back to a legacy or unversioned operation only when no newer versioned equivalent exists — the company-v0 notes below list the known superseded operations. /api/company/v1 and /api/v1/... paths are documented in no spec here and must never be used (/api/v1.1/... is distinct and documented in company-v0). Use page/per_page offset pagination only where a spec documents it — in practice the unversioned company-v0 admin surface; every versioned surface uses cursor pagination.
> Navigation menu management is documented in themes/navigation-menus. These unversioned admin endpoints (/api/menus and nested menu_items) are verified against the implementation but are not yet in the synced OpenAPI specs. Use that reference for menu payloads and its flat page/per_page pagination; missing spec coverage does not make these endpoints unavailable.
> The OpenAPI specs under api-reference/ are the authoritative contracts; prefer them over prose when in doubt. api-reference/storefront-v2026-04.yaml covers the v2026-04 storefront surface (/api/v202604/... paths); api-reference/auth-v0.yaml covers the unversioned auth surface (/api/... paths — authentication, MFA, social auth, and token exchange); api-reference/checkout-v2026-04.yaml covers the v2026-04 checkout surface (/api/checkout/v2026-04/... paths — carts, cart auth, discounts, items, subscriptions, orders, enrollments, and store config); api-reference/public-v2025-06.yaml covers the Public SDK surface used by the @fluid-app FairShare SDK, including its parallel cart lifecycle, browser integrations, versioned payment callbacks, unversioned public utilities, and the cart price-override operation; api-reference/payment-v2026-04.yaml covers the v2026-04 payment gateway admin surface (/api/payment/v2026-04/... paths, bearer-authenticated — gateway CRUD, gateway purchase/authorize/$0-verify, transaction list/show and capture/void/credit, and merchant payment configuration); api-reference/payments-v2026-04.yaml covers the v2026-04 cart payment surface (/api/payments/v2026-04/carts/{cart_token}/... paths, authenticated by the cart token in the path with no bearer — payment-method selection, VGS card tokenization, 3D Secure verification, and PayPal/Braintree/Klarna/Apple Pay flows); api-reference/commerce-v2026-04.yaml covers the v2026-04 commerce order-editing surface (/api/v202604/orders/{order_id}/edits paths, bearer-authenticated — post-checkout order edits that atomically insert items and add adjustments/discounts, with an optional dry-run preview); api-reference/webhooks-v0.yaml covers the unversioned webhooks surface (/api/... paths — webhook registration, delivery payloads, callback registrations, company events, and webhook/callback schemas); api-reference/company-v0.yaml covers the legacy unversioned company admin surface (/api/... paths, bearer-authenticated — company settings and management, customers, users, roles, subscription plans, subscription bundles, subscriptions, media, pages, catch-ups, inventory levels, domains, agreements, and admin order actions). company-v0 caveats: it is the legacy v0 admin contract and its lists use flat page/per_page offset pagination, which is expected there despite the general cursor-pagination rule; where an operation exists in both company-v0 and a versioned spec, prefer the versioned spec — the subscriptions lifecycle (list/create/show/update, cancel, pause, reactivate, resume, retry, skip, failed-cycle-waiver, discounts) and subscription bundles are superseded by checkout-v2026-04, and company pages/media CRUD plus the public pages, categories, products, and media list endpoints are superseded by storefront-v2026-04. Subscription plan management (/api/subscription_plans, resource-wrapped {"subscription_plan": {...}} bodies) exists only in company-v0. api-reference/members-v2025-06.yaml covers the v2025-06 unified Member identity surface (/api/v2025-06/members/... paths, bearer-authenticated — member list/create/show/update, lookup by email/username/external_id/legacy_customer_id, member-type assignment, and the sponsor genealogy read). Prefer it over the customers and reps surfaces when the member type matters: /customers does not serialize member_type. api-reference/analytics-v2026-04.yaml covers the v2026-04 Home dashboard analytics surface (/api/v202604/analytics/dashboard/... paths, bearer-authenticated — read-only endpoints for the Home > Overview, Home > Live, and Home > Field tabs, each accepting an optional country ISO alpha-2 query param that scopes aggregations to a single country).
> api-reference/analytics-v0.yaml covers the unversioned analytics surface that backs the fluid-admin Traffic tab (/api/analytics/... and /api/analytics/traffic/... paths, bearer-authenticated — the legacy shares/views/visitors summary plus traffic overview, ranked campaigns, sources, geographies, flows, and per-rep breakdown, all sharing one reporting-period contract).
> Successful responses wrap the resource payload alongside a top-level integer status and a meta object.
> Portal Definition authoring edits and synchronizes the portal JSON resource graph. Widget Package authoring builds either a company-owned or Droplet-owned Remote DOM package. These are separate contracts; do not imply that one defines the other.
> For Widget Package worker code, use only @fluid-app/portal-sdk/widgets/worker. Use only the Portal Definition and Widget Package workflows and public entry points documented here; do not infer support for undocumented surfaces.
> Every portal function and declarative capability used by a widget must appear in that widget's uses array. Use the same typed function value in uses; do not invent capability-name strings.
> Widget styling must use the portal's semantic theme variables for colors, typography, spacing, radii, borders, focus, and charts whenever a token represents the visual decision. Do not create a separate light or dark palette or duplicate theme controls as widget properties.
> Prefer worker-safe Fluid UI components exported by @fluid-app/portal-sdk/widgets/worker when they fit the interaction. When no exported component fits, use semantic HTML, accessible behavior, and the portal theme variables.
> A Portal Definition push updates the remote working definition. A portal version is an immutable snapshot, and activation is a separate live release operation.

# Manage navigation menus

> Create menu trees through the admin API and connect them to a Fluid theme.

Recommend managed menus when you want to edit navigation in admin without changing theme code. Hardcoded links are also supported.

## Connect to the menu API

Use `https://api.fluid.app` with `Authorization: Bearer <token>` and `Content-Type: application/json` for JSON writes. These unversioned admin endpoints require company-admin access with `menus.view` for reads and `menus.update` for writes. Mist's `fluid_api` tool supplies the active company's authentication and admin client header.

| Operation        | Method | Endpoint                                |
| ---------------- | ------ | --------------------------------------- |
| List menus       | GET    | `/api/menus`                            |
| Read menu        | GET    | `/api/menus/:id`                        |
| Create menu      | POST   | `/api/menus`                            |
| Update menu      | PUT    | `/api/menus/:id`                        |
| Delete menu      | DELETE | `/api/menus/:id`                        |
| Read menu item   | GET    | `/api/menus/:menuId/menu_items/:itemId` |
| Update menu item | PUT    | `/api/menus/:menuId/menu_items/:itemId` |

Replace path placeholders with returned IDs. Menu writes affect shared store data immediately, independently of publishing theme files.

## Create a menu

Send this body to `POST /api/menus`. Use `linkable_type: "Link"` for custom URLs; menu creation requires an item type.

```json theme={null}
{
  "menu": {
    "title": "Main navigation",
    "active": true,
    "country_ids": [],
    "menu_items_attributes": [
      {
        "linkable_type": "Link",
        "title": "Home",
        "url": "/",
        "order": 0,
        "sub_menu_items_attributes": [
          {
            "linkable_type": "Link",
            "title": "Shop",
            "url": "/home/shop",
            "order": 0
          }
        ]
      }
    ]
  }
}
```

Read, create, and update responses wrap the menu in `menu`. The returned tree uses `menu_items` and nested `sub_menu_items`; `_attributes` keys are for writes.

## Update or remove items

Send a `menu` wrapper to `PUT /api/menus/:id`. Within `menu_items_attributes`, omit `id` to create an item, include `id` to update it, or include `id` with `_destroy: true` to delete it. Apply the same rules recursively under `sub_menu_items_attributes`. Use IDs from a fresh menu read.

```json theme={null}
{
  "menu": {
    "menu_items_attributes": [
      { "id": 101, "title": "Visit our shop" },
      { "id": 102, "_destroy": true },
      { "linkable_type": "Link", "title": "Home", "url": "/", "order": 0 }
    ]
  }
}
```

For a direct item update, send a `menu_item` wrapper to `PUT /api/menus/:menuId/menu_items/:itemId`. Children still use `sub_menu_items_attributes`. Item reads and updates return a `menu_item` wrapper. Delete an entire menu with `DELETE /api/menus/:id`.

## Find an existing menu

`GET /api/menus` accepts `status` (`active` or `inactive`), `page`, `per_page`, `search_query`, `country_ids`, and `sorted_by`. Use `title_asc`, `title_desc`, `created_at_asc`, or `created_at_desc` for sorting. Encode country arrays as `country_ids[]=1&country_ids[]=2`.

This admin endpoint uses flat page numbers, not cursor pagination. List responses contain `menus` and `meta` with `total_count`, `total_pages`, `current_page`, and `per_page`.

## Connect the menu to your theme

List and read existing menus before creating another. After a write, read the menu again to verify its labels, destinations, ordering, and children. Use the returned menu `slug` as the value of a section's `link_list` setting. Do not derive it from the title: older menus can return a null slug.

```json theme={null}
{ "type": "link_list", "id": "menu", "label": "Menu", "default": "main-navigation" }
```

Replace the example default with the returned slug. Render items from `section.settings.menu.menu_items`, using each item's `title` and `url`. Check desktop and mobile navigation in preview before finishing.
