> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fitsociety.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Changelog

> Externally relevant changes to FITsociety developer API documentation and contracts.

## 2026-09-09

### Brand assets

* Added a [Brand assets](/brand-assets) page with logo and icon previews,
  SVG/PNG/JPG downloads, a complete ZIP kit and the original brand guidelines.

### Form templates and client actions

* Added form template creation, updates and archive actions with `forms:write`.
* Separated Forms, Intakes and Check-ups in the API reference and guides.
* Form updates preserve the existing answered-form edit lock and immutable form type.
* Archiving preserves existing assignments and answers and prevents new assignments.
* Removed `POST /public/v1/clients/{clientId}/relationship/approve` from the Public API.

## 2026-08-26

### Public API async exports

* **Added** asynchronous company exports under `/public/v1/exports`, using the
  same export types, validation, export request records, and background
  processor as the FITsociety software.
* **Added** `exports:read` for export type discovery, export request status,
  and temporary download metadata, plus `exports:write` for queueing,
  canceling, retrying, and deleting export requests.
* XLSX export types can now also be requested as `csv`. Multi-sheet CSV
  requests return a ZIP containing one CSV file per worksheet.
* Completed export responses return signed temporary download URLs while the
  export file has not expired.
* Public API clients can only see export requests created by the same Public
  API client. Responses expose allowlisted DTO fields only and do not include
  raw params, metadata, internal actors, provider payloads, or internal error
  details.
* Legacy direct XLSX routes and coach export templates remain outside the
  Public API. See [Async exports](/public-api/exports).

## 2026-08-23

### Documentation overhaul

* Added a [Quickstart](/public-api/quickstart) that takes integrators from
  OAuth credential creation to a first successful `GET /public/v1/me` call.
* Added a dedicated [Errors](/public-api/errors) reference for the Public API
  error envelope and error keys.
* Added documentation for the client-AI MCP tool modules (account, bookings,
  check-ups, documents, goals, habits, measurements, messages, nutrition, WOD,
  and workout), covering the tools exposed to client-approved AI grants.
* Restructured the MCP tab into task-oriented groups: Get started, Connect
  your AI client, Concepts, Tools, Workflows, and Reference & operations.
* Replaced the hand-maintained endpoint list on the Public API overview with a
  domain summary; the generated API Reference tab is now the single source for
  the endpoint inventory.
* Added prerequisite callouts (company `mcp` feature + grant) to every AI
  client connect guide, and rebuilt the landing page around task-based cards.

## 2026-08-14

### Public API contracts

* Froze Public API response contracts: documented output fields are now
  explicit allowlists, so backend model changes do not silently change the
  external API surface.
* Added response and error examples across Public API guide pages.

## 2026-08-11

### MCP agent setup

* Added [Agent Setup](/mcp/agent-setup) and the machine-readable
  [agent setup prompt](/mcp/agent-setup-prompt.md) so AI coding agents (Codex,
  Cursor, OpenCode, Windsurf, Copilot, and generic MCP clients) can configure
  the FITsociety MCP server themselves.

## 2026-08-07

### Finance products

* Credit-pack `creditValidity.value` now accepts decimal values (type changed
  from `integer` to `number` in the contract). Membership validity values
  remain whole numbers. Credit-pack create requests now require
  `creditValidity.value` (greater than `0`) and `creditValidity.unit`.

## 2026-07-27

### Event templates

* Event templates gained default location handling and validation. Templates
  without an explicit location fall back to the configured default; create and
  update payloads validate location references.

## 2026-07-21

### Calendar availability

* Added coach and location availability management endpoints:
  `GET`/`PUT /public/v1/coaches/{coachId}/availability` and
  `GET`/`PUT /public/v1/locations/{locationId}/availability`, guarded by the
  `coach_availability:*` and `location_availability:*` scopes.

### Event types and templates

* Removed legacy lesson types from the Public API in favor of event types and
  event templates (`/public/v1/event-types`, `/public/v1/event-templates`),
  including create, update, and archive resources.

### Legacy company API keys removed

* Removed the legacy company API key integration. Public API access now uses
  OAuth client credentials exclusively; access-device documentation no longer
  references company API keys. The `x-api-key` header is not accepted on
  Public API resources.

### MCP

* Enhanced client MCP policy management and error handling for client-approved
  AI access.

## 2026-07-18

### MCP

* Added client AI nutrition tools for logging and searching food products and
  recipes.
* Moved the MCP server to `https://mcp.fitsociety.io/mcp/v1`; documentation
  and OAuth discovery references updated to the new domain.

## 2026-07-15

### Public API

* Documented full finance product catalog CRUD: membership products, credit
  packs, day passes, and single sessions, including list, create, update,
  delete, and per-product client listings.
* Expanded company catalog schemas (company profile, facilities and services,
  policies) with detailed response structures.
* Tightened outbound webhook target URL validation and improved the OpenAPI
  export used for the API Reference tab.

## 2026-07-14

### Documentation structure

* Added the top-level developer documentation structure with separate
  **Docs**, **API Reference**, **MCP**, and **Changelog** tabs.
* Added a generated Public API OpenAPI export for Mintlify endpoint reference
  pages, filtered to developer Public API endpoints only (provider callback
  receivers, storefront routes, public widgets, and QR/access-device endpoints
  are intentionally excluded).
* Added outbound webhook management routes (`/public/v1/webhooks`,
  webhook deliveries) and Access Devices documentation.
* Public API docs describe the stable DTO allowlist policy, response
  envelopes, validation behavior, idempotency, pagination, rate-limit
  metadata, and sensitive-field exclusions.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.