curl -X PATCH "https://api.fitsociety.io/public/v1/workout/plans/assigned/{planId}/status" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'PATCH',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({status: 'Inactive'})
};
fetch('https://api.fitsociety.io/public/v1/workout/plans/assigned/{planId}/status', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/plans/assigned/{planId}/status"
payload = { "status": "Inactive" }
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"data": {
"_id": "67f1234567890abcdef1234",
"name": "Weekly Strength Program",
"clientId": "67f1234567890abcdef1234",
"templateType": "Assigned",
"status": "Inactive",
"previousStatus": "Active",
"isActive": false,
"changed": true,
"updatedAt": "2026-07-14T10:00:00.000Z"
},
"meta": {
"requestId": "4f849d7d-f4f1-45cc-b4b7-3984a3d17f83",
"rateLimit": {
"limit": 10,
"remaining": 9,
"resetSeconds": 1
},
"idempotency": {
"replayed": false
}
}
}Activate or deactivate a client's assigned plan
Switch an Assigned plan between Active and Inactive.
Send status to set a state exactly (idempotent — asking for the state the plan is already in succeeds and reports changed: false). Omit it to flip the current one. Prefer sending it: a blind flip races with a second tab or a double tap and lands on whichever value it happened to read.
Inactive is what HIDES the plan from the client — every client-facing read filters on status: "Active". Nothing is deleted and no session or logged performance is touched, so switching back restores the plan as it was.
Assigned plans only. Publishing a library Template is a different action with its own permission: PUT /app/v1/workout/plans/publish/{templateId}.
Requires the workout_plans:write scope. This operation maps to /app/v1/workout/plans/assigned/:planId/status and retains its Workout V2 permission, feature-flag, and resource-scope checks.
The clientId path parameter is resolved inside the company bound to the Public API token when present.
curl -X PATCH "https://api.fitsociety.io/public/v1/workout/plans/assigned/{planId}/status" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'PATCH',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({status: 'Inactive'})
};
fetch('https://api.fitsociety.io/public/v1/workout/plans/assigned/{planId}/status', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/plans/assigned/{planId}/status"
payload = { "status": "Inactive" }
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"data": {
"_id": "67f1234567890abcdef1234",
"name": "Weekly Strength Program",
"clientId": "67f1234567890abcdef1234",
"templateType": "Assigned",
"status": "Inactive",
"previousStatus": "Active",
"isActive": false,
"changed": true,
"updatedAt": "2026-07-14T10:00:00.000Z"
},
"meta": {
"requestId": "4f849d7d-f4f1-45cc-b4b7-3984a3d17f83",
"rateLimit": {
"limit": 10,
"remaining": 9,
"resetSeconds": 1
},
"idempotency": {
"replayed": false
}
}
}Authorizations
Public API access token issued by /public/v1/oauth/token. Example: Authorization: Bearer fspt_.... Each resource request rechecks the token company's current provider access. Disabling access blocks existing tokens with 403 auth.provider_unavailable.
Headers
Required for Public API write requests. Reusing the same key with the same method, path, and body replays the stored successful response; reusing it with a different request returns 409 idempotency.conflict.
1 - 200"booking-create-20260714-001"
Path Parameters
Assigned workout plan id.
"67f1234567890abcdef1234"
Body
The state to set. Omit to flip the plan's current state.
Active, Inactive "Inactive"