> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fitsociety.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a workout v2 plan

> Creates a workout plan in the authenticated company scope. Accepts `multipart/form-data` only — the route is gated by the workout media upload middleware. Send structured arrays and objects (e.g. `name`, `description`, `duration`, `defaultExerciseValues`) as JSON strings. Use `imageFiles` and `videoFiles` for media uploads; the legacy aliases `images` and `videos` are still accepted.

Requires the workout_plans:write scope. This operation maps to /app/v1/workout/plans and retains its Workout V2 permission, feature-flag, and resource-scope checks.

The clientId path parameter is resolved inside the company bound to the Public API token when present.



## OpenAPI

````yaml /openapi/public-v1.json post /public/v1/workout/plans
openapi: 3.1.0
info:
  title: FITsociety Public API v1
  version: 1.0.0
  description: >-
    Developer Public API endpoints under `/public/v1`. This reference is
    filtered to OAuth/Bearer Public API resources and excludes provider callback
    receivers, storefront routes, public widgets, wishlist routes, and
    access-device validation endpoints.
  contact:
    name: FITsociety Engineering
servers:
  - url: https://api.fitsociety.io
    description: Production
security: []
tags:
  - name: Workout
    description: >-
      Workout V2 libraries, programmes, client plans, calendars, sessions,
      groups, settings and progress. AI operations are excluded.
  - name: OAuth
    description: Public API OAuth endpoints for server-to-server client credentials.
  - name: Health
    description: Public API token health checks.
  - name: Platform
    description: >-
      Inspect Public API client context, capabilities, scopes, and redacted
      audit logs.
  - name: Company Catalog
    description: Read and manage company profile metadata and locations.
  - name: Clients
    description: >-
      Create and manage clients through the Public API using Bearer access
      tokens.
  - name: Coaches
    description: Retrieve coaches for the authenticated company via integrations.
  - name: Calendar Events
    description: Read Public API calendar events.
  - name: Calendar Templates
    description: >-
      Read and manage event types and event templates used by calendar
      availability and bookings.
  - name: Calendar Extensions
    description: >-
      Read recurring bookings, booking requests, calendar tasks, and
      availability closure metadata.
  - name: Availability
    description: Read bookable availability slots and signed availability tokens.
  - name: Availability Management
    description: >-
      Manage coach and location availability templates used to derive bookable
      slots.
  - name: Bookings
    description: Read and manage Public API bookings.
  - name: Finance
    description: >-
      Read invoices, transactions, products, subscriptions, and memberships with
      guarded finance writes.
  - name: Credits
    description: >-
      Read company-wide and client-scoped credit allocations, mutations, and
      guarded credit adjustments.
  - name: Exports
    description: >-
      Create and monitor asynchronous company exports through Public API Bearer
      endpoints.
  - name: Webhooks
    description: >-
      Manage outbound webhook subscriptions and inspect delivery attempts
      through Public API Bearer endpoints.
  - name: Measurements
    description: Read and write client measurement entries.
  - name: Progress Photos
    description: Read client progress photo metadata and short-lived signed media URLs.
  - name: Forms
    description: Read, create, update, and archive company form templates.
  - name: Intakes
    description: Assign intake forms and read client intake assignments and submissions.
  - name: Check-ups
    description: >-
      Schedule and cancel client check-ups and read their status and
      submissions.
  - name: Documents
    description: >-
      Read client document and folder metadata, register external document
      links, update metadata, and archive documents from Public API listings.
      Binary upload, permanent deletion, and company-wide document management
      are not exposed.
  - name: Habits
    description: Read habits and habit entries.
  - name: Goals
    description: Read client goal summaries.
  - name: Conversations
    description: >-
      Read and manage direct and group chat conversations through the Public
      API.
  - name: Reports
    description: Read aggregate attendance, revenue, and retention summaries.
paths:
  /public/v1/workout/plans:
    post:
      tags:
        - Workout
      summary: Create a workout v2 plan
      description: >-
        Creates a workout plan in the authenticated company scope. Accepts
        `multipart/form-data` only — the route is gated by the workout media
        upload middleware. Send structured arrays and objects (e.g. `name`,
        `description`, `duration`, `defaultExerciseValues`) as JSON strings. Use
        `imageFiles` and `videoFiles` for media uploads; the legacy aliases
        `images` and `videos` are still accepted.


        Requires the workout_plans:write scope. This operation maps to
        /app/v1/workout/plans and retains its Workout V2 permission,
        feature-flag, and resource-scope checks.


        The clientId path parameter is resolved inside the company bound to the
        Public API token when present.
      operationId: publicWorkoutpostPublicV1WorkoutPlans
      parameters:
        - name: Idempotency-Key
          in: header
          required: true
          schema:
            type: string
            minLength: 1
            maxLength: 200
            example: booking-create-20260714-001
          description: >-
            Required for Public API write requests. Reusing the same key with
            the same method, path, and body replays the stored successful
            response; reusing it with a different request returns `409
            idempotency.conflict`.
      requestBody:
        required: true
        content:
          multipart/form-data:
            schema:
              type: object
              required:
                - name
                - description
              properties:
                name:
                  type: string
                  description: Multipart JSON string for `WorkoutLocalizedTextArray`.
                  example: >-
                    [{"lang":"en","value":"4-Day Strength
                    Block"},{"lang":"nl","value":"4-Daags Krachtblok"}]
                description:
                  type: string
                  description: Multipart JSON string for `WorkoutLocalizedTextArray`.
                  example: >-
                    [{"lang":"en","value":"Progressive upper/lower
                    split."},{"lang":"nl","value":"Progressieve upper/lower
                    split."}]
                category:
                  type: string
                  enum:
                    - Agility & Speed
                    - Strength
                    - Hypertrophy
                    - Strength - Dynamic
                    - Strength - Explosive
                    - Strength - Static
                    - Cardio
                    - Cardio - Duration
                    - Cardio - Interval
                    - HIIT
                    - Crossfit
                    - Mobility
                    - Stretching
                    - Core
                    - Coordination & Balance
                    - Movement Prep
                    - Functional Training
                    - Recovery
                    - Sports
                    - Martial Arts
                    - Yoga
                    - Other
                    - GROUP_WORKOUT_TEMPLATE
                    - Plyometric
                    - Cycling
                    - Cardio - interval
                    - Mobilisation
                    - Stabilisation
                    - Daily Living
                    - Target zone
                    - Respiration
                    - Breathing
                    - Massage
                    - Outdoor sports
                    - Indoor sports
                    - Dance
                    - Group Lessons
                    - Martial arts
                    - Material Arts
                    - Fight skills
                    - Mind and body
                    - ''
                    - default
                  example: Strength
                goal:
                  type: string
                  enum:
                    - Weight Loss
                    - Hypertrophy
                    - Endurance
                    - Flexibility
                    - General Fitness
                    - Strength
                  example: Strength
                periodizationType:
                  type: string
                  enum:
                    - Linear
                    - Non-Linear
                    - Block
                    - Undulating
                    - None
                  example: Linear
                difficulty:
                  type: string
                  enum:
                    - Beginner
                    - Intermediate
                    - Advanced
                  example: Intermediate
                intensity:
                  type: string
                  enum:
                    - Low
                    - Medium
                    - High
                  example: High
                visibility:
                  type: string
                  enum:
                    - Everyone
                    - Company
                    - Fitsociety
                  example: Company
                status:
                  type: string
                  enum:
                    - Active
                    - Inactive
                    - Draft
                  example: Draft
                templateType:
                  type: string
                  enum:
                    - Template
                    - Assigned
                  example: Template
                duration:
                  type: string
                  description: Multipart JSON string for `WorkoutPlanDuration`.
                  example: >-
                    {"startDate":"2026-04-15","endDate":"2026-06-15","hasEndDate":true}
                schedule:
                  type: string
                  description: >-
                    Multipart JSON string for
                    `WorkoutProgrammeTemplateSchedule`. Multi-week library
                    templates always store a blank start date; the assignment
                    supplies the real start date.
                  example: >-
                    {"mode":"multi_week","releasePolicy":"weekly_from_start","startDate":""}
                useDefaultExerciseSettings:
                  type: string
                  enum:
                    - 'true'
                    - 'false'
                  example: 'true'
                  description: >-
                    Whether new exercises use plan-level defaults. Send false
                    with defaultExerciseValues set to the JSON literal null to
                    disable defaults.
                defaultExerciseValues:
                  type: string
                  description: >-
                    Multipart JSON string for `WorkoutDefaultExerciseValues`, or
                    the JSON literal null when useDefaultExerciseSettings is
                    false.
                  example: >-
                    {"sets":4,"reps":8,"rest":120,"weight":0,"repTempo":"3010","duration":0}
                images:
                  type: string
                  description: >-
                    Multipart JSON string for `WorkoutImageAsset[]`. Combine
                    with uploaded `imageFiles` when you want to attach uploaded
                    media.
                  example: >-
                    [{"url":"https://cdn.example.com/workouts/plan-cover.jpg","width":1280,"height":720}]
                videos:
                  type: string
                  description: >-
                    Multipart JSON string for `WorkoutVideoAsset[]`. Combine
                    with uploaded `videoFiles` when you want to attach uploaded
                    media.
                  example: >-
                    [{"url":"https://cdn.example.com/workouts/plan-demo.mp4","platform":"s3","videoId":"","thumbnail":"https://cdn.example.com/workouts/plan-demo-thumb.jpg","duration":95,"width":1920,"height":1080}]
                imageFiles:
                  type: array
                  items:
                    type: string
                    format: binary
                  maxItems: 5
                  description: >-
                    Preferred binary fields are `imageFiles` and `videoFiles`.
                    Legacy binary aliases `images` and `videos` remain accepted
                    by the backend for backward compatibility. Structured
                    array/object fields must be sent as JSON strings. Max 5
                    image files.
                videoFiles:
                  type: array
                  items:
                    type: string
                    format: binary
                  maxItems: 3
                  description: >-
                    Preferred binary fields are `imageFiles` and `videoFiles`.
                    Legacy binary aliases `images` and `videos` remain accepted
                    by the backend for backward compatibility. Structured
                    array/object fields must be sent as JSON strings. Max 3
                    video files.
      responses:
        '204':
          description: >-
            Workout plan created. Runtime still returns the standard response
            envelope without a `data` property.
          content:
            application/json: {}
        '400':
          description: Missing required fields or workout-plan payload validation failed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
              examples:
                invalidRequest:
                  summary: Invalid request
                  value:
                    error:
                      code: 400
                      key: request.invalid
                      message: The request is invalid.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
                idempotencyRequired:
                  summary: Missing Idempotency-Key
                  value:
                    error:
                      code: 400
                      key: idempotency.required
                      message: >-
                        Idempotency-Key header is required for Public API write
                        requests.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
                idempotencyInvalid:
                  summary: Invalid Idempotency-Key
                  value:
                    error:
                      code: 400
                      key: idempotency.invalid
                      message: Idempotency-Key header must be 200 characters or fewer.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
        '401':
          $ref: '#/components/schemas/ErrorResponse'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
              examples:
                missingBearer:
                  summary: Missing Bearer token
                  value:
                    error:
                      code: 401
                      key: auth.missing_bearer
                      message: Authorization Bearer token is required.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
                invalidToken:
                  summary: Invalid or expired token
                  value:
                    error:
                      code: 401
                      key: auth.invalid_token
                      message: The access token is invalid or expired.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
                invalidClient:
                  summary: Inactive or revoked client
                  value:
                    error:
                      code: 401
                      key: auth.invalid_client
                      message: The Public API client is inactive or revoked.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
        '403':
          description: >-
            Workout V2 programme calendar is disabled for the active company
            (`WORKOUT_V2_PROGRAMME_CALENDAR_DISABLED`) or the caller lacks
            access.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
              examples:
                insufficientScopes:
                  summary: Missing required scope
                  value:
                    error:
                      code: 403
                      key: scopes.insufficient
                      message: The access token does not include the required scope.
                      details:
                        requiredScopes:
                          - required:scope
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
        '404':
          $ref: '#/components/schemas/ErrorResponse'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
              examples:
                notFound:
                  summary: Resource not found
                  value:
                    error:
                      code: 404
                      key: resource.not_found
                      message: The requested Public API resource was not found.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
        '409':
          $ref: '#/components/schemas/ErrorResponse'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
              examples:
                idempotencyConflict:
                  summary: Idempotency-Key conflict
                  value:
                    error:
                      code: 409
                      key: idempotency.conflict
                      message: >-
                        Idempotency-Key was already used with a different
                        request.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
                idempotencyInProgress:
                  summary: Idempotency-Key in progress
                  value:
                    error:
                      code: 409
                      key: idempotency.in_progress
                      message: >-
                        Idempotency-Key is already processing for this Public
                        API client.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
        '413':
          description: One or more uploaded files exceeded the allowed size.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
              examples:
                serverInternalError:
                  summary: Unexpected server error
                  value:
                    error:
                      code: 413
                      key: server.internal_error
                      message: An unexpected Public API server error occurred.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
        '422':
          $ref: '#/components/schemas/ErrorResponse'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
              examples:
                emptyBody:
                  summary: Empty or invalid JSON object body
                  value:
                    error:
                      code: 422
                      key: EMPTY_BODY
                      message: Request body must be a non-empty JSON object.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
        '429':
          $ref: '#/components/schemas/ErrorResponse'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
              examples:
                rateLimitExceeded:
                  summary: Rate limit exceeded
                  value:
                    error:
                      code: 429
                      key: rate_limit.exceeded
                      message: Too many Public API requests. Retry later.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 0
                        resetSeconds: 1
                        retryAfterSeconds: 1
        '500':
          description: Unexpected server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
              examples:
                serverInternalError:
                  summary: Unexpected server error
                  value:
                    error:
                      code: 500
                      key: server.internal_error
                      message: An unexpected Public API server error occurred.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
      security:
        - PublicBearerAuth: []
      x-codeSamples:
        - lang: cURL
          label: cURL
          source: |-
            curl -X POST "https://api.fitsociety.io/public/v1/workout/plans" \
              -H "Authorization: Bearer <access_token>" \
              -H "Idempotency-Key: <stable_request_key>" \
              -H "Content-Type: application/json" \
              -d '{}'
components:
  schemas:
    PublicApiError:
      type: object
      additionalProperties: false
      required:
        - error
        - meta
      properties:
        error:
          type: object
          additionalProperties: false
          required:
            - code
            - key
            - message
          properties:
            code:
              type: integer
              example: 401
            key:
              type: string
              example: auth.invalid_token
            message:
              type: string
              example: The access token is invalid.
            details:
              type: object
              additionalProperties: true
        meta:
          $ref: '#/components/schemas/PublicApiMeta'
    ErrorResponse:
      allOf:
        - $ref: '#/components/schemas/StandardResponse'
        - example:
            status: 401
            error: true
            message: MISSING_AUTH
    PublicApiMeta:
      type: object
      additionalProperties: false
      required:
        - requestId
      properties:
        requestId:
          type: string
          description: Stable request correlation id. Mirrors `X-Request-Id` when supplied.
          example: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
        rateLimit:
          $ref: '#/components/schemas/PublicApiRateLimitMeta'
    StandardResponse:
      type: object
      properties:
        status:
          type: integer
          example: 200
        error:
          type: boolean
          example: false
        message:
          type: string
          example: SUCCESS
      required:
        - status
        - error
        - message
    PublicApiRateLimitMeta:
      type: object
      additionalProperties: false
      properties:
        limit:
          type: integer
          example: 10
        remaining:
          type: integer
          example: 9
        resetSeconds:
          type: integer
          description: Seconds until the current rate limit window resets.
          example: 1
        retryAfterSeconds:
          type: integer
          description: Present when the request was rate limited.
          example: 1
  securitySchemes:
    PublicBearerAuth:
      type: http
      scheme: bearer
      bearerFormat: Opaque
      description: >-
        Public API access token issued by `/public/v1/oauth/token`. Example:
        `Authorization: Bearer fspt_...`. Each resource request rechecks the
        token company's current provider access. Disabling access blocks
        existing tokens with `403 auth.provider_unavailable`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.