> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fitsociety.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Read the latest 100 plan decisions and pending reviews

> Requires all cardio company gates and client Training V2. Staff reads/writes enforce linked-client member scope and training.programmes.view/update. Apply requires expectedUpdatedAt from preview and explicit complete prescriptions. Changes are transactional, preserve historical logs, IDs, unrelated activities and weekly volume limits. Goal time/challenge may change; distance/race date require a new plan. Undo uses stored server patches, requires the latest unchanged plan and no affected execution or past sessions, and cannot restore intensity during an active athlete niggle. Worker queues coach reviews rather than inventing prescription inputs. Undo intentionally accepts an empty body.

Requires the workout_client_plans:read scope. This operation maps to /app/v1/workout/cardio/clients/:clientId/plans/:planId/adaptation/decisions and retains its Workout V2 permission, feature-flag, and resource-scope checks.

The clientId path parameter is resolved inside the company bound to the Public API token when present.



## OpenAPI

````yaml /openapi/public-v1.json get /public/v1/workout/cardio/clients/{clientId}/plans/{planId}/adaptation/decisions
openapi: 3.1.0
info:
  title: FITsociety Public API v1
  version: 1.0.0
  description: >-
    Developer Public API endpoints under `/public/v1`. This reference is
    filtered to OAuth/Bearer Public API resources and excludes provider callback
    receivers, storefront routes, public widgets, wishlist routes, and
    access-device validation endpoints.
  contact:
    name: FITsociety Engineering
servers:
  - url: https://api.fitsociety.io
    description: Production
security: []
tags:
  - name: Workout
    description: >-
      Workout V2 libraries, programmes, client plans, calendars, sessions,
      groups, settings and progress. AI operations are excluded.
  - name: OAuth
    description: Public API OAuth endpoints for server-to-server client credentials.
  - name: Health
    description: Public API token health checks.
  - name: Platform
    description: >-
      Inspect Public API client context, capabilities, scopes, and redacted
      audit logs.
  - name: Company Catalog
    description: Read and manage company profile metadata and locations.
  - name: Clients
    description: >-
      Create and manage clients through the Public API using Bearer access
      tokens.
  - name: Coaches
    description: Retrieve coaches for the authenticated company via integrations.
  - name: Calendar Events
    description: Read Public API calendar events.
  - name: Calendar Templates
    description: >-
      Read and manage event types and event templates used by calendar
      availability and bookings.
  - name: Calendar Extensions
    description: >-
      Read recurring bookings, booking requests, calendar tasks, and
      availability closure metadata.
  - name: Availability
    description: Read bookable availability slots and signed availability tokens.
  - name: Availability Management
    description: >-
      Manage coach and location availability templates used to derive bookable
      slots.
  - name: Bookings
    description: Read and manage Public API bookings.
  - name: Finance
    description: >-
      Read invoices, transactions, products, subscriptions, and memberships with
      guarded finance writes.
  - name: Credits
    description: >-
      Read company-wide and client-scoped credit allocations, mutations, and
      guarded credit adjustments.
  - name: Exports
    description: >-
      Create and monitor asynchronous company exports through Public API Bearer
      endpoints.
  - name: Webhooks
    description: >-
      Manage outbound webhook subscriptions and inspect delivery attempts
      through Public API Bearer endpoints.
  - name: Measurements
    description: Read and write client measurement entries.
  - name: Progress Photos
    description: Read client progress photo metadata and short-lived signed media URLs.
  - name: Forms
    description: Read, create, update, and archive company form templates.
  - name: Intakes
    description: Assign intake forms and read client intake assignments and submissions.
  - name: Check-ups
    description: >-
      Schedule and cancel client check-ups and read their status and
      submissions.
  - name: Documents
    description: >-
      Read client document and folder metadata, register external document
      links, update metadata, and archive documents from Public API listings.
      Binary upload, permanent deletion, and company-wide document management
      are not exposed.
  - name: Habits
    description: Read habits and habit entries.
  - name: Goals
    description: Read client goal summaries.
  - name: Conversations
    description: >-
      Read and manage direct and group chat conversations through the Public
      API.
  - name: Reports
    description: Read aggregate attendance, revenue, and retention summaries.
paths:
  /public/v1/workout/cardio/clients/{clientId}/plans/{planId}/adaptation/decisions:
    get:
      tags:
        - Workout
      summary: Read the latest 100 plan decisions and pending reviews
      description: >-
        Requires all cardio company gates and client Training V2. Staff
        reads/writes enforce linked-client member scope and
        training.programmes.view/update. Apply requires expectedUpdatedAt from
        preview and explicit complete prescriptions. Changes are transactional,
        preserve historical logs, IDs, unrelated activities and weekly volume
        limits. Goal time/challenge may change; distance/race date require a new
        plan. Undo uses stored server patches, requires the latest unchanged
        plan and no affected execution or past sessions, and cannot restore
        intensity during an active athlete niggle. Worker queues coach reviews
        rather than inventing prescription inputs. Undo intentionally accepts an
        empty body.


        Requires the workout_client_plans:read scope. This operation maps to
        /app/v1/workout/cardio/clients/:clientId/plans/:planId/adaptation/decisions
        and retains its Workout V2 permission, feature-flag, and resource-scope
        checks.


        The clientId path parameter is resolved inside the company bound to the
        Public API token when present.
      operationId: >-
        publicWorkoutgetPublicV1WorkoutCardioClientsClientIdPlansPlanIdAdaptationDecisions
      parameters:
        - name: clientId
          in: path
          required: true
          schema:
            type: string
        - name: planId
          in: path
          required: true
          schema:
            type: string
        - name: before
          in: query
          required: false
          schema:
            type: string
          description: >-
            Opaque nextCursor from the previous page. Decisions sort by
            descending ID; at most 100 are returned.
      responses:
        '200':
          description: Review result. Preview diagnostics are returned without writing.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/PublicApiSuccessResponse'
                  - type: object
                    properties:
                      data:
                        $ref: >-
                          #/components/schemas/PublicWorkoutSourceGETAppV1WorkoutCardioClientsClientIdPlansPlanIdAdaptationDecisionsResponse200
              examples:
                success:
                  summary: Successful response
                  value:
                    data:
                      decisions:
                        - _id: 66f7b8b1e13c8d25f4d3d90a
                          planId: 66f7b8b1e13c8d25f4d3d90a
                          kind: weekly_review
                          status: review_required
                          reviewWeek: 1
                          reasonCodes:
                            - string
                          evidence:
                            source: string
                            throughDate: '2026-07-14'
                            qualifyingRunCount: 1
                            missedRunCount: 1
                            latestRunDate: '2026-07-14'
                            reportedAt: '2026-07-14T10:00:00.000Z'
                          affectedItemIds:
                            - string
                          createdAt: '2026-07-14T10:00:00.000Z'
                          appliedAt: '2026-07-14T10:00:00.000Z'
                          appliedBy: string
                          undoneAt: '2026-07-14T10:00:00.000Z'
                          undoneBy: string
                      hasMore: true
                      nextCursor: string
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
        '400':
          description: Invalid IDs or missing body.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
              examples:
                invalidRequest:
                  summary: Invalid request
                  value:
                    error:
                      code: 400
                      key: request.invalid
                      message: The request is invalid.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
        '401':
          $ref: '#/components/schemas/ErrorResponse'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
              examples:
                missingBearer:
                  summary: Missing Bearer token
                  value:
                    error:
                      code: 401
                      key: auth.missing_bearer
                      message: Authorization Bearer token is required.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
                invalidToken:
                  summary: Invalid or expired token
                  value:
                    error:
                      code: 401
                      key: auth.invalid_token
                      message: The access token is invalid or expired.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
                invalidClient:
                  summary: Inactive or revoked client
                  value:
                    error:
                      code: 401
                      key: auth.invalid_client
                      message: The Public API client is inactive or revoked.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
        '403':
          description: >-
            Wrong actor, disabled gate, client not linked, or insufficient
            member scope/permission.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
              examples:
                insufficientScopes:
                  summary: Missing required scope
                  value:
                    error:
                      code: 403
                      key: scopes.insufficient
                      message: The access token does not include the required scope.
                      details:
                        requiredScopes:
                          - required:scope
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
        '404':
          description: Scoped assigned plan or decision not found.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
              examples:
                notFound:
                  summary: Resource not found
                  value:
                    error:
                      code: 404
                      key: resource.not_found
                      message: The requested Public API resource was not found.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
        '409':
          $ref: '#/components/schemas/ErrorResponse'
        '422':
          description: >-
            Invalid, unresolved, not-due, out-of-order, stale or unsafe
            review/undo. No partial writes.
        '429':
          $ref: '#/components/schemas/ErrorResponse'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
              examples:
                rateLimitExceeded:
                  summary: Rate limit exceeded
                  value:
                    error:
                      code: 429
                      key: rate_limit.exceeded
                      message: Too many Public API requests. Retry later.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 0
                        resetSeconds: 1
                        retryAfterSeconds: 1
        '500':
          description: Unexpected server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PublicApiError'
              examples:
                serverInternalError:
                  summary: Unexpected server error
                  value:
                    error:
                      code: 500
                      key: server.internal_error
                      message: An unexpected Public API server error occurred.
                    meta:
                      requestId: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
                      rateLimit:
                        limit: 10
                        remaining: 9
                        resetSeconds: 1
      security:
        - PublicBearerAuth: []
      x-codeSamples:
        - lang: cURL
          label: cURL
          source: >-
            curl -X GET
            "https://api.fitsociety.io/public/v1/workout/cardio/clients/{clientId}/plans/{planId}/adaptation/decisions"
            \
              -H "Authorization: Bearer <access_token>"
components:
  schemas:
    PublicApiSuccessResponse:
      type: object
      additionalProperties: false
      required:
        - data
        - meta
      properties:
        data:
          type: object
        meta:
          $ref: '#/components/schemas/PublicApiMeta'
    PublicWorkoutSourceGETAppV1WorkoutCardioClientsClientIdPlansPlanIdAdaptationDecisionsResponse200:
      type: object
      properties:
        decisions:
          type: array
          items:
            type: object
            properties:
              _id:
                type: string
              planId:
                type: string
              kind:
                type: string
                enum:
                  - weekly_review
                  - niggle_suppression
              status:
                type: string
                enum:
                  - review_required
                  - applied
                  - undone
                  - superseded
              reviewWeek:
                type: integer
              reasonCodes:
                type: array
                items:
                  type: string
                description: Server evidence/diagnostic codes; no fitness-change claim.
              evidence:
                type: object
                properties:
                  source:
                    type: string
                  throughDate:
                    type:
                      - string
                      - 'null'
                    format: date
                  qualifyingRunCount:
                    type: integer
                    minimum: 0
                  missedRunCount:
                    type: integer
                    minimum: 0
                  latestRunDate:
                    type:
                      - string
                      - 'null'
                    format: date
                  reportedAt:
                    type:
                      - string
                      - 'null'
                    format: date-time
                additionalProperties: false
              affectedItemIds:
                type: array
                items:
                  type: string
              createdAt:
                type: string
                format: date-time
              appliedAt:
                type: string
                format: date-time
              appliedBy:
                type: string
              undoneAt:
                type: string
                format: date-time
              undoneBy:
                type: string
        hasMore:
          type: boolean
        nextCursor:
          type:
            - string
            - 'null'
    PublicApiError:
      type: object
      additionalProperties: false
      required:
        - error
        - meta
      properties:
        error:
          type: object
          additionalProperties: false
          required:
            - code
            - key
            - message
          properties:
            code:
              type: integer
              example: 401
            key:
              type: string
              example: auth.invalid_token
            message:
              type: string
              example: The access token is invalid.
            details:
              type: object
              additionalProperties: true
        meta:
          $ref: '#/components/schemas/PublicApiMeta'
    ErrorResponse:
      allOf:
        - $ref: '#/components/schemas/StandardResponse'
        - example:
            status: 401
            error: true
            message: MISSING_AUTH
    PublicApiMeta:
      type: object
      additionalProperties: false
      required:
        - requestId
      properties:
        requestId:
          type: string
          description: Stable request correlation id. Mirrors `X-Request-Id` when supplied.
          example: 4f849d7d-f4f1-45cc-b4b7-3984a3d17f83
        rateLimit:
          $ref: '#/components/schemas/PublicApiRateLimitMeta'
    StandardResponse:
      type: object
      properties:
        status:
          type: integer
          example: 200
        error:
          type: boolean
          example: false
        message:
          type: string
          example: SUCCESS
      required:
        - status
        - error
        - message
    PublicApiRateLimitMeta:
      type: object
      additionalProperties: false
      properties:
        limit:
          type: integer
          example: 10
        remaining:
          type: integer
          example: 9
        resetSeconds:
          type: integer
          description: Seconds until the current rate limit window resets.
          example: 1
        retryAfterSeconds:
          type: integer
          description: Present when the request was rate limited.
          example: 1
  securitySchemes:
    PublicBearerAuth:
      type: http
      scheme: bearer
      bearerFormat: Opaque
      description: >-
        Public API access token issued by `/public/v1/oauth/token`. Example:
        `Authorization: Bearer fspt_...`. Each resource request rechecks the
        token company's current provider access. Disabling access blocks
        existing tokens with `403 auth.provider_unavailable`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.