curl -X PATCH "https://api.fitsociety.io/public/v1/workout/plans/template/{planId}/moments/{planMomentId}/reorder" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'PATCH',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({exerciseIds: ['6a2695e980ea215a52485b82', '6a2691fd80ea215a52485aed']})
};
fetch('https://api.fitsociety.io/public/v1/workout/plans/template/{planId}/moments/{planMomentId}/reorder', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/plans/template/{planId}/moments/{planMomentId}/reorder"
payload = { "exerciseIds": ["6a2695e980ea215a52485b82", "6a2691fd80ea215a52485aed"] }
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"data": {
"planId": "67f1234567890abcdef1234",
"planMomentId": "67f1234567890abcdef1234",
"exerciseCount": 2,
"exercises": [
{
"planExerciseId": "67f1234567890abcdef1234",
"exerciseId": "67f1234567890abcdef1234",
"groupId": "",
"order": 0
}
]
},
"meta": {
"requestId": "4f849d7d-f4f1-45cc-b4b7-3984a3d17f83",
"rateLimit": {
"limit": 10,
"remaining": 9,
"resetSeconds": 1
},
"idempotency": {
"replayed": false
}
}
}Reorder exercises within a plan moment
Reorder the exercises within one plan moment (day). The request must list the full set of the moment’s active planExercise subdoc _ids in the desired top-to-bottom order; each exercise’s order is reassigned to its index in the array. Superset grouping (groupId) is preserved — only order changes. Keep superset members adjacent in the array to keep the group contiguous.
Requires the workout_plans:write scope. This operation maps to /app/v1/workout/plans/template/:planId/moments/:planMomentId/reorder and retains its Workout V2 permission, feature-flag, and resource-scope checks.
The clientId path parameter is resolved inside the company bound to the Public API token when present.
curl -X PATCH "https://api.fitsociety.io/public/v1/workout/plans/template/{planId}/moments/{planMomentId}/reorder" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'PATCH',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({exerciseIds: ['6a2695e980ea215a52485b82', '6a2691fd80ea215a52485aed']})
};
fetch('https://api.fitsociety.io/public/v1/workout/plans/template/{planId}/moments/{planMomentId}/reorder', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/plans/template/{planId}/moments/{planMomentId}/reorder"
payload = { "exerciseIds": ["6a2695e980ea215a52485b82", "6a2691fd80ea215a52485aed"] }
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"data": {
"planId": "67f1234567890abcdef1234",
"planMomentId": "67f1234567890abcdef1234",
"exerciseCount": 2,
"exercises": [
{
"planExerciseId": "67f1234567890abcdef1234",
"exerciseId": "67f1234567890abcdef1234",
"groupId": "",
"order": 0
}
]
},
"meta": {
"requestId": "4f849d7d-f4f1-45cc-b4b7-3984a3d17f83",
"rateLimit": {
"limit": 10,
"remaining": 9,
"resetSeconds": 1
},
"idempotency": {
"replayed": false
}
}
}Authorizations
Public API access token issued by /public/v1/oauth/token. Example: Authorization: Bearer fspt_.... Each resource request rechecks the token company's current provider access. Disabling access blocks existing tokens with 403 auth.provider_unavailable.
Headers
Required for Public API write requests. Reusing the same key with the same method, path, and body replays the stored successful response; reusing it with a different request returns 409 idempotency.conflict.
1 - 200"booking-create-20260714-001"
Path Parameters
Workout plan id.
"67f1234567890abcdef1234"
Plan moment (day) id.
"67f1234567890abcdef1234"
Body
Every active planExercise subdoc _id in this moment, in the new order. Must be an exact permutation of the moment's active exercises.
1[
"6a2695e980ea215a52485b82",
"6a2691fd80ea215a52485aed"
]