curl -X PATCH "https://api.fitsociety.io/public/v1/workout/performance/sessions/{sessionId}/items/reorder" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'PATCH',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
items: [
{type: 'superset', groupId: '6a2b1c3d4e5f60718293a4b5'},
{type: 'exercise', performanceId: '67f1234567890abcdef9103'}
]
})
};
fetch('https://api.fitsociety.io/public/v1/workout/performance/sessions/{sessionId}/items/reorder', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/performance/sessions/{sessionId}/items/reorder"
payload = { "items": [
{
"type": "superset",
"groupId": "6a2b1c3d4e5f60718293a4b5"
},
{
"type": "exercise",
"performanceId": "67f1234567890abcdef9103"
}
] }
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"data": {
"sessionId": "67f1234567890abcdef1234",
"itemCount": 2,
"items": [
{
"type": "exercise",
"performanceId": "67f1234567890abcdef1234",
"groupId": "66f7b8b1e13c8d25f4d3d90a",
"order": 0
}
]
},
"meta": {
"requestId": "4f849d7d-f4f1-45cc-b4b7-3984a3d17f83",
"rateLimit": {
"limit": 10,
"remaining": 9,
"resetSeconds": 1
},
"idempotency": {
"replayed": false
}
}
}Reorder the top-level items of a session (freestyle)
Freestyle (performance-based) equivalent of the plan-day item reorder. Reorders the TOP-LEVEL list the freestyle screen renders, where a superset is a single block. List EVERY top-level unit in the new order: a standalone performance as { type: "exercise", performanceId }, or a whole superset as { type: "superset", groupId } (its internal order is preserved). order is reassigned as a contiguous sequence, expanding each superset into a contiguous run. Must be a full cover — every standalone and every superset listed exactly once.
Requires the workout_sessions:write scope. This operation maps to /app/v1/workout/performance/sessions/:sessionId/items/reorder and retains its Workout V2 permission, feature-flag, and resource-scope checks.
The clientId path parameter is resolved inside the company bound to the Public API token when present.
curl -X PATCH "https://api.fitsociety.io/public/v1/workout/performance/sessions/{sessionId}/items/reorder" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'PATCH',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
items: [
{type: 'superset', groupId: '6a2b1c3d4e5f60718293a4b5'},
{type: 'exercise', performanceId: '67f1234567890abcdef9103'}
]
})
};
fetch('https://api.fitsociety.io/public/v1/workout/performance/sessions/{sessionId}/items/reorder', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/performance/sessions/{sessionId}/items/reorder"
payload = { "items": [
{
"type": "superset",
"groupId": "6a2b1c3d4e5f60718293a4b5"
},
{
"type": "exercise",
"performanceId": "67f1234567890abcdef9103"
}
] }
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text){
"data": {
"sessionId": "67f1234567890abcdef1234",
"itemCount": 2,
"items": [
{
"type": "exercise",
"performanceId": "67f1234567890abcdef1234",
"groupId": "66f7b8b1e13c8d25f4d3d90a",
"order": 0
}
]
},
"meta": {
"requestId": "4f849d7d-f4f1-45cc-b4b7-3984a3d17f83",
"rateLimit": {
"limit": 10,
"remaining": 9,
"resetSeconds": 1
},
"idempotency": {
"replayed": false
}
}
}Authorizations
Public API access token issued by /public/v1/oauth/token. Example: Authorization: Bearer fspt_.... Each resource request rechecks the token company's current provider access. Disabling access blocks existing tokens with 403 auth.provider_unavailable.
Headers
Required for Public API write requests. Reusing the same key with the same method, path, and body replays the stored successful response; reusing it with a different request returns 409 idempotency.conflict.
1 - 200"booking-create-20260714-001"
Path Parameters
Workout session id.
"67f1234567890abcdef1234"