curl -X PATCH "https://api.fitsociety.io/public/v1/workout/performance/sessions/{sessionId}/supersets/{groupId}/rest" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'PATCH',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({supersetRest: 90})
};
fetch('https://api.fitsociety.io/public/v1/workout/performance/sessions/{sessionId}/supersets/{groupId}/rest', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/performance/sessions/{sessionId}/supersets/{groupId}/rest"
payload = { "supersetRest": 90 }
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)Set a superset's rest (client's own)
Sets (or clears) the CLIENT’s own rest for one superset in this session — the single “Rest time” a group gets, since a superset is executed as a round and rests once after its last member rather than per set. Stored against the group’s groupId on the session.
The session-side twin of PATCH …/plans/template//moments//supersets//rest (the coach’s prescription). The two are INDEPENDENT and are surfaced separately by the read screens — this one drives supersetRest, the plan one supersetRestPlan — so neither overwrites the other.
Addresses each superset DIRECTLY by its groupId, so several groups in one session can be set in any order and at any time — unlike supersetRest on PUT …/exercises/, which can only reach a group through a member that has already been logged. Works for plan-day, freestyle and WOD sessions.
Requires the workout_sessions:write scope. This operation maps to /app/v1/workout/performance/sessions/:sessionId/supersets/:groupId/rest and retains its Workout V2 permission, feature-flag, and resource-scope checks.
The clientId path parameter is resolved inside the company bound to the Public API token when present.
curl -X PATCH "https://api.fitsociety.io/public/v1/workout/performance/sessions/{sessionId}/supersets/{groupId}/rest" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'PATCH',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({supersetRest: 90})
};
fetch('https://api.fitsociety.io/public/v1/workout/performance/sessions/{sessionId}/supersets/{groupId}/rest', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/performance/sessions/{sessionId}/supersets/{groupId}/rest"
payload = { "supersetRest": 90 }
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)Authorizations
Public API access token issued by /public/v1/oauth/token. Example: Authorization: Bearer fspt_.... Each resource request rechecks the token company's current provider access. Disabling access blocks existing tokens with 403 auth.provider_unavailable.
Headers
Required for Public API write requests. Reusing the same key with the same method, path, and body replays the stored successful response; reusing it with a different request returns 409 idempotency.conflict.
1 - 200"booking-create-20260714-001"
Path Parameters
Workout session id.
"67f1234567890abcdef1234"
Superset group id.
"67f1234567890abcdef1234"
Query Parameters
Target client id (coaches/admins only).
"67f1234567890abcdef1234"
Body
Rest for the whole superset, in seconds. null (or "") clears it; 0 is a real value meaning no rest. The key must be PRESENT — an empty body is rejected so a stray request cannot blank the value.
x >= 090
"67f1234567890abcdef1234"