curl -X DELETE "https://api.fitsociety.io/public/v1/workout/exercises/delete-multiple" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>"const options = {
method: 'DELETE',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({exerciseIds: ['67f1234567890abcdef1234', '67f1234567890abcdef5678']})
};
fetch('https://api.fitsociety.io/public/v1/workout/exercises/delete-multiple', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/exercises/delete-multiple"
payload = { "exerciseIds": ["67f1234567890abcdef1234", "67f1234567890abcdef5678"] }
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.delete(url, json=payload, headers=headers)
print(response.text){
"data": {
"deletedIds": [
"67f1234567890abcdef1234"
],
"skipped": [
{
"exerciseId": "66f7b8b1e13c8d25f4d3d90a",
"reason": "string"
}
],
"totalRequested": 3,
"totalDeleted": 2
},
"meta": {
"requestId": "4f849d7d-f4f1-45cc-b4b7-3984a3d17f83",
"rateLimit": {
"limit": 10,
"remaining": 9,
"resetSeconds": 1
},
"idempotency": {
"replayed": false
}
}
}Soft-delete several workout v2 exercises
Soft-deletes MANY exercises in one request (sets isDeleted=true, deletedAt=now), applying the exact per-exercise checks of DELETE /app/v1/workout/exercises/exercise/{id}: the caller must pass the company/ownership scope AND be an admin or the exercise’s own creator (a coach may delete only exercises they created; a client only their own). PARTIAL SUCCESS — an id that is malformed, already deleted, out of scope, or not owned by the caller is NOT fatal: it is returned in skipped[] with the message key the single delete would have used, and the rest are still deleted. The response is a 404 only when NOT ONE exercise could be deleted. A coach with no company context fails the whole call with 400 COMPANYID_MISSING.
Requires the workout_library:write scope. This operation maps to /app/v1/workout/exercises/delete-multiple and retains its Workout V2 permission, feature-flag, and resource-scope checks.
The clientId path parameter is resolved inside the company bound to the Public API token when present.
curl -X DELETE "https://api.fitsociety.io/public/v1/workout/exercises/delete-multiple" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>"const options = {
method: 'DELETE',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({exerciseIds: ['67f1234567890abcdef1234', '67f1234567890abcdef5678']})
};
fetch('https://api.fitsociety.io/public/v1/workout/exercises/delete-multiple', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/exercises/delete-multiple"
payload = { "exerciseIds": ["67f1234567890abcdef1234", "67f1234567890abcdef5678"] }
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.delete(url, json=payload, headers=headers)
print(response.text){
"data": {
"deletedIds": [
"67f1234567890abcdef1234"
],
"skipped": [
{
"exerciseId": "66f7b8b1e13c8d25f4d3d90a",
"reason": "string"
}
],
"totalRequested": 3,
"totalDeleted": 2
},
"meta": {
"requestId": "4f849d7d-f4f1-45cc-b4b7-3984a3d17f83",
"rateLimit": {
"limit": 10,
"remaining": 9,
"resetSeconds": 1
},
"idempotency": {
"replayed": false
}
}
}Authorizations
Public API access token issued by /public/v1/oauth/token. Example: Authorization: Bearer fspt_.... Each resource request rechecks the token company's current provider access. Disabling access blocks existing tokens with 403 auth.provider_unavailable.
Headers
Required for Public API write requests. Reusing the same key with the same method, path, and body replays the stored successful response; reusing it with a different request returns 409 idempotency.conflict.
1 - 200"booking-create-20260714-001"
Body
The workout v2 exercise ids to delete.
1