curl -X PATCH "https://api.fitsociety.io/public/v1/workout/clients/{clientId}/plans/template/{templateId}/status" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'PATCH',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({status: 'Inactive', clientId: '67f1234567890abcdef1234'})
};
fetch('https://api.fitsociety.io/public/v1/workout/clients/{clientId}/plans/template/{templateId}/status', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/clients/{clientId}/plans/template/{templateId}/status"
payload = {
"status": "Inactive",
"clientId": "67f1234567890abcdef1234"
}
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)Switch the client's assigned plan on or off
Sets one of the client’s OWN assigned plans to Active or Inactive.
Inactive is a reversible pause, not a removal: nothing is deleted and no session, logged performance or schedule is touched, so switching back restores the plan exactly as it was. The client’s own screens keep listing a paused plan (GET /app/v1/workout/client/training-page, GET /app/v1/workout/plans/client/template-with-progress/{templateId}), each carrying status and isActive, so it never becomes unreachable. Use .../archive instead to take a plan out of the lists entirely.
Body status given → set exactly that. Body status omitted (an empty body is valid) → flip the current status. Prefer sending the explicit value: a blind flip races with a second device and lands on whichever value it happened to read.
Idempotent — asking for the state it is already in returns 200 with changed: false, never a conflict. Draft is rejected: it belongs to an unpublished library template, not to an assigned plan.
Scoped to templateType: "Assigned" and to the caller’s own plan, so a shared library template can never be switched off for everyone. A coach/admin token must pass clientId. The coach-side equivalent is PATCH /app/v1/workout/plans/assigned/{planId}/status.
Requires the workout_client_plans:write scope. This operation maps to /app/v1/workout/plans/client/template/:templateId/status and retains its Workout V2 permission, feature-flag, and resource-scope checks.
The clientId path parameter identifies the client represented by the request context.
curl -X PATCH "https://api.fitsociety.io/public/v1/workout/clients/{clientId}/plans/template/{templateId}/status" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'PATCH',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({status: 'Inactive', clientId: '67f1234567890abcdef1234'})
};
fetch('https://api.fitsociety.io/public/v1/workout/clients/{clientId}/plans/template/{templateId}/status', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/clients/{clientId}/plans/template/{templateId}/status"
payload = {
"status": "Inactive",
"clientId": "67f1234567890abcdef1234"
}
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)Authorizations
Public API access token issued by /public/v1/oauth/token. Example: Authorization: Bearer fspt_.... Each resource request rechecks the token company's current provider access. Disabling access blocks existing tokens with 403 auth.provider_unavailable.
Headers
Required for Public API write requests. Reusing the same key with the same method, path, and body replays the stored successful response; reusing it with a different request returns 409 idempotency.conflict.
1 - 200"booking-create-20260714-001"
Path Parameters
Assigned workout plan id.
"67f1234567890abcdef1234"
Client in the company bound to the Public API token.
^[a-fA-F0-9]{24}$