curl -X POST "https://api.fitsociety.io/public/v1/workout/clients/{clientId}/library/exercises/{exerciseId}/favourite" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'POST',
headers: {'Idempotency-Key': '<idempotency-key>', Authorization: 'Bearer <token>'}
};
fetch('https://api.fitsociety.io/public/v1/workout/clients/{clientId}/library/exercises/{exerciseId}/favourite', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/clients/{clientId}/library/exercises/{exerciseId}/favourite"
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>"
}
response = requests.post(url, headers=headers)
print(response.text){
"data": {
"exerciseId": "67f1234567890abcdef2222",
"isFavourite": true
},
"meta": {
"requestId": "4f849d7d-f4f1-45cc-b4b7-3984a3d17f83",
"rateLimit": {
"limit": 10,
"remaining": 9,
"resetSeconds": 1
},
"idempotency": {
"replayed": false
}
}
}Toggle exercise favourite
Client-only. Toggles the favourite state for the exercise. If already favourited the record is deleted and isFavourite: false is returned (CLIENT_EXERCISE_UNFAVOURITED_SUCCESS). If not yet favourited a new record is created and isFavourite: true is returned (CLIENT_EXERCISE_FAVOURITED_SUCCESS).
Requires the workout_client_plans:write scope. This operation maps to /app/v1/workout/client/library/exercises/:exerciseId/favourite and retains its Workout V2 permission, feature-flag, and resource-scope checks.
The clientId path parameter identifies the client represented by the request context.
curl -X POST "https://api.fitsociety.io/public/v1/workout/clients/{clientId}/library/exercises/{exerciseId}/favourite" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'POST',
headers: {'Idempotency-Key': '<idempotency-key>', Authorization: 'Bearer <token>'}
};
fetch('https://api.fitsociety.io/public/v1/workout/clients/{clientId}/library/exercises/{exerciseId}/favourite', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/clients/{clientId}/library/exercises/{exerciseId}/favourite"
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>"
}
response = requests.post(url, headers=headers)
print(response.text){
"data": {
"exerciseId": "67f1234567890abcdef2222",
"isFavourite": true
},
"meta": {
"requestId": "4f849d7d-f4f1-45cc-b4b7-3984a3d17f83",
"rateLimit": {
"limit": 10,
"remaining": 9,
"resetSeconds": 1
},
"idempotency": {
"replayed": false
}
}
}Authorizations
Public API access token issued by /public/v1/oauth/token. Example: Authorization: Bearer fspt_.... Each resource request rechecks the token company's current provider access. Disabling access blocks existing tokens with 403 auth.provider_unavailable.
Headers
Required for Public API write requests. Reusing the same key with the same method, path, and body replays the stored successful response; reusing it with a different request returns 409 idempotency.conflict.
1 - 200"booking-create-20260714-001"
Path Parameters
Exercise id.
"67f1234567890abcdef1234"
Client in the company bound to the Public API token.
^[a-fA-F0-9]{24}$