curl -X POST "https://api.fitsociety.io/public/v1/workout/cardio/clients/{clientId}/plans/{planId}/adaptation/decisions/{decisionId}/undo" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'POST',
headers: {'Idempotency-Key': '<idempotency-key>', Authorization: 'Bearer <token>'}
};
fetch('https://api.fitsociety.io/public/v1/workout/cardio/clients/{clientId}/plans/{planId}/adaptation/decisions/{decisionId}/undo', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/cardio/clients/{clientId}/plans/{planId}/adaptation/decisions/{decisionId}/undo"
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>"
}
response = requests.post(url, headers=headers)
print(response.text)Undo the latest safe decision
Requires all cardio company gates and client Training V2. Staff reads/writes enforce linked-client member scope and training.programmes.view/update. Apply requires expectedUpdatedAt from preview and explicit complete prescriptions. Changes are transactional, preserve historical logs, IDs, unrelated activities and weekly volume limits. Goal time/challenge may change; distance/race date require a new plan. Undo uses stored server patches, requires the latest unchanged plan and no affected execution or past sessions, and cannot restore intensity during an active athlete niggle. Worker queues coach reviews rather than inventing prescription inputs. Undo intentionally accepts an empty body.
Requires the workout_client_plans:write scope. This operation maps to /app/v1/workout/cardio/clients/:clientId/plans/:planId/adaptation/decisions/:decisionId/undo and retains its Workout V2 permission, feature-flag, and resource-scope checks.
The clientId path parameter is resolved inside the company bound to the Public API token when present.
curl -X POST "https://api.fitsociety.io/public/v1/workout/cardio/clients/{clientId}/plans/{planId}/adaptation/decisions/{decisionId}/undo" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'POST',
headers: {'Idempotency-Key': '<idempotency-key>', Authorization: 'Bearer <token>'}
};
fetch('https://api.fitsociety.io/public/v1/workout/cardio/clients/{clientId}/plans/{planId}/adaptation/decisions/{decisionId}/undo', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/cardio/clients/{clientId}/plans/{planId}/adaptation/decisions/{decisionId}/undo"
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>"
}
response = requests.post(url, headers=headers)
print(response.text)Authorizations
Public API access token issued by /public/v1/oauth/token. Example: Authorization: Bearer fspt_.... Each resource request rechecks the token company's current provider access. Disabling access blocks existing tokens with 403 auth.provider_unavailable.
Headers
Required for Public API write requests. Reusing the same key with the same method, path, and body replays the stored successful response; reusing it with a different request returns 409 idempotency.conflict.
1 - 200"booking-create-20260714-001"