curl -X POST "https://api.fitsociety.io/public/v1/workout/clients/{clientId}/plans/workout-history/search" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'POST',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({search: 'fitness'})
};
fetch('https://api.fitsociety.io/public/v1/workout/clients/{clientId}/plans/workout-history/search', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/clients/{clientId}/plans/workout-history/search"
payload = { "search": "fitness" }
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)Workout History search (workoutPlans / exercises / activities)
Requires the workout_progress:read scope. This operation maps to /app/v1/workout/plans/client/workout-history/search and retains its Workout V2 permission, feature-flag, and resource-scope checks.
The clientId path parameter identifies the client represented by the request context.
curl -X POST "https://api.fitsociety.io/public/v1/workout/clients/{clientId}/plans/workout-history/search" \
-H "Authorization: Bearer <access_token>" \
-H "Idempotency-Key: <stable_request_key>" \
-H "Content-Type: application/json" \
-d '{}'const options = {
method: 'POST',
headers: {
'Idempotency-Key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({search: 'fitness'})
};
fetch('https://api.fitsociety.io/public/v1/workout/clients/{clientId}/plans/workout-history/search', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/workout/clients/{clientId}/plans/workout-history/search"
payload = { "search": "fitness" }
headers = {
"Idempotency-Key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)Authorizations
Public API access token issued by /public/v1/oauth/token. Example: Authorization: Bearer fspt_.... Each resource request rechecks the token company's current provider access. Disabling access blocks existing tokens with 403 auth.provider_unavailable.
Headers
Required for Public API write requests. Reusing the same key with the same method, path, and body replays the stored successful response; reusing it with a different request returns 409 idempotency.conflict.
1 - 200"booking-create-20260714-001"
Path Parameters
Client in the company bound to the Public API token.
^[a-fA-F0-9]{24}$Body
Required when the caller is a coach/admin; a client token resolves its own id.
"67f1234567890abcdef1234"
Case-insensitive substring, applied to EACH array on its own name field (plan / exercise / activity). Blank/absent returns everything. Also accepted as ?search=.
"fitness"