hosting
POST /v1/sites/{siteId}/panel-sessions
Mint one single-use panel link, at the moment the customer clicks.
Authentication
Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/panel-sessions \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "tool": <string<phpmyadmin, filemanager, web_ide>> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Returns a freshly minted single-use SSO link into **one** of the site's per-site tools — phpMyAdmin or the File Manager — for the caller to open immediately. **Why this exists rather than reusing `getSiteDatabase`.** The links that endpoint returns are single-use and expire in **180 seconds**, deliberately: a panel link that still works tomorrow is a credential. Rendering one into an `<a href>` on page load therefore hands the customer something that is dead before they have read the card — they click four minutes later and are told the token expired, which reads to them as being asked to log in. This endpoint moves the mint to the click, so the token's whole life is one redirect. Same authority as `getSiteDatabase`: **both** `sites.view` and `sites.panel_access`, RLS-scoped on the narrower key, so holding `sites.panel_access` in one org can never mint a link for another org's site. An out-of-scope or unknown id is a `404`, never a `403`, so this cannot be used to discover that a site exists. `POST` because it is **not idempotent**: every call writes a new single-use token to the hosting box. A `GET` would be re-issued by a prefetch, a proxy or the back button, burning a token each time. A site with no panel to open is a `409` carrying the same sentence the Tools card shows — never a `200` with a null URL.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
siteId (path) | Uuid | Yes | Site ID (UUIDv7). |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
tool | string<phpmyadmin, filemanager, web_ide> | Yes | `phpmyadmin` opens the site's own database; `filemanager` opens the site's own home directory; `web_ide` opens VS Code in the browser against the site's files. A closed set on p… |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
url | string | Yes | The HTTPS single-use SSO link. Never null on a `200` — a site with no panel to open is a `409`. |
reason | string | No | Empty on success; present so one client component can render both shapes. |
Errors this endpoint can return
401 · 403 · 404 · 409 · 422 · 429