partner

POST /v1/partner/customers/{externalId}/panel-sessions

One-click sign-in to your customer's own control panel.

All partner endpoints

All developer docs →

Authentication

Send an API key as a bearer token. The key must carry the partner.domains permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/partner/customers/{externalId}/panel-sessions \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{  }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Returns a URL that signs the customer straight into their own control panel — send their browser there at once. The single-use ticket rides in the URL fragment (never in a server log) and must be redeemed within 300 seconds; the session lasts one hour, is confined to the customer's organization, and can be ended at any time. With site_id the session opens on that site. The dashboard presents it as the customer's own sign-in ("Signed in from" the partner's name), never as a staff session. Audited as partner.panel_session.issued (the URL is never audited). Only for a customer whose organization YOU created (created_org): one who linked an account they already had is 422 not_delegable. 409 no_account_holder until the customer has accepted their invitation (see panel-access, panel-invite). An unknown customer, or a site_id outside their organization, is 404. 503 when sign-in grants are not configured. Requires partner.domains.

Parameters

NameTypeRequiredWhat it is
externalId (path)stringYesYOUR id for that customer — whatever your own system calls them. It is what makes linking idempotent, and it is scoped to your partner programme: another partner's id is a 404…

Request body

NameTypeRequiredWhat it is
site_idobjectNoOpen the session on this site (it must be in the customer's organization).

Response

NameTypeRequiredWhat it is
urlstringYesOpen this in the customer's browser. The single-use ticket is in the fragment; redeem once, within 300 seconds.
expires_atstringYesWhen the SESSION ends (one hour), not the ticket.
client_org_idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).

Errors this endpoint can return

401 · 403 · 404 · 409 · 422 · 429 · 503