partner
POST /v1/partner/customers/{externalId}/panel-sessions
One-click sign-in to your customer's own control panel.
Authentication
Send an API key as a bearer token. The key must carry the partner.domains permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/partner/customers/{externalId}/panel-sessions \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Returns a URL that signs the customer straight into their own control panel — send their browser there at once. The single-use ticket rides in the URL fragment (never in a server log) and must be redeemed within 300 seconds; the session lasts one hour, is confined to the customer's organization, and can be ended at any time. With site_id the session opens on that site. The dashboard presents it as the customer's own sign-in ("Signed in from" the partner's name), never as a staff session. Audited as partner.panel_session.issued (the URL is never audited). Only for a customer whose organization YOU created (created_org): one who linked an account they already had is 422 not_delegable. 409 no_account_holder until the customer has accepted their invitation (see panel-access, panel-invite). An unknown customer, or a site_id outside their organization, is 404. 503 when sign-in grants are not configured. Requires partner.domains.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
externalId (path) | string | Yes | YOUR id for that customer — whatever your own system calls them. It is what makes linking idempotent, and it is scoped to your partner programme: another partner's id is a 404… |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
site_id | object | No | Open the session on this site (it must be in the customer's organization). |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
url | string | Yes | Open this in the customer's browser. The single-use ticket is in the fragment; redeem once, within 300 seconds. |
expires_at | string | Yes | When the SESSION ends (one hour), not the ticket. |
client_org_id | Uuid | Yes | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
Errors this endpoint can return
401 · 403 · 404 · 409 · 422 · 429 · 503