partner
POST /v1/partner/customers/{externalId}/sites/{siteId}/wp-login
One-click WordPress admin for your customer's site.
Authentication
Send an API key as a bearer token. The key must carry the partner.domains permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/partner/customers/{externalId}/sites/{siteId}/wp-login \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Mints the same short-lived, single-use, site-bound WordPress sign-in as the customer's own "WordPress admin" button (wpLogin) — same preflight, same token, same audit row (site.wp_login.issued, recording the partner and external_id; the token and URL are never audited). Send the customer's browser to url at once: the token expires in about two minutes and works once. Only for a customer whose organization YOU created (created_org); one who linked an account they already had is refused 422 not_delegable. A site outside the customer's organization, or an unknown customer, is 404. 422 for a site that is not WordPress/WooCommerce, 409 for one that is not serving or not reachable, and 409 with details[].code move_in_progress (a move into the site is not live yet, so its domain still opens the original copy) or import_in_progress (an import into it has not finished); 503 when one-click login is not configured. Requires partner.domains.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
externalId (path) | string | Yes | YOUR id for that customer — whatever your own system calls them. It is what makes linking idempotent, and it is scoped to your partner programme: another partner's id is a 404… |
siteId (path) | Uuid | Yes | Site ID (UUIDv7). |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
wp_username | string | No | The WordPress user to sign in as. Omit or leave blank for the site's primary administrator (the plugin resolves it). |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
url | string | Yes | The site URL carrying the token — send the customer's browser here to complete one-click login, unchanged. The token is single-use and short-lived. When the site's plugin has the… |
token | string | Yes | The signed SSO token (also embedded in url). Never put it in a query string yourself — follow url as given. |
wp_username | string | Yes | The target WordPress user ("" = the site's primary administrator). |
expires_at | string | Yes | When the token expires (UTC). |
Errors this endpoint can return
401 · 403 · 404 · 409 · 422 · 429 · 503