partner

POST /v1/partner/customers/{externalId}/sites/{siteId}/wp-login

One-click WordPress admin for your customer's site.

All partner endpoints

All developer docs →

Authentication

Send an API key as a bearer token. The key must carry the partner.domains permission; a key without it is refused with 403, not 404.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/partner/customers/{externalId}/sites/{siteId}/wp-login \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{  }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Mints the same short-lived, single-use, site-bound WordPress sign-in as the customer's own "WordPress admin" button (wpLogin) — same preflight, same token, same audit row (site.wp_login.issued, recording the partner and external_id; the token and URL are never audited). Send the customer's browser to url at once: the token expires in about two minutes and works once. Only for a customer whose organization YOU created (created_org); one who linked an account they already had is refused 422 not_delegable. A site outside the customer's organization, or an unknown customer, is 404. 422 for a site that is not WordPress/WooCommerce, 409 for one that is not serving or not reachable, and 409 with details[].code move_in_progress (a move into the site is not live yet, so its domain still opens the original copy) or import_in_progress (an import into it has not finished); 503 when one-click login is not configured. Requires partner.domains.

Parameters

NameTypeRequiredWhat it is
externalId (path)stringYesYOUR id for that customer — whatever your own system calls them. It is what makes linking idempotent, and it is scoped to your partner programme: another partner's id is a 404…
siteId (path)UuidYesSite ID (UUIDv7).

Request body

NameTypeRequiredWhat it is
wp_usernamestringNoThe WordPress user to sign in as. Omit or leave blank for the site's primary administrator (the plugin resolves it).

Response

NameTypeRequiredWhat it is
urlstringYesThe site URL carrying the token — send the customer's browser here to complete one-click login, unchanged. The token is single-use and short-lived. When the site's plugin has the…
tokenstringYesThe signed SSO token (also embedded in url). Never put it in a query string yourself — follow url as given.
wp_usernamestringYesThe target WordPress user ("" = the site's primary administrator).
expires_atstringYesWhen the token expires (UTC).

Errors this endpoint can return

401 · 403 · 404 · 409 · 422 · 429 · 503