compute

POST /v1/panels/connections/{connectionId}/login-link

One-click login — a one-time administrative session on the panel.

Tous les points de terminaison compute

Authentification

Envoyez une clé d'API en tant que jeton du porteur (bearer token). Cet endpoint n'indique pas de permission spécifique dans la spécification, attribuez donc à votre clé le minimum requis et vérifiez la réponse plutôt que de faire des suppositions.

Cet endpoint ne prend aucun identifiant d'organisation. Votre clé identifie déjà l'organisation à laquelle elle appartient, et la réponse y est limitée.

Essayer

Remplacez tout ce qui se trouve entre crochets par vos propres valeurs, et le espace réservé à la clé par une clé de votre tableau de bord.

curl -X POST https://api.zinndigital.com/v1/panels/connections/{connectionId}/login-link \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{  }'

Connecté ? La console d'API de votre tableau de bord saisit votre véritable ID d'organisation ainsi que votre propre clé, et exécute la requête sur l'API de production afin que vous puissiez voir la réponse réelle. Ouvrir ce point de terminaison dans la console API

Détails

⚖️ The owner's ask of 2026-08-28, verbatim: *"one click login to the plesk panels"*. ⛔⛔ **The returned `url` is a LIVE CREDENTIAL.** It is an authenticated administrative session on the customer's panel. It is never logged, never persisted and never emailed — it is returned to one authenticated caller and belongs straight in their browser. Plesk's links are single-use and die on first redemption, which is a stronger guarantee than any expiry clock; `expiresAt` is therefore absent rather than guessed. ⛔ Gated on `sites.panel_access` — **not** `sites.view`. That key means *direct server-level access to a customer's hosting*: it is held by `owner`, `dev` and staff `ops`, and deliberately not by `support` or any read-only role. A read-only role must never be able to mint an administrative session. ⛔ Answers `422` when this connection has not proved it can create login links, and refuses BEFORE calling the panel. A button that reaches a panel which will refuse it fails on a third-party domain, where neither we nor the customer can see why. Every mint is written to the audit trail with the actor and the panel — never the URL.

Paramètres

NomTypeObligatoireQu'est-ce que c'est
connectionId (path)UuidOuiThe connected panel's id, as `listPanelConnections` reports it.

Corps de la requête

NomTypeObligatoireQu'est-ce que c'est
usernamestringNonA panel user to sign in as. Omit for the panel's administrator.

Réponse

NomTypeObligatoireQu'est-ce que c'est
urlstringOuiThe one-time login URL. Treat it as a secret.
usernamestringOuiWhich panel user the session belongs to. Empty means the administrator.
single_usebooleanOuiWhether the link dies on first use. ⛔ `null` is unknown, and a client must not promise single-use on the strength of it. Plesk's are single-use, which is a stronger guarantee th…

Erreurs que cet point de terminaison peut renvoyer

401 · 403 · 404 · 422 · 429 · 503