hosting
POST /v1/sites/{siteId}/wp-login
Mint a one-click WordPress admin login token.
प्रमाणीकरण
एपिआई कुञ्जीलाई बियरर टोकन (bearer token) को रूपमा पठाउनुहोस्। कुञ्जीसँग sites.wp_login अनुमति हुनुपर्छ; अनुमति नभएको कुञ्जीलाई 404 होइन, 403 मार्फत अस्वीकार गरिन्छ।
यो इन्डपोइन्टले कुनै संस्थाको आइडी लिँदैन। तपाईंको कुञ्जीले यस अन्तर्गत पर्ने संस्थालाई पहिल्यै पहिचान गर्छ, र प्रतिक्रिया त्यसैमा सीमित हुन्छ।
प्रयास गर्नुहोस्
कोणीय कोष्ठकभित्र भएका जुनसुकै कुरालाई आफ्नो मानहरूद्वारा बदल्नुहोस्, र मुख्य स्थानहोल्डरलाई तपाईंको ड्यासबोर्डको कुञ्जीद्वारा बदल्नुहोस्।
curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/wp-login \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ }'लगइन गर्नुभएको छ? तपाईंको ड्यासबोर्डमा रहेको API कन्सोलले तपाईंको वास्तविक संस्थाको आईडी र आफ्नै कुञ्जी भरिदिन्छ, र लाइभ API विरुद्ध अनुरोध चलाउँछ ताकि तपाईंले वास्तविक प्रतिक्रिया हेर्न सक्नुहोस्। यो एन्डपोइन्टलाई API कन्सोलमा खोल्नुहोस्
विवरणहरू
Returns a short-lived, signed SSO token (and the URL that carries it) for one-click sign-in to the site's `wp-admin` (V1 parity). The customer's browser is sent to the URL; the Zinn® plugin on the site verifies the token, enforces single-use, and establishes the wp-admin session. The token is bound to this site, expires in ~2 minutes, and its issuance is audit-logged with the real actor. Requires `sites.wp_login`. Only WordPress/WooCommerce sites that are **serving** are eligible (422 / 409 otherwise); if one-click login is not configured on the platform the endpoint returns 503 and mints nothing. ⛔⛔ **A `201` from this endpoint is a claim about the SITE, not merely about the signature, and it did not used to be.** Minting is local, cheap and always succeeds; every reason a grant cannot work lives on the box. Before the preflight below existed this endpoint answered `201` with a correctly-signed URL for a site whose WordPress had no SSO key, no plugin to serve the route, and — measured on 2026-08-15 — was returning **HTTP 500 to every request**. Three such grants were issued and audit-logged in one day, each of which opened an error page. So before signing anything the endpoint now checks, and repairs what it can: * the hosting platform can receive an SSO key at all — this platform exposes no shell and no wp-cli, so its sites can never honour one and are refused `422` (`PLATFORM_CANNOT_SSO`) rather than handed a token; * the plugin that serves the route is installed and active — **installed automatically if it is not**, because a precondition the platform can satisfy itself is not one the customer should read about; * the site's `ZINN_SSO_KEY` is present **on the box**, asked of the file rather than of our own record of having written it — the two disagreed; * and the site actually answers HTTP without a server error, probed from the box against the origin so a CDN cache cannot report health the site no longer has. A site that fails this is `409` (`SITE_NOT_REACHABLE`). The error body's `reason` carries which of those failed, so a client can say the true thing instead of "something went wrong".
प्यारामिटरहरू
| नाम | प्रकार | आवश्यक | यो के हो |
|---|---|---|---|
siteId (path) | Uuid | हुन्छ | Site ID (UUIDv7). |
अनुरोध बडी
| नाम | प्रकार | आवश्यक | यो के हो |
|---|---|---|---|
wp_username | string | हैन | The WordPress user to sign in as. Omit or leave blank for the site's primary administrator (the plugin resolves it). |
प्रतिक्रिया
| नाम | प्रकार | आवश्यक | यो के हो |
|---|---|---|---|
url | string | हुन्छ | The site URL carrying the token — send the customer's browser here to complete one-click login. The token is single-use and short-lived. |
token | string | हुन्छ | The signed SSO token (also embedded in `url`). |
wp_username | string | हुन्छ | The target WordPress user ("" = the site's primary administrator). |
expires_at | string | हुन्छ | When the token expires (UTC). |
यो इन्डपोइन्टले फर्काउन सक्ने त्रुटिहरू
401 · 403 · 404 · 409 · 422 · 429 · 503