compute

POST /v1/panels/connections/{connectionId}/login-link

One-click login — a one-time administrative session on the panel.

Alle compute-eindpunten

Authenticatie

Stuur een API-sleutel mee als bearer token. Dit eindpunt vermeldt geen specifieke toestemming in de specificatie, dus geef uw sleutel de minimale rechten die nodig zijn en controleer het antwoord in plaats van zomaar wat aan te nemen.

Dit eindpunt vereist geen organisatie-id. Uw sleutel identificeert al de organisatie waartoe deze behoort, en het antwoord is hierop afgestemd.

Probeer het

Vervang alles tussen punthaakjes door uw eigen waarden en de sleutelplaatsvervanger door een sleutel uit uw dashboard.

curl -X POST https://api.zinndigital.com/v1/panels/connections/{connectionId}/login-link \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{  }'

Ingelogd? De API-console in je dashboard vult je echte organisatie-id en je eigen sleutel in, en voert het verzoek uit tegen de live API zodat je de daadwerkelijke respons kunt zien. Open dit eindpunt in de API-console

Details

⚖️ The owner's ask of 2026-08-28, verbatim: *"one click login to the plesk panels"*. ⛔⛔ **The returned `url` is a LIVE CREDENTIAL.** It is an authenticated administrative session on the customer's panel. It is never logged, never persisted and never emailed — it is returned to one authenticated caller and belongs straight in their browser. Plesk's links are single-use and die on first redemption, which is a stronger guarantee than any expiry clock; `expiresAt` is therefore absent rather than guessed. ⛔ Gated on `sites.panel_access` — **not** `sites.view`. That key means *direct server-level access to a customer's hosting*: it is held by `owner`, `dev` and staff `ops`, and deliberately not by `support` or any read-only role. A read-only role must never be able to mint an administrative session. ⛔ Answers `422` when this connection has not proved it can create login links, and refuses BEFORE calling the panel. A button that reaches a panel which will refuse it fails on a third-party domain, where neither we nor the customer can see why. Every mint is written to the audit trail with the actor and the panel — never the URL.

Parameters

NaamTypeVerplichtWat dit is
connectionId (path)UuidJaThe connected panel's id, as `listPanelConnections` reports it.

Aanvraaglichaam

NaamTypeVerplichtWat dit is
usernamestringNeeA panel user to sign in as. Omit for the panel's administrator.

Reactie

NaamTypeVerplichtWat dit is
urlstringJaThe one-time login URL. Treat it as a secret.
usernamestringJaWhich panel user the session belongs to. Empty means the administrator.
single_usebooleanJaWhether the link dies on first use. ⛔ `null` is unknown, and a client must not promise single-use on the strength of it. Plesk's are single-use, which is a stronger guarantee th…

Fouten die dit eindpunt kan retourneren

401 · 403 · 404 · 422 · 429 · 503