access

POST /v1/access/impersonation/redeem

Exchange a single-use impersonation ticket for a session token.

ਸਾਰੇ access ਐਂਡਪੁਆਇੰਟ

ਸਾਰੇ ਡਿਵੈਲਪਰ ਦਸਤਾਵੇਜ਼

ਪ੍ਰਮਾਣੀਕਰਨ

ਇਹ ਐਂਡਪੁਆਇੰਟ ਜਨਤਕ ਹੈ। ਇਹ ਕੋਈ ਕ੍ਰੈਡਿਸ਼ੀਅਲ ਅਤੇ ਕੋਈ ਸੰਸਥਾ ਨਹੀਂ ਲੈਂਦਾ — ਇਹ ਉਹੀ ਹੈ ਜਿਸਨੂੰ ਸਾਡੀ ਆਪਣੀ ਮਾਰਕੀਟਿੰਗ ਸਾਈਟ ਅਤੇ AI ਜਵਾਬ ਇੰਜਣ ਪੜ੍ਹਦੇ ਹਨ।

ਇਹ ਐਂਡਪੁਆਇੰਟ ਕੋਈ ਸੰਸਥਾ ਆਈਡੀ ਨਹੀਂ ਲੈਂਦਾ। ਤੁਹਾਡੀ ਕੁੰਜੀ ਪਹਿਲਾਂ ਹੀ ਉਸ ਸੰਸਥਾ ਦੀ ਪਛਾਣ ਕਰਦੀ ਹੈ ਜਿਸ ਨਾਲ ਇਹ ਸਬੰਧਤ ਹੈ, ਅਤੇ ਜਵਾਬ ਉਸੇ ਤੱਕ ਸੀਮਤ ਹੈ।

ਕੋਸ਼ਿਸ਼ ਕਰੋ

ਕੋਈ ਵੀ ਚੀਜ਼ ਜੋ ਕੋਣ ਵਾਲੇ ਬਰੈਕਟਾਂ ਵਿੱਚ ਹੈ ਉਸਨੂੰ ਆਪਣੇ ਖੁਦ ਦੇ ਮੁੱਲਾਂ ਨਾਲ ਬਦਲੋ, ਅਤੇ ਕੁੰਜੀ ਪਲੇਸਹੋਲਡਰ ਨੂੰ ਆਪਣੇ ਡੈਸ਼ਬੋਰਡ ਦੀ ਇੱਕ ਕੁੰਜੀ ਨਾਲ ਬਦਲੋ।

curl -X POST https://api.zinndigital.com/v1/access/impersonation/redeem \
  -H "Content-Type: application/json" \
  -d '{ "ticket": <string> }'

ਲੌਗ ਇਨ ਕੀਤਾ ਹੋਇਆ ਹੈ? ਤੁਹਾਡੇ ਡੈਸ਼ਬੋਰਡ ਵਿੱਚ API ਕੰਸੋਲ ਤੁਹਾਡੀ ਅਸਲ ਸੰਸਥਾ ਆਈਡੀ (organisation id) ਅਤੇ ਤੁਹਾਡੀ ਆਪਣੀ ਕੁੰਜੀ ਨੂੰ ਭਰਦਾ ਹੈ, ਅਤੇ ਲਾਈਵ API ਦੇ ਵਿਰੁੱਧ ਬੇਨਤੀ ਚਲਾਉਂਦਾ ਹੈ ਤਾਂ ਜੋ ਤੁਸੀਂ ਅਸਲ ਜਵਾਬ ਦੇਖ ਸਕੋ। API ਕੰਸੋਲ ਵਿੱਚ ਇਸ ਐਂਡਪੁਆਇੰਟ ਨੂੰ ਖੋਲ੍ਹੋ

ਵੇਰਵੇ

Called by the customer dashboard when a staff member follows an ImpersonationGrant.url. Unauthenticated by design — the caller is the app at the instant it has no session, which is the whole point. Authorisation is the ticket: single-use, five minutes, 32 bytes of entropy, stored only as a SHA-256 digest, and bound to a grant a staff member is on the audit log for opening. Every refusal returns the same 401 message. Distinguishing "no such ticket" from "already redeemed" from "expired" would tell a caller which of their guesses was once real.

ਬੇਨਤੀ ਬਾਡੀ

ਨਾਮਕਿਸਮਲਾਜ਼ਮੀਕੀ ਹੈ ਇਹ
ticketstringਹਾਂ

ਜਵਾਬ

ਨਾਮਕਿਸਮਲਾਜ਼ਮੀਕੀ ਹੈ ਇਹ
tokenstringਹਾਂThe customer session bearer token (carries the staff act claim).
expires_atstringਹਾਂ
session_idstringਹਾਂ
org_idstringਹਾਂThe single org this grant is good for.
org_namestringਹਾਂ
actorstringਹਾਂThe real staff actor (user:<id>), for the banner.

ਇਹ ਐਂਡਪੁਆਇੰਟ ਜੋ ਗਲਤੀਆਂ ਵਾਪਸ ਕਰ ਸਕਦਾ ਹੈ

401 · 422 · 429 · 503