compute

POST /v1/panels/connections/{connectionId}/login-link

One-click login — a one-time administrative session on the panel.

Wszystkie punkty końcowe compute

Wszystkie dokumentacje dla programistów

Uwierzytelnianie

Wyślij klucz API jako token bearer. Ten punkt końcowy nie określa konkretnego uprawnienia w specyfikacji, więc nadaj swojemu kluczowi minimum potrzebnych uprawnień i sprawdź odpowiedź zamiast zakładać.

Ten punkt końcowy nie wymaga identyfikatora organizacji. Twój klucz już identyfikuje organizację, do której należy, a odpowiedź jest do niej ograniczona.

Wypróbuj

Zastąp wszystko w nawiasach ostrych własnymi wartościami, a zastępczy znacznik klucza kluczem ze swojego pulpitu nawigacyjnego.

curl -X POST https://api.zinndigital.com/v1/panels/connections/{connectionId}/login-link \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{  }'

Zalogowany? Konsola API w Twoim panelu uzupełnia rzeczywiste identyfikator organizacji oraz Twój własny klucz i wykonuje żądanie względem aktywnego API, dzięki czemu możesz zobaczyć rzeczywistą odpowiedź. Otwórz ten punkt końcowy w konsoli API

Szczegóły

⚖️ The owner's ask of 2026-08-28, verbatim: "one click login to the plesk panels". ⛔⛔ The returned url is a LIVE CREDENTIAL. It is an authenticated administrative session on the customer's panel. It is never logged, never persisted and never emailed — it is returned to one authenticated caller and belongs straight in their browser. Plesk's links are single-use and die on first redemption, which is a stronger guarantee than any expiry clock; expiresAt is therefore absent rather than guessed. ⛔ Gated on sites.panel_accessnot sites.view. That key means direct server-level access to a customer's hosting: it is held by owner, dev and staff ops, and deliberately not by support or any read-only role. A read-only role must never be able to mint an administrative session. ⛔ Answers 422 when this connection has not proved it can create login links, and refuses BEFORE calling the panel. A button that reaches a panel which will refuse it fails on a third-party domain, where neither we nor the customer can see why. Every mint is written to the audit trail with the actor and the panel — never the URL.

Parametry

NazwaTypWymaganeCo to jest
connectionId (path)UuidTakThe connected panel's id, as listPanelConnections reports it.

Treść żądania

NazwaTypWymaganeCo to jest
usernamestringNieA panel user to sign in as. Omit for the panel's administrator.

Odpowiedź

NazwaTypWymaganeCo to jest
urlstringTakThe one-time login URL. Treat it as a secret.
usernamestringTakWhich panel user the session belongs to. Empty means the administrator.
single_usebooleanTakWhether the link dies on first use. ⛔ null is unknown, and a client must not promise single-use on the strength of it. Plesk's are single-use, which is a stronger guarantee than…

Błędy, które ten punkt końcowy może zwrócić

401 · 403 · 404 · 422 · 429 · 503