compute
POST /v1/panels/connections/{connectionId}/login-link
One-click login — a one-time administrative session on the panel.
Xaqiijinta aqoonsiga
U dir fure API ahaan calaamad muujisa (bearer token). Barta dhammaadka ee kani ma caysino luqad ahaan oggolaansho gaar ah oo ku dhex jirta qeexidda, markaa sii furahaaga inta ugu yar ee uu u baahan yahay oo fiiri jawaabta halka aad wax ka qaadan lahayd.
Boggan ma qaato aqoonsiga ururka. Furahaagu wuxuu horay u aqoonsanayaa ururka uu ka tirsan yahay, jawaabtuna waxay ku kooban tahay halkaas.
Isku day
Ku beddel wax kasta oo ku dhex jira qeebaha xaglaha ah qiimayaashaada, sidoo kalena haystaaha furaha ku beddel fure ka dhex muuqda dashboordigaaga.
curl -X POST https://api.zinndigital.com/v1/panels/connections/{connectionId}/login-link \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ }'Ma sign-garaysay? Qalabka API ee ku jira dashboard-kaagu wuxuu buuxiyaa aqoonsigaaga ururka ee dhabta ah iyo furahaaga gaarka ah, wuxuuna ku shaqeysiiyaa codsiga API-ga nool si aad u aragto jawaabta dhabta ah. Kani ka fur barta kontoroolka ee API
Details
⚖️ The owner's ask of 2026-08-28, verbatim: *"one click login to the plesk panels"*. ⛔⛔ **The returned `url` is a LIVE CREDENTIAL.** It is an authenticated administrative session on the customer's panel. It is never logged, never persisted and never emailed — it is returned to one authenticated caller and belongs straight in their browser. Plesk's links are single-use and die on first redemption, which is a stronger guarantee than any expiry clock; `expiresAt` is therefore absent rather than guessed. ⛔ Gated on `sites.panel_access` — **not** `sites.view`. That key means *direct server-level access to a customer's hosting*: it is held by `owner`, `dev` and staff `ops`, and deliberately not by `support` or any read-only role. A read-only role must never be able to mint an administrative session. ⛔ Answers `422` when this connection has not proved it can create login links, and refuses BEFORE calling the panel. A button that reaches a panel which will refuse it fails on a third-party domain, where neither we nor the customer can see why. Every mint is written to the audit trail with the actor and the panel — never the URL.
Cabiraha
| Magaca | Nooc | Loo baahan yahay | Maxay tahay |
|---|---|---|---|
connectionId (path) | Uuid | Haa | The connected panel's id, as `listPanelConnections` reports it. |
Codsiga jidhkiisa
| Magaca | Nooc | Loo baahan yahay | Maxay tahay |
|---|---|---|---|
username | string | Maya | A panel user to sign in as. Omit for the panel's administrator. |
Jawaab
| Magaca | Nooc | Loo baahan yahay | Maxay tahay |
|---|---|---|---|
url | string | Haa | The one-time login URL. Treat it as a secret. |
username | string | Haa | Which panel user the session belongs to. Empty means the administrator. |
single_use | boolean | Haa | Whether the link dies on first use. ⛔ `null` is unknown, and a client must not promise single-use on the strength of it. Plesk's are single-use, which is a stronger guarantee th… |
Cilladaha ay bartaani soo celin karto
401 · 403 · 404 · 422 · 429 · 503