hosting
POST /v1/sites/{siteId}/panel-sessions
Mint one single-use panel link, at the moment the customer clicks.
Xaqiijinta aqoonsiga
U dir fure API ahaan calaamad muujisa (bearer token). Barta dhammaadka ee kani ma caysino luqad ahaan oggolaansho gaar ah oo ku dhex jirta qeexidda, markaa sii furahaaga inta ugu yar ee uu u baahan yahay oo fiiri jawaabta halka aad wax ka qaadan lahayd.
Boggan ma qaato aqoonsiga ururka. Furahaagu wuxuu horay u aqoonsanayaa ururka uu ka tirsan yahay, jawaabtuna waxay ku kooban tahay halkaas.
Isku day
Ku beddel wax kasta oo ku dhex jira qeebaha xaglaha ah qiimayaashaada, sidoo kalena haystaaha furaha ku beddel fure ka dhex muuqda dashboordigaaga.
curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/panel-sessions \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "tool": <string<phpmyadmin, filemanager, web_ide>> }'Ma sign-garaysay? Qalabka API ee ku jira dashboard-kaagu wuxuu buuxiyaa aqoonsigaaga ururka ee dhabta ah iyo furahaaga gaarka ah, wuxuuna ku shaqeysiiyaa codsiga API-ga nool si aad u aragto jawaabta dhabta ah. Kani ka fur barta kontoroolka ee API
Details
Returns a freshly minted single-use SSO link into **one** of the site's per-site tools — phpMyAdmin or the File Manager — for the caller to open immediately. **Why this exists rather than reusing `getSiteDatabase`.** The links that endpoint returns are single-use and expire in **180 seconds**, deliberately: a panel link that still works tomorrow is a credential. Rendering one into an `<a href>` on page load therefore hands the customer something that is dead before they have read the card — they click four minutes later and are told the token expired, which reads to them as being asked to log in. This endpoint moves the mint to the click, so the token's whole life is one redirect. Same authority as `getSiteDatabase`: **both** `sites.view` and `sites.panel_access`, RLS-scoped on the narrower key, so holding `sites.panel_access` in one org can never mint a link for another org's site. An out-of-scope or unknown id is a `404`, never a `403`, so this cannot be used to discover that a site exists. `POST` because it is **not idempotent**: every call writes a new single-use token to the hosting box. A `GET` would be re-issued by a prefetch, a proxy or the back button, burning a token each time. A site with no panel to open is a `409` carrying the same sentence the Tools card shows — never a `200` with a null URL.
Cabiraha
| Magaca | Nooc | Loo baahan yahay | Maxay tahay |
|---|---|---|---|
siteId (path) | Uuid | Haa | Site ID (UUIDv7). |
Codsiga jidhkiisa
| Magaca | Nooc | Loo baahan yahay | Maxay tahay |
|---|---|---|---|
tool | string<phpmyadmin, filemanager, web_ide> | Haa | `phpmyadmin` opens the site's own database; `filemanager` opens the site's own home directory; `web_ide` opens VS Code in the browser against the site's files. A closed set on p… |
Jawaab
| Magaca | Nooc | Loo baahan yahay | Maxay tahay |
|---|---|---|---|
url | string | Haa | The HTTPS single-use SSO link. Never null on a `200` — a site with no panel to open is a `409`. |
reason | string | Maya | Empty on success; present so one client component can render both shapes. |
Cilladaha ay bartaani soo celin karto
401 · 403 · 404 · 409 · 422 · 429