access

POST /v1/access/impersonation/redeem

Exchange a single-use impersonation ticket for a session token.

Све access крајње тачке

Сва документација за програмере →

Аутентификација

Ова крајња тачка је јавна. Не захтева никакве акредитиве нити организацију — то је оно што читају наш сопствени маркетиншки сајт и машине за одговоре са вештачком интелигенцијом.

Ова крајња тачка не прихвата id организације. Ваш кључ већ идентификује организацију којој припада, а одговор је ограничен на њу.

Испробајте

Замените све што је у угластим заградама сопственим вредностима, а чувар места кључа кључем са своје контролне табле.

curl -X POST https://api.zinndigital.com/v1/access/impersonation/redeem \
  -H "Content-Type: application/json" \
  -d '{ "ticket": <string> }'

Пријављени сте? API конзола на вашој контролној табли попуњава ваш прави id организације и ваш сопствени кључ, и покреће захтев према живом API-ју како бисте могли да видите стварни одговор. Отворите ову крајњу тачку у API конзоли

Детаљи

Called by the customer dashboard when a staff member follows an ImpersonationGrant.url. Unauthenticated by design — the caller is the app at the instant it has no session, which is the whole point. Authorisation is the ticket: single-use, five minutes, 32 bytes of entropy, stored only as a SHA-256 digest, and bound to a grant a staff member is on the audit log for opening. Every refusal returns the same 401 message. Distinguishing "no such ticket" from "already redeemed" from "expired" would tell a caller which of their guesses was once real.

Тело захтева

НазивТипОбавезноШта је ово
ticketstringДа—

Одговор

НазивТипОбавезноШта је ово
tokenstringДаThe customer session bearer token (carries the staff act claim).
expires_atstringДа—
session_idstringДа—
org_idstringДаThe single org this grant is good for.
org_namestringДа—
actorstringДаThe real staff actor (user:<id>), for the banner.
kindstring<support, delegated_sign_in>Неsupport — a staff member is viewing the customer's account (the non-dismissable staff banner). delegated_sign_in — the customer's OWN sign-in, handed over by the partner or…
delegated_bystringНеThe partner's (or reseller's) name for delegated_sign_in, else "".

Грешке које ова крајња тачка може вратити

401 · 422 · 429 · 503