access
POST /v1/access/impersonation/redeem
Exchange a single-use impersonation ticket for a session token.
Аутентификација
Ова крајња тачка је јавна. Не захтева никакве акредитиве нити организацију — то је оно што читају наш сопствени маркетиншки сајт и машине за одговоре са вештачком интелигенцијом.
Ова крајња тачка не прихвата id организације. Ваш кључ већ идентификује организацију којој припада, а одговор је ограничен на њу.
Испробајте
Замените све што је у угластим заградама сопственим вредностима, а чувар места кључа кључем са своје контролне табле.
curl -X POST https://api.zinndigital.com/v1/access/impersonation/redeem \
-H "Content-Type: application/json" \
-d '{ "ticket": <string> }'Пријављени сте? API конзола на вашој контролној табли попуњава ваш прави id организације и ваш сопствени кључ, и покреће захтев према живом API-ју како бисте могли да видите стварни одговор. Отворите ову крајњу тачку у API конзоли
Детаљи
Called by the customer dashboard when a staff member follows an ImpersonationGrant.url. Unauthenticated by design — the caller is the app at the instant it has no session, which is the whole point. Authorisation is the ticket: single-use, five minutes, 32 bytes of entropy, stored only as a SHA-256 digest, and bound to a grant a staff member is on the audit log for opening. Every refusal returns the same 401 message. Distinguishing "no such ticket" from "already redeemed" from "expired" would tell a caller which of their guesses was once real.
Тело захтева
| Назив | Тип | Обавезно | Шта је ово |
|---|---|---|---|
ticket | string | Да | — |
Одговор
| Назив | Тип | Обавезно | Шта је ово |
|---|---|---|---|
token | string | Да | The customer session bearer token (carries the staff act claim). |
expires_at | string | Да | — |
session_id | string | Да | — |
org_id | string | Да | The single org this grant is good for. |
org_name | string | Да | — |
actor | string | Да | The real staff actor (user:<id>), for the banner. |
kind | string<support, delegated_sign_in> | Не | support — a staff member is viewing the customer's account (the non-dismissable staff banner). delegated_sign_in — the customer's OWN sign-in, handed over by the partner or… |
delegated_by | string | Не | The partner's (or reseller's) name for delegated_sign_in, else "". |
Грешке које ова крајња тачка може вратити
401 · 422 · 429 · 503