compute
POST /v1/panels/connections/{connectionId}/login-link
One-click login — a one-time administrative session on the panel.
Uthibitishaji
Tuma ufunguo wa API kama tokeni ya kubeba. Sehemu hii ya mwisho haitaji ruhusa maalum katika maelezo, kwa hivyo ipe ufunguo wako kiwango cha chini kabisa kinachohitajika na uangalie jibu badala ya kukisia.
Endpoint hii haichukui kitambulisho cha shirika. Ufunguo wako tayari unalitambua shirika linalohusika, na jibu limewekewa kikomo kwa shirika hilo pekee.
Jaribu
Badilisha chochote kilicho ndani ya mabano ya pembe na maadili yako mwenyewe, na kishikiliaji cha ufunguo na ufunguo kutoka kwa dashibodi yako.
curl -X POST https://api.zinndigital.com/v1/panels/connections/{connectionId}/login-link \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ }'Umeingia kwenye akaunti? Dashibodi yako ya kiweko cha API inajaza kitambulisho chako halisi cha shirika na ufunguo wako mwenyewe, na kuendesha ombi dhidi ya API ya moja kwa moja ili uweze kuona jibu halisi. Fungua sehemu hii ya mwisho (endpoint) kwenye konsole ya API
Maelezo
⚖️ The owner's ask of 2026-08-28, verbatim: *"one click login to the plesk panels"*. ⛔⛔ **The returned `url` is a LIVE CREDENTIAL.** It is an authenticated administrative session on the customer's panel. It is never logged, never persisted and never emailed — it is returned to one authenticated caller and belongs straight in their browser. Plesk's links are single-use and die on first redemption, which is a stronger guarantee than any expiry clock; `expiresAt` is therefore absent rather than guessed. ⛔ Gated on `sites.panel_access` — **not** `sites.view`. That key means *direct server-level access to a customer's hosting*: it is held by `owner`, `dev` and staff `ops`, and deliberately not by `support` or any read-only role. A read-only role must never be able to mint an administrative session. ⛔ Answers `422` when this connection has not proved it can create login links, and refuses BEFORE calling the panel. A button that reaches a panel which will refuse it fails on a third-party domain, where neither we nor the customer can see why. Every mint is written to the audit trail with the actor and the panel — never the URL.
Vigezo
| Jina | Aina | Inayohitajika | Kilicho hiki |
|---|---|---|---|
connectionId (path) | Uuid | Ndiyo | The connected panel's id, as `listPanelConnections` reports it. |
Mwili wa ombi
| Jina | Aina | Inayohitajika | Kilicho hiki |
|---|---|---|---|
username | string | Hapana | A panel user to sign in as. Omit for the panel's administrator. |
Majibu
| Jina | Aina | Inayohitajika | Kilicho hiki |
|---|---|---|---|
url | string | Ndiyo | The one-time login URL. Treat it as a secret. |
username | string | Ndiyo | Which panel user the session belongs to. Empty means the administrator. |
single_use | boolean | Ndiyo | Whether the link dies on first use. ⛔ `null` is unknown, and a client must not promise single-use on the strength of it. Plesk's are single-use, which is a stronger guarantee th… |
Hitilafu ambazo mwisho huu unaweza kurudisha
401 · 403 · 404 · 422 · 429 · 503