hosting
POST /v1/sites/{siteId}/panel-sessions
Mint one single-use panel link, at the moment the customer clicks.
Uthibitishaji
Tuma ufunguo wa API kama tokeni ya kubeba. Sehemu hii ya mwisho haitaji ruhusa maalum katika maelezo, kwa hivyo ipe ufunguo wako kiwango cha chini kabisa kinachohitajika na uangalie jibu badala ya kukisia.
Endpoint hii haichukui kitambulisho cha shirika. Ufunguo wako tayari unalitambua shirika linalohusika, na jibu limewekewa kikomo kwa shirika hilo pekee.
Jaribu
Badilisha chochote kilicho ndani ya mabano ya pembe na maadili yako mwenyewe, na kishikiliaji cha ufunguo na ufunguo kutoka kwa dashibodi yako.
curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/panel-sessions \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "tool": <string<phpmyadmin, filemanager, web_ide>> }'Umeingia kwenye akaunti? Dashibodi yako ya kiweko cha API inajaza kitambulisho chako halisi cha shirika na ufunguo wako mwenyewe, na kuendesha ombi dhidi ya API ya moja kwa moja ili uweze kuona jibu halisi. Fungua sehemu hii ya mwisho (endpoint) kwenye konsole ya API
Maelezo
Returns a freshly minted single-use SSO link into **one** of the site's per-site tools — phpMyAdmin or the File Manager — for the caller to open immediately. **Why this exists rather than reusing `getSiteDatabase`.** The links that endpoint returns are single-use and expire in **180 seconds**, deliberately: a panel link that still works tomorrow is a credential. Rendering one into an `<a href>` on page load therefore hands the customer something that is dead before they have read the card — they click four minutes later and are told the token expired, which reads to them as being asked to log in. This endpoint moves the mint to the click, so the token's whole life is one redirect. Same authority as `getSiteDatabase`: **both** `sites.view` and `sites.panel_access`, RLS-scoped on the narrower key, so holding `sites.panel_access` in one org can never mint a link for another org's site. An out-of-scope or unknown id is a `404`, never a `403`, so this cannot be used to discover that a site exists. `POST` because it is **not idempotent**: every call writes a new single-use token to the hosting box. A `GET` would be re-issued by a prefetch, a proxy or the back button, burning a token each time. A site with no panel to open is a `409` carrying the same sentence the Tools card shows — never a `200` with a null URL.
Vigezo
| Jina | Aina | Inayohitajika | Kilicho hiki |
|---|---|---|---|
siteId (path) | Uuid | Ndiyo | Site ID (UUIDv7). |
Mwili wa ombi
| Jina | Aina | Inayohitajika | Kilicho hiki |
|---|---|---|---|
tool | string<phpmyadmin, filemanager, web_ide> | Ndiyo | `phpmyadmin` opens the site's own database; `filemanager` opens the site's own home directory; `web_ide` opens VS Code in the browser against the site's files. A closed set on p… |
Majibu
| Jina | Aina | Inayohitajika | Kilicho hiki |
|---|---|---|---|
url | string | Ndiyo | The HTTPS single-use SSO link. Never null on a `200` — a site with no panel to open is a `409`. |
reason | string | Hapana | Empty on success; present so one client component can render both shapes. |
Hitilafu ambazo mwisho huu unaweza kurudisha
401 · 403 · 404 · 409 · 422 · 429