hosting

POST /v1/sites/{siteId}/panel-sessions

Mint one single-use panel link, at the moment the customer clicks.

تمام hosting اینڈ پوائنٹس

توثيقِ شناخت

ایک API کلید بطور بیر ٹوکن (bearer token) ارسال کریں۔ یہ اینڈ پوائنٹ اسپیسیفیکیشن میں کسی مخصوص اجازت کا ذکر نہیں کرتا، اس لیے فرض کرنے کے بجائے اپنی کلید کو کم از کم درکار اجازت دیں اور رسپانس چیک کریں۔

یہ اینڈ پوائنٹ کوئی آرگنائزیشن آئی ڈی نہیں لیتا۔ آپ کی کلید پہلے ہی اس آرگنائزیشن کی شناخت کرتی ہے جس سے یہ تعلق رکھتی ہے، اور اس کا جواب اسی کے مطابق محدود ہوتا ہے۔

آزمائیں

کوئی بھی چیز جو زاویہ دار قوسین میں ہو اسے اپنی اقدار سے بدلیں، اور کلیدی پلیس ہولڈر کو اپنے ڈیش بورڈ کی کسی کلید سے بدلیں۔

curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/panel-sessions \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "tool": <string<phpmyadmin, filemanager, web_ide>> }'

لاگ ان ہیں؟ آپ کے ڈیش بورڈ میں موجود API کنسول آپ کی حقیقی تنظیم کی آئی ڈی اور آپ کی اپنی کلید خود بخود پُر کر دیتا ہے، اور لائیو API پر درخواست چلاتا ہے تاکہ آپ اصل ردعمل دیکھ سکیں۔ اس اینڈ پوائنٹ کو API کنسول میں کھولیں

تفصیلات

Returns a freshly minted single-use SSO link into **one** of the site's per-site tools — phpMyAdmin or the File Manager — for the caller to open immediately. **Why this exists rather than reusing `getSiteDatabase`.** The links that endpoint returns are single-use and expire in **180 seconds**, deliberately: a panel link that still works tomorrow is a credential. Rendering one into an `<a href>` on page load therefore hands the customer something that is dead before they have read the card — they click four minutes later and are told the token expired, which reads to them as being asked to log in. This endpoint moves the mint to the click, so the token's whole life is one redirect. Same authority as `getSiteDatabase`: **both** `sites.view` and `sites.panel_access`, RLS-scoped on the narrower key, so holding `sites.panel_access` in one org can never mint a link for another org's site. An out-of-scope or unknown id is a `404`, never a `403`, so this cannot be used to discover that a site exists. `POST` because it is **not idempotent**: every call writes a new single-use token to the hosting box. A `GET` would be re-issued by a prefetch, a proxy or the back button, burning a token each time. A site with no panel to open is a `409` carrying the same sentence the Tools card shows — never a `200` with a null URL.

پیرامیٹرز

نامقسملازمییہ کیا ہے
siteId (path)UuidہاںSite ID (UUIDv7).

درخواست کا باڈی

نامقسملازمییہ کیا ہے
toolstring<phpmyadmin, filemanager, web_ide>ہاں`phpmyadmin` opens the site's own database; `filemanager` opens the site's own home directory; `web_ide` opens VS Code in the browser against the site's files. A closed set on p…

جواب

نامقسملازمییہ کیا ہے
urlstringہاںThe HTTPS single-use SSO link. Never null on a `200` — a site with no panel to open is a `409`.
reasonstringنہیںEmpty on success; present so one client component can render both shapes.

وہ خرابیان جو یہ اینڈ پوائنٹ واپس کر سکتا ہے

401 · 403 · 404 · 409 · 422 · 429