hosting
POST /v1/sites/{siteId}/panel-sessions
Mint one single-use panel link, at the moment the customer clicks.
Xác thực
Gửi khóa API dưới dạng mã thông báo bearer. Điểm cuối này không nêu rõ quyền cụ thể trong thông số kỹ thuật, vì vậy hãy cấp cho khóa của bạn quyền tối thiểu cần thiết và kiểm tra phản hồi thay vì phỏng đoán.
Endpoint này không nhận ID tổ chức. Khóa của bạn đã xác định tổ chức mà nó thuộc về và phản hồi được giới hạn trong phạm vi đó.
Dùng thử
Thay thế bất kỳ nội dung nào trong ngoعل (angle brackets) bằng giá trị của riêng bạn và trình giữ chỗ key bằng một key từ trang tổng quan của bạn.
curl -X POST https://api.zinndigital.com/v1/sites/{siteId}/panel-sessions \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "tool": <string<phpmyadmin, filemanager, web_ide>> }'Đã đăng nhập? Bảng điều khiển API trong trang quản lý của bạn sẽ tự điền ID tổ chức thực tế và khóa của riêng bạn, sau đó chạy yêu cầu đối với API trực tiếp để bạn có thể xem phản hồi thực tế. Mở điểm cuối này trong bảng điều khiển API
Chi tiết
Returns a freshly minted single-use SSO link into **one** of the site's per-site tools — phpMyAdmin or the File Manager — for the caller to open immediately. **Why this exists rather than reusing `getSiteDatabase`.** The links that endpoint returns are single-use and expire in **180 seconds**, deliberately: a panel link that still works tomorrow is a credential. Rendering one into an `<a href>` on page load therefore hands the customer something that is dead before they have read the card — they click four minutes later and are told the token expired, which reads to them as being asked to log in. This endpoint moves the mint to the click, so the token's whole life is one redirect. Same authority as `getSiteDatabase`: **both** `sites.view` and `sites.panel_access`, RLS-scoped on the narrower key, so holding `sites.panel_access` in one org can never mint a link for another org's site. An out-of-scope or unknown id is a `404`, never a `403`, so this cannot be used to discover that a site exists. `POST` because it is **not idempotent**: every call writes a new single-use token to the hosting box. A `GET` would be re-issued by a prefetch, a proxy or the back button, burning a token each time. A site with no panel to open is a `409` carrying the same sentence the Tools card shows — never a `200` with a null URL.
Tham số
| Tên | Loại | Bắt buộc | Nội dung này là gì |
|---|---|---|---|
siteId (path) | Uuid | Có | Site ID (UUIDv7). |
Nội dung yêu cầu
| Tên | Loại | Bắt buộc | Nội dung này là gì |
|---|---|---|---|
tool | string<phpmyadmin, filemanager, web_ide> | Có | `phpmyadmin` opens the site's own database; `filemanager` opens the site's own home directory; `web_ide` opens VS Code in the browser against the site's files. A closed set on p… |
Phản hồi
| Tên | Loại | Bắt buộc | Nội dung này là gì |
|---|---|---|---|
url | string | Có | The HTTPS single-use SSO link. Never null on a `200` — a site with no panel to open is a `409`. |
reason | string | Không | Empty on success; present so one client component can render both shapes. |
Các lỗi điểm cuối này có thể trả về
401 · 403 · 404 · 409 · 422 · 429