compute
POST /v1/panels/connections/{connectionId}/login-link
One-click login — a one-time administrative session on the panel.
身份验证
请将 API 密钥作为 bearer 令牌发送。此端点在规范中未指明具体的权限,因此请为您的密钥赋予所需的最小权限,并通过检查响应来确认,而不是盲目假设。
此端点不需要组织 ID。您的密钥已用于识别其所属的组织,且响应范围也仅限于该组织。
免费试用
将尖括号中的内容替换为您自己的值,并将键占位符替换为您仪表板中的一个键。
curl -X POST https://api.zinndigital.com/v1/panels/connections/{connectionId}/login-link \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ }'已登录?您仪表板中的 API 控制台会自动填入您真实的组织 ID 和您自己的密钥,并针对实时 API 运行请求,以便您查看实际的响应。 在 API 控制台中打开此端点
详细信息
⚖️ The owner's ask of 2026-08-28, verbatim: "one click login to the plesk panels". ⛔⛔ The returned url is a LIVE CREDENTIAL. It is an authenticated administrative session on the customer's panel. It is never logged, never persisted and never emailed — it is returned to one authenticated caller and belongs straight in their browser. Plesk's links are single-use and die on first redemption, which is a stronger guarantee than any expiry clock; expiresAt is therefore absent rather than guessed. ⛔ Gated on sites.panel_access — not sites.view. That key means direct server-level access to a customer's hosting: it is held by owner, dev and staff ops, and deliberately not by support or any read-only role. A read-only role must never be able to mint an administrative session. ⛔ Answers 422 when this connection has not proved it can create login links, and refuses BEFORE calling the panel. A button that reaches a panel which will refuse it fails on a third-party domain, where neither we nor the customer can see why. Every mint is written to the audit trail with the actor and the panel — never the URL.
参数
| 名称 | 类型 | 必填 | 内容简介 |
|---|---|---|---|
connectionId (path) | Uuid | 是 | The connected panel's id, as listPanelConnections reports it. |
请求正文
| 名称 | 类型 | 必填 | 内容简介 |
|---|---|---|---|
username | string | 否 | A panel user to sign in as. Omit for the panel's administrator. |
响应
| 名称 | 类型 | 必填 | 内容简介 |
|---|---|---|---|
url | string | 是 | The one-time login URL. Treat it as a secret. |
username | string | 是 | Which panel user the session belongs to. Empty means the administrator. |
single_use | boolean | 是 | Whether the link dies on first use. ⛔ null is unknown, and a client must not promise single-use on the strength of it. Plesk's are single-use, which is a stronger guarantee than… |
此端点可能返回的错误
401 · 403 · 404 · 422 · 429 · 503