## POST /api/v2/shared-hosting/{accountId}/email-accounts/{address}/actions/sso

**Create webmail login link for an email account**

Create a one-time webmail login URL for one mailbox on a cPanel-backed shared-hosting account, so the mailbox can be read without knowing or resetting its password. Get `accountId` from `GET /api/v2/shared-hosting` `data[].id`. The `{address}` path value can be the email address (`hello@example.com`) or the public email account ID returned by `GET /api/v2/shared-hosting/{accountId}/email-accounts` `emailAccounts[].id`. Literal addresses may use a Unicode IDN or its punycode spelling. The mailbox domain must be hosted on the account, otherwise the request fails with 403 `domain_not_owned`. The URL is interactive and should be opened by the customer right away, not stored. Accounts on HostUp's previous hosting platform return 409 `account_not_eligible_cpanel`; contact support and we will migrate the existing account to cPanel at no extra charge.

### Related Endpoints

- `POST /api/v2/shared-hosting/{accountId}/email-accounts/{address}/actions/mail-profile-link`: Create Apple Mail setup profile link for an email account
- `DELETE /api/v2/shared-hosting/{accountId}/email-accounts/{address}`: Delete email account
- `PUT /api/v2/shared-hosting/{accountId}/email-accounts/{address}/quota`: Replace email account quota

### Headers

- `Accept`: application/json
- `Authorization`: Bearer YOUR_API_KEY
- Required API scopes: `console:services`, `write:hosting`

### Parameters

- `accountId` (path, string, required): Public shared-hosting account ID. Get it from `GET /api/v2/shared-hosting` `data[].id`. Do not invent this value; use the exact ID returned by the referenced API response. Example: `acct_01hxa3b4c5d6e7f8g9h0j1k2m3`
- `address` (path, string, required): Email address. Example: `user@example.com`

### Request Example

```bash
curl -X POST "https://cloud.hostup.se/api/v2/shared-hosting/acct_01hxa3b4c5d6e7f8g9h0j1k2m3/email-accounts/user@example.com/actions/sso" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Accept: application/json"
```

### Response Schema

- `loginUrl` (string, required) Example: `https://webmail.example.com/login/session/YOUR_TOKEN`
- `expiresAt` (string, required, nullable): Known expiry timestamp, or null when the control panel does not expose the exact token TTL. Example: `null`
- `singleUse` (boolean, required): Whether the generated login URL is intended for one interactive use. Example: `true`

### Responses

#### 200 - Webmail login link.
```json
{
  "loginUrl": "https://webmail.example.com/login/session/YOUR_TOKEN",
  "expiresAt": null,
  "singleUse": true
}
```

#### 400 - Invalid request. The response body is an RFC 7807 Problem Details document.
```json
{
  "type": "https://developer.hostup.se/errors/invalid_request",
  "title": "Invalid request",
  "status": 400,
  "detail": "The request body failed validation.",
  "code": "invalid_request",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z",
  "errors": [
    {
      "pointer": "/items/0/domainName",
      "detail": "`domainName` is required.",
      "code": "invalid_request"
    }
  ]
}
```

#### 401 - Unauthorized. Authentication is required.
```json
{
  "type": "https://developer.hostup.se/errors/unauthorized",
  "title": "Unauthorized",
  "status": 401,
  "detail": "Authentication is required.",
  "code": "unauthorized",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 403 - Forbidden. The caller lacks a required scope or does not own the resource.
```json
{
  "type": "https://developer.hostup.se/errors/forbidden",
  "title": "Forbidden",
  "status": 403,
  "detail": "The caller lacks a required scope or does not own the resource.",
  "code": "forbidden",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 404 - Not found. The resource does not exist or is not owned by the caller.
```json
{
  "type": "https://developer.hostup.se/errors/not_found",
  "title": "Not found",
  "status": 404,
  "detail": "The requested resource could not be found.",
  "code": "not_found",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 409 - Conflict. `code` is `account_suspended`, `account_not_eligible_cpanel`, or a route-specific blocker with its own recovery fields.
```json
{
  "type": "https://developer.hostup.se/errors/account_suspended",
  "title": "Hosting account suspended",
  "status": 409,
  "detail": "The hosting account is suspended, so this action is unavailable until the account is reactivated.",
  "code": "account_suspended",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 429 - Rate limited. Retry after the limit resets. 429 responses include `Retry-After` seconds plus `X-RateLimit-*` headers.
```json
{
  "type": "https://developer.hostup.se/errors/rate_limit_exceeded",
  "title": "Too many requests",
  "status": 429,
  "detail": "Too many requests. Retry after the limit resets.",
  "code": "rate_limit_exceeded",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 500 - Internal error. Retry later or contact support if the issue persists.
```json
{
  "type": "https://developer.hostup.se/errors/internal_error",
  "title": "Internal server error",
  "status": 500,
  "detail": "An unexpected error occurred. Retry later or contact support if the issue persists.",
  "code": "internal_error",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 502 - Upstream failure. A dependent provider request failed; the Problem Details `code` is `upstream_failed`. Retry later or contact support if the issue persists.
```json
{
  "type": "https://developer.hostup.se/errors/upstream_failed",
  "title": "Upstream failure",
  "status": 502,
  "detail": "An upstream provider request failed. Retry later or contact support if the issue persists.",
  "code": "upstream_failed",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```
