# Accessing search API using api key and acces token-based authentication

**URL:** <https://discuss.elastic.co/t/accessing-search-api-using-api-key-and-acces-token-based-authentication/287468>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [October 22, 2021, 9:04pm UTC](https://discuss.elastic.co/t/accessing-search-api-using-api-key-and-acces-token-based-authentication/287468 "2021-10-22T21:04:50Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![parkerjgit](https://avatars.discourse-cdn.com/v4/letter/p/898d66/32.png) [@parkerjgit](https://discuss.elastic.co/u/parkerjgit)\
**Post date:** [October 22, 2021, 9:04pm UTC](https://discuss.elastic.co/t/accessing-search-api-using-api-key-and-acces-token-based-authentication/287468/1 "2021-10-22T21:04:50Z")

</div>

Hi, I need some help accessing the Search API. I Have elastic cloud setup as azure managed service. I can access the cloud [Service API](https://www.elastic.co/guide/en/cloud/current/ec-restful-api.html) using API key-based authentication:

```auto
curl -X GET -H "Authorization: ApiKey <api_key>" https://api.elastic-cloud.com/api/v1/deployments

```

but its not clear how to access data through the [Search API](https://www.elastic.co/guide/en/elasticsearch/reference/master/search-search.html)

1. What baseurl do I use? Is it the console host endpoint? e.g., [https://xxx.es.australiaeast.azure.elastic-cloud.com](https://xxx.es.australiaeast.azure.elastic-cloud.com/) , i.e.,

```auto
curl -X GET "https://xxx.es.australiaeast.azure.elastic-cloud.com:<port>/<index>/_search" -H 'Content-Type: application/json' -d '{...}'

```

1. Can I use the same api key or do I have to generate a new key using the [Create API key API](https://www.elastic.co/guide/en/elasticsearch/reference/master/security-api-create-api-key.html)? and how do I authenticate the create api key request?
2. For OAuth2 flow, how do I create a user/password (or client key/secret) that I can then exchange for an access token, ie

```auto
curl -X POST "<base_url>/_security/oauth2/token" -H 'Content-Type: application/json' -d' 
{ 
  "grant_type" : "password", 
  "username" : "<username>", 
  "password" : "<password>" 
} 

curl -X POST "<base_url>/_security/oauth2/token" -H 'Content-Type: application/json' -d' 
{ 
  "grant_type" : "client_credentials", 
  "username" : "<key>", 
  "password" : "<secret>" 
}

```

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 19, 2021, 9:05pm UTC](https://discuss.elastic.co/t/accessing-search-api-using-api-key-and-acces-token-based-authentication/287468/2 "2021-11-19T21:05:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
