# Action \[indices:data/write/bulk\[s\]\] is unauthorized for API key id of user \[ \]

**URL:** <https://discuss.elastic.co/t/action-indices-data-write-bulk-s-is-unauthorized-for-api-key-id-of-user/313605>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 3, 2022, 3:48pm UTC](https://discuss.elastic.co/t/action-indices-data-write-bulk-s-is-unauthorized-for-api-key-id-of-user/313605 "2022-09-03T15:48:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kgeographer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kgeographer/32/26217_2.png) [@kgeographer](https://discuss.elastic.co/u/kgeographer)\
**Post date:** [September 3, 2022, 3:48pm UTC](https://discuss.elastic.co/t/action-indices-data-write-bulk-s-is-unauthorized-for-api-key-id-of-user/313605/1 "2022-09-03T15:48:13Z")

</div>

I have a 7.17 index I access routinely for reads and writes from a Django app with elasticsearch-py, performing snapshots to GCS, etc. This works fine with both the ES 7.17 on a Mac dev laptop against a copy of the prod index, and the Ubuntu prod server. All Python access uses an API\_KEY and API\_ID combo - one set on dev version and another on the prod server. I also use Kibana logged in with a superuser account.

All ES actions in the app work fine on both dev and prod, **except this query, which fails on the prod server only** (place\_id is unique):

```auto
es.delete_by_query(
	"myindex",
	body={"query": {"terms": {"place_id": ["123456"]}}}
)

```

which returns this error (the user named has the superuser role, and the \_id of the doc is 14192344):

```auto
elasticsearch7.exceptions.AuthorizationException: 
AuthorizationException(
	403, '
	{	"took":2,
		"timed_out":false,
		"total":1,
		"deleted":0,
		"batches":1,
		"version_conflicts":0,
		"noops":0,
		"retries":{"bulk":0,"search":0},
		"throttled_millis":0,
		"requests_per_second":-1.0,
		"throttled_until_millis":0,
		"failures":[
			{	"index": "myidx",
				"type":"_doc",
				"id":"14192344",
				"cause":{
					"type":"security_exception",
					"reason":
					"action [indices:data/write/bulk[s]] is unauthorized 
						for API key id [{api key id}] of user [{user}] 
						on indices [myidx], this action is granted by the index privileges 
						[create_doc,create,delete,index,write,all]"
				},
				"status":403
}]}')

```

The same query works fine in Kibana remotely, e.g.

```auto
POST /myindex/_delete_by_query
{
  "query": {
    "terms": {
      "place_id": ["123456"]
    }
  }
}

```

Thanks in advance for any suggestions. I've tried to find out what the active permissions are on prod, using the API ID and API KEY, can't find out how.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 3, 2022, 7:35pm UTC](https://discuss.elastic.co/t/action-indices-data-write-bulk-s-is-unauthorized-for-api-key-id-of-user/313605/2 "2022-09-03T19:35:22Z")

</div>

> [@kgeographer](#):
>
> ```auto
> "action [indices:data/write/bulk[s]] is unauthorized 
> for API key id [{api key id}] of user [{user}] 
> on indices [myidx], this action is granted by the index privileges 
> [create_doc,create,delete,index,write,all]
> 
> ```

Looks to me the API Key does not grant `delete` which is separate from `write` privilege

> [@kgeographer](#):
>
> The same query works fine in Kibana remotely, e.g.

That is because you are not logged in with that API keys so the privileges are different.

> [@kgeographer](#):
>
> I've tried to find out what the active permissions are on prod, using the API ID and API KEY, can't find out how.

As far as I know (perhaps someone else knows otherwise) You can not access an API KEY's detailed privileges once created.

If you are using one of the "Publisher/Writer" role type API KEYs (from the docs) they usually do not have `delete` privileges

You can probably test this pretty simple... Get the `_id` of the document you are trying to delete and run a simple `curl DELETE...` with the API KEY it will probably reject it with the same error message.

---

<div class="post-metadata">

**Author:** ![kgeographer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kgeographer/32/26217_2.png) [@kgeographer](https://discuss.elastic.co/u/kgeographer)\
**Post date:** [September 25, 2022, 8:26am UTC](https://discuss.elastic.co/t/action-indices-data-write-bulk-s-is-unauthorized-for-api-key-id-of-user/313605/3 "2022-09-25T08:26:04Z")

</div>

Thanks for this. Did not realize a user's (API\_KEY\_ID, API\_KEY\_KEY) pair are not relevant for a call from Python. Created a new unrestricted API Key in Kibana, and now use that for certain privileged operations executed with Python.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [September 26, 2022, 1:59am UTC](https://discuss.elastic.co/t/action-indices-data-write-bulk-s-is-unauthorized-for-api-key-id-of-user/313605/4 "2022-09-26T01:59:32Z")

</div>

> [@stephenb](#):
>
> As far as I know (perhaps someone else knows otherwise) You can not access an API KEY's detailed privileges once created.

This will be [possible](https://github.com/elastic/elasticsearch/pull/89166) in 8.5.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 24, 2022, 1:59am UTC](https://discuss.elastic.co/t/action-indices-data-write-bulk-s-is-unauthorized-for-api-key-id-of-user/313605/5 "2022-10-24T01:59:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
