# API Key Authentication for REST Requests

**URL:** <https://discuss.elastic.co/t/api-key-authentication-for-rest-requests/228862>\
**Category:** Elasticsearch\
**Created:** [April 20, 2020, 12:31pm UTC](https://discuss.elastic.co/t/api-key-authentication-for-rest-requests/228862 "2020-04-20T12:31:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Flaxline](https://avatars.discourse-cdn.com/v4/letter/f/ce7236/32.png) [@Flaxline](https://discuss.elastic.co/u/Flaxline)\
**Post date:** [April 20, 2020, 12:31pm UTC](https://discuss.elastic.co/t/api-key-authentication-for-rest-requests/228862/1 "2020-04-20T12:31:38Z")

</div>

Hi,

i have a JavaScript function (using Cypress) which uses REST API to query some data from elasticsearch. For a first version, I handled authentication with username/password as shown below and that worked fine.

```auto
    private readonly elasticDB = {
        node: 'http://elastic:9200',
        auth: {
           username: 'elastic',
           password: 'changeme'
        }
      };
    cy.request({
      method: 'POST',
      url: this.elasticDB.node,
      auth: this.elasticDB.auth,
      body: body
    })

```

Now I want to switch to using API Key instead, but "RequestError: Error: no auth mechanism defined" occurs.  
I changed the auth-JSON to:

```auto
     auth: {
      apiKey:
        {
          id: '<id>',
          api_key: '<api-key>'
        }
    }

```

Can you help me locate the error I'm making, or is it just not possible to use the api-key with the REST request?  
Thanks!

---

<div class="post-metadata">

**Author:** ![Flaxline](https://avatars.discourse-cdn.com/v4/letter/f/ce7236/32.png) [@Flaxline](https://discuss.elastic.co/u/Flaxline)\
**Post date:** [April 24, 2020, 7:28am UTC](https://discuss.elastic.co/t/api-key-authentication-for-rest-requests/228862/2 "2020-04-24T07:28:18Z")

</div>

So, update after a few more stolls through the documentation and some experiments:

The documentation itself doesn't give an example for using something else than basic auth, but it also doesn't state that basic auth was the only option.  
I tried some more configurations and also the old, experimental browser-build of the js-client, which results in the same error.

I am now working on a solution using the node-module, which apparently supports the API Key Authentication, but is quite inconvenient for usage in cypress tests.

Edit: ikakavas' solution works for me as well, so I'll go with that

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [April 24, 2020, 7:47am UTC](https://discuss.elastic.co/t/api-key-authentication-for-rest-requests/228862/3 "2020-04-24T07:47:03Z")

</div>

It looks like cypress uses the python requests library internally so you could ( see the docs: [https://github.com/request/request#custom-http-headers](https://github.com/request/request#custom-http-headers) ) add a custom `Authorization` header. Something like ( entirely untested 🙂 ) :

```auto
private readonly elasticDB = {
        node: 'http://elastic:9200',
        authHeaders: {
           'Authorization: 'ApiKey <base64encoded api key value here>'
        }
      };
    cy.request({
      method: 'POST',
      url: this.elasticDB.node,
      headers: this.elasticDB.authHeader,
      body: body
    })

```

Read [our docs, bottom of this page](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-create-api-key.html) on how to construct the `<base64encoded api key value here>` value

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 22, 2020, 7:47am UTC](https://discuss.elastic.co/t/api-key-authentication-for-rest-requests/228862/4 "2020-05-22T07:47:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
