# API key does or does not rely on permissions from user that created it

**URL:** <https://discuss.elastic.co/t/api-key-does-or-does-not-rely-on-permissions-from-user-that-created-it/383663>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security, ingest-pipeline\
**Created:** [November 26, 2025, 12:18am UTC](https://discuss.elastic.co/t/api-key-does-or-does-not-rely-on-permissions-from-user-that-created-it/383663 "2025-11-26T00:18:44Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 26, 2025, 7:17pm UTC](https://discuss.elastic.co/t/api-key-does-or-does-not-rely-on-permissions-from-user-that-created-it/383663/4 "2025-11-26T19:17:19Z")

</div>

Lots to parse there ...

> [@qd-danh](#):
>
> Is there a way to see the actual computed privileges for the API key, or am I misunderstanding?

Yes to see what the PIT privileges from the user that created the key use the `with_limited_by` flag.

Use the GET API with

> `with_limited_by` boolean Generally available; Added in 8.5.0
> 
> Return the snapshot of the owner user's role descriptors associated with the API key. An API key's actual permission is the intersection of its assigned role descriptors and the owner user's role descriptors.

> **[Get API key information | Elasticsearch API documentation](https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-security-get-api-key)**
>
> Retrieves information for one or more API keys.
> NOTE: If you have only the manage\_own\_api\_key privilege, this API returns only the API keys that you own.
> If you have read\_securi...

With respect to how you want to manage the user / how users create API keys there are several approaches... and it depends if you are using automation, your overal maturity etc... plus your overall security architecture / posture / philosopy. Who can / can not create API keys with what privileges is very use case dependent.

With respect to SSO users creating keys, yes that is an issue if they are disabled etc. that key can not be updated.

Personally I am not a big "Update API Keys" fan (there are valid uses cases), I prefer (preference) is to create new and rotate the keys which may or may not work for you, (understood that could be painful)

I have sophisticated customer where end users submit a PR / Github action, and their key shows up in a corp Secrets Store... a user never logs in directly to create an API key.

Generally, I see users use a "tightly managed" Native Realm user for API key creation.

But yes in basic the User that creates the key needs to have a Superset of the privileges that the key needs.

Hope that helps a bit....

---

_[View the full topic](https://discuss.elastic.co/t/api-key-does-or-does-not-rely-on-permissions-from-user-that-created-it/383663)._
