# API Key Minimum Permissions for Querying Kibana Fleet Agents

**URL:** <https://discuss.elastic.co/t/api-key-minimum-permissions-for-querying-kibana-fleet-agents/344093>\
**Category:** Kibana\
**Tags:** fleet\
**Created:** [September 28, 2023, 11:12pm UTC](https://discuss.elastic.co/t/api-key-minimum-permissions-for-querying-kibana-fleet-agents/344093 "2023-09-28T23:12:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![groth](https://avatars.discourse-cdn.com/v4/letter/g/b487fb/32.png) [@groth](https://discuss.elastic.co/u/groth)\
**Post date:** [September 28, 2023, 11:12pm UTC](https://discuss.elastic.co/t/api-key-minimum-permissions-for-querying-kibana-fleet-agents/344093/1 "2023-09-28T23:12:04Z")

</div>

I'm on Elastic Cloud 8.9.1 using the Kibana Fleet APIs to pull agent information. In trying to figure out the minimum permissions needed for /api/fleet/agents, I have created a user account with a custom role with permissions:

- Elasticsearch - none
- Kibana - All Spaces: Fleet - All, Integrations - Read

Submitting requests to [my\_kibana\_endpoint]/api/fleet/agents using that account is returning correct results. I am wondering if it is possible to create an API key with those same minimum permissions rather than user:password authentication for scripting.

Examples at [Kibana Fleet APIs | Fleet and Elastic Agent Guide [8.10] | Elastic](https://www.elastic.co/guide/en/fleet/current/fleet-api-docs.html) show using an API Key in the sample requests. However, with role descriptors for API keys I'm unsure how to specify Kibana only permissions but maybe that's not possible? Can someone point me in the right direction?

---

<div class="post-metadata">

**Author:** ![Julia\_Bardi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julia_bardi/32/79463_2.png) [@Julia\_Bardi](https://discuss.elastic.co/u/Julia_Bardi)\
**Post date:** [October 9, 2023, 2:02pm UTC](https://discuss.elastic.co/t/api-key-minimum-permissions-for-querying-kibana-fleet-agents/344093/2 "2023-10-09T14:02:43Z")

</div>

Hi Gary!

You can use the created user:password as API key by using the base64 encoded version of `username:password` string:

```auto
--header 'Authorization: ApiKey yourbase64encodedkey' \

```

---

<div class="post-metadata">

**Author:** ![groth](https://avatars.discourse-cdn.com/v4/letter/g/b487fb/32.png) [@groth](https://discuss.elastic.co/u/groth)\
**Post date:** [October 9, 2023, 4:09pm UTC](https://discuss.elastic.co/t/api-key-minimum-permissions-for-querying-kibana-fleet-agents/344093/3 "2023-10-09T16:09:31Z")

</div>

Using the base64 version of my specific `username:password` as the API Key produced the error:

`{"statusCode":401,"error":"Unauthorized","message":"[security_exception\n\tRoot causes:\n\t\tsecurity_exception: unable to authenticate with provided credentials and anonymous access is not allowed for this request]: unable to authenticate with provided credentials and anonymous access is not allowed for this request"}`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2023, 4:09pm UTC](https://discuss.elastic.co/t/api-key-minimum-permissions-for-querying-kibana-fleet-agents/344093/4 "2023-11-06T16:09:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
