# Api key name as additional field in apm-server data

**URL:** <https://discuss.elastic.co/t/api-key-name-as-additional-field-in-apm-server-data/230566>\
**Category:** APM\
**Created:** [April 30, 2020, 1:51pm UTC](https://discuss.elastic.co/t/api-key-name-as-additional-field-in-apm-server-data/230566 "2020-04-30T13:51:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![iorfix](https://avatars.discourse-cdn.com/v4/letter/i/9fc348/32.png) [@iorfix](https://discuss.elastic.co/u/iorfix)\
**Post date:** [April 30, 2020, 1:51pm UTC](https://discuss.elastic.co/t/api-key-name-as-additional-field-in-apm-server-data/230566/1 "2020-04-30T13:51:46Z")

</div>

Hi there,  
I created a couple of API-key on apmserver and tested it with a GO client. I have 2 comments:

1. I used the `Credentials` field and not the `API Key` field. This is not a problem, but it is not clear in the documenation.
2. I'd like to have the api-key `Name` field in the Elastic document. Since this field would be filled by apm-server and not by agents, it would be useful for a sort of _antitampering_. It could be configurated like `ssl_peer_metadata => true` in Logstash. Is this possible?

---

<div class="post-metadata">

**Author:** ![gil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gil/32/41911_2.png) [@gil](https://discuss.elastic.co/u/gil)\
**Post date:** [April 30, 2020, 10:01pm UTC](https://discuss.elastic.co/t/api-key-name-as-additional-field-in-apm-server-data/230566/2 "2020-04-30T22:01:45Z")

</div>

Hey @iorfix, keep the great posts coming!

1. Can you provide a link to the confusing documentation? I am not sure what which piece this is referring to but would love to improve anything that might be unclear.
2. I haven't been able to come up with a way to accomplish this. Please feel free to open an feature request in the [apm-server repo](https://github.com/elastic/apm-server/issues/) to record agent authentication information.

---

<div class="post-metadata">

**Author:** ![iorfix](https://avatars.discourse-cdn.com/v4/letter/i/9fc348/32.png) [@iorfix](https://discuss.elastic.co/u/iorfix)\
**Post date:** [May 1, 2020, 7:17am UTC](https://discuss.elastic.co/t/api-key-name-as-additional-field-in-apm-server-data/230566/3 "2020-05-01T07:17:36Z")

</div>

Hi @gil,  
Agent go configuration explicity talks about API KEY: [https://www.elastic.co/guide/en/apm/agent/go/current/configuration.html#config-api-key](https://www.elastic.co/guide/en/apm/agent/go/current/configuration.html#config-api-key)  
Creation of a key at server side creates both an Api Key and Credentials, so it is misleading which of the two should be used (instead, I don't understand when to use one, and when the other):  
[https://www.elastic.co/guide/en/apm/server/master/api-key.html](https://www.elastic.co/guide/en/apm/server/master/api-key.html)  
Moreover, documentation of API Keys on Elastic doesn't mention Credentials at all:  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-get-api-key.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-get-api-key.html)  
Finally, I was unable to understand how (if) to set apm-server keys on Elastic, and let them flow to apm-server nodes.  
I hope this clarifies better my statement.  
I'll open a feature request about recording agent authentication information

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 22, 2020, 3:17am UTC](https://discuss.elastic.co/t/api-key-name-as-additional-field-in-apm-server-data/230566/4 "2020-05-22T03:17:37Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
