# API key owner

**URL:** <https://discuss.elastic.co/t/api-key-owner/348167>\
**Category:** Elasticsearch\
**Created:** [November 28, 2023, 5:06pm UTC](https://discuss.elastic.co/t/api-key-owner/348167 "2023-11-28T17:06:19Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![mcosta](https://avatars.discourse-cdn.com/v4/letter/m/6a8cbe/32.png) [@mcosta](https://discuss.elastic.co/u/mcosta)\
**Post date:** [November 28, 2023, 5:06pm UTC](https://discuss.elastic.co/t/api-key-owner/348167/1 "2023-11-28T17:06:19Z")

</div>

Hi all,

Using Elastic Cloud V8.10.2

I need to create several API keys to be used on logstash.

When API key is created on Kibana -\> Security -\> API Keys, it ends with the owner being my user.  
When API key is created on Deployment portal -\> Elasticsearch -\> API console, it ends with the owner being "elastic-userconsole-proxy".

Can someone clarify who should be the owner?  
What is the difference between these two API keys if created with same privileges?

Thank you.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 28, 2023, 5:16pm UTC](https://discuss.elastic.co/t/api-key-owner/348167/2 "2023-11-28T17:16:45Z")

</div>

@mcosta

Great question!!

When you're in Kibana and you create that API key (and make sure you get the right format for logstash). That is an API key to read and write resources within the elastic cluster like writing indices.

When you're in the elastic cloud console, that API key can actually be used to run terraform or actually create, update and delete clusters. So think of it on the outside of the cluster.

So one is working within the cluster and the other is for managing clusters.

Hope that helps

---

<div class="post-metadata">

**Author:** ![mcosta](https://avatars.discourse-cdn.com/v4/letter/m/6a8cbe/32.png) [@mcosta](https://discuss.elastic.co/u/mcosta)\
**Post date:** [November 29, 2023, 10:42am UTC](https://discuss.elastic.co/t/api-key-owner/348167/3 "2023-11-29T10:42:16Z")

</div>

Hi Stephen

Thank you for your reply!

I'm now confused 🙂

Besides creating an API key using Kibana -\> Security -\> API Keys and then click "Create API key" blue button at top right (and of course Dev Tools console), there are **two more** options where one can create an API key :

1- [https://cloud.elastic.co/home](https://cloud.elastic.co/home) -\> Manage -\> Elasticsearch API console

2- [https://cloud.elastic.co/account/keys](https://cloud.elastic.co/account/keys)  
(You can create and manage deployments, configure remote clusters, set up traffic filters, manage extensions, and much more.)

From your reply I think you mean this option 2, but on my initial post I was referring option 1.

What's the difference between option 1 and 2?  
Is option 1 same as creating an API key from Kibana button? But API key owner ends being not the same...

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 29, 2023, 3:22pm UTC](https://discuss.elastic.co/t/api-key-owner/348167/4 "2023-11-29T15:22:14Z")

</div>

Ok lets use Screenshots 🙂

So #1:

That is just running the [Elasticsearch REST APIs](https://www.elastic.co/guide/en/elasticsearch/reference/current/rest-apis.html) (so that is the Within Cluster API) but it is running them from the Cloud Console (so yeah kinda weird but it can be used when say there are Kibana issues etc) .

This is the Equivalent to Running API Calls from Kibana - Dev Tools or directly via the Elasricsearch REST API Endpoint

**The key is you can always run this command to see what user you are**

`GET /_security/user`

In this case this is a special users from the cloud console it is effectively `superuser`

If you are saying you are creating API Keys from this API Console you are just creating Elasitcsearch API Keys within the cluseter just like you would from Kibana - Dev Tools or Kibana - Stack Management -\> API Keys

 ![Screenshot 2023-11-29 at 7.16.19 AM](https://us1.discourse-cdn.com/elastic/original/3X/7/3/739f638a08fec35442c352a4948a87de964527bc.png)

 ![Screenshot 2023-11-29 at 7.13.15 AM](https://us1.discourse-cdn.com/elastic/original/3X/0/7/07a8c691440ee78a43832336cc23685e2af58670.png)

And #2 Correct create and manage deployments, configure remote clusters, set up traffic filters, manage extensions, and much more.)

---

<div class="post-metadata">

**Author:** ![mcosta](https://avatars.discourse-cdn.com/v4/letter/m/6a8cbe/32.png) [@mcosta](https://discuss.elastic.co/u/mcosta)\
**Post date:** [November 30, 2023, 5:29pm UTC](https://discuss.elastic.co/t/api-key-owner/348167/5 "2023-11-30T17:29:21Z")

</div>

Once again, thank you for your prompt reply. I'm not confused anymore 🙂

But some question remains:

We have several application using logstash to ingest data into elastic. Each one has it's own pipeline and therefore we want to have one API key for each application.

As you can see bellow, "logs-airflw-dev" key, created on Kibana, have b10628 user (me) as owner. "dev-oshplt-oca-be-v2" key also created my be, but on API console, ended with "elastic-userconsole-proxy" as owner.

Q1: As best practice, should those applicational API keys be owned by "elastic-userconsole-proxy"?

Q2: What happen to API keys if they are created on Kibana by an user, say b10628, and that user is deleted from cluster? Are keys deleted too?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/0/6064886d4dd7650fbd9c5af61450d03e5d761525.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 30, 2023, 6:14pm UTC](https://discuss.elastic.co/t/api-key-owner/348167/6 "2023-11-30T18:14:02Z")

</div>

> [@mcosta](#):
>
> Q2: What happen to API keys if they are created on Kibana by an user, say b10628, and that user is deleted from cluster? Are keys deleted too?

No API keys are not deleted when the user that created them are deleted.

API Keys outlive the owners that created them as far as I understand..  
That is pretty easy to test if you want 🙂

Be carefull though as [stated in the documents](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-create-api-key.html#security-api-create-api-key-request-body).... the API key is an intersection of the User Creating the API with the Roles defined in the API key (otherwise this would allow and exploit / privilege escalation)

> `role_descriptors`
> 
> (Optional, object) The role descriptors for this API key. This parameter is optional. When it is not specified or is an empty array, then the API key will have a _point in time snapshot of permissions of the authenticated user_. If you supply role descriptors then the resultant permissions would be an intersection of API keys permissions and authenticated user’s permissions thereby limiting the access scope for API keys.

Personally, I like creating API for the cluster Directly Through Kibana or Dev Tools, NOT through the Elastic Cloud Console , but that is just my personal preference.

---

<div class="post-metadata">

**Author:** ![mcosta](https://avatars.discourse-cdn.com/v4/letter/m/6a8cbe/32.png) [@mcosta](https://discuss.elastic.co/u/mcosta)\
**Post date:** [December 3, 2023, 11:35pm UTC](https://discuss.elastic.co/t/api-key-owner/348167/7 "2023-12-03T23:35:39Z")

</div>

Concluding, I guess the best way is to have an user per application, that own all API keys needed for that application. This way, every member of the admin team can update the keys if necessary, as long as we keep the user's password in a shared vault.

API keys owned by "elastic-userconsole-proxy" cannot be updated.

BTW, "No API Keys outlive the owners that created them" seams not true.  
After removing the user "test", the key (also named "test") is apparently active.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/c/1c97406fbb15150d77f9ad22354b8cb14aee38ed.png)

Thank you!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 3, 2023, 11:40pm UTC](https://discuss.elastic.co/t/api-key-owner/348167/8 "2023-12-03T23:40:07Z")

</div>

> [@mcosta](#):
>
> Are keys deleted too?

> [@mcosta](#):
>
> BTW, "No API Keys outlive the owners that created them" seams not true.  
> After removing the user "test", the key (also named "test") is apparently active.

Just poor writing on my side....

You asked

> [@mcosta](#):
>
> Are keys deleted too?

I answered: No

Then I should have separated the next sentence

API Keys outlive the owners that created them as far as I understand..  
That is pretty easy to test if you want

So we are in agreement... I'll fix the wording above in case anyone else reads this topic.

---

<div class="post-metadata">

**Author:** ![mcosta](https://avatars.discourse-cdn.com/v4/letter/m/6a8cbe/32.png) [@mcosta](https://discuss.elastic.co/u/mcosta)\
**Post date:** [December 3, 2023, 11:59pm UTC](https://discuss.elastic.co/t/api-key-owner/348167/9 "2023-12-03T23:59:14Z")

</div>

I'm sorry, you were perfectly clear.  
It's my fault as I mix both sentences in one ☹

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 31, 2023, 11:59pm UTC](https://discuss.elastic.co/t/api-key-owner/348167/10 "2023-12-31T23:59:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
