# Api\_key privilege

**URL:** <https://discuss.elastic.co/t/api-key-privilege/330558>\
**Category:** Elasticsearch\
**Created:** [April 22, 2023, 6:53pm UTC](https://discuss.elastic.co/t/api-key-privilege/330558 "2023-04-22T18:53:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![7Alex7](https://avatars.discourse-cdn.com/v4/letter/7/97f17d/32.png) [@7Alex7](https://discuss.elastic.co/u/7Alex7)\
**Post date:** [April 22, 2023, 6:53pm UTC](https://discuss.elastic.co/t/api-key-privilege/330558/1 "2023-04-22T18:53:33Z")

</div>

I will use Search in my projects but would like to test it before buying. Projects need temporary credentials functionality. The Api\_key looks good for this. One more restriction is that the user must be able to create documents, read his own documents and edit his own documents.  
This functionality is available for the commercial only. So I enabled security and trial license.

 ![Screenshot 2023-04-22 at 21.32.35](https://us1.discourse-cdn.com/elastic/original/3X/2/5/258a077dfb2baf20ef5ae293e9a6848d89f0c3e8.png)

For testing functionality I created API\_key

 ![Screenshot 2023-04-22 at 21.32.07](https://us1.discourse-cdn.com/elastic/original/3X/2/7/27e5f5c42ab92d9b73f55d39f4ab606c914f446d.png)

But when I make a request for another user's document I get it. I am using the API\_key for auth.

 ![Screenshot 2023-04-22 at 21.31.52](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0ef3a3a74a217975b2915180276677403a21265f.png)

I have the same result with using the match query

What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2023, 6:53pm UTC](https://discuss.elastic.co/t/api-key-privilege/330558/2 "2023-05-20T18:53:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
