# API key: unable to find apikey with id

**URL:** <https://discuss.elastic.co/t/api-key-unable-to-find-apikey-with-id/322104>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 28, 2022, 2:57pm UTC](https://discuss.elastic.co/t/api-key-unable-to-find-apikey-with-id/322104 "2022-12-28T14:57:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![chaserb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chaserb/32/93305_2.png) [@chaserb](https://discuss.elastic.co/u/chaserb)\
**Post date:** [December 28, 2022, 2:57pm UTC](https://discuss.elastic.co/t/api-key-unable-to-find-apikey-with-id/322104/1 "2022-12-28T14:57:44Z")

</div>

I appear to be having the same issue that @inbox.ex was having [here](https://discuss.elastic.co/t/api-key-unable-to-find-apikey-with-id-id/297401), in that I'm receiving 401 when interacting with the Elastcisearch endpoint. According to [this doc](https://www.elastic.co/guide/en/cloud/current/ec-api-authentication.html#ec-api-authentication), I've created an API key for my deployment, and now I'm just trying to do a simple "cat" of the indices:

```auto
curl --location --request GET 'https://my-deployment-hostname.es.centralus.azure.elastic-cloud.com/_cat/indices' \
--header 'Authorization: ApiKey <my api key>'

```

This produces a 401 response with the following body:

```auto
{
    "error": {
        "root_cause": [
            {
                "type": "security_exception",
                "reason": "unable to authenticate with provided credentials and anonymous access is not allowed for this request",
                "additional_unsuccessful_credentials": "API key: unable to find apikey with id <my key id>",
                "header": {
                    "WWW-Authenticate": [
                        "Basic realm=\"security\" charset=\"UTF-8\"",
                        "Bearer realm=\"security\"",
                        "ApiKey"
                    ]
                }
            }
        ],
        "type": "security_exception",
        "reason": "unable to authenticate with provided credentials and anonymous access is not allowed for this request",
        "additional_unsuccessful_credentials": "API key: unable to find apikey with id <my key id>",
        "header": {
            "WWW-Authenticate": [
                "Basic realm=\"security\" charset=\"UTF-8\"",
                "Bearer realm=\"security\"",
                "ApiKey"
            ]
        }
    },
    "status": 401
}

```

It appears to at least recognize my authorization header, because it has decoded "my api key" and put "my key id" into the response message. Does anyone recognize what I'm doing wrong?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [December 28, 2022, 5:10pm UTC](https://discuss.elastic.co/t/api-key-unable-to-find-apikey-with-id/322104/2 "2022-12-28T17:10:32Z")

</div>

Hi @chaserb

You are using the wrong type of API key.

The docs you referenced are to create an Elasticsearch "Service" API key to operate on elasticsearch deployments in other words, API key to allow you to create, update, delete deployments not an API key to work on the data within a deployment.

For the operation you are trying...the elasticsearch normal REST APIs you need to create a "normal" API KEY from within Kibana

> **[API Keys | Kibana Guide \[8.5\] | Elastic](https://www.elastic.co/guide/en/kibana/current/api-keys.html)**
>
> Conceptual and step-by-step procedures for using runtime fields, scripted fields, and field formatters.

Or directly from the Security REST API

> **[Create API key API | Elasticsearch Guide \[8.5\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-create-api-key.html)**

Two entirely separate APIs

One to work CRUD entire elasticsearch deployments

And the normal elasticsearch APIs that work within an elasticsearch cluster

---

<div class="post-metadata">

**Author:** ![chaserb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chaserb/32/93305_2.png) [@chaserb](https://discuss.elastic.co/u/chaserb)\
**Post date:** [December 28, 2022, 5:20pm UTC](https://discuss.elastic.co/t/api-key-unable-to-find-apikey-with-id/322104/3 "2022-12-28T17:20:26Z")

</div>

That did it. Thanks for the clarification!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 25, 2023, 5:21pm UTC](https://discuss.elastic.co/t/api-key-unable-to-find-apikey-with-id/322104/4 "2023-01-25T17:21:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
