# API Secret key token

**URL:** <https://discuss.elastic.co/t/api-secret-key-token/263900>\
**Category:** APM\
**Tags:** elastic-stack-security, server\
**Created:** [February 10, 2021, 4:27pm UTC](https://discuss.elastic.co/t/api-secret-key-token/263900 "2021-02-10T16:27:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![lnitin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lnitin/32/63896_2.png) [@lnitin](https://discuss.elastic.co/u/lnitin)\
**Post date:** [February 10, 2021, 4:27pm UTC](https://discuss.elastic.co/t/api-secret-key-token/263900/1 "2021-02-10T16:27:34Z")

</div>

Elastic apm-server and agent configuration, what is a secret\_token for java agent is it an API key from elasticsearch.? Will it be a security issue if we have the api key as a part of java code.?

---

<div class="post-metadata">

**Author:** ![lnitin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lnitin/32/63896_2.png) [@lnitin](https://discuss.elastic.co/u/lnitin)\
**Post date:** [February 10, 2021, 4:27pm UTC](https://discuss.elastic.co/t/api-secret-key-token/263900/2 "2021-02-10T16:27:59Z")

</div>

@apm_user

---

<div class="post-metadata">

**Author:** ![axw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/axw/32/28197_2.png) [@axw](https://discuss.elastic.co/u/axw)\
**Post date:** [February 11, 2021, 1:49am UTC](https://discuss.elastic.co/t/api-secret-key-token/263900/3 "2021-02-11T01:49:49Z")

</div>

[Secure communication with APM agents | APM User Guide [8.11] | Elastic](https://www.elastic.co/guide/en/apm/server/current/secure-communication-agents.html) describes the two methods of auth supported by APM Server: Secret Token and API Key. They are different.

With the secret token method you specify a secret token (can be anything, e.g. randomly generated) in the APM Server configuration, and also in the APM Agent. The server simply checks that each request received from the agent has a secret token matching what is configured in the server.

> Will it be a security issue if we have the api key as a part of java code.?

That depends on who has access to the code -- both the source code, and the compiled JAR. Typically it's best to configure the agent using a property file or environment variable instead. How you do that securely depends on your method of deployment.

---

<div class="post-metadata">

**Author:** ![Sylvain\_Juge](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sylvain_juge/32/55521_2.png) [@Sylvain\_Juge](https://discuss.elastic.co/u/Sylvain_Juge)\
**Post date:** [February 11, 2021, 8:24am UTC](https://discuss.elastic.co/t/api-secret-key-token/263900/4 "2021-02-11T08:24:27Z")

</div>

Generally speaking, storing credentials within source code is considered to be a bad practice, as anyone that has access to your application binaries will be able to extract them (with Java it's pretty trivial to decompile binaries).

Also, it's quite likely that you will have to update those credentials at some point, and doing that would require to re-compile, package and deploy your application, which would have been made way easier if those were stored in environment variables, only an application restart would be required.

Also, I encourage you to read the (rather opinionated) "12 factor app" that is quite popular in the ruby ecosystem, especially the part about configuration: [The Twelve-Factor App](https://12factor.net/config)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 11, 2021, 8:24am UTC](https://discuss.elastic.co/t/api-secret-key-token/263900/5 "2021-03-11T08:24:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
