# API | Session management | User authentication and logout | Kibana / Elastic

**URL:** <https://discuss.elastic.co/t/api-session-management-user-authentication-and-logout-kibana-elastic/248509>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [September 14, 2020, 10:36am UTC](https://discuss.elastic.co/t/api-session-management-user-authentication-and-logout-kibana-elastic/248509 "2020-09-14T10:36:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![tarun1](https://avatars.discourse-cdn.com/v4/letter/t/8baadc/32.png) [@tarun1](https://discuss.elastic.co/u/tarun1)\
**Post date:** [September 14, 2020, 10:36am UTC](https://discuss.elastic.co/t/api-session-management-user-authentication-and-logout-kibana-elastic/248509/1 "2020-09-14T10:36:09Z")

</div>

I'm trying to use rest api to authenticate and logout session for Kibana.  
1)The only api I can see to authenticate in kibana is [https://localhost:9200/\_security/user/jacknich](https://localhost:9200/_security/user/jacknich) Which responds with user role, metadata but doesn't provide session cookie which i can utilize for further requests.  
How can i manage session by api ? Token authetication?

1. How can i logout from current session of user by hitting some api?

Thanks

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [September 14, 2020, 12:57pm UTC](https://discuss.elastic.co/t/api-session-management-user-authentication-and-logout-kibana-elastic/248509/2 "2020-09-14T12:57:08Z")

</div>

Token authentication is the answer there, indeed.

---

<div class="post-metadata">

**Author:** ![tarun1](https://avatars.discourse-cdn.com/v4/letter/t/8baadc/32.png) [@tarun1](https://discuss.elastic.co/u/tarun1)\
**Post date:** [September 15, 2020, 8:18am UTC](https://discuss.elastic.co/t/api-session-management-user-authentication-and-logout-kibana-elastic/248509/3 "2020-09-15T08:18:19Z")

</div>

Thanks Marius.  
I have configured Security between E & K. (SSL enabled) Now they are running on https.  
What will be next step for token authentication?  
I was hitting `POST /_security/oauth2/token with grant_type:password and basic auth credentials` and I got

> ```
> "type": "security_exception",
> "reason": "current license is non-compliant for [security tokens]",
> 
> ```

Will token authentication not work in Basic license? If not then how can i achieve session management by api without upgrading license.  
ELK version : 7.6.2

---

<div class="post-metadata">

**Author:** ![tarun1](https://avatars.discourse-cdn.com/v4/letter/t/8baadc/32.png) [@tarun1](https://discuss.elastic.co/u/tarun1)\
**Post date:** [September 22, 2020, 12:29pm UTC](https://discuss.elastic.co/t/api-session-management-user-authentication-and-logout-kibana-elastic/248509/4 "2020-09-22T12:29:22Z")

</div>

Any idea? @Marius_Dragomir

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [September 22, 2020, 2:15pm UTC](https://discuss.elastic.co/t/api-session-management-user-authentication-and-logout-kibana-elastic/248509/5 "2020-09-22T14:15:39Z")

</div>

The token service is Gold license and up, so it will not work with basic. As for workarounds, i don't really know of any.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 20, 2020, 2:15pm UTC](https://discuss.elastic.co/t/api-session-management-user-authentication-and-logout-kibana-elastic/248509/6 "2020-10-20T14:15:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
