# APIKey retains the cluster privileges at the time is was created

**URL:** <https://discuss.elastic.co/t/apikey-retains-the-cluster-privileges-at-the-time-is-was-created/296359>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 5, 2022, 11:33am UTC](https://discuss.elastic.co/t/apikey-retains-the-cluster-privileges-at-the-time-is-was-created/296359 "2022-02-05T11:33:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roger\_Clark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roger_clark/32/77615_2.png) [@Roger\_Clark](https://discuss.elastic.co/u/Roger_Clark)\
**Post date:** [February 5, 2022, 11:33am UTC](https://discuss.elastic.co/t/apikey-retains-the-cluster-privileges-at-the-time-is-was-created/296359/1 "2022-02-05T11:33:12Z")

</div>

We were testing out migration to APIKeys for application-level API access and I noticed something strange I can't find documented anywhere, this is under a ELK stack running 7.15.1

I created a new user and role, and forgot to add a specific cluster privilege before creating the API key for the user. Some actions on the cluster fail and a specific `_search` is valid but returns 0 docs.

I update the role for the user to be correct now, if I call into the `_search` with authorization `Basic username:password`, it returns a result. If I make the same query with the `Authorization ApiKey <user's Base64 string>`, the query returns 0 results.

If I create a second ApiKey while the user role has the correct privileges, and send this to `_search` it returns the correct results.

It almost seems that the ApiKey holds the privileges at the time it was created and not current to user who holds the ApiKey. Is this the intended behavior? I can understand arguments for this either way.

Thanks,  
Roger

---

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [February 5, 2022, 1:32pm UTC](https://discuss.elastic.co/t/apikey-retains-the-cluster-privileges-at-the-time-is-was-created/296359/2 "2022-02-05T13:32:07Z")

</div>

It is worded kind of weirdly in the [API Key created docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-create-api-key.html#security-api-create-api-key-request-body).

> When it is not specified or is an empty array, then the API key will have a point in time snapshot of permissions of the authenticated user.

Since the API Key is created with a point in time snapshot, the permissions will not be updated if you update the backing user.

---

<div class="post-metadata">

**Author:** ![Roger\_Clark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roger_clark/32/77615_2.png) [@Roger\_Clark](https://discuss.elastic.co/u/Roger_Clark)\
**Post date:** [February 5, 2022, 5:39pm UTC](https://discuss.elastic.co/t/apikey-retains-the-cluster-privileges-at-the-time-is-was-created/296359/3 "2022-02-05T17:39:20Z")

</div>

Thanks, yeah, I guess that's kinda clear. I had created it through Kibana and left the restrict privileges off thinking it would apply to the user/role under which it was created, but created the empty array and activating the point-in-time effect.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 5, 2022, 5:40pm UTC](https://discuss.elastic.co/t/apikey-retains-the-cluster-privileges-at-the-time-is-was-created/296359/4 "2022-03-05T17:40:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
