# Authenticated Elastic API - Best Practice

**URL:** <https://discuss.elastic.co/t/authenticated-elastic-api-best-practice/171397>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 7, 2019, 11:14pm UTC](https://discuss.elastic.co/t/authenticated-elastic-api-best-practice/171397 "2019-03-07T23:14:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![cgoss](https://avatars.discourse-cdn.com/v4/letter/c/65b543/32.png) [@cgoss](https://discuss.elastic.co/u/cgoss)\
**Post date:** [March 7, 2019, 11:14pm UTC](https://discuss.elastic.co/t/authenticated-elastic-api-best-practice/171397/1 "2019-03-07T23:14:34Z")

</div>

What would be the best practice to implement role based security between a back end service and Elasticsearch?

Basic Http Authentication or Token Based oAuth using bearer tokens.

I would lean towards the latter because it doesn't constantly transmit the user credentials for every call. Does the python library make use of the token approach or the basic auth?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 7, 2019, 11:53pm UTC](https://discuss.elastic.co/t/authenticated-elastic-api-best-practice/171397/2 "2019-03-07T23:53:47Z")

</div>

> [@cgoss](#):
>
> I would lean towards the latter because it doesn't constantly transmit the user credentials for every call.

That is true, but why is that important to you? It may not be the problem you think it is.

> [@cgoss](#):
>
> Token Based oAuth using bearer tokens.

This will work, but requires that you keep track of a refresh token and perform frequent refreshes that generate a new bearer token. It's not _hard_ but it's definitely more work than Basic Auth, so you'd want to be sure it's solving a real problem.

---

<div class="post-metadata">

**Author:** ![cgoss](https://avatars.discourse-cdn.com/v4/letter/c/65b543/32.png) [@cgoss](https://discuss.elastic.co/u/cgoss)\
**Post date:** [March 8, 2019, 7:33pm UTC](https://discuss.elastic.co/t/authenticated-elastic-api-best-practice/171397/3 "2019-03-08T19:33:07Z")

</div>

When I consider security settings I prefer to assume I am working in a hostile environment. Therefore I would choose the most secure option.

I recall reading that the access token can only be refreshed for up to 24 hours. Or is that the window in which the refresh token can be used to refresh the access token. "Provided it wasn't revoked"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2019, 7:33pm UTC](https://discuss.elastic.co/t/authenticated-elastic-api-best-practice/171397/4 "2019-04-05T19:33:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
