# Authentication in elastic agent

**URL:** <https://discuss.elastic.co/t/authentication-in-elastic-agent/284979>\
**Category:** Beats\
**Tags:** fleet\
**Created:** [September 23, 2021, 9:26am UTC](https://discuss.elastic.co/t/authentication-in-elastic-agent/284979 "2021-09-23T09:26:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paurav\_Thakkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paurav_thakkar/32/78190_2.png) [@Paurav\_Thakkar](https://discuss.elastic.co/u/Paurav_Thakkar)\
**Post date:** [September 23, 2021, 9:26am UTC](https://discuss.elastic.co/t/authentication-in-elastic-agent/284979/1 "2021-09-23T09:26:32Z")

</div>

Hi,  
I am trying to understand how the authentication is handled in elastic agent for Elasticsearch. just like we have multiple options to configure beats to send data to Elasticsearch by giving api\_key, id/pass or certificate so which option does the fleet server configure and which option is more secure?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [September 30, 2021, 1:01pm UTC](https://discuss.elastic.co/t/authentication-in-elastic-agent/284979/2 "2021-09-30T13:01:44Z")

</div>

With fleet-server and managed mode, the only option is API Keys as these will be generated for you automatically. In the case of standalone elastic agent it is up to you on what to use.

---

<div class="post-metadata">

**Author:** ![Paurav\_Thakkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paurav_thakkar/32/78190_2.png) [@Paurav\_Thakkar](https://discuss.elastic.co/u/Paurav_Thakkar)\
**Post date:** [September 30, 2021, 1:17pm UTC](https://discuss.elastic.co/t/authentication-in-elastic-agent/284979/3 "2021-09-30T13:17:29Z")

</div>

@ruflin even if I use production based and provide certificates, will fleet still use API\_key based authentication? if yes, isn't this API\_key based authentication less secure then certificate based authentication?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 28, 2021, 3:18pm UTC](https://discuss.elastic.co/t/authentication-in-elastic-agent/284979/4 "2021-10-28T15:18:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
