# Authentication not working and mixed docs over the web

**URL:** <https://discuss.elastic.co/t/authentication-not-working-and-mixed-docs-over-the-web/225053>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 25, 2020, 7:38pm UTC](https://discuss.elastic.co/t/authentication-not-working-and-mixed-docs-over-the-web/225053 "2020-03-25T19:38:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dean\_Hiller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dean_hiller/32/65058_2.png) [@Dean\_Hiller](https://discuss.elastic.co/u/Dean_Hiller)\
**Post date:** [March 25, 2020, 7:38pm UTC](https://discuss.elastic.co/t/authentication-not-working-and-mixed-docs-over-the-web/225053/1 "2020-03-25T19:38:35Z")

</div>

This was great for getting a key but it didn't show me how to use it at all in curl ...

[https://www.elastic.co/guide/en/beats/metricbeat/current/beats-api-keys.html](https://www.elastic.co/guide/en/beats/metricbeat/current/beats-api-keys.html)

Then I find this  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-create-api-key.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-create-api-key.html)

so, I in kabana console go get my 'id' which is a weird number(why not use the name which I called 'my\_api\_key' and instead use my weird id which is 'R7IAE3EB20gJv1tBoxY6'????)

and I go to website and type in my id:apikey to be used and tell website encode base 64.

2 questions

1. WHY are we encoding a string that is already a string in base64? base 64 is to put bytes into a string so you can put in json or some form of a string(this is backwards and should be fixed)

2. It's not working with header Www-Authenticate: ApiKey {key} in a curl command

curl -H "Www-Authenticate: ApiKey xxxxxxxxxxxxxxxxxxxxxxx1xNHRjeUcyUQ==" [https://669691555a414867xxxxxxxxxxxxxx.us-west1.gcp.cloud.es.io:9243](https://669691555a414867xxxxxxxxxxxxxx.us-west1.gcp.cloud.es.io:9243)

FAILURE doesn't really tell me much on what I should do:  
{"error":{"root\_cause":[{"type":"security\_exception","reason":"action [cluster:monitor/main] requires authentication","header":{"WWW-Authenticate":["Bearer realm="security"","ApiKey","Basic realm="security" charset="UTF-8""]}}],"type":"security\_exception","reason":"action [cluster:monitor/main] requires authentication","header":{"WWW-Authenticate":["Bearer realm="security"","ApiKey","Basic realm="security" charset="UTF-8""]}},"status":401}

oh and I was going off of this too

> **[Demystifying authentication and authorization in Elasticsearch](https://www.elastic.co/blog/demystifying-authentication-and-authorization-in-elasticsearch)**
>
> Find out how authentication and authorization works in Elasticsearch, including how to make sure only the proper APIs and users are allowed in, the types of authentication supported that are supported, how to make sure users see only the data they...

which also has the WWW-Authenticate: ApiKey in the response for some reason like I didn't supply that?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [March 26, 2020, 6:26am UTC](https://discuss.elastic.co/t/authentication-not-working-and-mixed-docs-over-the-web/225053/2 "2020-03-26T06:26:50Z")

</div>

Hi, thanks for your feedback!

> [@Dean\_Hiller](#):
>
> This was great for getting a key but it didn't show me how to use it at all in curl ...

This is not meant to be a generic API key documentation and thus it shows only how to use the API keys with the metricbeat.

> [@Dean\_Hiller](#):
>
> Then I find this  
> [Create API key API | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-create-api-key.html)

This is the correct reference documentation for creating API keys !

> [@Dean\_Hiller](#):
>
> so, I in kabana console go get my 'id' which is a weird number(why not use the name which I called 'my\_api\_key' and instead use my weird id which is 'R7IAE3EB20gJv1tBoxY6'????)

1. You don't actually "get your 'id'", you create an API key.
2. The API key has a name, an ID and a value. All serve different purposes, the name ID is something you specify to help you identify the API key, the id is something unique that identifies the API key in the system.

> [@Dean\_Hiller](#):
>
> and I go to website and type in my id:apikey to be used and tell website encode base 64.

Please don't do that. Your API key is your credentials, don't enter them in arbitrary websites, the same way you wouldn't enter your username and password in there. You can base64 encode it locally with i.e. :

```auto
echo -n 'theidhere:theapikeyhere' | base64

```

> [@Dean\_Hiller](#):
>
> WHY are we encoding a string that is already a string in base64? base 64 is to put bytes into a string so you can put in json or some form of a string(this is backwards and should be fixed)

This mimics the `Authorization` header where credentials are base64 encoded to allow for non-HTTP-compatible characters in them. We realize this extra step is cumbersome and we [are tracking adding support for this here](https://github.com/elastic/elasticsearch/issues/50235) so that we can return the base64 encoded string directly when you create the API key.

> [@Dean\_Hiller](#):
>
> It's not working with header Www-Authenticate: ApiKey {key} in a curl command

The header name is `Authorization` , not `Www-Authenticate`, it's shown in the example in the docs you referenced above too, the correct call is :

```auto
curl -H 'Authorization: ApiKey xxxxxxxxxxxxxxxxxxxxxxx1xNHRjeUcyUQ==' https://669691555a414867xxxxxxxxxxxxxx.us-west1.gcp.cloud.es.io:9243

```

[`Www-Authenticate`](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/WWW-Authenticate) is a response header , not a request header, and Elasticsearch is using that to tell you what kind of authentication schemes you can use.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 23, 2020, 6:28am UTC](https://discuss.elastic.co/t/authentication-not-working-and-mixed-docs-over-the-web/225053/3 "2020-04-23T06:28:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
