# AuthorizationException with python API to remote server

**URL:** <https://discuss.elastic.co/t/authorizationexception-with-python-api-to-remote-server/238514>\
**Category:** Elasticsearch\
**Created:** [June 24, 2020, 3:05pm UTC](https://discuss.elastic.co/t/authorizationexception-with-python-api-to-remote-server/238514 "2020-06-24T15:05:42Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuv\_c](https://avatars.discourse-cdn.com/v4/letter/y/f0a364/32.png) [@yuv\_c](https://discuss.elastic.co/u/yuv_c)\
**Post date:** [June 24, 2020, 3:05pm UTC](https://discuss.elastic.co/t/authorizationexception-with-python-api-to-remote-server/238514/1 "2020-06-24T15:05:42Z")

</div>

I am trying to use the elasticsearch python API but I get an AuthorizationException every time I run the query.

Here is the code:

```auto
host = "https:/foo.com/es" 
client = Elasticsearch(host, api_key='...MY_API_KEY...)
 
resp = client.search(
        index = "/some_index/_search",
        body = json.loads(get_query("query_name")),
    )

```

The response is 403 AuthorizationException.

The query returns the requested data when I run this code:

```auto
request_data = json.loads(request_data)
url = "/".join(["https:/foo.com/es" ,"some_index/_search"])
res = requests.get(
  url,
  json=request_data,
  timeout=(60, 60),
  headers={
  "Authorization": "...MY_API_KEY..."
   },
 )
res.raise_for_status()
return res.json()

```

Any ideas why it doesn't work with the elasticsearch API?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 24, 2020, 10:11pm UTC](https://discuss.elastic.co/t/authorizationexception-with-python-api-to-remote-server/238514/2 "2020-06-24T22:11:35Z")

</div>

What version of things are you using?

---

<div class="post-metadata">

**Author:** ![yuv\_c](https://avatars.discourse-cdn.com/v4/letter/y/f0a364/32.png) [@yuv\_c](https://discuss.elastic.co/u/yuv_c)\
**Post date:** [July 8, 2020, 1:55pm UTC](https://discuss.elastic.co/t/authorizationexception-with-python-api-to-remote-server/238514/3 "2020-07-08T13:55:47Z")

</div>

First - I'm sorry but I can't tell which version of ES the server is running (it's in a different part of my organisation and a different country).  
When I make the request to find out the basic info of it I get a 403 Error.

I solved my first problem, but came across a different problem.  
First - Here is the solution:

```auto
es = elasticsearch.Elasticsearch((HOST_URL))
res = es.search(
    index="some_index",
    body=request_data,
    headers={
            "Authorization": "ApiKey MY_API_KEY"
        }
) 

```

This returns the requested data.

However when I am trying to use the scroll method of the ES python client I'm getting strange results.

I have a code block that looks like this:

```auto
es = elasticsearch.Elasticsearch((HOST_URL))
res = es.search(
    index="some_index",
    body=request_data,
    headers={
            "Authorization": "ApiKey MY_API_KEY"
        },
    scroll='20s'
) 

# DO STUFF WITH THE RES...

while len(res["hits"]["hits"]) > 0:
        scroll_id = res['_scroll_id'] # Could change while scrolling
        res = es.scroll(body=scroll_id, 
                        scroll='20s',
                        headers={
                            "Authorization": "ApiKey MY_API_KEY"
                                }
                       )

```

When the scroll() function is called I get a 403 ERROR. These are the logs:

```auto
DEBUG:urllib3.connectionpool:Starting new HTTPS connection (1): ****.services.cloud.****.com:443

DEBUG:urllib3.connectionpool:[https:// ****.services.cloud.****.com:443](https://dashboard.services.cloud. ****.com/) "POST /es/INDEX_NAME/_search?scroll=20s HTTP/1.1" 200 1130281

INFO:elasticsearch:POST [https:// ****.services.cloud.****.com:443/es/INDEX_NAME/_search?scroll=20s](https:// ****.services.cloud.****.com/es/INDEX_NAME/_search?scroll=20s) [status:200 request:4.632s]

WARNING:elasticsearch:DELETE [https:// ****.services.cloud.****.com:443/es/_search/scroll](https:// ****.services.cloud.****.com/es/_search/scroll) [status:403 request:0.167s]

WARNING:elasticsearch:Undecodable raw error response from server: Expecting value: line 1 column 1 (char 0)
AuthorizationException Traceback (most recent call last)
...............
AuthorizationException: AuthorizationException(403, 'Das ist verboten')

```

I checked and I get a scroll\_id the way that I should.  
I also use the same function (with slight modifications) with a different ES server and this works fine.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 8, 2020, 9:20pm UTC](https://discuss.elastic.co/t/authorizationexception-with-python-api-to-remote-server/238514/4 "2020-07-08T21:20:16Z")

</div>

403 is an auth error, I would try the username and password with curl to check it works. If not, check the auth details with the team that is running the cluster.

---

<div class="post-metadata">

**Author:** ![yuv\_c](https://avatars.discourse-cdn.com/v4/letter/y/f0a364/32.png) [@yuv\_c](https://discuss.elastic.co/u/yuv_c)\
**Post date:** [July 9, 2020, 12:37pm UTC](https://discuss.elastic.co/t/authorizationexception-with-python-api-to-remote-server/238514/5 "2020-07-09T12:37:37Z")

</div>

I will check with them.  
I tried the same code with the requests library and it gets the same error when I make the second request (first request is a success, I retrieve the data along with a scroll\_id). The same code runs ok on different servers.

Since the first request is made to "some\_index":  
`https:// ****.services.cloud.****.com/es/INDEX_NAME/_search?scroll=20s`  
and the second goes to the scroll index:  
`https:// ****.services.cloud.****.com/es/_search/scroll`  
I'm guessing I don't have authorization for the scroll index. Is that possible?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 12, 2020, 10:16pm UTC](https://discuss.elastic.co/t/authorizationexception-with-python-api-to-remote-server/238514/6 "2020-07-12T22:16:07Z")

</div>

You may not have permission to scroll, yes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2020, 10:17pm UTC](https://discuss.elastic.co/t/authorizationexception-with-python-api-to-remote-server/238514/7 "2020-08-09T22:17:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
