# Auto-authenticate Kibana 5.3 dashboard embedded in iframe

**URL:** <https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059>\
**Category:** Kibana\
**Created:** [May 9, 2017, 10:22am UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059 "2017-05-09T10:22:36Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [May 16, 2017, 3:32pm UTC](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059/7 "2017-05-16T15:32:51Z")

</div>

You should be able to configure the CORS settings via the `server.cors` setting in `kibana.yml`, which will be forwarded to hapijs. For the valid values of that setting, please see the CORS-related settings in the [hapi route options documentation](https://hapijs.com/api/14.2.0#route-options). It would roughly look like this, but please check the linked documentation for specifics that might apply to your deployment environment:

```
server.cors:
  origin: ['YOUR', 'ORIGINS', 'HERE']
  credentials: true
```

---

_[View the full topic](https://discuss.elastic.co/t/auto-authenticate-kibana-5-3-dashboard-embedded-in-iframe/85059)._
