# Auto authenticating kibana iframe without logging in again from external web application

**URL:** <https://discuss.elastic.co/t/auto-authenticating-kibana-iframe-without-logging-in-again-from-external-web-application/199726>\
**Category:** Kibana\
**Created:** [September 16, 2019, 8:58pm UTC](https://discuss.elastic.co/t/auto-authenticating-kibana-iframe-without-logging-in-again-from-external-web-application/199726 "2019-09-16T20:58:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vishal\_M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_m/32/50559_2.png) [@vishal\_M](https://discuss.elastic.co/u/vishal_M)\
**Post date:** [September 16, 2019, 8:58pm UTC](https://discuss.elastic.co/t/auto-authenticating-kibana-iframe-without-logging-in-again-from-external-web-application/199726/1 "2019-09-16T20:58:14Z")

</div>

Hello Team,

I have embedded a dashboard into my external web application and able to see the dashboard (1 user). But, Kibana is asking me to enter the credentials every-time manually. I shouldn't enter the Kibana credentials once I log-in to my application. Is there any way I can configure my credentials in Kibana.YAML file or in the Nginx settings.

FYI: My web application, Kibana, and elastic-search have been deployed in Kubernetes cluster.

I am referring to the following post.  
[Auto-authenticating to iframe-embedded Kibana dashboard](https://discuss.elastic.co/t/auto-authenticating-to-iframe-embedded-kibana-dashboard/46091/4)

But, I have a few questions here...

1. My application, Kibana, and elastic search should be on the same domain (Meaning: Web application, Kibana, and elastic search should run on the same domain with different port numbers ([https://www.abc.net:8080](https://www.abc.net:8080/), 5601 and 9200) or can be in different domains ( my app in one domain, Kibana, and ES in another domain) .

If yes, can u please make any changes in my basic Nginx.conf

server {  
listen 80;  
listen [::]:80;  
root /usr/share/nginx/html;  
server\_name [www.dev-env.net](http://www.dev-env.net/)  
index index.html index.htm;  
location / {  
try\_files $uri $uri/ /index.html?/$request\_uri;  
}  
}

Thanks in Advance!  
Vishal Macha

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [September 16, 2019, 9:55pm UTC](https://discuss.elastic.co/t/auto-authenticating-kibana-iframe-without-logging-in-again-from-external-web-application/199726/2 "2019-09-16T21:55:32Z")

</div>

Hey @vishal_M, you'll want to use the [proxy\_set\_header](http://nginx.org/en/docs/http/ngx_http_proxy_module.html#proxy_set_header) directive to pass the [Authorization header](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Authorization) with a `Basic` scheme.

You'll first have to figure out the credentials to put in the Authorization headers. The following is how you'd do so on a variety of platforms. You'll have to substitute `elastic` for the actual and `changeme` for the actual password.

Ubuntu 16.04 and macOS

```auto
echo -n "elastic:changeme" | base64

```

Node

```auto
Buffer.from('elastic:changeme').toString('base64')

```

NGINX Configuration (replace `ZWxhc3RpYzpjaGFuZ2VtZQ==` with the output of the previous command)

```auto
server {
    listen 80;
    server_name localhost;

    location / {
        proxy_set_header Authorization "Basic ZWxhc3RpYzpjaGFuZ2VtZQ==";
        proxy_pass http://localhost:5601/;
    }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2019, 9:55pm UTC](https://discuss.elastic.co/t/auto-authenticating-kibana-iframe-without-logging-in-again-from-external-web-application/199726/3 "2019-10-14T21:55:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
