# Automatic login with embedded dashboard

**URL:** <https://discuss.elastic.co/t/automatic-login-with-embedded-dashboard/337179>\
**Category:** Kibana\
**Created:** [June 29, 2023, 11:13am UTC](https://discuss.elastic.co/t/automatic-login-with-embedded-dashboard/337179 "2023-06-29T11:13:44Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![aa09](https://avatars.discourse-cdn.com/v4/letter/a/e5b9ba/32.png) [@aa09](https://discuss.elastic.co/u/aa09)\
**Post date:** [June 29, 2023, 11:13am UTC](https://discuss.elastic.co/t/automatic-login-with-embedded-dashboard/337179/1 "2023-06-29T11:13:45Z")

</div>

I have a dashboard that I want to share to users who are logged in to my application.

I followed the documentation and added the following to my elastic.yml  
xpack.security.authc.providers:  
basic.basic1:  
order: 0  
anonymous.anonymous1:  
order: 1  
credentials:  
username: “username”  
password: “password”

this works great and allows the dashboard to load in an iframe. however I realised it also allows anyone with the dashboard URL to access the dashboard, my dashboards can sometimes contain sensitive information so this is not something I want.

If I remove the **anonymous.anonymous1** block then a password is required to log in , which is ok if the dashboard URL is just being shared, but really what we want is for our application,(php/html) which we’ve embedded it into, to automatically authenticate without needing to login. so is there some way to pass the username / password by code or something?

Is this something that is possible and if so how would I achieve it?

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [June 29, 2023, 2:20pm UTC](https://discuss.elastic.co/t/automatic-login-with-embedded-dashboard/337179/2 "2023-06-29T14:20:11Z")

</div>

Hi @aa09,

Can you share if you are using the free version of Elastic or have a license? Are you making use of any single sign on technologies in your organisation?

---

<div class="post-metadata">

**Author:** ![aa09](https://avatars.discourse-cdn.com/v4/letter/a/e5b9ba/32.png) [@aa09](https://discuss.elastic.co/u/aa09)\
**Post date:** [June 30, 2023, 5:19pm UTC](https://discuss.elastic.co/t/automatic-login-with-embedded-dashboard/337179/3 "2023-06-30T17:19:08Z")

</div>

Hi @carly.richmond thanks for the response. we do have a license but we are currently not using any single sign on technologies. would that be the only way to achieve what ive described ?

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [July 3, 2023, 10:07am UTC](https://discuss.elastic.co/t/automatic-login-with-embedded-dashboard/337179/4 "2023-07-03T10:07:58Z")

</div>

If you're not wanting users to explicitly specify their login credentials and don't want to make use of the anonymous authentication capabilities as you have described, I think you'll need to consider another authentication mechanism such as SAML or tokens if you're using a technology such as Kerberos. I would have a look at the [Kibana authentication documentation](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#token-authentication).

Hope that helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2023, 10:08am UTC](https://discuss.elastic.co/t/automatic-login-with-embedded-dashboard/337179/5 "2023-07-31T10:08:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
