# Bearer Tokens and Elasticsearch API

**URL:** <https://discuss.elastic.co/t/bearer-tokens-and-elasticsearch-api/166702>\
**Category:** Elastic Cloud Enterprise (ECE)\
**Created:** [February 1, 2019, 9:35am UTC](https://discuss.elastic.co/t/bearer-tokens-and-elasticsearch-api/166702 "2019-02-01T09:35:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![JamesNotJamez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamesnotjamez/32/45736_2.png) [@JamesNotJamez](https://discuss.elastic.co/u/JamesNotJamez)\
**Post date:** [February 1, 2019, 9:35am UTC](https://discuss.elastic.co/t/bearer-tokens-and-elasticsearch-api/166702/1 "2019-02-01T09:35:28Z")

</div>

Hi,  
Through the ECE ui there is the option of API console on each cluster which sends a request like this

```auto
https://<ECE_URL>:12443/api/v0.1/regions/ece-region/clusters/b5fa10fc95c940fdb85c3f2f800f0dae/proxy/_cluster/_search

```

However when I post this command in the browser I get

```auto
{"ok":false,"message":"The supplied authentication is invalid"}

```

So I have been trying to use

```auto
POST /api/v1/users/auth/_refresh
 - https://www.elastic.co/guide/en/cloud-enterprise/current/refresh-token.html

```

to get a token but this is giving me both

```auto
{'errors': [{'message': 'HTTP method not allowed, supported methods: [GET]', 'code': 'root.method_not_allowed'}]}
and 
{'errors': [{'message': 'The requested resource could not be found', 'code': 'root.resource_not_found'}]}

```

When I use POST and GET respectively. Not sure if this is a bug in the API?

Thanks

---

<div class="post-metadata">

**Author:** ![osykora](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/osykora/32/41464_2.png) [@osykora](https://discuss.elastic.co/u/osykora)\
**Post date:** [February 1, 2019, 12:19pm UTC](https://discuss.elastic.co/t/bearer-tokens-and-elasticsearch-api/166702/2 "2019-02-01T12:19:38Z")

</div>

Hi,

you are missing authorization header in the search request. It requires basic auth with ECE admin and password. Basically, you have to use Postman, curl or another tool to send these requests that allow you to specify headers.

The header you must include looks like this:  
`Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJhZG1pbiIsIm5iZiI6MTU0OTAyMjUwMCwiaXNzIjoiZm91bmQtYWRtaW5jb25zb2xlIiwiZXhwIjoxNTQ5MDI0MzAwLCJpYXQiOjE1NDkwMjI1MDB9.NLQ4Oe0gDfD_EuMbSAcFzHWPAgidISPzqB9JcrHcdlV`

[https://www.elastic.co/guide/en/cloud-enterprise/current/ece-api-reference.html#ece-authentication](https://www.elastic.co/guide/en/cloud-enterprise/current/ece-api-reference.html#ece-authentication)

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [February 1, 2019, 2:02pm UTC](https://discuss.elastic.co/t/bearer-tokens-and-elasticsearch-api/166702/3 "2019-02-01T14:02:54Z")

</div>

I think there is a v1 version of the "elasticsearch proxy" endpoint, which allows you to use basic auth

[link](https://www.elastic.co/guide/en/cloud-enterprise/current/Clusters_-_Elasticsearch_-_Proxy.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 15, 2019, 2:03pm UTC](https://discuss.elastic.co/t/bearer-tokens-and-elasticsearch-api/166702/4 "2019-02-15T14:03:15Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
