# callWithRequest putUser

**URL:** https://discuss.elastic.co/t/callwithrequest-putuser/233975
**Category:** Kibana
**Created:** [May 23, 2020, 3:24am UTC](https://discuss.elastic.co/t/callwithrequest-putuser/233975 "2020-05-23T03:24:42Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![McKittrick\_Kaminski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mckittrick_kaminski/32/59595_2.png) [@McKittrick\_Kaminski](https://discuss.elastic.co/u/McKittrick_Kaminski)
#### Post date: [May 23, 2020, 3:24am UTC](https://discuss.elastic.co/t/callwithrequest-putuser/233975/1 "2020-05-23T03:24:42Z")

</div>

Making a custom Kibana plugin, and I'm looking to create a user with the callWithRequest function. I'm able to do some operations like `ping` and `cluster.health`, but `putUser` doesn't seem to be available.

I even took a crawl in the `kibana/src/core/server/elasticsearch/api_types.ts`, and there doesn't appear to be any security endpoints available.

Is it possible to call `putUser` using the clients credentials? Push come to shove, I can just create an username, password box and have them enter in admin credentials, and use the nodejs library for ES separately, which I'm doing mostly anyway.

---

<div class="post-metadata">

### Author: ![lukeelmers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukeelmers/32/35230_2.png) [@lukeelmers](https://discuss.elastic.co/u/lukeelmers)
#### Post date: [May 26, 2020, 4:16pm UTC](https://discuss.elastic.co/t/callwithrequest-putuser/233975/2 "2020-05-26T16:16:33Z")

</div>

> I even took a crawl in the `kibana/src/core/server/elasticsearch/api_types.ts` , and there doesn't appear to be any security endpoints available.

This is correct -- currently the ES client doesn't have definitions for x-pack APIs. At the moment there are two ways to work around this:

1. You can use [`transport.request`](https://www.elastic.co/guide/en/elasticsearch/client/javascript-api/16.x/transport-reference.html) to send any arbitrary request to Elasticsearch. This is a catch-all to enable working with any ES APIs which don't have definitions in `api_types.ts`.
2. You can use `core.elasticsearch.createClient` to register a [custom plugin](https://www.elastic.co/guide/en/elasticsearch/client/javascript-api/16.x/extending_core_components.html) which extends the ES client and knows how to handle `putUser`. This is what the x-pack security plugin currently does because it handles some niceties like validation for you. Though I will note that this is all based on the legacy ES client; we have not yet migrated Kibana to using [the new JS client](https://www.elastic.co/guide/en/elasticsearch/client/javascript-api/current/introduction.html), which will offer [its own way of extending the client](https://www.elastic.co/guide/en/elasticsearch/client/javascript-api/current/extend-client.html).

Usage of the legacy `createClient` looks something like this:

```auto
setup(core) {
  const client = core.elasticsearch.createClient('foo', {
    plugins: [myClientPlugin],
  });

  const router = core.http.createRouter();
  router.post({
    path: '/my/api',
    validate: {...},
  },
  handler: async (ctx, req, res) => {
    await client.asScoped(request).callAsCurrentUser('putUser', {
      ...params for client plugin
    });
    return response.ok({...});
  });
}

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 23, 2020, 4:16pm UTC](https://discuss.elastic.co/t/callwithrequest-putuser/233975/3 "2020-06-23T16:16:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
