# Can a normal user get API read/write permissions?

**URL:** <https://discuss.elastic.co/t/can-a-normal-user-get-api-read-write-permissions/274066>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [May 26, 2021, 1:39pm UTC](https://discuss.elastic.co/t/can-a-normal-user-get-api-read-write-permissions/274066 "2021-05-26T13:39:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sandra\_Schlichting](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandra_schlichting/32/84122_2.png) [@Sandra\_Schlichting](https://discuss.elastic.co/u/Sandra_Schlichting)\
**Post date:** [May 26, 2021, 1:39pm UTC](https://discuss.elastic.co/t/can-a-normal-user-get-api-read-write-permissions/274066/1 "2021-05-26T13:39:34Z")

</div>

Dear all =)

Is it possible for a normal Kibana user to have API read/write permissions?

What I would like to be to do is create and delete Kibana Alerts, but when I do

```auto
$ curl -u sandra -X POST "https://kibana.example.com/s/example/api/alerts/rule -H 'kbn-xsrf: true' -H 'Content-Type: application/json' -d '" -H 'kbn-xsrf: true' -H 'Content-Type: application/json' -d @create.json 

```

I get `404` indicating I am missing a write permission.

From my understand Kibana Spaces should allow to users (or [API keys](https://www.elastic.co/guide/en/kibana/master/api-keys.html)) to get read/write access to specific spaces. Is that correct and if so, does that also apply for the API?

Hugs,  
Sandra =)

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [May 28, 2021, 3:47am UTC](https://discuss.elastic.co/t/can-a-normal-user-get-api-read-write-permissions/274066/2 "2021-05-28T03:47:47Z")

</div>

Are you sure space exists? I would expect a 403 if you didn't have permission to the resource. 404 indicates it doesn't exist.

---

<div class="post-metadata">

**Author:** ![Sandra\_Schlichting](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandra_schlichting/32/84122_2.png) [@Sandra\_Schlichting](https://discuss.elastic.co/u/Sandra_Schlichting)\
**Post date:** [May 28, 2021, 8:35am UTC](https://discuss.elastic.co/t/can-a-normal-user-get-api-read-write-permissions/274066/3 "2021-05-28T08:35:08Z")

</div>

@tylersmalley Thanks a lot for pointing that out! That helped me to find the problem =)

The above`curl` command is messed up from a bad copy/paste. It should have been

```auto
url="https://example.com/s/example/api/alerts/alert"
curl -u "x:x" -X POST $url \
     -H 'kbn-xsrf: true' -H 'Content-Type: application/json' \
     -d '{"a":"a"}'

```

Here I used the URL that I dumped from Chrome, but according to the [doc](https://www.elastic.co/guide/en/kibana/current/create-rule-api.html) I should have used

`/api/alerting/rule` instead of `/api/alerts/alert`.

What is the difference of the two?

I am so happy, that is works now. Thanks again =)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 25, 2021, 8:35am UTC](https://discuss.elastic.co/t/can-a-normal-user-get-api-read-write-permissions/274066/4 "2021-06-25T08:35:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
