# Cors in Kibana

**URL:** <https://discuss.elastic.co/t/cors-in-kibana/264575>\
**Category:** Kibana\
**Created:** [February 17, 2021, 1:07pm UTC](https://discuss.elastic.co/t/cors-in-kibana/264575 "2021-02-17T13:07:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![seba\_galban](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seba_galban/32/58429_2.png) [@seba\_galban](https://discuss.elastic.co/u/seba_galban)\
**Post date:** [February 17, 2021, 1:07pm UTC](https://discuss.elastic.co/t/cors-in-kibana/264575/1 "2021-02-17T13:07:15Z")

</div>

Hi Everyone,

We have a problem when we want to get the cookie from Kibana 7.10.0.  
We have two scenarios:

- If we don´t use the **credentials: true** , In the header response we have the set-cookie attribute but the browser doesn't put it.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/d/1dab34fc3a237ed87166b80cfc90faf4a11879f2.png)

- If we use the **credentials: true** , we obtain the CORS error.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/5/357b66f0c172a532bfed83be95dfc12ff92347a5.png)

We need to set up the cookie avoid to the login for the user.

Thanks.

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [February 17, 2021, 3:52pm UTC](https://discuss.elastic.co/t/cors-in-kibana/264575/2 "2021-02-17T15:52:35Z")

</div>

> [@seba\_galban](#):
>
> We need to set up the cookie avoid to the login for the user.

@Larry_Gregory / @jportner can you throw some light on this please when you get a chance ?

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![jportner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jportner/32/75692_2.png) [@jportner](https://discuss.elastic.co/u/jportner)\
**Post date:** [February 17, 2021, 6:06pm UTC](https://discuss.elastic.co/t/cors-in-kibana/264575/3 "2021-02-17T18:06:39Z")

</div>

@seba_galban I'll start off by saying the internal APIs (such as the login API) are explicitly not supported for use outside of Kibana, and they can break at any time.

Are you running Kibana from source? Additional cors settings were technically available prior to 7.11, but only when running in dev mode ([https://github.com/elastic/kibana/issues/16714#issuecomment-593662086](https://github.com/elastic/kibana/issues/16714#issuecomment-593662086)).

If you aren't running from source, how are you setting the `Access-Control-Allow-Credentials: true` header? Are you using the `server.customResponseHeaders` Kibana config option? We did not add support for configuring CORS in a granular manner until Kibana 7.11 ([align cors settings names with elasticsearch by restrry · Pull Request #85738 · elastic/kibana · GitHub](https://github.com/elastic/kibana/pull/85738)).

What is the end goal you are trying to achieve? If you want to embed Kibana in another webpage, and/or allow anonymous access in Kibana, I would suggest upgrading to 7.11 where this is supported as a first-class feature ([What’s new in 7.11 | Kibana Guide [7.11] | Elastic](https://www.elastic.co/guide/en/kibana/7.11/whats-new.html#anonymous-access-available)).

---

<div class="post-metadata">

**Author:** ![seba\_galban](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seba_galban/32/58429_2.png) [@seba\_galban](https://discuss.elastic.co/u/seba_galban)\
**Post date:** [February 19, 2021, 8:07am UTC](https://discuss.elastic.co/t/cors-in-kibana/264575/4 "2021-02-19T08:07:12Z")

</div>

Thanks @jportner for your reply. We are using ELK stack from source and we want to allow anonymous access in Kibana. We are following your advice and we will try the new version.

Regards

---

<div class="post-metadata">

**Author:** ![jportner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jportner/32/75692_2.png) [@jportner](https://discuss.elastic.co/u/jportner)\
**Post date:** [February 22, 2021, 2:27pm UTC](https://discuss.elastic.co/t/cors-in-kibana/264575/5 "2021-02-22T14:27:33Z")

</div>

> [@seba\_galban](#):
>
> We are following your advice and we will try the new version.

Great, I hope it works out for you!

I just want to mention that we suggest no one run from source in production. We make a lot of assumptions and trade-offs while in developer mode, for example we only support the most recent version of Chrome/Firefox among lots of other things.

If you don't need to change any of the code, you should download the [distribution](https://www.elastic.co/downloads/kibana) and run that. Otherwise, you should [create a build](https://www.elastic.co/guide/en/kibana/master/building-kibana.html) and run that instead!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2021, 2:27pm UTC](https://discuss.elastic.co/t/cors-in-kibana/264575/6 "2021-03-22T14:27:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
