# Creating an API Key for KIBANA

**URL:** <https://discuss.elastic.co/t/creating-an-api-key-for-kibana/381931>\
**Category:** Kibana\
**Created:** [September 14, 2025, 11:50am UTC](https://discuss.elastic.co/t/creating-an-api-key-for-kibana/381931 "2025-09-14T11:50:34Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Viktor\_Movita](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/viktor_movita/32/135707_2.png) [@Viktor\_Movita](https://discuss.elastic.co/u/Viktor_Movita)\
**Post date:** [September 14, 2025, 11:50am UTC](https://discuss.elastic.co/t/creating-an-api-key-for-kibana/381931/1 "2025-09-14T11:50:34Z")

</div>

Hello everyone,  
I am trying to create an API key that has permissions to query the `/api/fleet/agents` endpoint.  
It is important for me to minimize its permissions as much as possible.  
Which permissions do I need to provide in the request body (I am creating the API key via the API)?  
I have tried various options without success.

Thank you very much.

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [September 23, 2025, 8:31am UTC](https://discuss.elastic.co/t/creating-an-api-key-for-kibana/381931/2 "2025-09-23T08:31:16Z")

</div>

Hello @Viktor_Movita

> **If we create API key with minimal privileges :**
>
> ```auto
> POST /_security/api_key
> {
> "name": "fleet_minimal_privileges",
> "role_descriptors": {
> "fleet_agents_query_role": {
> "cluster": [],
> "index": [
> {
> "names": [".fleet-agents"],
> "privileges": ["read"]
> }
> ],
> "applications": [
> {
> "application": "fleet",
> "privileges": ["read"],
> "resources": ["*"]
> }
> ]
> }
> }
> }
> 
> curl -X GET "https://<kibana-endpoint>/api/fleet/agents" \
> -H "Content-Type: application/json" \
> -H "Authorization: ApiKey <encoded-api-key>"
> 
> Received error => {"statusCode":403,"error":"Forbidden","message":"Forbidden"}
> 
> ```

> **If we create API key with full privileges :**
>
> ```auto
> POST /_security/api_key
> {
> "name": "fleet_full_permissions",
> "role_descriptors": {
> "fleet_full_access_role": {
> "cluster": ["all"],
> "index": [
> {
> "names": ["*"],
> "privileges": ["all"]
> }
> ],
> "applications": [
> {
> "application": "*",
> "privileges": ["*"],
> "resources": ["*"]
> }
> ]
> }
> }
> }
> 
> The curl works & returns data.
> 
> ```

> **To curl with minimal permission only found below way :**
>
> ```auto
> Create kibana role :
> POST /_security/role/fleet_agents_read
> {
> "cluster": ["monitor"],
> "index": [
> {
> "names": [".fleet-agents"],
> "privileges": ["read"]
> }
> ],
> "applications": [
> {
> "application": "kibana-.kibana",
> "privileges": ["read"],
> "resources": ["*"]
> }
> ]
> }
> 
> Assigned a new user to this role :
> 
> POST /_security/user/fleet_reader
> {
> "password": "set_password",
> "roles": ["fleet_agents_read"],
> "full_name": "Fleet Reader",
> "email": "fleet.reader@example.com"
> }
> 
> curl -X GET "https://your-kibana-url/api/fleet/agents" \
> -H "Content-Type: application/json" \
> -u "fleet_reader:set_password"
> 
> ```

Thanks!!
