# Displaying a dashboard via iframe without anonymous user access enabled

**URL:** <https://discuss.elastic.co/t/displaying-a-dashboard-via-iframe-without-anonymous-user-access-enabled/368644>\
**Category:** Kibana\
**Tags:** dashboard\
**Created:** [October 10, 2024, 6:28pm UTC](https://discuss.elastic.co/t/displaying-a-dashboard-via-iframe-without-anonymous-user-access-enabled/368644 "2024-10-10T18:28:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![trudesea](https://avatars.discourse-cdn.com/v4/letter/t/e480ec/32.png) [@trudesea](https://discuss.elastic.co/u/trudesea)\
**Post date:** [October 10, 2024, 6:28pm UTC](https://discuss.elastic.co/t/displaying-a-dashboard-via-iframe-without-anonymous-user-access-enabled/368644/1 "2024-10-10T18:28:48Z")

</div>

Hi,

I'm trying to display a dashboard in an iframe. My Kibana instance is required to use basic auth. I've setup a user specifically for this purpose.

I've tried setting up anonymous access but I don't want just anyone to be able to access the dashboard. And other users having to click on an auth method is a cumbersome solution.

Is there any way to use credentials in an iframe? I've read about setting up and nginx reverse proxy with headers containing user/pass but I'd rather simplify the solution rather than adding another piece.

How does everyone else do this without enabling anonymous auth and using a "service account"

Currently on 8.14.3

Thanks for any input.

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [October 11, 2024, 1:09pm UTC](https://discuss.elastic.co/t/displaying-a-dashboard-via-iframe-without-anonymous-user-access-enabled/368644/2 "2024-10-11T13:09:11Z")

</div>

Besides external procedures like the one you mentioned, only anonymous access and Single Sign-On mechanisms (SAML, OpenID) allow users to log in to an embedded Kibana without the login interface.

More details are available in this section of the documentation

> **[Authentication in Kibana | Kibana Guide \[8.15\] | Elastic](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#embedded-content-authentication)**

---

<div class="post-metadata">

**Author:** ![trudesea](https://avatars.discourse-cdn.com/v4/letter/t/e480ec/32.png) [@trudesea](https://discuss.elastic.co/u/trudesea)\
**Post date:** [October 11, 2024, 1:30pm UTC](https://discuss.elastic.co/t/displaying-a-dashboard-via-iframe-without-anonymous-user-access-enabled/368644/3 "2024-10-11T13:30:57Z")

</div>

Thank you for the response, I've read that doc more times than I can count.

So, second question....is there a way to login within the URL? I think I read somewhere that it isn't possible with xpack.

Thanks

---

<div class="post-metadata">

**Author:** ![Hadj\_Hassine\_Younes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hadj_hassine_younes/32/136002_2.png) [@Hadj\_Hassine\_Younes](https://discuss.elastic.co/u/Hadj_Hassine_Younes)\
**Post date:** [October 11, 2024, 2:34pm UTC](https://discuss.elastic.co/t/displaying-a-dashboard-via-iframe-without-anonymous-user-access-enabled/368644/4 "2024-10-11T14:34:25Z")

</div>

you cant desactivate xpack.security in the new version of elasticsearch 8.X . you should pay money to have the option of integrating an sso , saml , oidc .  
if you dont pay money you have only the option of anonymous authentication.

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [October 11, 2024, 3:14pm UTC](https://discuss.elastic.co/t/displaying-a-dashboard-via-iframe-without-anonymous-user-access-enabled/368644/5 "2024-10-11T15:14:21Z")

</div>

> [@trudesea](#):
>
> Thank you for the response, I've read that doc more times than I can count.

Same 😅

> [@trudesea](#):
>
> So, second question....is there a way to login within the URL? I think I read somewhere that it isn't possible with xpack.

Not that I'm aware.
