# Elasticsearch REST API Authorization

**URL:** <https://discuss.elastic.co/t/elasticsearch-rest-api-authorization/339332>\
**Category:** Elasticsearch\
**Created:** [July 26, 2023, 4:42pm UTC](https://discuss.elastic.co/t/elasticsearch-rest-api-authorization/339332 "2023-07-26T16:42:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ksobon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ksobon/32/103774_2.png) [@ksobon](https://discuss.elastic.co/u/ksobon)\
**Post date:** [July 26, 2023, 4:42pm UTC](https://discuss.elastic.co/t/elasticsearch-rest-api-authorization/339332/1 "2023-07-26T16:42:37Z")

</div>

OK, so I tried using the Elastic.Client.Elasticsearch library to get an index template, but it had some JSON serialization issues that was causing an exception. Next up, I tried using just a regular REST call.

I have create a RestSharp client like so:

```auto
var client = new RestClient("https://v8-test.elastic-cloud.com:9243")

ServicePointManager.Expect100Continue = true;
ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls12;

var request = new RestRequest("/_index_template/*", Method.GET)
{
  OnBeforeDeserialization = rest => { rest.ContentType = "application/json"; }
};
request.AddHeader("Content-Type", "application/json");
request.AddHeader("authorization", "ApiKey Base64ApiKey");

var response = client.Execute(request);

```

I am getting a 401 authorization exception for this one. The API Key is one created in Elastic Cloud but it looks like I am not able to use that, and it needs additional authorization. I thought I can create another API Key in Kibana and feed that in via `es-secondary-authorization` header, but that doesn't work. What kind of authorization do I need to get a template via the Elastic Search API?

---

<div class="post-metadata">

**Author:** ![Opster\_support](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/opster_support/32/56687_2.png) [@Opster\_support](https://discuss.elastic.co/u/Opster_support)\
**Post date:** [July 26, 2023, 6:09pm UTC](https://discuss.elastic.co/t/elasticsearch-rest-api-authorization/339332/2 "2023-07-26T18:09:28Z")

</div>

The 401 error indicates that the server is unable to authenticate your request. This could be due to an incorrect API key or incorrect usage of the API key.

When using an API key for authentication in Elasticsearch, you should include it in the Authorization header of your HTTP request. The format should be as follows:

```auto
Authorization: ApiKey <base64_encoded_credentials>

```

The `<base64_encoded_credentials>` part is a Base64-encoded string that is formed by concatenating the API key id and API key secret with a colon (`:`), like `id:secret`.

Here's how you can modify your code:

```csharp
var apiKey = "id:secret"; // replace with your actual id and secret
var encodedApiKey = Convert.ToBase64String(Encoding.UTF8.GetBytes(apiKey));
request.AddHeader("Authorization", "ApiKey " + encodedApiKey);

```

Please replace `"id:secret"` with your actual API key id and secret. If you're still facing issues, please ensure that the API key has the necessary permissions to get the index template.

[OpsGPT.io](http://OpsGPT.io) helped with part of this answer!

---

<div class="post-metadata">

**Author:** ![ksobon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ksobon/32/103774_2.png) [@ksobon](https://discuss.elastic.co/u/ksobon)\
**Post date:** [July 26, 2023, 7:16pm UTC](https://discuss.elastic.co/t/elasticsearch-rest-api-authorization/339332/3 "2023-07-26T19:16:26Z")

</div>

@Opster_support OK, your answer wasn't exactly what I was looking for, but it gave me a clue about what was wrong.

When I was creating the encoding for the API Key, I was using the `Encoding.ASCII.GetBytes()` method, and you suggested using `Encoding.UTF8.GetBytes()` That works.

In summary, you can use the basic authentication which would be the following:

```auto
var auth = Convert.ToBase64String(Encoding.UTF8.GetBytes("username:password"));
request.AddHeader("authorization", "Basic " + auth);

```

or the method you suggested for using the API Key method. Thank you, I will mark your answer as the solution here as it was good enough to get me on a right track. Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2023, 7:16pm UTC](https://discuss.elastic.co/t/elasticsearch-rest-api-authorization/339332/4 "2023-08-23T19:16:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
