# Embedded Kibana auto login

**URL:** <https://discuss.elastic.co/t/embedded-kibana-auto-login/203656>\
**Category:** Kibana\
**Created:** [October 15, 2019, 1:26pm UTC](https://discuss.elastic.co/t/embedded-kibana-auto-login/203656 "2019-10-15T13:26:30Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [October 15, 2019, 1:56pm UTC](https://discuss.elastic.co/t/embedded-kibana-auto-login/203656/2 "2019-10-15T13:56:47Z")

</div>

Hi @nickgregz,

I can confirm that there are only two ways that we recommend for such use case currently:

- Use SSO ([SAML](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#saml), [OIDC](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#oidc), Kerberos) or [PKI](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#pki-authentication)
- Use reverse proxy in front of Kibana that will be adding `Authorization` header

> [@nickgregz](#):
>
> Another suggested approach is to use an NGINX reverse proxy to add authentication, but wouldn't that mean that every request to Kibana would be authorized and unprotected?

Yes, all requests will be made on behalf of a dedicated user. You can of course create a dedicated read-only user with specific set of permissions, privileges etc, but it may not work for your use case.

You can also try to [integrate Third Party Auth](https://www.elastic.co/blog/user-impersonation-with-x-pack-integrating-third-party-auth-with-kibana).

Let me know if you still have questions,  
Oleg

---

_[View the full topic](https://discuss.elastic.co/t/embedded-kibana-auto-login/203656)._
