# Embedding Kibana dashboard in HTML Anonymously

**URL:** <https://discuss.elastic.co/t/embedding-kibana-dashboard-in-html-anonymously/256653>\
**Category:** Kibana\
**Tags:** canvas\
**Created:** [November 25, 2020, 12:07pm UTC](https://discuss.elastic.co/t/embedding-kibana-dashboard-in-html-anonymously/256653 "2020-11-25T12:07:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nathansegers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathansegers/32/79690_2.png) [@nathansegers](https://discuss.elastic.co/u/nathansegers)\
**Post date:** [November 25, 2020, 12:07pm UTC](https://discuss.elastic.co/t/embedding-kibana-dashboard-in-html-anonymously/256653/1 "2020-11-25T12:07:14Z")

</div>

Hi there,

**I am using latest Elasticsearch and Kibana version through Elastic Cloud.**

I wish to embed a Kibana dashboard into a HTML, but I seem to have encountered some problems.  
I have tried the options to setup the NGINX headers.

```auto
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-Host $proxy_add_x_forwarded_for;
proxy_set_header X-Found-Cluster <CLUSTER_ID>;
proxy_set_header Authorization "Bearer <API TOKEN>";
proxy_pass <KIBANA URL>;

```

With those settings, I get the error:

```json
{"ok":false,"message":"Unknown resource."}

```

When I do not pass the `Host` and `X-Found-Cluster` proxy\_headers, I get the following error:

```json
{
"statusCode":401,
"error":"Unauthorized",
"message":"[security_exception] missing authentication credentials for REST request [/_security/_authenticate], with { header={ WWW-Authenticate={ 0=\"Basic realm=\\\"security\\\" charset=\\\"UTF-8\\\"\" & 1=\"Bearer realm=\\\"security\\\"\" & 2=\"ApiKey\" } } }"
}

```

The API Key was generated with the Python Elasticsearch SDK and the User that creates this API key is Superuser on Elasticsearch.

```python
es_security = SecurityClient(es)
api_key = es_security.create_api_key({
  "name": "my_api_key_name", # Normally dynamic, now hardcoded for demo
  "role_descriptors": {
    "superuser-role": { 
      "cluster": ["all"],
      "index": [
        {
          "names": ["*"], # All indices to test
          "privileges": ["all"] # All Privileges to test
        }
       ]
    }
}})

```

I am developping locally and I have no way to generate an SSL certificate for my local machines.

I found out there was a security option to allow an anonymous user, but I can't seem to get that setup in Elastic Cloud, which I am using now.

> **[Enabling anonymous access | Elasticsearch Reference \[7.x\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.x/anonymous-access.html)**

Is there any way to embed a whole Kibana Space without requiring a user login?

---

<div class="post-metadata">

**Author:** ![jportner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jportner/32/75692_2.png) [@jportner](https://discuss.elastic.co/u/jportner)\
**Post date:** [December 2, 2020, 3:05pm UTC](https://discuss.elastic.co/t/embedding-kibana-dashboard-in-html-anonymously/256653/2 "2020-12-02T15:05:31Z")

</div>

I noticed that you've got the wrong authorization value prefix:

```auto
proxy_set_header Authorization "Bearer <API TOKEN>";

```

According to the [docs](https://www.elastic.co/guide/en/kibana/master/api-keys.html#create-api-key), it should look like this:

```auto
proxy_set_header Authorization "ApiKey <API TOKEN>";

```

That prefix tells Kibana what authentication provider to use when dealing with this credential.

If that doesn't work, can you try to test it directly against Kibana? Keep in mind the token must be base64-encoded first. E.g.,

```auto
curl --location --request GET 'http://localhost:5601/api/security/role' \
--header 'Content-Type: application/json;charset=UTF-8' \
--header 'kbn-xsrf: true' \
--header 'Authorization: ApiKey aVZlLUMzSUJuYndxdDJvN0k1bU46aGxlYUpNS2lTa2FKeVZua1FnY1VEdw==' \

```

---

<div class="post-metadata">

**Author:** ![jportner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jportner/32/75692_2.png) [@jportner](https://discuss.elastic.co/u/jportner)\
**Post date:** [December 2, 2020, 3:18pm UTC](https://discuss.elastic.co/t/embedding-kibana-dashboard-in-html-anonymously/256653/3 "2020-12-02T15:18:15Z")

</div>

> [@nathansegers](#):
>
> I found out there was a security option to allow an anonymous user, but I can't seem to get that setup in Elastic Cloud, which I am using now.

Elastic Cloud will allow you to use the `anonymous` user for Elasticsearch, you just have to create one or more roles for that user. However, Elasticsearch anonymous access can't currently be used in Kibana. We made an [enhancement](https://github.com/elastic/kibana/pull/84074) to enable this though, and it's expected to be included in the 7.11 release!

[Starting in 7.11](https://github.com/elastic/kibana/pull/79985), you'll also be able to configure your own anonymous access all within in Kibana (for example, using the API key you generated).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2020, 3:18pm UTC](https://discuss.elastic.co/t/embedding-kibana-dashboard-in-html-anonymously/256653/4 "2020-12-30T15:18:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
