# Error: called with an invalid endpoint: security.getToken

**URL:** <https://discuss.elastic.co/t/error-called-with-an-invalid-endpoint-security-gettoken/246194>\
**Category:** Kibana\
**Created:** [August 24, 2020, 9:55pm UTC](https://discuss.elastic.co/t/error-called-with-an-invalid-endpoint-security-gettoken/246194 "2020-08-24T21:55:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![npm\_install](https://avatars.discourse-cdn.com/v4/letter/n/c68b51/32.png) [@npm\_install](https://discuss.elastic.co/u/npm_install)\
**Post date:** [August 24, 2020, 9:55pm UTC](https://discuss.elastic.co/t/error-called-with-an-invalid-endpoint-security-gettoken/246194/1 "2020-08-24T21:55:55Z")

</div>

I am creating a Kibana Plugin using the kibana plugin generator, and I have a route defined that is using the elasticsearch dataClient to get a token:

```
context.core.elasticsearch.dataClient.callAsCurrentUser('security.getToken', {"grant_type":"client_credentials"})

```

However, I get an error:

```
Error: called with an invalid endpoint: security.getToken

```

But I know that this should be a valid endpoint because it is listed [here](https://www.elastic.co/guide/en/elasticsearch/client/javascript-api/current/api-reference.html#_security_gettoken) as an API.

Why is this error being thrown? Is there another way to get the token?

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [August 25, 2020, 6:24pm UTC](https://discuss.elastic.co/t/error-called-with-an-invalid-endpoint-security-gettoken/246194/2 "2020-08-25T18:24:18Z")

</div>

Hi which version of Kibana are you working with? If you are not working off the `master` branch but using a version branch instead, the ES client might not be the same version as the documentation that you found and it might not be new enough to support X-Pack APIs.

If that is the case, you can try using `transport.request`:  
[https://www.elastic.co/guide/en/elasticsearch/client/javascript-api/7.x/transport\_request\_examples.html](https://www.elastic.co/guide/en/elasticsearch/client/javascript-api/7.x/transport_request_examples.html)

---

<div class="post-metadata">

**Author:** ![npm\_install](https://avatars.discourse-cdn.com/v4/letter/n/c68b51/32.png) [@npm\_install](https://discuss.elastic.co/u/npm_install)\
**Post date:** [August 25, 2020, 6:26pm UTC](https://discuss.elastic.co/t/error-called-with-an-invalid-endpoint-security-gettoken/246194/3 "2020-08-25T18:26:38Z")

</div>

Hi! I am using version 7.6.2. I will go ahead and try the transport.request!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 22, 2020, 6:26pm UTC](https://discuss.elastic.co/t/error-called-with-an-invalid-endpoint-security-gettoken/246194/4 "2020-09-22T18:26:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
