# Fail to get access token

**URL:** <https://discuss.elastic.co/t/fail-to-get-access-token/101960>\
**Category:** Elasticsearch\
**Created:** [September 27, 2017, 9:35am UTC](https://discuss.elastic.co/t/fail-to-get-access-token/101960 "2017-09-27T09:35:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wu\_Chun\_Wa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wu_chun_wa/32/22563_2.png) [@Wu\_Chun\_Wa](https://discuss.elastic.co/u/Wu_Chun_Wa)\
**Post date:** [September 27, 2017, 9:35am UTC](https://discuss.elastic.co/t/fail-to-get-access-token/101960/1 "2017-09-27T09:35:02Z")

</div>

Hi Sir,

i just follow the doc.  
[https://www.elastic.co/guide/en/elasticsearch/reference/5.6/security-api-tokens.html](https://www.elastic.co/guide/en/elasticsearch/reference/5.6/security-api-tokens.html)

Call the following command  
POST /\_xpack/security/oauth2/token  
{  
"grant\_type" : "password",  
"username" : "elastic",  
"password" : "changeme"  
}

But, i get the following error.  
{  
"error" : {  
"root\_cause" : [  
{  
"type" : "security\_exception",  
"reason" : "missing authentication token for REST request [/\_xpack/security/oauth2/token?pretty]",  
"header" : {  
"WWW-Authenticate" : "Basic realm="security" charset="UTF-8""  
}  
}  
],  
"type" : "security\_exception",  
"reason" : "missing authentication token for REST request [/\_xpack/security/oauth2/token?pretty]",  
"header" : {  
"WWW-Authenticate" : "Basic realm="security" charset="UTF-8""  
}  
},  
"status" : 401  
}

Would you mind give me a suggestion to solve it?  
Thanks

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [September 27, 2017, 10:13am UTC](https://discuss.elastic.co/t/fail-to-get-access-token/101960/2 "2017-09-27T10:13:53Z")

</div>

The token endpoint is a secured URL. You need to authenticate using the standard mechanism (Authorization header, or PKI cert) as well as providing the username/password in the body.

From memory, the REST authentication does not need to match the username in the body.

---

<div class="post-metadata">

**Author:** ![Wu\_Chun\_Wa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wu_chun_wa/32/22563_2.png) [@Wu\_Chun\_Wa](https://discuss.elastic.co/u/Wu_Chun_Wa)\
**Post date:** [September 28, 2017, 3:22am UTC](https://discuss.elastic.co/t/fail-to-get-access-token/101960/3 "2017-09-28T03:22:19Z")

</div>

Any document to teach about how to use Authorization header to get access right?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [September 28, 2017, 7:07am UTC](https://discuss.elastic.co/t/fail-to-get-access-token/101960/4 "2017-09-28T07:07:13Z")

</div>

It sounds like you don't want to use the token service at all.  
The token service is for a very specific use case - if you're just trying to setup authentication to Elasticsearch, then it's not what you need.

You want to start here: [https://www.elastic.co/guide/en/x-pack/5.6/how-security-works.html#\_user\_authentication](https://www.elastic.co/guide/en/x-pack/5.6/how-security-works.html#_user_authentication)

If you have a username and password, then you just want to configure your HTTP client to do "Basic authentication". The specifics for that depend entirely on what client you are using to connect to ES.

---

<div class="post-metadata">

**Author:** ![Wu\_Chun\_Wa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wu_chun_wa/32/22563_2.png) [@Wu\_Chun\_Wa](https://discuss.elastic.co/u/Wu_Chun_Wa)\
**Post date:** [September 29, 2017, 8:28am UTC](https://discuss.elastic.co/t/fail-to-get-access-token/101960/5 "2017-09-29T08:28:55Z")

</div>

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 27, 2017, 8:29am UTC](https://discuss.elastic.co/t/fail-to-get-access-token/101960/6 "2017-10-27T08:29:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
