# Get Kibana Cookie with Custom Realm

**URL:** <https://discuss.elastic.co/t/get-kibana-cookie-with-custom-realm/216747>\
**Category:** Kibana\
**Created:** [January 28, 2020, 3:31am UTC](https://discuss.elastic.co/t/get-kibana-cookie-with-custom-realm/216747 "2020-01-28T03:31:57Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![YanbangLiuUiPath](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yanbangliuuipath/32/60975_2.png) [@YanbangLiuUiPath](https://discuss.elastic.co/u/YanbangLiuUiPath)\
**Post date:** [January 28, 2020, 3:31am UTC](https://discuss.elastic.co/t/get-kibana-cookie-with-custom-realm/216747/1 "2020-01-28T03:31:57Z")

</div>

Is there a way to get Kibana session cookie with custom realm?

Right now I'm using Bearer token generated by ES for API calls in Kibana, but ultimately I want the users to be able to automatically login to their own kibana spaces. This wouldn't be practical if I cannot generate session cookie for the browser.

I have tried curl "localhost:5601/api/security/v1/login" -H 'Authorization: Bearer 86auAxZ6bV9SdktRdVNOR3ZzSjBRcWFPazln' -H 'kbn-xsrf: kibana' -X POST

And obviously it did not work because this api requires username and password  
{"statusCode":400,"error":"Bad Request","message":""value" must be an object","validation":{"source":"payload","keys":["value"]}}

If there is a way to get cookies for custom realm please advice. If not then is there another way to automatically log users in Kibana?

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [January 29, 2020, 10:14am UTC](https://discuss.elastic.co/t/get-kibana-cookie-with-custom-realm/216747/2 "2020-01-29T10:14:45Z")

</div>

My best suggestion would be to use the token API in ES to get the tokens. Most of Kibana's auth is based on ES. [https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html)

---

<div class="post-metadata">

**Author:** ![YanbangLiuUiPath](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yanbangliuuipath/32/60975_2.png) [@YanbangLiuUiPath](https://discuss.elastic.co/u/YanbangLiuUiPath)\
**Post date:** [January 29, 2020, 5:36pm UTC](https://discuss.elastic.co/t/get-kibana-cookie-with-custom-realm/216747/3 "2020-01-29T17:36:23Z")

</div>

I did get the token from the API you mentioned. That's exactly the one I used in the Authorization header. However, the current issue is that I want the cookies to be set in the browser so that each request sent by the users would not still require the same token in the header.

---

<div class="post-metadata">

**Author:** ![YanbangLiuUiPath](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yanbangliuuipath/32/60975_2.png) [@YanbangLiuUiPath](https://discuss.elastic.co/u/YanbangLiuUiPath)\
**Post date:** [January 29, 2020, 11:16pm UTC](https://discuss.elastic.co/t/get-kibana-cookie-with-custom-realm/216747/4 "2020-01-29T23:16:50Z")

</div>

In the [documentation](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#oidc) it says:

> The session cookies that are issued by the token authentication provider are stateful, and logging out of Kibana invalidates the session cookies for reuse.

But how can I get the cookies? That's my question.

---

<div class="post-metadata">

**Author:** ![YanbangLiuUiPath](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yanbangliuuipath/32/60975_2.png) [@YanbangLiuUiPath](https://discuss.elastic.co/u/YanbangLiuUiPath)\
**Post date:** [February 3, 2020, 5:41pm UTC](https://discuss.elastic.co/t/get-kibana-cookie-with-custom-realm/216747/5 "2020-02-03T17:41:52Z")

</div>

Bump. I need an answer for this. At least I need to know if it is doable. Thanks.

---

<div class="post-metadata">

**Author:** ![virgilp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/virgilp/32/49291_2.png) [@virgilp](https://discuss.elastic.co/u/virgilp)\
**Post date:** [February 7, 2020, 11:59am UTC](https://discuss.elastic.co/t/get-kibana-cookie-with-custom-realm/216747/6 "2020-02-07T11:59:41Z")

</div>

For the benefit of others: It's not doable. What the documentation says (in a somewhat misleading way) is that the Token authentication provider will save the access/refresh token in the session cookie - and signing out will also invalidate the tokens(meaning, if you signed in on the web & then signed out, the access token won't work anymore for API calls either).

BUT: the Token authentication provider still uses the user/pass credentials for sign in. The only difference between it & Basic is that Basic provider will save the user/pass in session cookie, so logging out will not invalidate bearer tokens (if Kibana was configured to log in with basic authentication).

Also, the list of providers in x-pack security plugin is constant as of the time of this response (7.5.3) - which means that one can't write a new provider. One can though write a full plugin & store the access/refresh tokens in the session cookie for the Token provider to perform the authentication for user session (or at least, that's the theory I'm working on right now).

---

<div class="post-metadata">

**Author:** ![YanbangLiuUiPath](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yanbangliuuipath/32/60975_2.png) [@YanbangLiuUiPath](https://discuss.elastic.co/u/YanbangLiuUiPath)\
**Post date:** [February 10, 2020, 7:59pm UTC](https://discuss.elastic.co/t/get-kibana-cookie-with-custom-realm/216747/7 "2020-02-10T19:59:08Z")

</div>

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2020, 8:11pm UTC](https://discuss.elastic.co/t/get-kibana-cookie-with-custom-realm/216747/8 "2020-03-09T20:11:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
