# GET /\_security/api\_key does not show "role\_descriptors"

**URL:** <https://discuss.elastic.co/t/get-security-api-key-does-not-show-role-descriptors/373029>\
**Category:** Elasticsearch\
**Created:** [January 9, 2025, 7:48pm UTC](https://discuss.elastic.co/t/get-security-api-key-does-not-show-role-descriptors/373029 "2025-01-09T19:48:51Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Byungsoo\_Kim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/byungsoo_kim/32/139800_2.png) [@Byungsoo\_Kim](https://discuss.elastic.co/u/Byungsoo_Kim)\
**Post date:** [January 9, 2025, 7:48pm UTC](https://discuss.elastic.co/t/get-security-api-key-does-not-show-role-descriptors/373029/1 "2025-01-09T19:48:51Z")

</div>

I am using ES cloud and create api\_key through "API Console" UI on ES cloud. The following is an example of the payload to create an api\_key

```auto
POST /_security/api_key
{
  "name": "midtier-2025",
  "role_descriptors": {
    "midtier": {
      "index": [
        {
          "names": [
            "index1",
            "index2"
          ],
          "privileges": [
            "read",
            "write",
            "maintenance"
          ]
        }
      ]
    }
  }
}

```

I am trying to get the `role_descriptors` I supplied for the api\_key. According to the doc, a simple GET call should return this but the response does not include it at all. The following is an example

```auto
GET /_security/api_key?name=midtier-2024

{
  "api_keys": [
    {
      "id": "fakeid2432",
      "name": "midtier-2024",
      "creation": 1707506042878,
      "invalidated": false,
      "username": "elastic-userconsole-proxy",
      "realm": "found",
      "metadata": {}
    }
  ]
}

```

What am I missing? Is this a permission issue or something? I would appreciate for any help.

Byungsoo Kim

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 9, 2025, 8:02pm UTC](https://discuss.elastic.co/t/get-security-api-key-does-not-show-role-descriptors/373029/2 "2025-01-09T20:02:55Z")

</div>

Hi @Byungsoo_Kim Welcome to the community

Welll assuming you are logged in as the `elastic` user this should work...

I did notice your `POST` is malformed and does not work so perhaps you somehow submitted it with no roles once or something

Worked for me

```auto
POST /_security/api_key
{
  "name": "midtier-2025",
  "role_descriptors": {
    "midtier": {
      "index": [
        {
          "names": [
            "index1",
            "index2"
          ],
          "privileges": [
            "read",
            "write",
            "maintenance"
          ]
        }
      ]
    }
  }
}

GET /_security/api_key?name=discuss-2025

# Results
# POST /_security/api_key 200 OK
{
  "id": "9b2oTJQBmcDx6OSl_IVj",
  "name": "midtier-2025",
  "api_key": "Fd8J9DeySjiHpXwi7UvDYQ",
  "encoded": "OWIyb1RKUUJtY0R4Nk9TbF9JVmo6RmQ4SjlEZXlTamlIcFh3aTdVdkRZUQ=="
}
# GET /_security/api_key?name=discuss-2025 200 OK
{
  "api_keys": [
    {
      "id": "VbykTJQBS9VyZaU1NbtQ",
      "name": "discuss-2025",
      "type": "rest",
      "creation": 1736452617570,
      "invalidated": true,
      "invalidation": 1736452908001,
      "username": "elastic",
      "realm": "found",
      "realm_type": "file",
      "metadata": {},
      "role_descriptors": {
        "midtier": {
          "cluster": [],
          "indices": [
            {
              "names": [
                "index1",
                "index2"
              ],
              "privileges": [
                "read",
                "write",
                "maintenance"
              ],
              "allow_restricted_indices": false
            }
          ],
          "applications": [],
          "run_as": [],
          "metadata": {},
          "transient_metadata": {
            "enabled": true
          }
        }
      }
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![Byungsoo\_Kim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/byungsoo_kim/32/139800_2.png) [@Byungsoo\_Kim](https://discuss.elastic.co/u/Byungsoo_Kim)\
**Post date:** [January 10, 2025, 12:40pm UTC](https://discuss.elastic.co/t/get-security-api-key-does-not-show-role-descriptors/373029/3 "2025-01-10T12:40:03Z")

</div>

Stephen,

Thanks for correcting the JSON; I manually modified the production payload and I am 100% sure I submitted the right payload when I generated the api key. Otherwise, we would have an outage in the prod. I updated it in the original post.

> Welll assuming you are logged in as the `elastic` user this should work...

I am not an admin and UI is the only way I can make API calls; I login to Elastic Cloud, "Manage" next to the cloud deployment, and select "API Console". From there, I run the API calls. Maybe this is a permission issue for my user?

Byungsoo

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 10, 2025, 4:02pm UTC](https://discuss.elastic.co/t/get-security-api-key-does-not-show-role-descriptors/373029/4 "2025-01-10T16:02:50Z")

</div>

Well as Elastic Cloud Admin I see the complete response so I suspect your privileges are limited...

 ![Screenshot 2025-01-10 at 8.01.16 AM](https://us1.discourse-cdn.com/elastic/original/3X/b/b/bb5987b068f8e4f381ff039e5594487c793aa3a9.png)

---

<div class="post-metadata">

**Author:** ![Byungsoo\_Kim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/byungsoo_kim/32/139800_2.png) [@Byungsoo\_Kim](https://discuss.elastic.co/u/Byungsoo_Kim)\
**Post date:** [January 10, 2025, 5:33pm UTC](https://discuss.elastic.co/t/get-security-api-key-does-not-show-role-descriptors/373029/5 "2025-01-10T17:33:06Z")

</div>

Stephen,

Thanks for trying it from UI. I agree that it has something to do with privileges.

I have little knowledge in user security model in Elasticsearch and I don't know which permission is missing. Could you direct me to a doc or something? (Admin will ask which permission I need. One thing he will NOT give away is a general read permission since we limit the access to the customer data)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 10, 2025, 5:54pm UTC](https://discuss.elastic.co/t/get-security-api-key-does-not-show-role-descriptors/373029/6 "2025-01-10T17:54:46Z")

</div>

I am not sure there is enough granular access ...

Docs

> **[User roles and privileges | Elasticsearch Service Documentation | Elastic](https://www.elastic.co/guide/en/cloud/current/ec-user-privileges.html)**

Go to Elastic Cloud Console and go to your profile and check your role.

I suspect you are a viewer

> - **Viewer** - Can view deployments, and can sign on to the deployment with the viewer Stack role. This role can be scoped to one or more deployments.

So you should be able to click on the Kibana link and then Go To Dev Tools and run the command.

I am not sure... you can also open a support ticket

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 13, 2025, 6:35am UTC](https://discuss.elastic.co/t/get-security-api-key-does-not-show-role-descriptors/373029/7 "2025-01-13T06:35:43Z")

</div>

> [@Byungsoo\_Kim](#):
>
> According to the doc

This is almost certainly due to looking at the docs for a different version than you are actually running.

The role descriptors were not shown before Elasticsearch version 8.5, and I suspect you are running an older version

---

<div class="post-metadata">

**Author:** ![Byungsoo\_Kim](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/byungsoo_kim/32/139800_2.png) [@Byungsoo\_Kim](https://discuss.elastic.co/u/Byungsoo_Kim)\
**Post date:** [January 13, 2025, 12:19pm UTC](https://discuss.elastic.co/t/get-security-api-key-does-not-show-role-descriptors/373029/8 "2025-01-13T12:19:25Z")

</div>

Tim,

Thanks for checking. That may be the case; we are using Elastic Stack version 7.13. I did check some old doc (7.17) and the example in it did not have the content for `role_descriptor` so I was not sure if it was supposed to return or not.

I will ask my admin if we have any plan to upgrade the version. If not, I guess I am stuck on this issue.

Thanks for your help

Byungsoo

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 14, 2025, 12:52am UTC](https://discuss.elastic.co/t/get-security-api-key-does-not-show-role-descriptors/373029/9 "2025-01-14T00:52:48Z")

</div>

> [@Byungsoo\_Kim](#):
>
> Elastic Stack version 7.13

[7.13 is three and half years old](https://www.elastic.co/blog/whats-new-elasticsearch-7-13-0), has a number of published vulnerabilities, and is no longer supported or maintained. You should definitely encourage your admin to upgrade.

All of 7.x will cease to be maintained once 9.0 is released so you should be planning to move to 8.x soon.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2025, 12:53am UTC](https://discuss.elastic.co/t/get-security-api-key-does-not-show-role-descriptors/373029/10 "2025-02-11T00:53:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
