# GET /\_security/api\_key?name=any\_key returns 200 when no key present

**URL:** <https://discuss.elastic.co/t/get-security-api-key-name-any-key-returns-200-when-no-key-present/290682>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 1, 2021, 2:48pm UTC](https://discuss.elastic.co/t/get-security-api-key-name-any-key-returns-200-when-no-key-present/290682 "2021-12-01T14:48:19Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![JGreene](https://avatars.discourse-cdn.com/v4/letter/j/c68b51/32.png) [@JGreene](https://discuss.elastic.co/u/JGreene)\
**Post date:** [December 1, 2021, 2:48pm UTC](https://discuss.elastic.co/t/get-security-api-key-name-any-key-returns-200-when-no-key-present/290682/1 "2021-12-01T14:48:19Z")

</div>

ES Version: 7.15.2 and prior

The `/_security/api_key` api returns a 200 response code even when the requested key does not exists.

Example:

```auto
curl -X GET "https://172.19.18.17:9200/_security/api_key?name=bobs_key" -u elastic:changeme --insecure
{"api_keys":[]}

```

```auto
curl -i -X GET "https://172.19.18.17:9200/_security/api_key?name=bobs_key" -u elastic:changeme --insecure
HTTP/1.1 200 OK
X-elastic-product: Elasticsearch
content-type: application/json; charset=UTF-8
content-length: 15

{"api_keys":[]}

```

This prevents programmatic determination if a key exists as all queries for implicit or explicit keys by their name return a 200 status code. It should be possible to determine if a key exists by the status code when requesting via the API for a key by name and not relying on parsing a null set.  
After the key is created, the response code is the same:

```auto
 curl -X GET "https://172.19.18.17:9200/_security/api_key?name=bobs_key" -u elastic:changeme --insecure
{"api_keys":[{"id":"VTRudn0Bwr2FyyO2_JlK","name":"bobs_key","creation":1638369524771,"invalidated":false,"username":"elastic","realm":"reserved","metadata":{}}]}

```

```auto
curl -i -X GET "https://172.19.18.17:9200/_security/api_key?name=bobs_key" -u elastic:changeme --insecure
HTTP/1.1 200 OK
X-elastic-product: Elasticsearch
content-type: application/json; charset=UTF-8
content-length: 161

{"api_keys":[{"id":"VTRudn0blahhh2F2_JlK","name":"bobs_key","creation":1638369524771,"invalidated":false,"username":"elastic","realm":"reserved","metadata":{}}]}[

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2021, 2:48pm UTC](https://discuss.elastic.co/t/get-security-api-key-name-any-key-returns-200-when-no-key-present/290682/2 "2021-12-29T14:48:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
