# How can I get access token of OIDC (Open ID Connect) provider?

**URL:** <https://discuss.elastic.co/t/how-can-i-get-access-token-of-oidc-open-id-connect-provider/215080>\
**Category:** Kibana\
**Created:** [January 15, 2020, 6:34am UTC](https://discuss.elastic.co/t/how-can-i-get-access-token-of-oidc-open-id-connect-provider/215080 "2020-01-15T06:34:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![RaghibHuda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raghibhuda/32/59613_2.png) [@RaghibHuda](https://discuss.elastic.co/u/RaghibHuda)\
**Post date:** [January 15, 2020, 6:34am UTC](https://discuss.elastic.co/t/how-can-i-get-access-token-of-oidc-open-id-connect-provider/215080/1 "2020-01-15T06:34:39Z")

</div>

Hi there,  
We are developing a custom plugin in Kibana. We integrate our authentication with OIDC. Now we want to make external API requests from our custom plugin. These requests need the access token of the same OIDC provider. How can I get the provider OIDC token? What should be the approach?

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [January 17, 2020, 4:51pm UTC](https://discuss.elastic.co/t/how-can-i-get-access-token-of-oidc-open-id-connect-provider/215080/2 "2020-01-17T16:51:27Z")

</div>

Hi!  
Here's some feedback by our security team, if it's possible to access that Token in Kibana:

> it's not possible. It's ES that talks to OIDC Identity Provider and returns its own access/refresh token pair to Kibana.

Best,  
Matthias

---

<div class="post-metadata">

**Author:** ![firabby](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/firabby/32/58342_2.png) [@firabby](https://discuss.elastic.co/u/firabby)\
**Post date:** [January 18, 2020, 8:26am UTC](https://discuss.elastic.co/t/how-can-i-get-access-token-of-oidc-open-id-connect-provider/215080/3 "2020-01-18T08:26:36Z")

</div>

@matw , thanks for your answer. Is there any way to use elasticsearch as a relay between that external API and our custom plugin?

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [January 21, 2020, 4:43am UTC](https://discuss.elastic.co/t/how-can-i-get-access-token-of-oidc-open-id-connect-provider/215080/4 "2020-01-21T04:43:00Z")

</div>

Sorry, there is no way to do what they are asking. Our realm is an authentication Realm and OpenID Connect is an authentication standard.Your use case seems to fall under delegation of authorization use cases ( i.e. closer to oAuth2 )  
[https://tools.ietf.org/html/draft-ietf-oauth-security-topics-13#section-3.1.2](https://tools.ietf.org/html/draft-ietf-oauth-security-topics-13#section-3.1.2)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 18, 2020, 4:43am UTC](https://discuss.elastic.co/t/how-can-i-get-access-token-of-oidc-open-id-connect-provider/215080/5 "2020-02-18T04:43:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
