# How do I insert a token into Kibana client HTTP request header

**URL:** <https://discuss.elastic.co/t/how-do-i-insert-a-token-into-kibana-client-http-request-header/53898>\
**Category:** Kibana\
**Created:** [June 24, 2016, 2:46pm UTC](https://discuss.elastic.co/t/how-do-i-insert-a-token-into-kibana-client-http-request-header/53898 "2016-06-24T14:46:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Danny\_Lieberman](https://avatars.discourse-cdn.com/v4/letter/d/c89c15/32.png) [@Danny\_Lieberman](https://discuss.elastic.co/u/Danny_Lieberman)\
**Post date:** [June 24, 2016, 2:46pm UTC](https://discuss.elastic.co/t/how-do-i-insert-a-token-into-kibana-client-http-request-header/53898/1 "2016-06-24T14:46:58Z")

</div>

I want to set a custom HTTP header with a token that will be sent to the Kibana server.

I've been reading the code the past couple days and I see that there is a file in ui/public/chrome/api/xsrf.js that sets a XHR request header like  
jqXHR.setRequestHeader('kbn-version', internals.version);

So - I pulled the code, built with Grunt, added a line to setRequestHeader my token and it doesn't seem to be working

Grepping thru the source tree - I'm not seeing other places where a setRequestHeader method is called and I'm wondering what I'm missing.

The idea is to implement the encrypted token pattern (used in xsrf) in session-less situations and use the token to authorise Kibana users who have logged into an auth server first. So conceptually this might be a nice light-weight way of authenticating users using a Kibana plugin.

But first I have to figure out how to put the token into a request header - which seemed simple enough...  
Thanks  
Danny

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [June 24, 2016, 8:55pm UTC](https://discuss.elastic.co/t/how-do-i-insert-a-token-into-kibana-client-http-request-header/53898/2 "2016-06-24T20:55:56Z")

</div>

Hm. If you want a lightweight authentication solution, I think you can't really get any more lightweight than using a proxy like nginx paired with basic authentication via htpasswd. If you need more than that, such as user roles and permissions to certain indices, there is the Shield plugin already.

---

<div class="post-metadata">

**Author:** ![Danny\_Lieberman](https://avatars.discourse-cdn.com/v4/letter/d/c89c15/32.png) [@Danny\_Lieberman](https://discuss.elastic.co/u/Danny_Lieberman)\
**Post date:** [June 25, 2016, 6:15pm UTC](https://discuss.elastic.co/t/how-do-i-insert-a-token-into-kibana-client-http-request-header/53898/3 "2016-06-25T18:15:21Z")

</div>

Heah Thanks Tim!

I'm currently using nginx with basic authentication with htpasswd.  
OK for small number of users but -

The problem is that users login to a portal and get authenticated - and in order to access Kibana they have to enter a Basic authentication (or other flow) which force the user to login twice which is a pain.

Since we have other applications that use OTT for "session-less" access,  
my thinking was to leverage nginx like this:

user logs in to the auth server and gets an encrypted token  
kibana client includes the token in the Ajax requests which go to nginx  
nginx http\_auth\_request sends a sub request back to the auth server with the toekn  
auth verifies the token and returns 201 to nginx and kibana gets the request

We don't need more granular role-based access at this stage and we cant afford Shield-level pricing...

So - the question is fairly specific - where do I tweak the Kibana client JS code to send a token in the XHR request.

Thanks!

Danny

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:49pm UTC](https://discuss.elastic.co/t/how-do-i-insert-a-token-into-kibana-client-http-request-header/53898/4 "2017-07-06T13:49:11Z")

</div>


