# How to authenticate to Elastic via API with PowerShell?

**URL:** <https://discuss.elastic.co/t/how-to-authenticate-to-elastic-via-api-with-powershell/365714>\
**Category:** Kibana\
**Created:** [August 28, 2024, 4:46pm UTC](https://discuss.elastic.co/t/how-to-authenticate-to-elastic-via-api-with-powershell/365714 "2024-08-28T16:46:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![logalicious](https://avatars.discourse-cdn.com/v4/letter/l/dfb087/32.png) [@logalicious](https://discuss.elastic.co/u/logalicious)\
**Post date:** [August 28, 2024, 4:46pm UTC](https://discuss.elastic.co/t/how-to-authenticate-to-elastic-via-api-with-powershell/365714/1 "2024-08-28T16:46:22Z")

</div>

I am trying to generate a dashboard PDF via POST URL. The documentation provides the following curl command:

```auto
curl \
-XPOST \ 
-u elastic \ 
-H 'kbn-xsrf: true' \ 
'http://0.0.0.0:5601/api/reporting/generate/csv?jobParams=...' 

```

How can I achieve this with PowerShell while using a username and password?

I found the following examples, has anyone had any luck with these?

```auto
$user = 'user'
$pass = 'pass'

$pair = "$($user):$($pass)"

$encodedCreds = [System.Convert]::ToBase64String([System.Text.Encoding]::ASCII.GetBytes($pair))

$basicAuthValue = "Basic $encodedCreds"

$Headers = @{
    Authorization = $basicAuthValue
}

Invoke-WebRequest -Uri 'https://whatever' -Headers $Headers

```

OR

```auto
$root = 'REST_SERVICE_URL'
$user = "user"
$pass= "password"
$secpasswd = ConvertTo-SecureString $pass -AsPlainText -Force
$credential = New-Object System.Management.Automation.PSCredential($user, $secpasswd)

$result = Invoke-RestMethod $root -Credential $credential

```

[powershell - Use Invoke-WebRequest with a username and password for basic authentication on the GitHub API - Stack Overflow](https://stackoverflow.com/questions/27951561/use-invoke-webrequest-with-a-username-and-password-for-basic-authentication-on-t)

[Automatically generate reports | Kibana Guide [8.15] | Elastic](https://www.elastic.co/guide/en/kibana/current/automating-report-generation.html)

---

<div class="post-metadata">

**Author:** ![ashishtiwari1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashishtiwari1993/32/135241_2.png) [@ashishtiwari1993](https://discuss.elastic.co/u/ashishtiwari1993)\
**Post date:** [August 29, 2024, 3:53am UTC](https://discuss.elastic.co/t/how-to-authenticate-to-elastic-via-api-with-powershell/365714/2 "2024-08-29T03:53:47Z")

</div>

Hi @logalicious, Welcome to Elastic community. While running above snippet have you faced any error?

---

<div class="post-metadata">

**Author:** ![taniumalloy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/taniumalloy/32/136858_2.png) [@taniumalloy](https://discuss.elastic.co/u/taniumalloy)\
**Post date:** [September 11, 2024, 1:01am UTC](https://discuss.elastic.co/t/how-to-authenticate-to-elastic-via-api-with-powershell/365714/3 "2024-09-11T01:01:26Z")

</div>

Hello Ashish, thank you for your response. After further exploration and learning, I have found a way to get it to work. I will share this for the community and hope it helps someone moving forward. The key points missed in the examples above were the Method HTTP Verb and converting the responses to JSON.

Here is a working example of authenticating to Kibana from PowerShell:

```auto
$user = "elastic"
$pass = "<securepasswordhere>"
$url = "http://192.168.X.X:5601/api/status"
$secpasswd = ConvertTo-SecureString $pass -AsPlainText -Force
$credential = New-Object System.Management.Automation.PSCredential($user, $secpasswd)

$result = Invoke-RestMethod -Method GET -Uri $url -Credential $credential
$result | ConvertTo-Json

```

The associated output is as follows:

```auto
{
    "status": {
                   "overall": {
                                   "level": "available"
                               }
               }
}

```

It works! I am now able to use API endpoints for Kibana. I am just running this in my home lab so I am not using certs for Kibana. However, I do have X Pack Security enabled for my three-node Elasticsearch cluster. I am using the self-signed SSL certs and I am not able to connect to the Elasticsearch API using the same method.

Here is what I tried:

```auto
$user = "elastic"
$pass = "<securepasswordhere>"
$urlElasticsearch = "https://192.168.X.X:9200/_cat/indices?v"
$secpasswd = ConvertTo-SecureString $pass -AsPlainText -Force
$credential = New-Object System.Management.Automation.PSCredential($user, $secpasswd)

<#I tried with and without this section based on some suggestions online to trust invalid certs ([Cert Error Workaround PowerShell](https://stackoverflow.com/questions/11696944/powershell-v3-invoke-webrequest-https-error) #>
[System.Net.ServicePointManager]::CertificatePolicy = New-Object TrustAllCertsPolicy
$AllProtocols = [System.Net.SecurityProtocolType]'Ssl3,Tls,Tls11,Tls12'
[System.Net.ServicePointManager]::SecurityProtocol = $AllProtocols

$resultElasticsearch = Invoke-RestMethod -Method GET -Uri $urlElasticsearch -Credential $credential
$resultElasticsearch | ConvertTo-Json

```

This is the response I get:

```auto
Invoke-RestMethod : The underlying connection was closed: An unexpected error occurred on a send.
At line:11 char:24
+ ... ticsearch = Invoke-RestMethod -Method GET -Uri $urlElasticsearch -Cre ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo : InvalidOperation: (System.Net.HttpWebRequest:HttpWebRequest) [Invoke-RestMethod], WebException
    + FullyQualifiedErrorId : WebCmdletWebResponseException,Microsoft.PowerShell.Commands.InvokeRestMethodCommand

```

I wish I could figure out what is going on there. Another post on the StackOverflow [link](https://stackoverflow.com/questions/11696944/powershell-v3-invoke-webrequest-https-error) showed another method that works, so I know its not a firewall issue.

```auto
$user = "elastic"
$pass = "<securepasswordhere>"
$url = "https://192.168.X.X:9200/_cat/indices?v"
$wc = New-Object System.Net.WebClient
$wc.Credentials = New-Object System.Net.NetworkCredential($user,$pass)
$wc.DownloadString($url)

```

The method above works, but I would prefer to use the Secure String method with Invoke-RestMethod like I did with Kibana.

Please let me know if there is a better way to use Elasticsearch API with PowerShell. Thanks!

---

<div class="post-metadata">

**Author:** ![Mamta\_Bankoti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mamta_bankoti/32/140518_2.png) [@Mamta\_Bankoti](https://discuss.elastic.co/u/Mamta_Bankoti)\
**Post date:** [June 1, 2026, 7:13am UTC](https://discuss.elastic.co/t/how-to-authenticate-to-elastic-via-api-with-powershell/365714/4 "2026-06-01T07:13:16Z")

</div>

Yes, you can use PowerShell to make the POST request and authenticate with your Kibana username and password. Both approaches you found are commonly used for Basic Authentication, although many users find the credential-based method easier to manage.

The key requirement is to ensure that the request includes the required `kbn-xsrf: true` header, as Kibana's Reporting API expects it for report generation requests.

If your main goal is simply to generate a PDF from a dashboard URL, you could also consider using a URL-to-PDF service. I was looking into a similar requirement and came across [Geekflare URL to PDF API](https://geekflare.com/api/url2pdf/), which can convert a web page directly into a PDF. However, if you need Kibana-specific reporting features, it is generally better to continue using the Kibana Reporting API with the appropriate authentication and headers.
