# How to create API Key for user with \`viewer\` role?

**URL:** <https://discuss.elastic.co/t/how-to-create-api-key-for-user-with-viewer-role/318359>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [November 7, 2022, 5:22pm UTC](https://discuss.elastic.co/t/how-to-create-api-key-for-user-with-viewer-role/318359 "2022-11-07T17:22:21Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![learningelastic](https://avatars.discourse-cdn.com/v4/letter/l/958977/32.png) [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Post date:** [November 7, 2022, 5:22pm UTC](https://discuss.elastic.co/t/how-to-create-api-key-for-user-with-viewer-role/318359/1 "2022-11-07T17:22:21Z")

</div>

I've been able to successfully create api keys for super user accounts. But I don't seem to have the option to create api keys for users that only have the role `viewer`. So for example, I made this user:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/0/f07d9d25c67dcb38ae49817f66e8c1bc28dbad8d.png)

But when I go to the API Key section, I do not see the option to choose the user for which I wish to create an API key for...see this image:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/0/6078f62baffa2f2447c129f4b46a73e9b67b4663.png)

The user is stuck as `elastic` as circled in the image.

Where do I go to set the api key for a user with `viewer` role only? As of right now, the `apmuser@test.com` makes curl requests like this

```auto
curl -X GET -u apmuser:mypassexample "https://localhost:9200/myindex/_search?pretty"

```

Would be great if I could change it to

```auto
curl -X GET -H 'Authorization: ApiKey ...thekey...' "https://localhost:9200/myindex/_search?pretty"

```

---

<div class="post-metadata">

**Author:** ![learningelastic](https://avatars.discourse-cdn.com/v4/letter/l/958977/32.png) [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Post date:** [November 7, 2022, 7:12pm UTC](https://discuss.elastic.co/t/how-to-create-api-key-for-user-with-viewer-role/318359/2 "2022-11-07T19:12:11Z")

</div>

I have a temporary solution, it goes as follows. I start with a user called `elastic` which is a super user.

1. Login as `elastic`
2. Create a user called `apmuser` and give the role `superuser`.
3. Login as the `apmuser`
4. Go to Stack Management\>API Keys and create an API Key for yourself since you're currenlty the `apmuser` (because it seems you can only create api keys for the user you're logged in as, there's no option to create api keys for any other user). Save the API Key
5. Go to Users and click on your own account, then change your role to `viewer` instead of `superuser`.
6. Press `Update User`. This should cause a screen to appear to say you've lost access to the user management session. Which maeks sense because you're no longer a super user as soon as you've saved your profile.

And now the API Key for `apmuser` should work fine.

Is there a way to do the same thing without resorting to this round-a-bout way?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 8, 2022, 12:48am UTC](https://discuss.elastic.co/t/how-to-create-api-key-for-user-with-viewer-role/318359/3 "2022-11-08T00:48:50Z")

</div>

Does [Create API key API | Elasticsearch Guide [8.5] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.5/security-api-create-api-key.html) provide any clarity there?

There are required permissions, but you should be able to create one yourself if you have those.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [November 8, 2022, 5:11am UTC](https://discuss.elastic.co/t/how-to-create-api-key-for-user-with-viewer-role/318359/4 "2022-11-08T05:11:07Z")

</div>

> [@learningelastic](#):
>
> there's no option to create api keys for any other user

This is not true. You can "grant" an API key to another user. I think this might be what you were looking for. Please refer to [this documentation page](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-grant-api-key.html).

---

<div class="post-metadata">

**Author:** ![learningelastic](https://avatars.discourse-cdn.com/v4/letter/l/958977/32.png) [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Post date:** [November 8, 2022, 5:29am UTC](https://discuss.elastic.co/t/how-to-create-api-key-for-user-with-viewer-role/318359/5 "2022-11-08T05:29:01Z")

</div>

thanks for clarification. In my question, I meant to say "there's no option to create api keys for any other user FROM WITHIN KIBANA UI". Is that still true? I understand you can do it programmatically, but I didn't see an option to do it through Kibana's user interface.

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [November 8, 2022, 6:00am UTC](https://discuss.elastic.co/t/how-to-create-api-key-for-user-with-viewer-role/318359/6 "2022-11-08T06:00:00Z")

</div>

That depends on whether you count [Kibana Dev Tools](https://www.elastic.co/guide/en/kibana/current/console-kibana.html) as part of its UI.

Also, did you enable "Restrict privileges" when you creating the API key using the `apmuser` when it still has the superuser role? If not, the API key was created with more permission than you might expect, i.e. it has superuser privileges. I understand that you removed `superuser` role from `apmuser` _afterwards_. But that does not affect any API keys created before the change.

---

<div class="post-metadata">

**Author:** ![learningelastic](https://avatars.discourse-cdn.com/v4/letter/l/958977/32.png) [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Post date:** [November 8, 2022, 4:51pm UTC](https://discuss.elastic.co/t/how-to-create-api-key-for-user-with-viewer-role/318359/7 "2022-11-08T16:51:00Z")

</div>

Thank you. THe grant api key rest api worked. So basically I did this:

1. Login as `elastic` super user.
2. Go to Stack Management\>Users.
3. Create the user `apmuser` with password `mypassexample` with role `viewer`.
4. Go to Dev Tools.
5. Paste this code to generate api key for the `apmuser`

```auto
POST /_security/api_key/grant
{
  "grant_type": "password",
  "username": "apmuser",
  "password": "mypassexample",
  "api_key" : {
    "name": "apmuser-key"
  }
}

```

On separate note, thanks for mentioning the point about `Restricted Privileges` in my earlier workflow, that it will still use the privileges of the superuser even if i change the role afterwards. Actually, can you point in me in the right direction on understanding the use cases for Roles vs. Roles Descriptors for API Keys? Why are there two paradigms for managing a user's capabilities?

---

<div class="post-metadata">

**Author:** ![learningelastic](https://avatars.discourse-cdn.com/v4/letter/l/958977/32.png) [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Post date:** [November 8, 2022, 4:57pm UTC](https://discuss.elastic.co/t/how-to-create-api-key-for-user-with-viewer-role/318359/8 "2022-11-08T16:57:16Z")

</div>

i actually i guess i understand the difference between Role vs. Role Descriptors for API Keys. It's concievable for two different entities to use the `apmuser` account. One entity is a real human being that actually logs into the kibana website. And the other entity could be programmatic software that needs to access the elastic api. These two entities can have different privileges by distinguishing Roles for human users and Role Descriptors for API keys.

When setting up api keys, if you don't explicitly specify role descriptions, then elastic will generate default role descriptors based on the user's role.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 6, 2022, 4:57pm UTC](https://discuss.elastic.co/t/how-to-create-api-key-for-user-with-viewer-role/318359/9 "2022-12-06T16:57:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
