# How to get currently logged in USERID in plugin?

**URL:** <https://discuss.elastic.co/t/how-to-get-currently-logged-in-userid-in-plugin/58627>\
**Category:** Kibana\
**Created:** [August 22, 2016, 9:55pm UTC](https://discuss.elastic.co/t/how-to-get-currently-logged-in-userid-in-plugin/58627 "2016-08-22T21:55:08Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![dianadijan](https://avatars.discourse-cdn.com/v4/letter/d/958977/32.png) [@dianadijan](https://discuss.elastic.co/u/dianadijan)\
**Post date:** [August 22, 2016, 9:55pm UTC](https://discuss.elastic.co/t/how-to-get-currently-logged-in-userid-in-plugin/58627/1 "2016-08-22T21:55:08Z")

</div>

I am developing a plugin for Kibana 4.3.0

How to get the userid of currently logged in Kibana user?

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [August 23, 2016, 6:06pm UTC](https://discuss.elastic.co/t/how-to-get-currently-logged-in-userid-in-plugin/58627/2 "2016-08-23T18:06:19Z")

</div>

Hi Diana,

Users don't have IDs; instead they're only identified by user name. When developing the server portion of your plugin, you can define a route handler which can access the `request.auth.credentials` object, which has a `username` property. Does this meet your needs?

Thanks,  
CJ

---

<div class="post-metadata">

**Author:** ![dianadijan](https://avatars.discourse-cdn.com/v4/letter/d/958977/32.png) [@dianadijan](https://discuss.elastic.co/u/dianadijan)\
**Post date:** [September 2, 2016, 6:07pm UTC](https://discuss.elastic.co/t/how-to-get-currently-logged-in-userid-in-plugin/58627/3 "2016-09-02T18:07:23Z")

</div>

Hi @cjcenizal  
Can you please provide sample code snippet ?

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [September 2, 2016, 9:01pm UTC](https://discuss.elastic.co/t/how-to-get-currently-logged-in-userid-in-plugin/58627/4 "2016-09-02T21:01:02Z")

</div>

Hi Diana,

I'm sorry, I just realized that there's no way to do what you want in 4.3.0, but we will be able to access Shield user information in 5.0. I apologize for my mistake!

CJ

---

<div class="post-metadata">

**Author:** ![dianadijan](https://avatars.discourse-cdn.com/v4/letter/d/958977/32.png) [@dianadijan](https://discuss.elastic.co/u/dianadijan)\
**Post date:** [September 2, 2016, 9:09pm UTC](https://discuss.elastic.co/t/how-to-get-currently-logged-in-userid-in-plugin/58627/5 "2016-09-02T21:09:24Z")

</div>

Hi @cjcenizal ,

In my case, Authentication is incorporated in 4.3.0 using armor plugin (in our case). When user hits kibana URL, it redirects to SSO page (single sign on) and returns back to kibana main page after authentication. Thus 3 URLs are hit in a single call

I wonder how i can get the user credential detail , just by using Angular JS code (and not going thorugh server programming)

I have got this link , to read response headers

> <https://stackoverflow.com/questions/28805589/how-to-read-response-headers-in-angularjs>

Wondering how to read request header, when I do not know which of the 3 URL sends credentials

Any suggesstions?

Thank you!!

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [September 6, 2016, 5:21pm UTC](https://discuss.elastic.co/t/how-to-get-currently-logged-in-userid-in-plugin/58627/6 "2016-09-06T17:21:48Z")

</div>

Hi Diana, I'm afraid I'm not familiar with the Armor plugin. Is this the one? [https://github.com/petalmd/armor](https://github.com/petalmd/armor)

Have you tried asking the implementers of this plugin for help?

CJ

---

<div class="post-metadata">

**Author:** ![Kikketer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kikketer/32/13813_2.png) [@Kikketer](https://discuss.elastic.co/u/Kikketer)\
**Post date:** [April 17, 2017, 8:26pm UTC](https://discuss.elastic.co/t/how-to-get-currently-logged-in-userid-in-plugin/58627/7 "2017-04-17T20:26:05Z")

</div>

Hey @cjcenizal,  
This doesn't seem to work in 5.2.2. According to the docs for Hapi.js the `request.auth.credentials.user` should be the current user. However credentials is undefined when I'm using xpack.

How do I get the currently logged in user when using xpack?

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [April 17, 2017, 10:51pm UTC](https://discuss.elastic.co/t/how-to-get-currently-logged-in-userid-in-plugin/58627/8 "2017-04-17T22:51:47Z")

</div>

Hi Chris,

So your server-side plugin should define an init method which accepts `server` as an argument. You can retrieve a `getUser` method exposed by X-Pack's security plugin at `server.plugins.security.getUser`. Then, whenever Hapi handles a request, you can call this method to get information about the user, like this:

```auto
const handleRequest = request => {
    const getUser = server.plugins.security.getUser;
    const user = request;
};

```

Keep in mind that our plugin API is not stable, so it's very possible this will break without warning at some point in the future! I hope this helps.

Thanks,  
CJ

---

<div class="post-metadata">

**Author:** ![Kikketer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kikketer/32/13813_2.png) [@Kikketer](https://discuss.elastic.co/u/Kikketer)\
**Post date:** [April 18, 2017, 2:16am UTC](https://discuss.elastic.co/t/how-to-get-currently-logged-in-userid-in-plugin/58627/9 "2017-04-18T02:16:35Z")

</div>

Fantastic, thank you. Was there documentation I missed on this?

---

<div class="post-metadata">

**Author:** ![Kikketer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kikketer/32/13813_2.png) [@Kikketer](https://discuss.elastic.co/u/Kikketer)\
**Post date:** [April 18, 2017, 2:01pm UTC](https://discuss.elastic.co/t/how-to-get-currently-logged-in-userid-in-plugin/58627/10 "2017-04-18T14:01:02Z")

</div>

For anyone that has a similar question, this is what I ended up doing to get the currently logged in user.

```auto
      if (server.plugins.security) {
        server.plugins.security.getUser(req).then(user => {
          ticket.fields.reporter.name = user.username

```

This is all within my handler for an endpoint. Thanks @cjcenizal and I know it may break without warning, but I enjoy living on the edge 😉

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [April 18, 2017, 9:00pm UTC](https://discuss.elastic.co/t/how-to-get-currently-logged-in-userid-in-plugin/58627/11 "2017-04-18T21:00:25Z")

</div>

Thanks for posting your solution, Chris! Glad I could help. I don't think this was noted anywhere in the documentation, but if you or anyone else is interested, here are some resources:

- [https://www.elastic.co/guide/en/kibana/current/development-plugin-resources.html](https://www.elastic.co/guide/en/kibana/current/development-plugin-resources.html)
- [https://www.timroes.de/2016/02/21/writing-kibana-plugins-custom-applications/#creating-a-new-server-api](https://www.timroes.de/2016/02/21/writing-kibana-plugins-custom-applications/#creating-a-new-server-api)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:32pm UTC](https://discuss.elastic.co/t/how-to-get-currently-logged-in-userid-in-plugin/58627/12 "2017-07-06T13:32:13Z")

</div>


