# How to login automatically with request header

**URL:** <https://discuss.elastic.co/t/how-to-login-automatically-with-request-header/155104>\
**Category:** Kibana\
**Created:** [November 2, 2018, 3:27am UTC](https://discuss.elastic.co/t/how-to-login-automatically-with-request-header/155104 "2018-11-02T03:27:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![wujiaxin159](https://avatars.discourse-cdn.com/v4/letter/w/e68b1a/32.png) [@wujiaxin159](https://discuss.elastic.co/u/wujiaxin159)\
**Post date:** [November 2, 2018, 3:27am UTC](https://discuss.elastic.co/t/how-to-login-automatically-with-request-header/155104/1 "2018-11-02T03:27:41Z")

</div>

The gateway actively writes user information to the header, and I want to know how to log in directly through this header information.

For example:  
Request Headers:  
userID: admin  
userName: admin

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [November 2, 2018, 4:47am UTC](https://discuss.elastic.co/t/how-to-login-automatically-with-request-header/155104/2 "2018-11-02T04:47:16Z")

</div>

Hi, When the user accesses Kibana they are then forced to authenticate, and this information is "proxied" to Elasticsearch. If you were to install and enable X-Pack Security in Kibana, they'd be prompted with the Login screen at this point and allowed to login. Using the `elasticsearch.customHeaders` setting in the kibana.yml you can pass the same Basic Auth headers to Elasticsearch on every request. However, you'll have to disable X-Pack Security in Kibana for this option to work.  
This solution doesn't require a reverse proxy; however, you will be forced to use Kibana as the same user, and disable X-Pack Security. Hope this helps. I have cc'd @Brandon_Kobel for more insights.

Cheers  
Rashmi

---

<div class="post-metadata">

**Author:** ![wujiaxin159](https://avatars.discourse-cdn.com/v4/letter/w/e68b1a/32.png) [@wujiaxin159](https://discuss.elastic.co/u/wujiaxin159)\
**Post date:** [November 2, 2018, 9:30am UTC](https://discuss.elastic.co/t/how-to-login-automatically-with-request-header/155104/3 "2018-11-02T09:30:02Z")

</div>

Is that so?

```
elasticsearch.customHeaders: {
    "userID": "userID",
    "userName": "userName",
    ...
}

```

Are there any examples?

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [November 2, 2018, 2:57pm UTC](https://discuss.elastic.co/t/how-to-login-automatically-with-request-header/155104/4 "2018-11-02T14:57:14Z")

</div>

This post gives you a very detailed reply: [Kibana default basic auth](https://discuss.elastic.co/t/kibana-default-basic-auth/86045)

Hope it helps  
Rashmi

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2018, 2:57pm UTC](https://discuss.elastic.co/t/how-to-login-automatically-with-request-header/155104/5 "2018-11-30T14:57:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
