# I want authentication only for ES, not Kibana dashboards

**URL:** <https://discuss.elastic.co/t/i-want-authentication-only-for-es-not-kibana-dashboards/78553>\
**Category:** Kibana\
**Created:** [March 14, 2017, 3:37pm UTC](https://discuss.elastic.co/t/i-want-authentication-only-for-es-not-kibana-dashboards/78553 "2017-03-14T15:37:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![DrBatoon](https://avatars.discourse-cdn.com/v4/letter/d/cc9497/32.png) [@DrBatoon](https://discuss.elastic.co/u/DrBatoon)\
**Post date:** [March 14, 2017, 3:37pm UTC](https://discuss.elastic.co/t/i-want-authentication-only-for-es-not-kibana-dashboards/78553/1 "2017-03-14T15:37:45Z")

</div>

I am using ES, logstash and Kibana and I want to be able to put an embedded kibana dashboard on my webpage without authentication. But at the same time I want my ES to have a password.

I installed X-pack to ES and now i have to write usrname and password to access ES. I did not install X-pack to kibana but I am still forced to authenticate myself. What should I change?

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [March 14, 2017, 4:01pm UTC](https://discuss.elastic.co/t/i-want-authentication-only-for-es-not-kibana-dashboards/78553/2 "2017-03-14T16:01:58Z")

</div>

It looks like two have two main options, though others may exist.

Option 1: Configure anonymous access, so that Kibana can access ES without a username/password. You can choose what roles and level of access the anonymous users should get [https://www.elastic.co/guide/en/x-pack/current/anonymous-access.html](https://www.elastic.co/guide/en/x-pack/current/anonymous-access.html)

Option 2: If you don't want to enable anonymous access in ES, but you do want anonymous access via Kibana, you can have Kibana send authentication headers with each request, using the `kibana.yml` setting `elasticsearch.customHeaders` to set the basic auth headers for the user you want requests to be run as.

---

<div class="post-metadata">

**Author:** ![DrBatoon](https://avatars.discourse-cdn.com/v4/letter/d/cc9497/32.png) [@DrBatoon](https://discuss.elastic.co/u/DrBatoon)\
**Post date:** [March 15, 2017, 8:37am UTC](https://discuss.elastic.co/t/i-want-authentication-only-for-es-not-kibana-dashboards/78553/3 "2017-03-15T08:37:13Z")

</div>

What should I put in elasticsearch.customHeader {} ???  
I tried {elasticsearch.username: " **", elasticsearch.password: "**"} but did not seem to work

---

<div class="post-metadata">

**Author:** ![skearns](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skearns/32/125945_2.png) [@skearns](https://discuss.elastic.co/u/skearns)\
**Post date:** [March 15, 2017, 3:23pm UTC](https://discuss.elastic.co/t/i-want-authentication-only-for-es-not-kibana-dashboards/78553/4 "2017-03-15T15:23:31Z")

</div>

You'll need to specify the HTTP Basic Auth header:

> **[Basic access authentication](https://en.wikipedia.org/wiki/Basic_access_authentication)**
>
> In the context of an HTTP transaction, basic access authentication is a method for an HTTP user agent to provide a user name and password when making a request. HTTP Basic authentication (BA) implementation is the simplest technique for enforcing access controls to web resources because it does not require cookies, session identifiers, or login pages; rather, HTTP Basic authentication uses standard fields in the HTTP header, removing the need for handshakes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2017, 3:23pm UTC](https://discuss.elastic.co/t/i-want-authentication-only-for-es-not-kibana-dashboards/78553/5 "2017-04-12T15:23:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
