# Is it safe to use Elastic App Search directly from my Android and iOS app?

**URL:** <https://discuss.elastic.co/t/is-it-safe-to-use-elastic-app-search-directly-from-my-android-and-ios-app/249427>\
**Category:** Elastic Search\
**Tags:** elastic-app-search\
**Created:** [September 21, 2020, 9:29pm UTC](https://discuss.elastic.co/t/is-it-safe-to-use-elastic-app-search-directly-from-my-android-and-ios-app/249427 "2020-09-21T21:29:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![susi\_pogba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/susi_pogba/32/54966_2.png) [@susi\_pogba](https://discuss.elastic.co/u/susi_pogba)\
**Post date:** [September 21, 2020, 9:29pm UTC](https://discuss.elastic.co/t/is-it-safe-to-use-elastic-app-search-directly-from-my-android-and-ios-app/249427/1 "2020-09-21T21:29:01Z")

</div>

Hi all,

I am new in Elastic product. I am actually an Android and iOS developer. so I have limited knowledge about backend.

I have tried to read app search authentication documentation in [here](https://www.elastic.co/guide/en/app-search/current/authentication.html) , it seems I can directly make a query directly from my Android/iOS app, by using this

> curl -X GET 'https://[HOST\_IDENTIFIER].api.swiftype.com/api/as/v1/engines/[ENGINE]/documents'   
> -H 'Content-Type: application/json'   
> -H 'Authorization: Bearer [API\_KEY]' \

If use that endpoint and use public search key for the [API\_KEY], is it safe to use Elastic App Search just like that ?

search key is read-only access, so malicious users can't delete my documents, but if the endpoint is exposed in my mobile app like that, I am worried that will be a malicious user that can make millions of requests in short period of time and it will make my elastic app search down.

can I prevent this ?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 22, 2020, 5:23am UTC](https://discuss.elastic.co/t/is-it-safe-to-use-elastic-app-search-directly-from-my-android-and-ios-app/249427/2 "2020-09-22T05:23:33Z")

</div>

Hi @susi_pogba

Welcome to the community.

Others can chime in but in general it's not a best practice to allow direct authentication from a client or mobile app directly to your data store / data API whether that data store is Elasticsearch or Oracle, mySQL or Mongodb etc .

Typically you would have an API gateway or a microservice layer that handles your end user's authentication and authorization and session management then that microservice or another service like a data access service would actually authenticate and make the calls to the data store so that data store is isolated from the end user / client app. This is how so how you isolate SQL /query injection and other security concerns.

Hope that helps s bit.

---

<div class="post-metadata">

**Author:** ![JasonStoltz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasonstoltz/32/49893_2.png) [@JasonStoltz](https://discuss.elastic.co/u/JasonStoltz)\
**Post date:** [September 22, 2020, 11:45am UTC](https://discuss.elastic.co/t/is-it-safe-to-use-elastic-app-search-directly-from-my-android-and-ios-app/249427/3 "2020-09-22T11:45:29Z")

</div>

Hey @susi_pogba,

Just wanted to chime in quick. Generally speaking, we consider it expected and acceptable to make API calls to the Elastic App Search API directly from a client or browser. As you said, the public search key is read-only and available with this use case in mind.

To better protect against a denial of service attack as you describe, your best bet would be to handle that in some sort of API gateway or proxy like @stephenb describes.

Jason

---

<div class="post-metadata">

**Author:** ![susi\_pogba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/susi_pogba/32/54966_2.png) [@susi\_pogba](https://discuss.elastic.co/u/susi_pogba)\
**Post date:** [September 24, 2020, 2:51am UTC](https://discuss.elastic.co/t/is-it-safe-to-use-elastic-app-search-directly-from-my-android-and-ios-app/249427/4 "2020-09-24T02:51:47Z")

</div>

Thank you very much @JasonStoltz and @stephenb . is there any rate limiter per IP per hour for search key or something like that in elastic search ?

---

<div class="post-metadata">

**Author:** ![JasonStoltz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasonstoltz/32/49893_2.png) [@JasonStoltz](https://discuss.elastic.co/u/JasonStoltz)\
**Post date:** [September 24, 2020, 11:38am UTC](https://discuss.elastic.co/t/is-it-safe-to-use-elastic-app-search-directly-from-my-android-and-ios-app/249427/5 "2020-09-24T11:38:51Z")

</div>

Elastic App Search does not have per IP rate limiting.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 22, 2020, 11:39am UTC](https://discuss.elastic.co/t/is-it-safe-to-use-elastic-app-search-directly-from-my-android-and-ios-app/249427/6 "2020-10-22T11:39:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
