# Is there API for mapping groups/users to roles

**URL:** <https://discuss.elastic.co/t/is-there-api-for-mapping-groups-users-to-roles/52149>\
**Category:** Elasticsearch\
**Created:** [June 8, 2016, 4:47am UTC](https://discuss.elastic.co/t/is-there-api-for-mapping-groups-users-to-roles/52149 "2016-06-08T04:47:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wei\_Huang](https://avatars.discourse-cdn.com/v4/letter/w/dbc845/32.png) [@Wei\_Huang](https://discuss.elastic.co/u/Wei_Huang)\
**Post date:** [June 8, 2016, 4:47am UTC](https://discuss.elastic.co/t/is-there-api-for-mapping-groups-users-to-roles/52149/1 "2016-06-08T04:47:22Z")

</div>

groups/users to roles can be configured by role\_mapping.yaml file, but this requires ES restart to take effect. Is there any API can change group/user to role mapping dynamically.

I'll use ELK5 with x-pack

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 8, 2016, 8:31pm UTC](https://discuss.elastic.co/t/is-there-api-for-mapping-groups-users-to-roles/52149/2 "2016-06-08T20:31:24Z")

</div>

Yes, there are now [APIs available](https://www.elastic.co/guide/en/x-pack/current/security-api.html) for managing this.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [June 9, 2016, 12:44pm UTC](https://discuss.elastic.co/t/is-there-api-for-mapping-groups-users-to-roles/52149/3 "2016-06-09T12:44:20Z")

</div>

There is not an API for role mapping yet. We have this API on our roadmap.

> role\_mapping.yaml file, but this requires ES restart to take effect

No restart is required. The files are monitored by elasticsearch and the changes will be detected and automatically updated.

---

<div class="post-metadata">

**Author:** ![Wei\_Huang](https://avatars.discourse-cdn.com/v4/letter/w/dbc845/32.png) [@Wei\_Huang](https://discuss.elastic.co/u/Wei_Huang)\
**Post date:** [June 17, 2016, 8:31am UTC](https://discuss.elastic.co/t/is-there-api-for-mapping-groups-users-to-roles/52149/4 "2016-06-17T08:31:45Z")

</div>

perfect

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:41pm UTC](https://discuss.elastic.co/t/is-there-api-for-mapping-groups-users-to-roles/52149/5 "2017-07-06T13:41:00Z")

</div>


