# JWT Realm configuration for Elasticsearch REST APIs authentication

**URL:** <https://discuss.elastic.co/t/jwt-realm-configuration-for-elasticsearch-rest-apis-authentication/334776>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [May 31, 2023, 9:36am UTC](https://discuss.elastic.co/t/jwt-realm-configuration-for-elasticsearch-rest-apis-authentication/334776 "2023-05-31T09:36:53Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![asimelastic](https://avatars.discourse-cdn.com/v4/letter/a/4bbf92/32.png) [@asimelastic](https://discuss.elastic.co/u/asimelastic)\
**Post date:** [May 31, 2023, 9:36am UTC](https://discuss.elastic.co/t/jwt-realm-configuration-for-elasticsearch-rest-apis-authentication/334776/1 "2023-05-31T09:36:53Z")

</div>

I am new to Elasticsearch JWT Realm configuration.

I am using trail version of Elasticsearch 8.7.1. I am configuring JWT Realm as follows in elasticsearch.yml

xpack.security.authc.realms.jwt.jwt1:  
order: 1  
token\_type: access\_token  
client\_authentication.type: shared\_secret  
allowed\_issuer: "issuer"  
allowed\_subjects: ["subject"]  
allowed\_audiences: ["elasticsearch"]  
required\_claims:  
token\_use: access  
version: ["1.0", "2.0"]  
allowed\_signature\_algorithms: [RS256,HS256]  
pkc\_jwkset\_path: ../config/secretkey.json  
fallback\_claims.sub: client\_id  
fallback\_claims.aud: scope  
claims.principal: sub

I am setting up shared secret using below command:  
bin/elasticsearch-keystore add xpack.security.authc.realms.jwt.jwt1.client\_authentication.shared\_secret

Also saving HMAC keys using below command:  
bin/elasticsearch-keystore add-file xpack.security.authc.realms.jwt.jwt1.hmac\_jwkset

Content of my json file are as below:

{  
"keys": [  
{  
"kty": "oct",  
"use": "sig",  
"kid": "0mwcVHMGsUCu8znizJR4jqD00OD6uNo27447s2Zj1Ss",  
"k": "mry7QjXVIv13EUefZEdigdRFS2C8t5F1WTntaprvvS7JuHaulIsx5aPjgz9yFTYmftBAox8SkjR3E6FH8h9yIPaUEW8TI6U\_Cknlvs9m9ecvpLBFzTWKofm5x9zihefNutQihjLvTKx-81JZYbsgvLwTJBwy0fBQ9I1aglj05ldQS2QS5D8xKSw4wZUKH9RmFo1JW7CnrkCkYeiOVq6fNgzML\_8Kkje2xe3IBWsjef8MmbTrLi\_Bs7VR9xmtX-z4KsQdYbBVPiP6N-\_NGdNh2bzsPIqi3cnlc9uQhj-xgGqlCaJFI9hm1zM\_f-fYUV40nG1T5HJc8B794OtxrBpMOA",  
"alg": "HS256"  
}  
]  
}

My question is after configuring JWT realm as mentioned above, now how and from where I can get JWT Token?

---

<div class="post-metadata">

**Author:** ![asimelastic](https://avatars.discourse-cdn.com/v4/letter/a/4bbf92/32.png) [@asimelastic](https://discuss.elastic.co/u/asimelastic)\
**Post date:** [June 1, 2023, 11:38am UTC](https://discuss.elastic.co/t/jwt-realm-configuration-for-elasticsearch-rest-apis-authentication/334776/2 "2023-06-01T11:38:05Z")

</div>

Anyone have any thoughts about this, thanks in advance.

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [June 3, 2023, 9:00am UTC](https://discuss.elastic.co/t/jwt-realm-configuration-for-elasticsearch-rest-apis-authentication/334776/3 "2023-06-03T09:00:34Z")

</div>

> [@asimelastic](#):
>
> My question is after configuring JWT realm as mentioned above, now how and from where I can get JWT Token?

The Elasticsearch JWT realm supports authenticating using JWTs generated by an external issuer. It doesn't not generate JWTs for you.

It is intended for use when you have an existing component in your infrastructure that issues JWT tokens to either users or services, and you want Elasticsearch to be able to authenticate using those JWTs rather than passwords (or any other credential).

---

<div class="post-metadata">

**Author:** ![asimelastic](https://avatars.discourse-cdn.com/v4/letter/a/4bbf92/32.png) [@asimelastic](https://discuss.elastic.co/u/asimelastic)\
**Post date:** [June 5, 2023, 11:30am UTC](https://discuss.elastic.co/t/jwt-realm-configuration-for-elasticsearch-rest-apis-authentication/334776/4 "2023-06-05T11:30:52Z")

</div>

@TimV Thank you so much.

One more question. Do Elasticsearch Basic License support JWT Realms?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 5, 2023, 11:35am UTC](https://discuss.elastic.co/t/jwt-realm-configuration-for-elasticsearch-rest-apis-authentication/334776/5 "2023-06-05T11:35:13Z")

</div>

The best place to consult around license level cover is the [subscriptions page](https://www.elastic.co/subscriptions). According to this JWT is not supported with the Basic level license.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2023, 11:35am UTC](https://discuss.elastic.co/t/jwt-realm-configuration-for-elasticsearch-rest-apis-authentication/334776/6 "2023-07-03T11:35:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
