# Kibana auto login (with security enabled)

**URL:** <https://discuss.elastic.co/t/kibana-auto-login-with-security-enabled/292934>\
**Category:** Kibana\
**Tags:** elastic-stack-security, docker\
**Created:** [December 26, 2021, 12:37pm UTC](https://discuss.elastic.co/t/kibana-auto-login-with-security-enabled/292934 "2021-12-26T12:37:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![borisr84](https://avatars.discourse-cdn.com/v4/letter/b/da6949/32.png) [@borisr84](https://discuss.elastic.co/u/borisr84)\
**Post date:** [December 26, 2021, 12:37pm UTC](https://discuss.elastic.co/t/kibana-auto-login-with-security-enabled/292934/1 "2021-12-26T12:37:42Z")

</div>

Hi,  
I've enabled Kibana security with x-pack security and now when I access Kibana UI I need to provide credentials.  
My preferred behavior is to authenticate users automatically (as my system already has a login screen so I do not want to force users to login again when access to logs is needed).  
I've seen the following post:  
**[Kibana default basic auth - #2 by Brandon\_Kobel](https://discuss.elastic.co/t/kibana-default-basic-auth/86045/2)**  
However, I prefer providing the credentials from code and not hard coded in the reverse proxy (e.g. NGINX).  
Is there a way to do it via an API while still allowing me to access the Kibana UI with credentials if I access the Kibana directly (i.e. for cases when I want to login with a different user, for example - a more privileged one)?  
i.e. something like the /internal/security/login API, but official?

Thanks!

---

<div class="post-metadata">

**Author:** ![lukeelmers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukeelmers/32/35230_2.png) [@lukeelmers](https://discuss.elastic.co/u/lukeelmers)\
**Post date:** [December 29, 2021, 7:10pm UTC](https://discuss.elastic.co/t/kibana-auto-login-with-security-enabled/292934/2 "2021-12-29T19:10:21Z")

</div>

Hey there,

It sounds like you might want to look into [anonymous access](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#anonymous-authentication), which would allow you to specify an existing user account to automatically log users in with. But this is assuming that:

- your Kibana deployment is already protected behind your own authentication system
- you want your users to access Kibana via a shared/service account
- you aren't interested in using SSO (SAML/Kerberos/OIDC)

> Is there a way to do it via an API while still allowing me to access the Kibana UI with credentials if I access the Kibana directly (i.e. for cases when I want to login with a different user, for example - a more privileged one)?

For this case, you could [configure the auth providers](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#multiple-authentication-providers) to still allow for basic auth, in addition to guest/anonymous access, so that you are able to [choose an option at login](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#_anonymous_access_and_other_types_of_authentication).

---

<div class="post-metadata">

**Author:** ![Krithika\_Natarajan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krithika_natarajan/32/99660_2.png) [@Krithika\_Natarajan](https://discuss.elastic.co/u/Krithika_Natarajan)\
**Post date:** [January 3, 2022, 1:49pm UTC](https://discuss.elastic.co/t/kibana-auto-login-with-security-enabled/292934/3 "2022-01-03T13:49:47Z")

</div>

How to authenticate Kibana login API without nginix proxy server? Please suggest me any ideas. I tried AJAX call but getting CORS issue.  
$.ajax({

```
    type: "POST",

    url: "https:// **** :5601/internal/security/login",

    data: {   

```

'providerType':'basic',

```
         'providerName': 'basic',

         "currentURL": "/",

        "params": JSON.stringify({username: 'username',password:'password'})

    },

    headers: {

        'Authorization': 'Basic ****************',

        'kbn-version': '7.15.2',

        'kbn-xsrf': 'reporting',

    },

    success: function(){},

    dataType: "json",

    contentType : "application/json"

});
```

---

<div class="post-metadata">

**Author:** ![borisr84](https://avatars.discourse-cdn.com/v4/letter/b/da6949/32.png) [@borisr84](https://discuss.elastic.co/u/borisr84)\
**Post date:** [January 4, 2022, 10:42am UTC](https://discuss.elastic.co/t/kibana-auto-login-with-security-enabled/292934/4 "2022-01-04T10:42:13Z")

</div>

Hi,  
You can do this using the following code (however do note that this is internal API, i.e. it might change tomorrow or be deleted and your code will stop working, that's why I'm looking for a different API/solution):

```auto
fetch('https://YOUR_URI_PREFIX/internal/security/login', {
method: 'POST',
body: JSON.stringify({
    providerType: "basic",
    providerName: "basic",
    currentURL: "https://YOUR_URI_PREFIX/logs/app/discover#",
    params: {
        username: "log_viewer_user",
        password: "log_viewer_user_pass"
    }
}),
headers: {
    "Content-Type": "application/json",
    "kbn-version": "7.15.2",
    "kbn-system-request": "true"
}
}).then(async res => res.json()).then(d => console.log(d))

```

Where YOUR\_URI\_PREFIX can be 'localhost', for example.

---

<div class="post-metadata">

**Author:** ![Krithika\_Natarajan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krithika_natarajan/32/99660_2.png) [@Krithika\_Natarajan](https://discuss.elastic.co/u/Krithika_Natarajan)\
**Post date:** [January 4, 2022, 10:57am UTC](https://discuss.elastic.co/t/kibana-auto-login-with-security-enabled/292934/5 "2022-01-04T10:57:16Z")

</div>

Thanks for your reply. I tried the above code. But still getting CORS issue  
"Access to fetch at 'https://\*\*\*\*/internal/security/login' from origin '\*\*\*\*\*' has been blocked by CORS policy: Response to preflight request doesn't pass access control check: No 'Access-Control-Allow-Origin' header is present on the requested resource. If an opaque response serves your needs, set the request's mode to 'no-cors' to fetch the resource with CORS disabled."

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 1, 2022, 10:57am UTC](https://discuss.elastic.co/t/kibana-auto-login-with-security-enabled/292934/6 "2022-02-01T10:57:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
