# Kibana iframe with Token (Authentication purpose)

**URL:** <https://discuss.elastic.co/t/kibana-iframe-with-token-authentication-purpose/207744>\
**Category:** Elasticsearch\
**Created:** [November 13, 2019, 4:24pm UTC](https://discuss.elastic.co/t/kibana-iframe-with-token-authentication-purpose/207744 "2019-11-13T16:24:21Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![vishal\_M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_m/32/50559_2.png) [@vishal\_M](https://discuss.elastic.co/u/vishal_M)\
**Post date:** [November 13, 2019, 4:24pm UTC](https://discuss.elastic.co/t/kibana-iframe-with-token-authentication-purpose/207744/1 "2019-11-13T16:24:22Z")

</div>

Hello Team,

I have integrated the Kibana dashboard "iframe" with my react application. But, each time I have to log-in to see the Kibana dashboard. (FYI: My Kibana version 7.4.0)

So, I have followed a few paths to bypass the authentication mechanism. But, didn't succeed.

- Used Nginx proxy to bypass the authentication. However, this is a 50% result. Because the Dashboard URL will be accessible even without logging in to my application.

- Tried to pass userName and password as a part of the Kibana iframe URL. But, it didn't work.

> [@Auto-authenticating to iframe-embedded Kibana dashboard](https://discuss.elastic.co/t/auto-authenticating-to-iframe-embedded-kibana-dashboard/46091/3):
>
> If you are using Shield 2.3, and you have the front-end plugin installed in Kibana, then yes, this is possible. It doesn't work as you've put in your example. Instead, pass a valid Basic Authorization header with the request will cause Shield will validate the session, creating and using an authorization cookie in the background. Note that prior to 2.3, I don't believe this was possible at all.

I have also seen a few Api's from the Elasticsearch that will provide us Tokens (Please refer below).

[Get token API | Elasticsearch Guide [7.4] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/security-api-get-token.html)

If I receive a successful bearer token using the above API. Will I be able to see the dashboard if I append the token with Kibana iframe URL ?

Ex:  
`<iframe src="http://localhost:1.1.1.1/app/kibana#/dashboard/yy6asd-hasdgj-88789?embed=true&_g=()&_a=(description:'',filters:!(),fullScreenMode:!f,options:(hidePanelTitles:!f)?Token=8u88i996ggsghasdujeusiwk899></iframe>`

or

Do I need to make any custom header configurations to send the token as a separate header along with iframe url to make it work?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 15, 2019, 9:53am UTC](https://discuss.elastic.co/t/kibana-iframe-with-token-authentication-purpose/207744/2 "2019-11-15T09:53:21Z")

</div>

Elasticsearch Token Service tokens have specific properties that make them difficult to use for your use case, specifically that they have very short life ( by default 20 mins and up to 1hr ) after which you either need to use the refresh token to refresh it or get another access token. You can use bearer tokens in your requests to Kibana but you need to enable the `Token` authentication provider in kibana , see [Authentication in Kibana | Kibana Guide [8.11] | Elastic](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#token-authentication), but whether this is suitable for your scenario, I doubt it.

> [@vishal\_M](#):
>
> - Used Nginx proxy to bypass the authentication. However, this is a 50% result. Because the Dashboard URL will be accessible even without logging in to my application.
> - Tried to pass userName and password as a part of the Kibana iframe URL. But, it didn't work.

I can't really unwrap how you tried it and what _Exactly_ failed ? This is the most obvious way forward for you, so I'd suggest we focus on making this work. There are numerous examples in previous posts in this forum to help you, start with [Nginx reverse proxy for kibana](https://discuss.elastic.co/t/nginx-reverse-proxy-for-kibana/179024) that contains further links to other relevant posts

---

<div class="post-metadata">

**Author:** ![vishal\_M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_m/32/50559_2.png) [@vishal\_M](https://discuss.elastic.co/u/vishal_M)\
**Post date:** [November 15, 2019, 3:46pm UTC](https://discuss.elastic.co/t/kibana-iframe-with-token-authentication-purpose/207744/3 "2019-11-15T15:46:28Z")

</div>

Hello @ikakavas,

As per your comments. i have used token service made a [POST] call to my elastic api "/\_security/oauth2/token" which is running on"9200" to generate tokens and it is successful in getting access token and refresh token. Please may i know the next step to store the token in my browser. I don't think it will work if i set the bearer token in my browser with any "keyname"..

 ![41%20AM](https://us1.discourse-cdn.com/elastic/original/3X/d/a/dac759d614bf3f02a6e5701d6e3b2a4204c37c6e.png)

Also, I have also tried another alternative using this post:

> [@Authenticating to iframe-embedded Kibana dashboard](https://discuss.elastic.co/t/authenticating-to-iframe-embedded-kibana-dashboard/71129/7):
>
> Sorry for the delay, @rupaln and sorry for giving incomplete advice. I was able to get the Kibana server to respond with a cookie header by POSTing to /api/security/v1/login with a JSON request body of { "password": "\<YOURPASSWORD\>", "username": "\<YOURUSERNAME\>" } and the appropriate kbn-version: 5.1.1 header.

If you refer to the screenshot, I was able to get some JSON response. But i am not getting the cookie.

 ![57%20AM](https://us1.discourse-cdn.com/elastic/original/3X/4/6/46a0704ff9eef276e2addd7ea81053c1ebd7de51.png)

Do I need to make any changes in elasticsearch.yaml or kibana.yaml files in order to get the cookie? If i get the cookie. I can store it in my browser. But, Will it work after getting the cookie?  
Please can you provide me a right path in achieving this.

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 15, 2019, 4:42pm UTC](https://discuss.elastic.co/t/kibana-iframe-with-token-authentication-purpose/207744/4 "2019-11-15T16:42:47Z")

</div>

> [@vishal\_M](#):
>
> As per your comments. i have used token service made a [POST] call to my elastic api "/\_security/oauth2/token" which is running on"9200" to generate tokens and it is successful in getting access token and refresh token

Hi there, my comment was that you should _not_ use tokens for your use case ,not the other way around:)

> [@vishal\_M](#):
>
> Please may i know the next step to store the token in my browser. I don't think it will work if i set the bearer token in my browser with any "keyname"..

Not sure i follow. Our docs detail how to use a token as a bearer token for authentication 139732 but again, I cant see how this can help you with your use case.

> [@vishal\_M](#):
>
> you refer to the screenshot, I was able to get some JSON response. But i am not getting the cookie

The cookie comes in a response header, not in the body of the response, you need to examine the headers in postman

---

<div class="post-metadata">

**Author:** ![vishal\_M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_m/32/50559_2.png) [@vishal\_M](https://discuss.elastic.co/u/vishal_M)\
**Post date:** [November 18, 2019, 8:57pm UTC](https://discuss.elastic.co/t/kibana-iframe-with-token-authentication-purpose/207744/6 "2019-11-18T20:57:29Z")

</div>

Hello @ikakavas,

I am able to call the Kibana Api and can see all the response headers in the network Tab.

 ![43%20PM](https://us1.discourse-cdn.com/elastic/original/3X/b/f/bf7b41fe85cd6eb5adb9b85f2de8f6a0aaf7f196.png)

Also, I can print all the headers in the console window. But, except ['Set-Cookie']. Is it because of http -only?

 ![27%20PM](https://us1.discourse-cdn.com/elastic/original/3X/0/f/0fa04b40e7ff8c51d9d7bb7a3b89259f123b7ddd.png)

 ![51%20PM](https://us1.discourse-cdn.com/elastic/original/3X/7/8/785bd425404981dc2553689224b67b943f4e963c.png)

Please, may I know how to grab the cookie?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 18, 2019, 9:14pm UTC](https://discuss.elastic.co/t/kibana-iframe-with-token-authentication-purpose/207744/7 "2019-11-18T21:14:56Z")

</div>

I will repeat once more that this path forward doesn't satisfy your use case, so I'm unsure if you should be pursuing this further.

This question has now become: "How can I handle response headers in React" and I can't be of any help. Maybe someone else from the community can assist you

---

<div class="post-metadata">

**Author:** ![vishal\_M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_m/32/50559_2.png) [@vishal\_M](https://discuss.elastic.co/u/vishal_M)\
**Post date:** [November 21, 2019, 2:30pm UTC](https://discuss.elastic.co/t/kibana-iframe-with-token-authentication-purpose/207744/8 "2019-11-21T14:30:57Z")

</div>

Thanks for your info @ikakavas ,

As a developer, I have to try every possibility to get the things done in a proper way. I felt working with access tokens and cookies will be more secure than Nginx proxy. Because, I hope we have to hardcode basic authentication header in the nginx configuration file. So that, whomever hits the url will be re-directed to kibana dashboards. Please let me know if my understanding is wrong and can you suggest me a good Nginx configuration where i can pass dynamic authentication from my web application.So that, I can configure multiple users and pass the auth headers in the runtime.

FYI : I am currently using kibana 7.3.0 and will be upgrading to 7.4.0 in the near future.

Thanks,  
Vishal

---

<div class="post-metadata">

**Author:** ![vishal\_M](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_m/32/50559_2.png) [@vishal\_M](https://discuss.elastic.co/u/vishal_M)\
**Post date:** [November 26, 2019, 6:31pm UTC](https://discuss.elastic.co/t/kibana-iframe-with-token-authentication-purpose/207744/9 "2019-11-26T18:31:11Z")

</div>

Hello @ikakavas ,

Please can you POST your response.

Thanks,  
Vishal

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [November 27, 2019, 7:19am UTC](https://discuss.elastic.co/t/kibana-iframe-with-token-authentication-purpose/207744/10 "2019-11-27T07:19:45Z")

</div>

Hi @vishal_M,

Please refrain from pinging folks directly in this forum. This is a community forum, it may take time for someone to reply to your question, and other people might have insights or ideas to share that will help you get to the bottom of your issue. For more information please refer to the [Community Code of Conduct](https://www.elastic.co/community/codeofconduct) specifically the section "Be patient".  
If you are in need of a service with an SLA that covers response times for questions then you may want to consider talking to us about a [subscription](https://www.elastic.co/subscriptions).

As I wrote above

> [@ikakavas](#):
>
> This question has now become: "How can I handle response headers in React" and I can't be of any help. Maybe someone else from the community can assist you

Also

> [@vishal\_M](#):
>
> and can you suggest me a good Nginx configuration where i can pass dynamic authentication from my web application.So that, I can configure multiple users and pass the auth headers in the runtime.

Again, not the best person to help you with this, but I have shared a few links to setups that folk have used successfully with nginx earlier in this thread

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2019, 7:19am UTC](https://discuss.elastic.co/t/kibana-iframe-with-token-authentication-purpose/207744/11 "2019-12-25T07:19:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
