# Kibana iframes

**URL:** <https://discuss.elastic.co/t/kibana-iframes/280969>\
**Category:** Kibana\
**Created:** [August 10, 2021, 10:47pm UTC](https://discuss.elastic.co/t/kibana-iframes/280969 "2021-08-10T22:47:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cgr\_EQ](https://avatars.discourse-cdn.com/v4/letter/c/f14d63/32.png) [@Cgr\_EQ](https://discuss.elastic.co/u/Cgr_EQ)\
**Post date:** [August 10, 2021, 10:47pm UTC](https://discuss.elastic.co/t/kibana-iframes/280969/1 "2021-08-10T22:47:07Z")

</div>

Hello,

I've setup Elastic/Kibana with basic authentication using x-pack. I understand that I can set up a reverse proxy using Nginx and specify a base 64 encoded username/password to the header to authenticate and use the iframe via the reverse proxy from within my web application.

However, Is there a way to pass in a specific username/password retrieved from my application login and pass it to the proxy so that Kibana will display the iframe with permissions set for that specific user ?

---

<div class="post-metadata">

**Author:** ![jportner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jportner/32/75692_2.png) [@jportner](https://discuss.elastic.co/u/jportner)\
**Post date:** [August 30, 2021, 9:47pm UTC](https://discuss.elastic.co/t/kibana-iframes/280969/2 "2021-08-30T21:47:57Z")

</div>

Here are the relevant docs for customizing HTTP authentication in Kibana: [Authentication in Kibana | Kibana Guide [7.14] | Elastic](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#http-authentication)

If you have the Basic authentication provider enabled in Kibana (it is enabled default if you are running Elasticsearch with Security enabled), you can pass in _any_ valid base64-encoded `username:password` combination in the HTTP `Authorization` header. That's simply called [Basic HTTP Authentication](https://datatracker.ietf.org/doc/html/rfc7617#section-2).

You could customize your proxy to handle this; I'm not sure of the specifics of how to do it in Nginx though, and that would involve exposing something like a cookie to your proxy. Alternatively you could make your own application-layer proxy to do this for you.

If your license permits and you have the infrastructure in place, you would be better off using some form of single sign-on such as [SAML](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#saml) or [OIDC](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#oidc).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2021, 9:48pm UTC](https://discuss.elastic.co/t/kibana-iframes/280969/3 "2021-09-27T21:48:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
