# Kibana realm-specific login URL (or another way to pre-select the realm)?

**URL:** <https://discuss.elastic.co/t/kibana-realm-specific-login-url-or-another-way-to-pre-select-the-realm/263533>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 8, 2021, 2:07am UTC](https://discuss.elastic.co/t/kibana-realm-specific-login-url-or-another-way-to-pre-select-the-realm/263533 "2021-02-08T02:07:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ngrigoriev](https://avatars.discourse-cdn.com/v4/letter/n/3be4f8/32.png) [@ngrigoriev](https://discuss.elastic.co/u/ngrigoriev)\
**Post date:** [February 8, 2021, 2:07am UTC](https://discuss.elastic.co/t/kibana-realm-specific-login-url-or-another-way-to-pre-select-the-realm/263533/1 "2021-02-08T02:07:17Z")

</div>

Hi!

I am trying to define several authc providers/realms in Elastic + Kibana but I do not want my clients to select a realm. Instead, I would like to drive them to a particular one that corresponds to them. Is there a way to generate a realm-specific login URL that I could include in my web app configuration?

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [February 8, 2021, 4:44am UTC](https://discuss.elastic.co/t/kibana-realm-specific-login-url-or-another-way-to-pre-select-the-realm/263533/2 "2021-02-08T04:44:09Z")

</div>

Why do you need this?  
Your realms will be checked in the order you configured them.  
So if users fail to authenticate in realm-1, they will be checked against realm-2 and so on.  
If you have many realms configured, this might take some time and the UX will be decreased.

---

<div class="post-metadata">

**Author:** ![ngrigoriev](https://avatars.discourse-cdn.com/v4/letter/n/3be4f8/32.png) [@ngrigoriev](https://discuss.elastic.co/u/ngrigoriev)\
**Post date:** [February 8, 2021, 3:50pm UTC](https://discuss.elastic.co/t/kibana-realm-specific-login-url-or-another-way-to-pre-select-the-realm/263533/3 "2021-02-08T15:50:51Z")

</div>

My users cannot be "checked". I use multiple OpenID Connect providers so there can be no "checking" of any kind. The realm/provider needs to be selected. There may be dozens of them. When my web app redirects to Kibana, it knows which realm the user belongs to.

---

<div class="post-metadata">

**Author:** ![ngrigoriev](https://avatars.discourse-cdn.com/v4/letter/n/3be4f8/32.png) [@ngrigoriev](https://discuss.elastic.co/u/ngrigoriev)\
**Post date:** [February 8, 2021, 6:43pm UTC](https://discuss.elastic.co/t/kibana-realm-specific-login-url-or-another-way-to-pre-select-the-realm/263533/4 "2021-02-08T18:43:24Z")

</div>

So far I only found an internal API (/internal/security/login) which takes a small JSON structure with the name of the desired provider and returns the location (authorization URL) for it with appropriate state/nonce values. And it needs kbn-xsrf header. I am wondering if there is more "public" option or this is the best one?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [February 9, 2021, 12:20am UTC](https://discuss.elastic.co/t/kibana-realm-specific-login-url-or-another-way-to-pre-select-the-realm/263533/5 "2021-02-09T00:20:40Z")

</div>

You might be able to use [Third Party initiated login](https://www.elastic.co/guide/en/elasticsearch/reference/current/oidc-guide-authentication.html#third-party-login) for this.

---

<div class="post-metadata">

**Author:** ![ngrigoriev](https://avatars.discourse-cdn.com/v4/letter/n/3be4f8/32.png) [@ngrigoriev](https://discuss.elastic.co/u/ngrigoriev)\
**Post date:** [February 9, 2021, 9:07pm UTC](https://discuss.elastic.co/t/kibana-realm-specific-login-url-or-another-way-to-pre-select-the-realm/263533/6 "2021-02-09T21:07:45Z")

</div>

Hi @TimV

The OIDC spec says "In this case, the initiator redirects to the RP at its login initiation endpoint, which requests that the RP send an Authentication Request to a specified OP". Given that Elasticsearch is the RP in this scenario, what is the "login initiation endpoint" that "can be a deep link at the RP, rather than a default landing page"? I cannot find it anywhere in the documentation. Elastic Stack does not implement the dynamic client registration (which it does not need anyway) so there is no such login endpoint provided. What am I missing?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2021, 9:08pm UTC](https://discuss.elastic.co/t/kibana-realm-specific-login-url-or-another-way-to-pre-select-the-realm/263533/7 "2021-03-09T21:08:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
