# Login kibana without UI (using token)

**URL:** <https://discuss.elastic.co/t/login-kibana-without-ui-using-token/203763>\
**Category:** Kibana\
**Created:** [October 16, 2019, 7:14am UTC](https://discuss.elastic.co/t/login-kibana-without-ui-using-token/203763 "2019-10-16T07:14:16Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![frankShih](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frankshih/32/51976_2.png) [@frankShih](https://discuss.elastic.co/u/frankShih)\
**Post date:** [October 16, 2019, 7:14am UTC](https://discuss.elastic.co/t/login-kibana-without-ui-using-token/203763/1 "2019-10-16T07:14:17Z")

</div>

Hi,

I am new in the elastic stack.

My requirement is:  
after users login to our website, they do not need to key in account/password again in order to access kibana.

So, I find this  
[https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#token-authentication](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#token-authentication)

It says that I can access user info & perform some operations with that TOKEN.  
However, what I want is bypassing the login page with that TOKEN. Is it possible?

Any suggestion is appreciated.

Many Thanks,

Han Shih

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [October 16, 2019, 9:54pm UTC](https://discuss.elastic.co/t/login-kibana-without-ui-using-token/203763/2 "2019-10-16T21:54:55Z")

</div>

@Larry_Gregory / @Brandon_Kobel can you please shed some light here ?

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [October 17, 2019, 11:34am UTC](https://discuss.elastic.co/t/login-kibana-without-ui-using-token/203763/3 "2019-10-17T11:34:12Z")

</div>

@frankShih,

Welcome to the discussion boards!

You can't directly use the Token Auth provider to bypass the login screen, as Kibana still requires a username and password to create the initial token. How are your users authenticating to your website? I have a couple of ideas for you:

If you're using a Single Sign-On solution such as SAML, AD/LDAP, or OpenID Connect, then you can take advantage of [Kibana's SSO solutions](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html) to bypass the login screen.

Otherwise, you may want to consider putting a reverse-proxy (such as nginx) in front of Kibana which handles authentication on behalf of your users. An example of that can be found here: [Auto-authenticating to iframe-embedded Kibana dashboard](https://discuss.elastic.co/t/auto-authenticating-to-iframe-embedded-kibana-dashboard/46091/4)

---

<div class="post-metadata">

**Author:** ![frankShih](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frankshih/32/51976_2.png) [@frankShih](https://discuss.elastic.co/u/frankShih)\
**Post date:** [October 19, 2019, 1:43pm UTC](https://discuss.elastic.co/t/login-kibana-without-ui-using-token/203763/5 "2019-10-19T13:43:35Z")

</div>

Hi @Larry_Gregory ,

"How are your users authenticating to your website?"  
=\> Simply username and password

According to the link you provide, I think the scenario of that topic is:  
When the user login the website, the dashboard embedded in the webpage (from kibana) should be shown automatically without another login.  
(Correct me if I understand it wrong.)

My goal is very similar to the topic you provide:  
After the user provide the username and password, I hope to find some "trick" that can use this information to bypass the login page from kibana.

So, is "reverse proxy" the right way I should go?

Thanks for your suggestion.

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [October 21, 2019, 11:46am UTC](https://discuss.elastic.co/t/login-kibana-without-ui-using-token/203763/6 "2019-10-21T11:46:06Z")

</div>

Yeah it sounds like a reverse proxy is the way to go here

---

<div class="post-metadata">

**Author:** ![frankShih](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frankshih/32/51976_2.png) [@frankShih](https://discuss.elastic.co/u/frankShih)\
**Post date:** [October 24, 2019, 8:16am UTC](https://discuss.elastic.co/t/login-kibana-without-ui-using-token/203763/7 "2019-10-24T08:16:20Z")

</div>

Hi,

It seems that I have to set "username:password" in base64 inside nginx config file

However, if I want to let users access the server with their own account.

Is it possible for nginx to change the header settings dynamically?

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [October 24, 2019, 12:21pm UTC](https://discuss.elastic.co/t/login-kibana-without-ui-using-token/203763/8 "2019-10-24T12:21:47Z")

</div>

I don't think that's possible out-of-the-box. You'd likely have to write your own logic for nginx to support that, and it'd be highly dependent on how you store your existing user sessions. It sounds like you need a true SSO solution for what you're trying to accomplish.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 21, 2019, 12:36pm UTC](https://discuss.elastic.co/t/login-kibana-without-ui-using-token/203763/9 "2019-11-21T12:36:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
