# Login to Kibana instance with automatic user generation based on Proxy Header

**URL:** <https://discuss.elastic.co/t/login-to-kibana-instance-with-automatic-user-generation-based-on-proxy-header/361181>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [June 10, 2024, 4:37pm UTC](https://discuss.elastic.co/t/login-to-kibana-instance-with-automatic-user-generation-based-on-proxy-header/361181 "2024-06-10T16:37:28Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Songspore2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/songspore2/32/135185_2.png) [@Songspore2](https://discuss.elastic.co/u/Songspore2)\
**Post date:** [June 10, 2024, 4:37pm UTC](https://discuss.elastic.co/t/login-to-kibana-instance-with-automatic-user-generation-based-on-proxy-header/361181/1 "2024-06-10T16:37:28Z")

</div>

I am looking for a method to login to my organizations Kibana using a Request Header rather than actually authenticating. My organization uses Cloudflare Access, which provides the header `Cf-Access-Authenticated-User-Email` to our Elastic installation which is provided when an employee has successfully authenticated with our identity provider.

I've seen a few related threads to this, but would like to know if there is a way to enable this behavior without having to write a custom plugin. For example, [the Elastic docs](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#http-authentication) provide a method for specifying a custom http scheme, but don't seem to give a method for doing much with it.

So my question is, how can we extract this header for authentication, and create a user and put them into some type of default role?

Any ideas would be much appreciated, thank you.

---

<div class="post-metadata">

**Author:** ![Soucy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/soucy/32/119756_2.png) [@Soucy](https://discuss.elastic.co/u/Soucy)\
**Post date:** [June 12, 2024, 5:55am UTC](https://discuss.elastic.co/t/login-to-kibana-instance-with-automatic-user-generation-based-on-proxy-header/361181/2 "2024-06-12T05:55:40Z")

</div>

Hi Ryan. I don't think it is possible to create a Kibana session using only a request header. Is it your goal to bypass the Kibana login screen? If so, you have a couple of options...

I found this post: [Login kibana without UI (using token)](https://discuss.elastic.co/t/login-kibana-without-ui-using-token/203763)  
Which describes two options:

1. Use a [Single sign-on (SSO)](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html) solution
2. Set up a reverse proxy in front of Kibana to handle authentication. An example: [Auto-authenticating to iframe-embedded Kibana dashboard](https://discuss.elastic.co/t/auto-authenticating-to-iframe-embedded-kibana-dashboard/46091/4)

Is this helpful, or are you ultimately trying to accomplish something else?
