# Missing authentication token for REST

**URL:** <https://discuss.elastic.co/t/missing-authentication-token-for-rest/29373>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [September 16, 2015, 8:44am UTC](https://discuss.elastic.co/t/missing-authentication-token-for-rest/29373 "2015-09-16T08:44:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![JPVay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpvay/32/61768_2.png) [@JPVay](https://discuss.elastic.co/u/JPVay)\
**Post date:** [September 16, 2015, 8:44am UTC](https://discuss.elastic.co/t/missing-authentication-token-for-rest/29373/1 "2015-09-16T08:44:58Z")

</div>

ES + SHIELD - 1 node (everythig is local)  
admin account ( **realm** )  
SHIELD : trial version

curl -u jpv -XGET '[http://localhost:9200/](http://localhost:9200/)' **works fine**

[http://localhost:9200/](http://localhost:9200/) in browser (chrome) **works fine (ask user/passw dialog)**

with elasticsearch.js (nodejs/iojs and in browser/js app ) :

var es = require('elasticsearch');  
var client = new es.Client({  
host: '[http://localhost:9200](http://localhost:9200)',  
auth : "admin:admin",  
log: 'trace'  
});

client.count(function(err,resp,sta) {  
console.log(err,resp); // \*\*got 401 !!! AuthenticationException[missing authentication token for REST \*\*!  
})

Please notice in the browser (javascript app) : **no** Authorization headers like

**Authorization:Basic blablablabla=**

Something wrong somewhere ?

**Update**  
WTF ? for EACH query, adding parameters:

size : 100,  
body : { .....},  
**headers: {**  
**Authorization: "Basic anB2Omtlcm5pc2k=" //base64 user:pwd**  
}

WORKS FINE. But it's a absurd !!!!!!!

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [September 16, 2015, 2:29pm UTC](https://discuss.elastic.co/t/missing-authentication-token-for-rest/29373/3 "2015-09-16T14:29:28Z")

</div>

The `auth` config needs to be configured as a part of the host definition. This would make your config look like this:

```auto
var es = require('elasticsearch');
var client = new es.Client({
  host: 'http://admin:admin@localhost:9200',
  log: 'trace'
});

```

Please see the [SSL and Authentication](https://www.elastic.co/guide/en/elasticsearch/client/javascript-api/current/auth-reference.html) documentation for more information.

---

<div class="post-metadata">

**Author:** ![JPVay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpvay/32/61768_2.png) [@JPVay](https://discuss.elastic.co/u/JPVay)\
**Post date:** [September 16, 2015, 4:23pm UTC](https://discuss.elastic.co/t/missing-authentication-token-for-rest/29373/4 "2015-09-16T16:23:40Z")

</div>

It works. I tried first this config but with a bad CORS config in elasticsearch.yml :-(.  
Thanks.

---

<div class="post-metadata">

**Author:** ![SKumarMN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/skumarmn/32/27537_2.png) [@SKumarMN](https://discuss.elastic.co/u/SKumarMN)\
**Post date:** [November 12, 2015, 2:13am UTC](https://discuss.elastic.co/t/missing-authentication-token-for-rest/29373/5 "2015-11-12T02:13:02Z")

</div>

I am facing the same issue,How do you set the headers for each request.

For ES i have set the CORS as follows

http.cors.allow-origin : "\*"  
http.cors.allow-methods : OPTIONS, HEAD, GET, POST, PUT, DELETE  
http.cors.allow-headers : X-Requested-With,X-Auth-Token,Content-Type, Content-Length

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:47pm UTC](https://discuss.elastic.co/t/missing-authentication-token-for-rest/29373/6 "2017-07-06T13:47:52Z")

</div>


