# OIDC based user level authorization without Kibana

**URL:** <https://discuss.elastic.co/t/oidc-based-user-level-authorization-without-kibana/239530>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 1, 2020, 6:48pm UTC](https://discuss.elastic.co/t/oidc-based-user-level-authorization-without-kibana/239530 "2020-07-01T18:48:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![soumendra](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@soumendra](https://discuss.elastic.co/u/soumendra)\
**Post date:** [July 1, 2020, 6:48pm UTC](https://discuss.elastic.co/t/oidc-based-user-level-authorization-without-kibana/239530/1 "2020-07-01T18:48:33Z")

</div>

Please help us with the following issue.

Current scenario:  
UI A --\> OIDC provider --\> UI B (SU) --\> Kibana dashboard  
We have a custom OIDC provider through which users get authenticated in Kibana. In UI B we use AngularJS. As we used elastic superuser (SU) to do API get calls in ES and display over AngularJS, a user without access to DB also can see the data in Angular.

Planned scenario:  
UI A --\> OIDC provider --\> UI B (Individual User) --\> Kibana dashboard  
We are planning to replace the SU based ES API calls with UserID based ES API calls. A user gets already authenticated before seeing on UI B through the OIDC provider. However, the problem is how can we use the OIDC realm based authenticated user to see data over ANgularJS only s/he has access to.  
We have followed this guideline, [https://www.elastic.co/guide/en/elasticsearch/reference/7.6/oidc-without-kibana.html?blade=supportportalv1](https://www.elastic.co/guide/en/elasticsearch/reference/7.6/oidc-without-kibana.html?blade=supportportalv1)  
However, there seems to not have much info on User authorization. There is realm based bearer token but no user-level bearer token we can use to make API calls to ES to fetch data. Is it possible to have user-level bearer token with OIDC realm authenticated user?  
Please help. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 29, 2020, 6:48pm UTC](https://discuss.elastic.co/t/oidc-based-user-level-authorization-without-kibana/239530/2 "2020-07-29T18:48:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
