# Secured API-Keys in elastic

**URL:** <https://discuss.elastic.co/t/secured-api-keys-in-elastic/85365>\
**Category:** Elasticsearch\
**Created:** [May 11, 2017, 9:59am UTC](https://discuss.elastic.co/t/secured-api-keys-in-elastic/85365 "2017-05-11T09:59:37Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![mwysinski](https://avatars.discourse-cdn.com/v4/letter/m/c37758/32.png) [@mwysinski](https://discuss.elastic.co/u/mwysinski)\
**Post date:** [May 11, 2017, 9:59am UTC](https://discuss.elastic.co/t/secured-api-keys-in-elastic/85365/1 "2017-05-11T09:59:37Z")

</div>

Hello,

With Algolia we use Secured API-Keys feature and we really like it. We're wondering is there anything similar that we could use with Elastic?

Here is how Algolia's docs describe it:

The goal of a secured API key is to ensure a set of query parameters cannot be changed by the end user. In order to do that, we compute a HMAC SHA-256 hash between one of your API keys that is used as a secret and the set of query parameters you want to enforce.

- On your backend, you use our API Client to compute the hash with a set of query parameters that you want to have applied in a secure way. The method to do that is generate\_secured\_api\_key. The input is the API key that you want to use and the query parameters. The output is a hash containing inputs encoded in base 64. This method is just a hash computation, there is no network call to our service.
- You pass this hash to the end-user browser or mobile app and the string is used as an API Key.
- In our backend, we will scan all of your API keys and compute the hash corresponding to the set of query parameters. When the hash matches one key, this key, and associated restrictions, will be used to perform the query and the query parameters will be used. If the user tries to change the forced query parameters in the string, then the hash won’t match and the query will be rejected.

More info:

> **[API Keys](https://www.algolia.com/doc/guides/security/api-keys/#secured-api-keys)**
>
> Algolia: Across 15 languages, read up on Algolia concepts, get access to Tutorials with concrete use-cases and sample datasets, or explore our API Reference.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 13, 2017, 4:48am UTC](https://discuss.elastic.co/t/secured-api-keys-in-elastic/85365/2 "2017-05-13T04:48:52Z")

</div>

There's templated searches that might match this, same with a filtered alias. Which specific part are you interested in?

---

<div class="post-metadata">

**Author:** ![njt1982](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/njt1982/32/18699_2.png) [@njt1982](https://discuss.elastic.co/u/njt1982)\
**Post date:** [June 1, 2017, 9:00am UTC](https://discuss.elastic.co/t/secured-api-keys-in-elastic/85365/3 "2017-06-01T09:00:59Z")

</div>

Hi @warkolm

It doesn't seem to be, no.

The HMAC Keys from Algolia let us provide each logged in user to the site with their own key to access Algolia directly via the client. This means we dont have to hand each user a non-expiring global key; each user has their own key which has short-expiry and can even be restricted in its own way (ie limited to specific indexes or preset filters (this is possibly where templates share some features)).

From what I can see, there is no such feature in Elastic.

Currently, we route Elastic searches through a Rails app to protect the access key. This lets us use Rails (via Warden and Devise) to authenticate the requests. Obviously, this adds overhead to each search in both request speed and server load. It would be nice for the client to hit Elastic directly.

We are moving to 5.x imminently, so it looks like X-Pack ([https://www.elastic.co/guide/en/x-pack/current/how-security-works.html](https://www.elastic.co/guide/en/x-pack/current/how-security-works.html)) is the way forward. It seems we could define a restricted user for the frontend (eg read-only, etc), but we will have to send those user credentials in plain text to our users. That's not great. 🙂

LDAP and AD are not really valid options here.

How hard is PKI to setup? Doesn't this still suffer the same problem that we'll be giving out the same cert to all users?

The Algolia HMAC system uses a single base key as part of the generated key for each user:

> **[Api keys](https://www.algolia.com/doc/api-client/api-keys/)**
>
> Algolia: Across 15 languages, read up on Algolia concepts, get access to Tutorials with concrete use-cases and sample datasets, or explore our API Reference.

Are there any documented examples of how to securely use Elastic Search in a frontend JS application (like Ember, Angular or React)?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 2, 2017, 9:36am UTC](https://discuss.elastic.co/t/secured-api-keys-in-elastic/85365/4 "2017-06-02T09:36:20Z")

</div>

Ahh it's a bit deeper than I thought then 🙂

Lemme move this to the X-Pack section as one of the devs there will have a better idea!

---

<div class="post-metadata">

**Author:** ![njt1982](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/njt1982/32/18699_2.png) [@njt1982](https://discuss.elastic.co/u/njt1982)\
**Post date:** [June 5, 2017, 10:30am UTC](https://discuss.elastic.co/t/secured-api-keys-in-elastic/85365/5 "2017-06-05T10:30:49Z")

</div>

Thanks @warkolm 🙂

---

<div class="post-metadata">

**Author:** ![njt1982](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/njt1982/32/18699_2.png) [@njt1982](https://discuss.elastic.co/u/njt1982)\
**Post date:** [June 5, 2017, 10:48am UTC](https://discuss.elastic.co/t/secured-api-keys-in-elastic/85365/6 "2017-06-05T10:48:58Z")

</div>

I wonder if there is anything with JWT we could use here?!

---

<div class="post-metadata">

**Author:** ![joshbressers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshbressers/32/42332_2.png) [@joshbressers](https://discuss.elastic.co/u/joshbressers)\
**Post date:** [June 5, 2017, 12:42pm UTC](https://discuss.elastic.co/t/secured-api-keys-in-elastic/85365/7 "2017-06-05T12:42:07Z")

</div>

I would look at using PKI authentication to solve this today:  
[https://www.elastic.co/guide/en/x-pack/current/pki-realm.html](https://www.elastic.co/guide/en/x-pack/current/pki-realm.html)

You give each user a different certificate for authentication, no worries about having to share a single certificate.

We don't currently support JWT for authentication.

---

<div class="post-metadata">

**Author:** ![njt1982](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/njt1982/32/18699_2.png) [@njt1982](https://discuss.elastic.co/u/njt1982)\
**Post date:** [June 5, 2017, 5:42pm UTC](https://discuss.elastic.co/t/secured-api-keys-in-elastic/85365/8 "2017-06-05T17:42:47Z")

</div>

Thanks @joshbressers - so does this mean we need one certificate setup in Elastic per user? If we onboard a new user, we have to setup a new cert (and the reverse; when we remove users, we remove certs?)

---

<div class="post-metadata">

**Author:** ![joshbressers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshbressers/32/42332_2.png) [@joshbressers](https://discuss.elastic.co/u/joshbressers)\
**Post date:** [June 5, 2017, 8:13pm UTC](https://discuss.elastic.co/t/secured-api-keys-in-elastic/85365/9 "2017-06-05T20:13:16Z")

</div>

You would sign the user certificates with a trusted certificate authority. Only the users would need certificates on their end. The server only needs a copy of the public CA certificate.

If a user leaves the organization you would remove their username from the role mapping file.  
[https://www.elastic.co/guide/en/x-pack/current/mapping-roles.html#pki-role-mapping](https://www.elastic.co/guide/en/x-pack/current/mapping-roles.html#pki-role-mapping)

Then you would configure Role Based Access Control to determine what a given user can or can't do.  
[https://www.elastic.co/guide/en/x-pack/current/authorization.html](https://www.elastic.co/guide/en/x-pack/current/authorization.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2017, 8:13pm UTC](https://discuss.elastic.co/t/secured-api-keys-in-elastic/85365/10 "2017-07-03T20:13:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
