# Securing search endpoint

**URL:** <https://discuss.elastic.co/t/securing-search-endpoint/288624>\
**Category:** Elastic Search\
**Tags:** elastic-app-search\
**Created:** [November 8, 2021, 12:43pm UTC](https://discuss.elastic.co/t/securing-search-endpoint/288624 "2021-11-08T12:43:50Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![reka.gay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/reka.gay/32/91470_2.png) [@reka.gay](https://discuss.elastic.co/u/reka.gay)\
**Post date:** [November 8, 2021, 12:43pm UTC](https://discuss.elastic.co/t/securing-search-endpoint/288624/1 "2021-11-08T12:43:50Z")

</div>

We have a self-hosted Enterprise Search instance with sensitive search data in it. A permanent public search API key doesn't meet our security standards.

What is the best way to ensure that only authenticated users can access the search endpoint? Our users are authenticated through AWS Cognito.

Thanks a lot in advance.

---

<div class="post-metadata">

**Author:** ![JasonStoltz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasonstoltz/32/49893_2.png) [@JasonStoltz](https://discuss.elastic.co/u/JasonStoltz)\
**Post date:** [November 8, 2021, 3:55pm UTC](https://discuss.elastic.co/t/securing-search-endpoint/288624/2 "2021-11-08T15:55:43Z")

</div>

If a public search key does not meet your standards, then I would recommend proxying the search endpoint through your own API endpoint, which would implement whatever security protocols you wish.

---

<div class="post-metadata">

**Author:** ![reka.gay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/reka.gay/32/91470_2.png) [@reka.gay](https://discuss.elastic.co/u/reka.gay)\
**Post date:** [November 8, 2021, 5:24pm UTC](https://discuss.elastic.co/t/securing-search-endpoint/288624/3 "2021-11-08T17:24:30Z")

</div>

@JasonStoltz thanks, will look into doing that. However, I'm currently using the SearchUI to handle all search requests - do you know of an easy way to add extra headers into the query - for the authentication token?

---

<div class="post-metadata">

**Author:** ![JasonStoltz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasonstoltz/32/49893_2.png) [@JasonStoltz](https://discuss.elastic.co/u/JasonStoltz)\
**Post date:** [November 8, 2021, 7:44pm UTC](https://discuss.elastic.co/t/securing-search-endpoint/288624/4 "2021-11-08T19:44:39Z")

</div>

Sure. The App Search API connector is configured to pass through any additional options to the underlying API client: [search-ui/packages/search-ui-app-search-connector at master · elastic/search-ui · GitHub](https://github.com/elastic/search-ui/tree/master/packages/search-ui-app-search-connector). The underlying api client supports an `additionalHeaders` option, so you can use that: [GitHub - elastic/app-search-javascript: Elastic App Search Official JavaScript Client](https://github.com/elastic/app-search-javascript).

---

<div class="post-metadata">

**Author:** ![reka.gay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/reka.gay/32/91470_2.png) [@reka.gay](https://discuss.elastic.co/u/reka.gay)\
**Post date:** [November 10, 2021, 8:42am UTC](https://discuss.elastic.co/t/securing-search-endpoint/288624/5 "2021-11-10T08:42:11Z")

</div>

> [@JasonStoltz](#):
>
> `additionalHeaders`

Worked like a charm, thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2021, 8:42am UTC](https://discuss.elastic.co/t/securing-search-endpoint/288624/6 "2021-12-08T08:42:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
