# Security - how to avoid exposing app search keys (searchKey,host identifier,engineName) in search ui

**URL:** <https://discuss.elastic.co/t/security-how-to-avoid-exposing-app-search-keys-searchkey-host-identifier-enginename-in-search-ui/207993>\
**Category:** Elastic Search\
**Tags:** elastic-app-search\
**Created:** [November 15, 2019, 5:52am UTC](https://discuss.elastic.co/t/security-how-to-avoid-exposing-app-search-keys-searchkey-host-identifier-enginename-in-search-ui/207993 "2019-11-15T05:52:30Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Swapnil\_Ghorpade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/swapnil_ghorpade/32/56943_2.png) [@Swapnil\_Ghorpade](https://discuss.elastic.co/u/Swapnil_Ghorpade)\
**Post date:** [November 15, 2019, 5:52am UTC](https://discuss.elastic.co/t/security-how-to-avoid-exposing-app-search-keys-searchkey-host-identifier-enginename-in-search-ui/207993/1 "2019-11-15T05:52:30Z")

</div>

I'm using app search with search ui [GitHub - elastic/search-ui: Search UI. Libraries for the fast development of modern, engaging search experiences.](https://github.com/elastic/search-ui)

Everything looks great about search ui except security. All keys Credentials (searchKey,host identifier,engineName) are visible in api call.

I thought to move [Connectors](https://github.com/elastic/search-ui#2-connectors) key logic to backend.

So the flow will be like 1.search ui call backend api. 2 backend will call app search-api and return response as it is to show result on ui.  
is the right way to go?

I haven’t found any way to give own api call from search-ui.

How can I do this?

---

<div class="post-metadata">

**Author:** ![JasonStoltz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasonstoltz/32/49893_2.png) [@JasonStoltz](https://discuss.elastic.co/u/JasonStoltz)\
**Post date:** [November 15, 2019, 11:31am UTC](https://discuss.elastic.co/t/security-how-to-avoid-exposing-app-search-keys-searchkey-host-identifier-enginename-in-search-ui/207993/2 "2019-11-15T11:31:33Z")

</div>

Hey @Swapnil_Ghorpade. We consider it safe to expose Public Search Keys. They have limited, read-only access. Did you have a specific concern around that?

There are instructions and an example for using Search UI with other back ends here: [https://github.com/elastic/search-ui/blob/master/ADVANCED.md#implementing-handlers-without-a-connector](https://github.com/elastic/search-ui/blob/master/ADVANCED.md#implementing-handlers-without-a-connector).

---

<div class="post-metadata">

**Author:** ![Swapnil\_Ghorpade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/swapnil_ghorpade/32/56943_2.png) [@Swapnil\_Ghorpade](https://discuss.elastic.co/u/Swapnil_Ghorpade)\
**Post date:** [November 18, 2019, 7:10am UTC](https://discuss.elastic.co/t/security-how-to-avoid-exposing-app-search-keys-searchkey-host-identifier-enginename-in-search-ui/207993/3 "2019-11-18T07:10:31Z")

</div>

@JasonStoltz yeah documents are private thats why...  
If anyone get these keys then he can easily access documents without logging which I don't want.

Could you please suggest any better way to handle this?

PFA : search-ui default demo-examples

 ![search-ui%20park-demo%20(1)](https://us1.discourse-cdn.com/elastic/original/3X/8/f/8f4fb982d784cfeb590cddee302f4efddf5723ce.png)

---

<div class="post-metadata">

**Author:** ![JasonStoltz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasonstoltz/32/49893_2.png) [@JasonStoltz](https://discuss.elastic.co/u/JasonStoltz)\
**Post date:** [November 18, 2019, 12:44pm UTC](https://discuss.elastic.co/t/security-how-to-avoid-exposing-app-search-keys-searchkey-host-identifier-enginename-in-search-ui/207993/4 "2019-11-18T12:44:31Z")

</div>

@Swapnil_Ghorpade You could set up a thin proxy to our API that handles authentication and injects the correct authentication token, and then point Search UI at your proxy server. There is an `endpointBase` configuration option that lets configure the URL where the App Search API is located.

---

<div class="post-metadata">

**Author:** ![Swapnil\_Ghorpade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/swapnil_ghorpade/32/56943_2.png) [@Swapnil\_Ghorpade](https://discuss.elastic.co/u/Swapnil_Ghorpade)\
**Post date:** [November 18, 2019, 1:12pm UTC](https://discuss.elastic.co/t/security-how-to-avoid-exposing-app-search-keys-searchkey-host-identifier-enginename-in-search-ui/207993/5 "2019-11-18T13:12:56Z")

</div>

hey @JasonStoltz I didn’t get that.  
could you please elaborate a bit , how to use this ?

---

<div class="post-metadata">

**Author:** ![JasonStoltz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasonstoltz/32/49893_2.png) [@JasonStoltz](https://discuss.elastic.co/u/JasonStoltz)\
**Post date:** [November 18, 2019, 1:36pm UTC](https://discuss.elastic.co/t/security-how-to-avoid-exposing-app-search-keys-searchkey-host-identifier-enginename-in-search-ui/207993/6 "2019-11-18T13:36:11Z")

</div>

If you need to protect search and put it behind a login, then you'll need to make the API requests to App Search server-side. One way to do that, would be to create your own search endpoint that just proxies our App Search API.

Browser -\> Your Server -\> App Search API

Your server could just pass through App Search API requests through to the App Search API. Your server though, would be responsible for authentication. Additionally, your server would append the correct **API Key** to the request before forwarding the request, so that it is never exposed in the browser.

Does that make sense?

---

<div class="post-metadata">

**Author:** ![Swapnil\_Ghorpade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/swapnil_ghorpade/32/56943_2.png) [@Swapnil\_Ghorpade](https://discuss.elastic.co/u/Swapnil_Ghorpade)\
**Post date:** [November 18, 2019, 1:42pm UTC](https://discuss.elastic.co/t/security-how-to-avoid-exposing-app-search-keys-searchkey-host-identifier-enginename-in-search-ui/207993/7 "2019-11-18T13:42:16Z")

</div>

@JasonStoltz thanks for the responding.  
yes..it's look like this will work.

---

<div class="post-metadata">

**Author:** ![Swapnil\_Ghorpade](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/swapnil_ghorpade/32/56943_2.png) [@Swapnil\_Ghorpade](https://discuss.elastic.co/u/Swapnil_Ghorpade)\
**Post date:** [November 19, 2019, 6:28am UTC](https://discuss.elastic.co/t/security-how-to-avoid-exposing-app-search-keys-searchkey-host-identifier-enginename-in-search-ui/207993/8 "2019-11-19T06:28:29Z")

</div>

hey thank you @JasonStoltz I have a question,

I think it will add unnecessary load on own server to just forward request to app-search on every time users do search?

is there any other way to handle this case?

---

<div class="post-metadata">

**Author:** ![JasonStoltz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasonstoltz/32/49893_2.png) [@JasonStoltz](https://discuss.elastic.co/u/JasonStoltz)\
**Post date:** [November 19, 2019, 12:23pm UTC](https://discuss.elastic.co/t/security-how-to-avoid-exposing-app-search-keys-searchkey-host-identifier-enginename-in-search-ui/207993/9 "2019-11-19T12:23:32Z")

</div>

@Swapnil_Ghorpade If your documents are private, then I think you _must_ make these calls on the server side, behind your authentication. I don't think there's any way around that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 17, 2019, 12:23pm UTC](https://discuss.elastic.co/t/security-how-to-avoid-exposing-app-search-keys-searchkey-host-identifier-enginename-in-search-ui/207993/10 "2019-12-17T12:23:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
