# Sending metadata with external users

**URL:** <https://discuss.elastic.co/t/sending-metadata-with-external-users/258551>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [December 14, 2020, 8:58am UTC](https://discuss.elastic.co/t/sending-metadata-with-external-users/258551 "2020-12-14T08:58:24Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mahi2](https://avatars.discourse-cdn.com/v4/letter/m/9fc29f/32.png) [@mahi2](https://discuss.elastic.co/u/mahi2)\
**Post date:** [December 14, 2020, 8:58am UTC](https://discuss.elastic.co/t/sending-metadata-with-external-users/258551/1 "2020-12-14T08:58:24Z")

</div>

Hi,  
I have a scenario where the OpenID Connect users (external users) login to elastic search cloud. Is there a way to send some metadata along with the external user using an API ?

To explain clearly, I've given an example below.

I have an oidc user (external user) 'ext User1' who login to elastic cloud. External users are not shown in the list of users in _Kibana stack management_ under _security_.  
It shows internal users only.

 ![users](https://us1.discourse-cdn.com/elastic/original/3X/0/2/02039ce330d842ca2c510e5cd350934b0f0f3a5e.png)

For the internal users, we can GET user info(metadata ) using an API.  
 ![getAPI](https://us1.discourse-cdn.com/elastic/original/3X/6/5/65f27c9a0ba8eeb2ae1627bab60129798aca67f3.png)  
In 'testuser1', I added some metadata using an API and I could see the added data in response.  
 ![response](https://us1.discourse-cdn.com/elastic/original/3X/f/1/f1d7d2ff0ceb4cbb6072804b97f0af1736185bf5.png)

My question is-

1. Is there a way I can send metadata with external users in an API like we are able to do for internal users?
2. Is there an endpoint to GET the list of external users in Kibana?

Thanks in advance.  
Regards  
Mahi

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [December 15, 2020, 12:33am UTC](https://discuss.elastic.co/t/sending-metadata-with-external-users/258551/2 "2020-12-15T00:33:21Z")

</div>

In a default configuration, Elastic does not store any local data about users coming from external sources.

So, there is no way to list external users, or store metadata for them because nothing exists locally.

You have 2 options:

1. You can provide metadata for users from your OIDC OP to the Elastic Stack as part of the OIDC claims. If the data you want to use is in your OIDC security provider, then you can configure that system to pass it across when users authenticate
2. You can create local native users for your OIDC users and use Elasticsearch `authorization_realms` support so that very OIDC user is actually an internal native user.

---

<div class="post-metadata">

**Author:** ![mahi2](https://avatars.discourse-cdn.com/v4/letter/m/9fc29f/32.png) [@mahi2](https://discuss.elastic.co/u/mahi2)\
**Post date:** [December 15, 2020, 12:52pm UTC](https://discuss.elastic.co/t/sending-metadata-with-external-users/258551/3 "2020-12-15T12:52:00Z")

</div>

Hi Tim,  
thanks for the reply.

can you send some example steps for the second point(create local native users for your OIDC users)?  
This might really solve our purpose.

Thanks again.  
Mahi

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [December 16, 2020, 2:12am UTC](https://discuss.elastic.co/t/sending-metadata-with-external-users/258551/4 "2020-12-16T02:12:49Z")

</div>

> **[Configuring authorization delegation | Elasticsearch Reference \[7.10\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/configuring-authorization-delegation.html)**

This shows various examples, around Kerberos and LDAP, but in your case you'd want to set your `oidc` realm to have `authorization_realms` pointing to your `native` realm.

---

<div class="post-metadata">

**Author:** ![mahi2](https://avatars.discourse-cdn.com/v4/letter/m/9fc29f/32.png) [@mahi2](https://discuss.elastic.co/u/mahi2)\
**Post date:** [December 22, 2020, 7:53am UTC](https://discuss.elastic.co/t/sending-metadata-with-external-users/258551/5 "2020-12-22T07:53:17Z")

</div>

Hi Tim  
Sorry for the late reply.

Thanks for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 19, 2021, 7:53am UTC](https://discuss.elastic.co/t/sending-metadata-with-external-users/258551/6 "2021-01-19T07:53:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
