# Single Logout using Kibana and Keycloak

**URL:** <https://discuss.elastic.co/t/single-logout-using-kibana-and-keycloak/216094>\
**Category:** Kibana\
**Created:** [January 22, 2020, 4:09pm UTC](https://discuss.elastic.co/t/single-logout-using-kibana-and-keycloak/216094 "2020-01-22T16:09:32Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dennis\_Rietvink](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dennis_rietvink/32/60342_2.png) [@Dennis\_Rietvink](https://discuss.elastic.co/u/Dennis_Rietvink)\
**Post date:** [January 22, 2020, 4:09pm UTC](https://discuss.elastic.co/t/single-logout-using-kibana-and-keycloak/216094/1 "2020-01-22T16:09:32Z")

</div>

We are integrating Kibana in our Keycloak identity management solution but have problems getting ‘single logout’ working when triggered from another client.  
This is the scenario:

- User enters the portal but has to login in Keycloak first
- Keycloak handles authentication and redirects back to portal
- In the portal is a link to the Kibana dashboard and the user clicks it
- Kibana does OIDC single sign on with keycloak and the dashboard is presented
- User goes back to portal and clicks on logout in the portal
- Keycloak logoff is called and the portal session is gone
- The Kibana session with the user still exists

In the normal situation the Single Logoff scenario would mean that the Keycloak server calls the Kibana logoff endpoint with the session-id used for single sign on.  
Does this work for Kibana? Do you have examples for Single or Global Logoff and Kibana where the action is performed from server to server.

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [January 24, 2020, 12:10am UTC](https://discuss.elastic.co/t/single-logout-using-kibana-and-keycloak/216094/2 "2020-01-24T00:10:12Z")

</div>

@Larry_Gregory can u please shed more light on this ?

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [January 24, 2020, 3:29pm UTC](https://discuss.elastic.co/t/single-logout-using-kibana-and-keycloak/216094/3 "2020-01-24T15:29:40Z")

</div>

Hey @Dennis_Rietvink, welcome to the discussion boards!

We don't have a published example of Single or Global Logoff, and Kibana/Elasticsearch don't currently support OP-initiated logout as the [specs](https://openid.net/developers/specs/) define it, but we can come pretty close if you are able to configure Keycloak for [front-channel logout](https://openid.net/specs/openid-connect-frontchannel-1_0.html).

If so, it should be sufficient to register Kibana's logout URL (e.g. `https://your-kibana-host:5601/logout`) as the `frontchannel_logout_uri`.

The one caveat here is that we do not currently support the optional `iss` or `sid` parameters which may be used by the OP. We just opened an issue in response to your question to track this initiative: [https://github.com/elastic/elasticsearch/issues/51424](https://github.com/elastic/elasticsearch/issues/51424)

---

<div class="post-metadata">

**Author:** ![Dennis\_Rietvink](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dennis_rietvink/32/60342_2.png) [@Dennis\_Rietvink](https://discuss.elastic.co/u/Dennis_Rietvink)\
**Post date:** [January 25, 2020, 10:48am UTC](https://discuss.elastic.co/t/single-logout-using-kibana-and-keycloak/216094/4 "2020-01-25T10:48:10Z")

</div>

Thanks @Larry_Gregory!

---

<div class="post-metadata">

**Author:** ![Dennis\_Rietvink](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dennis_rietvink/32/60342_2.png) [@Dennis\_Rietvink](https://discuss.elastic.co/u/Dennis_Rietvink)\
**Post date:** [January 26, 2020, 9:54am UTC](https://discuss.elastic.co/t/single-logout-using-kibana-and-keycloak/216094/5 "2020-01-26T09:54:42Z")

</div>

Btw @Larry_Gregory, could you have a look at another issue I posted related to OIDC en canvas? [Losing a session in a Canvas](https://discuss.elastic.co/t/losing-a-session-in-a-canvas/216095)

Thanks,  
Dennis

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [January 26, 2020, 1:18pm UTC](https://discuss.elastic.co/t/single-logout-using-kibana-and-keycloak/216094/6 "2020-01-26T13:18:48Z")

</div>

@Dennis_Rietvink I’m very sorry nobody has replied to that question yet. I’ll take a look on Monday morning EST for you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 23, 2020, 1:28pm UTC](https://discuss.elastic.co/t/single-logout-using-kibana-and-keycloak/216094/7 "2020-02-23T13:28:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
