# SSO, query API, index privileges

**URL:** https://discuss.elastic.co/t/sso-query-api-index-privileges/368741
**Category:** Elasticsearch
**Tags:** esql
**Created:** [October 13, 2024, 10:54pm UTC](https://discuss.elastic.co/t/sso-query-api-index-privileges/368741 "2024-10-13T22:54:31Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![johnwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johnwood/32/78918_2.png) [@johnwood](https://discuss.elastic.co/u/johnwood)
#### Post date: [October 13, 2024, 10:54pm UTC](https://discuss.elastic.co/t/sso-query-api-index-privileges/368741/1 "2024-10-13T22:54:31Z")

</div>

Hi ElasticBrains

I have an ES cloud that I wish to access via the API - my users are defined in Auth0 SSO and I use role mapping to set their index privileges in ES.

I have an app that front ends their ES/QL queries via the ES API - how can I map their role based index privileges to the queries that are sent over the 'shared' API call using a shared API Key to authenticate.

I read that SSO does not support "Run As" - what is the solution to retain their Index privilege restrictions with SSO?

Thanks

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [October 14, 2024, 3:39am UTC](https://discuss.elastic.co/t/sso-query-api-index-privileges/368741/2 "2024-10-14T03:39:48Z")

</div>

There is no solution here.

You users only exist in Auth0, Elasticsearch doesn't know anything about them.

You either need to:

- authenticate the user via Auth0
- create an API key for each user
- determine the users roles yourself, and then create an API key for that set of roles.

---

<div class="post-metadata">

### Author: ![johnwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johnwood/32/78918_2.png) [@johnwood](https://discuss.elastic.co/u/johnwood)
#### Post date: [October 14, 2024, 9:34am UTC](https://discuss.elastic.co/t/sso-query-api-index-privileges/368741/3 "2024-10-14T09:34:04Z")

</div>

Thanks Tim

Right now I create a role for each user.

I don’t really see how I can use auth0 to authenticate the users for the back end

Creating an API key for each user would work if that key can be constrained by the same role as the user is?

I’ll go do some more reading about api keys and roles
