# Super user that creates api keys on behalf of other user

**URL:** <https://discuss.elastic.co/t/super-user-that-creates-api-keys-on-behalf-of-other-user/289511>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [November 17, 2021, 11:20pm UTC](https://discuss.elastic.co/t/super-user-that-creates-api-keys-on-behalf-of-other-user/289511 "2021-11-17T23:20:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Scotturbina](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scotturbina/32/97246_2.png) [@Scotturbina](https://discuss.elastic.co/u/Scotturbina)\
**Post date:** [November 17, 2021, 11:20pm UTC](https://discuss.elastic.co/t/super-user-that-creates-api-keys-on-behalf-of-other-user/289511/1 "2021-11-17T23:20:31Z")

</div>

I got a super user, I need this super user can grant api keys on behalf other user (these users are not native, they sign in via SSO with Open Id)  
I saw that [Grant API key API | Elasticsearch Guide [7.15] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/security-api-grant-api-key.html) needs user and password, but we do not have that, since user is using SSO, access\_token it is not an option since we need human intervention

Our ultimate goal is that the super user can provide those api keys without human intervention.

Is there some way I can do this?

---

<div class="post-metadata">

**Author:** ![Yang\_Wang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yang_wang/32/48857_2.png) [@Yang\_Wang](https://discuss.elastic.co/u/Yang_Wang)\
**Post date:** [November 19, 2021, 4:36am UTC](https://discuss.elastic.co/t/super-user-that-creates-api-keys-on-behalf-of-other-user/289511/2 "2021-11-19T04:36:05Z")

</div>

> Our ultimate goal is that the super user can provide those api keys without human intervention.

Authenticating to Elasticsearch with either SAML or OIDC requires a web-browser, which generally implies human users. So it is unlikely achievable.

That said, superuser can create API keys with any permission. What prevent you from creating (instead of granting) API keys directly using the superuser if (1) you will be using `superuser` anyway and (2) human intervention is not wanted? One major benefit of "grant API Keys" is that the granter does not have to have all privileges of the grantee. But since the granter is `superuser`, the benefit no longer applies.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 17, 2021, 4:36am UTC](https://discuss.elastic.co/t/super-user-that-creates-api-keys-on-behalf-of-other-user/289511/3 "2021-12-17T04:36:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
