# Token vs Clear text user/password

**URL:** <https://discuss.elastic.co/t/token-vs-clear-text-user-password/72212>\
**Category:** Elasticsearch\
**Created:** [January 19, 2017, 7:28pm UTC](https://discuss.elastic.co/t/token-vs-clear-text-user-password/72212 "2017-01-19T19:28:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lhorsky1](https://avatars.discourse-cdn.com/v4/letter/l/b2d939/32.png) [@lhorsky1](https://discuss.elastic.co/u/lhorsky1)\
**Post date:** [January 19, 2017, 7:28pm UTC](https://discuss.elastic.co/t/token-vs-clear-text-user-password/72212/1 "2017-01-19T19:28:11Z")

</div>

Is it possible to send User creds using a token instead of sending clear text? I know that we can use the statement below and that it is sent encrypted:  
curl --user user1:password2 -XGET '[https://elasticserver:9200/](https://elasticserver:9200/).....'

But, in the case of using [elasticsearch.pm](http://elasticsearch.pm), that means that the username and password are stored in clear text on the server running the connection to Elasticsaerch. Not something we want to do, especially given that the documentation says that Elasticsearch running X-Pack processes the creds as a Base64 token.

Ideally we want to be able to tokenize the creds, then save that token in our scripts. That way not only is the data encrypted in transmission, but it is also not stored in clear text on the server.

Thanks.  
Laura

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [January 23, 2017, 9:13am UTC](https://discuss.elastic.co/t/token-vs-clear-text-user-password/72212/2 "2017-01-23T09:13:16Z")

</div>

Hey,

right now you cannot use tokens. However as a workaround, you could use the [PKI realm](https://www.elastic.co/guide/en/x-pack/5.1/pki-realm.html) and use certificates to authenticate users, requiring you not to store passwords locally.

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2017, 9:13am UTC](https://discuss.elastic.co/t/token-vs-clear-text-user-password/72212/3 "2017-02-20T09:13:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
