# Unable to create actions client because the Encrypted Saved Objects plugin is missing encryption key

**URL:** <https://discuss.elastic.co/t/unable-to-create-actions-client-because-the-encrypted-saved-objects-plugin-is-missing-encryption-key/378530>\
**Category:** Elastic Security\
**Created:** [May 26, 2025, 7:46am UTC](https://discuss.elastic.co/t/unable-to-create-actions-client-because-the-encrypted-saved-objects-plugin-is-missing-encryption-key/378530 "2025-05-26T07:46:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![felixwong](https://avatars.discourse-cdn.com/v4/letter/f/ed8c4c/32.png) [@felixwong](https://discuss.elastic.co/u/felixwong)\
**Post date:** [May 26, 2025, 7:46am UTC](https://discuss.elastic.co/t/unable-to-create-actions-client-because-the-encrypted-saved-objects-plugin-is-missing-encryption-key/378530/1 "2025-05-26T07:46:16Z")

</div>

This is my first time to launch elastic security . There is a pop up showed

Unable to create actions client because the Encrypted Saved Objects plugin is missing encryption key. Please set xpack.encryptedSavedObjects.encryptionKey in the kibana.yml or use the bin/kibana-encryption-keys command. (500)

{  
"name": "Error",  
"body": {  
"message": "Unable to create actions client because the Encrypted Saved Objects plugin is missing encryption key. Please set xpack.encryptedSavedObjects.encryptionKey in the kibana.yml or use the bin/kibana-encryption-keys command.",  
"status\_code": 500  
},  
"message": "Internal Server Error",  
"stack": "Error: Internal Server Error\n at Fetch.fetchResponse ([http://elasearch01.ln.edu.hk:5601/0df588b1a307/bundles/core/core.entry.js:1:226935](http://elasearch01.ln.edu.hk:5601/0df588b1a307/bundles/core/core.entry.js:1:226935))\n at async [http://elasearch01.ln.edu.hk:5601/0df588b1a307/bundles/core/core.entry.js:1:224968\n](http://elasearch01.ln.edu.hk:5601/0df588b1a307/bundles/core/core.entry.js:1:224968%5Cn) at async [http://elasearch01.ln.edu.hk:5601/0df588b1a307/bundles/core/core.entry.js:1:224925](http://elasearch01.ln.edu.hk:5601/0df588b1a307/bundles/core/core.entry.js:1:224925)"  
}

I tried to fix it to run kibana-encryption-keys. IT gave me error  
[dcadmin@elasearch01 bin]$ ./kibana-encryption-keys  
Error: ENOENT: no such file or directory, open '/usr/share/kibana/config/kibana.yml'  
at Object.openSync (node:fs:573:18)  
at readFileSync (node:fs:452:35)  
at new EncryptionConfig (/usr/share/kibana/src/cli\_encryption\_keys/encryption\_config.js:30:86)  
at Object. (/usr/share/kibana/src/cli\_encryption\_keys/cli\_encryption\_keys.js:20:26)  
at Module.\_compile (node:internal/modules/cjs/loader:1469:14)  
at Object.Module.\_extensions..js (node:internal/modules/cjs/loader:1548:10)  
at Module.load (node:internal/modules/cjs/loader:1288:32)  
at Function.Module.\_load (node:internal/modules/cjs/loader:1104:12)  
at Module.require (node:internal/modules/cjs/loader:1311:19)  
at Module.patchedRequire (/usr/share/kibana/node\_modules/require-in-the-middle/index.js:256:27)  
[dcadmin@elasearch01 bin]$

Does anyone experience it ? Thanks

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [May 26, 2025, 8:19am UTC](https://discuss.elastic.co/t/unable-to-create-actions-client-because-the-encrypted-saved-objects-plugin-is-missing-encryption-key/378530/2 "2025-05-26T08:19:27Z")

</div>

> [@felixwong](#):
>
> [dcadmin@elasearch01 bin]$ ./kibana-encryption-keys  
> Error: ENOENT: no such file or directory, open '/usr/share/kibana/config/kibana.yml'

Is kibana running on this same host, i.e. elasearch01 ?

Is the error accurate, i.e. does the file /usr/share/kibana/config/kibana.yml exist on that system? How did you install kibana? (and elasticsearch)?

usual "fix" is to just add a line like

```auto
xpack.encryptedSavedObjects.encryptionKey: <min-32-byte-long-strong-encryption-key?

```

to kibana.yml, once you've located that file and restart kibana.

Replace `"<min-32-byte-long-strong-encryption-key>"` with say a random 32-char hex string.

---

<div class="post-metadata">

**Author:** ![felixwong](https://avatars.discourse-cdn.com/v4/letter/f/ed8c4c/32.png) [@felixwong](https://discuss.elastic.co/u/felixwong)\
**Post date:** [May 26, 2025, 9:15am UTC](https://discuss.elastic.co/t/unable-to-create-actions-client-because-the-encrypted-saved-objects-plugin-is-missing-encryption-key/378530/3 "2025-05-26T09:15:46Z")

</div>

Yes , elasticsearcha and kibana are running in same host . kibana.yml is located in /etc/kibana. The command searched wrong location . I have restarted kibana . It seems kibana-encryption-keys look for wrong file location . Would you shed some light ? Thanks

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [May 26, 2025, 9:32am UTC](https://discuss.elastic.co/t/unable-to-create-actions-client-because-the-encrypted-saved-objects-plugin-is-missing-encryption-key/378530/4 "2025-05-26T09:32:40Z")

</div>

maybe, but did you try what I suggested?

And how did you install elasticsearch/kibana - from .rpm file, from .deb file, apt , yum, ...

---

<div class="post-metadata">

**Author:** ![felixwong](https://avatars.discourse-cdn.com/v4/letter/f/ed8c4c/32.png) [@felixwong](https://discuss.elastic.co/u/felixwong)\
**Post date:** [May 26, 2025, 10:30am UTC](https://discuss.elastic.co/t/unable-to-create-actions-client-because-the-encrypted-saved-objects-plugin-is-missing-encryption-key/378530/5 "2025-05-26T10:30:58Z")

</div>

Thanks . I got it fix . I executed the command with root user .
