# Unable to get deployment users through the API

**URL:** <https://discuss.elastic.co/t/unable-to-get-deployment-users-through-the-api/362411>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [July 2, 2024, 9:40pm UTC](https://discuss.elastic.co/t/unable-to-get-deployment-users-through-the-api/362411 "2024-07-02T21:40:14Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gustavo\_Valente](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavo_valente/32/135727_2.png) [@Gustavo\_Valente](https://discuss.elastic.co/u/Gustavo_Valente)\
**Post date:** [July 2, 2024, 9:40pm UTC](https://discuss.elastic.co/t/unable-to-get-deployment-users-through-the-api/362411/1 "2024-07-02T21:40:14Z")

</div>

Hi team,

I am trying to create a script to get all users and roles from a specific Elasticsearch deployment instance. I have prepared the API call as "{deployment\_URL}/\_security/user", but I am getting this 401 error. I tried using API keys and user credentials, but the error persists. My instance is fully hosted in the cloud. Any thoughts?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [July 4, 2024, 2:39am UTC](https://discuss.elastic.co/t/unable-to-get-deployment-users-through-the-api/362411/2 "2024-07-04T02:39:15Z")

</div>

If you're getting a `401` then I suspect you're mixing up Cloud/Deployment credentials and URLs.

If you want a list of **_deployment_** users (\*) then the URL will be something like `https://my-project-abc123.es.us-east-1.aws.elastic.cloud/_security/user` (depending on your cloud provider and region) and you will need to use either:

- Basic authentication with the `elastic` user and the password provided to your when you created the deployment
- Basic authentication with another user that you created _inside_ the deployment (via API or the Kibana UI)
- An API key that was created inside the deployment (either via the API or the Kibana UI).

You will not be able to use a user that logs via the Cloud login page ([cloud.elastic.co](http://cloud.elastic.co)) or an API Key for the Cloud API.

(\*) This may not include all users who have access to your deployment. That API will only return those who are managed within the deployment. It does not include users who have been granted access via Cloud Console, and login via Elastic Cloud, nor any users that login via other SSO protocols such as SAML or OpenID Connect.
