# Unable to log into embedded Kibana anonymously

**URL:** <https://discuss.elastic.co/t/unable-to-log-into-embedded-kibana-anonymously/291797>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [December 14, 2021, 12:31pm UTC](https://discuss.elastic.co/t/unable-to-log-into-embedded-kibana-anonymously/291797 "2021-12-14T12:31:14Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arrick](https://avatars.discourse-cdn.com/v4/letter/a/ba9def/32.png) [@Arrick](https://discuss.elastic.co/u/Arrick)\
**Post date:** [December 14, 2021, 12:31pm UTC](https://discuss.elastic.co/t/unable-to-log-into-embedded-kibana-anonymously/291797/1 "2021-12-14T12:31:14Z")

</div>

I tried to embed Kibana into a webpage but was unable to login as they kept bringing me back to the login page.  
So I decided to take a different approach and allow user to log in anonymously.  
I create an API-Key and link a newly created role to the api-key. However, when I try to login anonymously, I received this error

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/6/a6b648a8f53333964263621e1839da17496b7e42.png)  
This is how I create my api-key in dev tools

```auto
POST /_security/api_key
{
  "name": "anonymous",
  "expiration": "1d",   
  "role_descriptors": { 
    "role-a": {
      "cluster": ["all"],
      "index": [
        {
          "names": ["anonymous-role"],
          "privileges": ["all"]
        }
      ]
    }
  },
  "metadata": {
    "application": "my-application",
    "environment": {
       "level": 1,
       "trusted": true,
       "tags": ["dev", "staging"]
    }
  }
}

```

This is the privileges I gave to my newly created role

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/e/eedf2ad5fac8a58fa510a8163d8ff183cca07895.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/4/a489439d56ecf45c3285ecfb9c230212c4da9ac3.png)  
And in my `kibana.yml` file I added the following xpack code.

```auto
xpack.security.authc.providers:
    basic.basic1:
        order: 0
    anonymous.anonymous1:
        order: 1
        credentials:
            apiKey.id: "ve_guH0BuaYiJNe0VH1r"
            apiKey.key: "cyivUsIkQBKybk2v6XiOYQ"

```

I'm sorry if this is an easy fix. I am still new and learning Kibana. Any advice is greatly appreciated! Thank you for your time!

---

<div class="post-metadata">

**Author:** ![dosant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dosant/32/64489_2.png) [@dosant](https://discuss.elastic.co/u/dosant)\
**Post date:** [December 14, 2021, 1:51pm UTC](https://discuss.elastic.co/t/unable-to-log-into-embedded-kibana-anonymously/291797/2 "2021-12-14T13:51:23Z")

</div>

Docs recommend to change `sameSiteCookies` policy and use `auth_provider_hint` for this approach

> **[Authentication in Kibana | Kibana Guide \[7.16\] | Elastic](https://www.elastic.co/guide/en/kibana/current/kibana-authentication.html#embedded-content-authentication)**

Have you tried this?

---

<div class="post-metadata">

**Author:** ![Arrick](https://avatars.discourse-cdn.com/v4/letter/a/ba9def/32.png) [@Arrick](https://discuss.elastic.co/u/Arrick)\
**Post date:** [December 15, 2021, 4:41am UTC](https://discuss.elastic.co/t/unable-to-log-into-embedded-kibana-anonymously/291797/3 "2021-12-15T04:41:52Z")

</div>

Hello @dosant sorry I forgot to add that I did use `auth_provider_hint` in my iFrame code.

```auto
<iframe src="http://localhost:5601/app/dashboards?auth_provider_hint=anonymous1#/view/e1eb4b30-3ba1-11ec-818d-cba5e7ef064e?embed=true&_g=(...)" height="600" width="800"></iframe>

```

and when I tried to use `sameSiteCookies` by adding `xpack.security.sameSiteCookies: "None"` in my `kibana.yml`, I received this error instead

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/4/24fe81347cb6dee449c3fb7d6d46fa34e36a4398.png)  
This is the error I saw in my console

1. `[error][server][Kibana][http] Error: "SameSite: None" requires Secure connection at validateOptions`
2. `[warning][process] PromiseRejectionHandledWarning: Promise rejection was handled asynchronously (rejection id: 2)`
3. `Error: Internal Server Error at HapiResponseAdapter.toInternalError`

---

<div class="post-metadata">

**Author:** ![yanwencheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yanwencheng/32/97045_2.png) [@yanwencheng](https://discuss.elastic.co/u/yanwencheng)\
**Post date:** [January 11, 2022, 9:05am UTC](https://discuss.elastic.co/t/unable-to-log-into-embedded-kibana-anonymously/291797/4 "2022-01-11T09:05:45Z")

</div>

> [@Arrick](#):
>
> `?auth_provider_hint=anonymous1`

I Have the same error ,did you solve it?

---

<div class="post-metadata">

**Author:** ![Arrick](https://avatars.discourse-cdn.com/v4/letter/a/ba9def/32.png) [@Arrick](https://discuss.elastic.co/u/Arrick)\
**Post date:** [January 11, 2022, 9:31am UTC](https://discuss.elastic.co/t/unable-to-log-into-embedded-kibana-anonymously/291797/5 "2022-01-11T09:31:28Z")

</div>

Hello @yanwencheng , I went with a different approach. Instead of giving an API key the privilege role (in my case the role is called `anonymous-role`), I gave the `anonymous-role` to a newly created user and used the following code instead;

```auto
xpack.security.authc.providers:
    basic.basic1:
        order: 0
    anonymous.anonymous1:
        order: 1
        credentials:
            username: "[insert username here]"
            password: "[insert password here]"

```

You can refer to my post here regarding it [here](https://discuss.elastic.co/t/embedded-kibana-dashboard-login-page-keeps-reloading-back-to-the-same-page/293028)

---

<div class="post-metadata">

**Author:** ![yanwencheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yanwencheng/32/97045_2.png) [@yanwencheng](https://discuss.elastic.co/u/yanwencheng)\
**Post date:** [January 11, 2022, 10:10am UTC](https://discuss.elastic.co/t/unable-to-log-into-embedded-kibana-anonymously/291797/6 "2022-01-11T10:10:05Z")

</div>

You mean that you only need to configure kibana.yml, I see the official documentation needs to add Elasticsearch.yml

xpack.security.authc:  
anonymous:  
username: anonymous1  
roles: anonymousRole  
authz\_exception: true

---

<div class="post-metadata">

**Author:** ![yanwencheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yanwencheng/32/97045_2.png) [@yanwencheng](https://discuss.elastic.co/u/yanwencheng)\
**Post date:** [January 11, 2022, 10:31am UTC](https://discuss.elastic.co/t/unable-to-log-into-embedded-kibana-anonymously/291797/7 "2022-01-11T10:31:49Z")

</div>

I got a new error again

```auto
Error: [security_exception: [security_exception] Reason: unable to authenticate user [anonymousUser1] for REST request [/_security/_authenticate]]: unable to authenticate user [anonymousUser1] for REST request [/_security/_authenticate]
    at login_form_LoginForm.loginWithSelector (http://192.168.30.243:5601/44266/bundles/plugin/security/8.0.0/security.chunk.5.js:8:22037)
    at async login_form_LoginForm.componentDidMount (http://192.168.30.243:5601/44266/bundles/plugin/security/8.0.0/security.chunk.5.js:8:23159)

```

---

<div class="post-metadata">

**Author:** ![Arrick](https://avatars.discourse-cdn.com/v4/letter/a/ba9def/32.png) [@Arrick](https://discuss.elastic.co/u/Arrick)\
**Post date:** [January 11, 2022, 10:44am UTC](https://discuss.elastic.co/t/unable-to-log-into-embedded-kibana-anonymously/291797/8 "2022-01-11T10:44:24Z")

</div>

that's what I did last time but I got the same error. So I add the roles to a newly created user and am able to log in anonymously using my iFrame code.

---

<div class="post-metadata">

**Author:** ![yanwencheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yanwencheng/32/97045_2.png) [@yanwencheng](https://discuss.elastic.co/u/yanwencheng)\
**Post date:** [January 11, 2022, 11:07am UTC](https://discuss.elastic.co/t/unable-to-log-into-embedded-kibana-anonymously/291797/9 "2022-01-11T11:07:04Z")

</div>

I set a user password of 888888 on kibana page, and in kibana YML is configured as

```auto
xpack.security.authc.providers:
    basic.basic1:
        order: 0
    anonymous.anonymous1:
        order: 1
        credentials:
            username: "ceshiyonghu"
            password: "888888"

```

---

<div class="post-metadata">

**Author:** ![yanwencheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yanwencheng/32/97045_2.png) [@yanwencheng](https://discuss.elastic.co/u/yanwencheng)\
**Post date:** [January 11, 2022, 12:08pm UTC](https://discuss.elastic.co/t/unable-to-log-into-embedded-kibana-anonymously/291797/10 "2022-01-11T12:08:51Z")

</div>

Kibana Do you need to configure other YML? I still have this error

---

<div class="post-metadata">

**Author:** ![yanwencheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yanwencheng/32/97045_2.png) [@yanwencheng](https://discuss.elastic.co/u/yanwencheng)\
**Post date:** [January 12, 2022, 7:59am UTC](https://discuss.elastic.co/t/unable-to-log-into-embedded-kibana-anonymously/291797/11 "2022-01-12T07:59:26Z")

</div>

Thank you very much. After using STL, iframe can be embedded easily。

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 9, 2022, 8:00am UTC](https://discuss.elastic.co/t/unable-to-log-into-embedded-kibana-anonymously/291797/12 "2022-02-09T08:00:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
