# User authorized in KeyCloak rejected access to Kibana space

**URL:** <https://discuss.elastic.co/t/user-authorized-in-keycloak-rejected-access-to-kibana-space/357997>\
**Category:** Kibana\
**Tags:** elastic-stack-security\
**Created:** [April 23, 2024, 9:09am UTC](https://discuss.elastic.co/t/user-authorized-in-keycloak-rejected-access-to-kibana-space/357997 "2024-04-23T09:09:29Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![vnovotny98](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vnovotny98/32/124809_2.png) [@vnovotny98](https://discuss.elastic.co/u/vnovotny98)\
**Post date:** [June 17, 2024, 8:56pm UTC](https://discuss.elastic.co/t/user-authorized-in-keycloak-rejected-access-to-kibana-space/357997/4 "2024-06-17T20:56:31Z")

</div>

Hi @fgjensen  
I am dealing with same idea.  
I have the same assignment as you.

I'm also having trouble assigning users to roles in Elasticsearch.

When I tried to simulate the problem using the command line, it returned that Elasticsearch could not decode the token.

Could you share some tips?

My topic:

> [@How Elasticsearch does verify JWT tokens?](https://discuss.elastic.co/t/how-elasticsearch-does-verify-jwt-tokens/361581/8):
>
> did you try with single quotes curl -X GET 'https://xxx-xxx:9200/\_security/\_authenticate' -H 'ES-Client-Authentication: SharedSecret 0qUPuF\*\*\*\*mzvjG' -H 'Authorization: Bearer eyJhbGciOiJSUzI1N\*\*\*\*\*Hq-Sf-T-lHyYWotGyWL4k\_g'

Thanks a lot!

---

_[View the full topic](https://discuss.elastic.co/t/user-authorized-in-keycloak-rejected-access-to-kibana-space/357997)._
